DevFlow vs GitHub Copilot cloud agent: 7 dimensions, sourced

DevFlow and GitHub Copilot cloud agent are compared on 7 dimensions below, each read from GitHub's own documentation on 1 Oct 2026; 3 cases where GitHub Copilot cloud agent fits better are listed too.

GitHub Copilot cloud agent, formerly known as Copilot coding agent, works on a branch, can produce an implementation plan for you to approve before it writes code, and opens a pull request when you are ready.↗

Each claim about the other product was read on 1 Oct 2026 from the page its ↗ link opens. Cells in the DevFlow column are written from files in DevFlow's own codebase, named next to each cell; that codebase is not public. A comparison left unchecked for 90 days is flagged for review.

Compared on 1 Oct 2026
DimensionDevFlowGitHub Copilot cloud agent
Where it runsOn the hosted instance at devflow.fraway.io. A self-hosted install is not self-serve: it is arranged with Fraway on request.site/src/lib/site.tsENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelteIn an ephemeral development environment powered by GitHub Actions, on a standard GitHub-hosted runner by default; larger runners or GitHub Actions self-hosted runners can be configured instead.↗
Where your code goesOn the hosted instance at devflow.fraway.io, DevFlow clones repositories into worktrees on the servers that run it. Prompts, which include code, go to the model provider the workspace chooses.CLAUDE.mdsite/src/lib/site.tsIt works only with repositories hosted on GitHub, and it can make changes only in the repository specified when a task starts.↗
Model choiceEach workspace stores its own key for OpenRouter, Anthropic, OpenAI or Google. On Pro and higher plans, managed OpenRouter inference can stand in when no OpenRouter key is stored.internal/relay/providers.gointernal/entitlement/entitlement.goCLAUDE.mdWhere a model picker is available, you choose Auto or one of the listed Claude, Gemini, GPT or Grok models, and the reasoning level for supported models; elsewhere Auto is used.↗
IsolationEach task gets its own git worktree. Agent CLIs run under a Landlock sandbox or, when enabled, in a per-invocation container; test and build commands run in non-root containers capped at 4 CPUs and 4 GB of memory by default.CLAUDE.mdinternal/agent/depcache.goThe agent can push to a single branch, usually a new copilot/ branch, cannot run git push itself, and GitHub restricts its access to the internet with a firewall.↗
VerificationRuns the repository's configured test commands plus an AI code review and records both in a merge evidence report. A repository with no configured commands is not built or tested, and the report shows the skipped check.CLAUDE.mdinternal/agent/evidence.gointernal/agent/gate_command.goBy default the agent checks generated code with CodeQL, secret scanning and the GitHub Advisory Database, gets a second opinion from Copilot code review, and tries to resolve the issues before completing the pull request.↗
Human gatesA person approves, edits or rejects the plan before code is written, and a person marks the task done, which starts the squash, push and pull request when GitHub is connected. Opt-in autopilot keeps both gates.CLAUDE.mdinternal/agent/evidence.goDraft pull requests must be reviewed and merged by a human, and the agent cannot approve or merge them. By default, GitHub Actions workflows wait until a user with write access clicks Approve and run workflows.↗
Pricing modelThe self-serve plans are Free, Pro and Team; an Enterprise plan is arranged with Fraway on request. Model usage is paid to the provider whose key the workspace stores, or through managed inference on Pro and above.internal/entitlement/entitlement.goENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelteAvailable on all paid Copilot plans. Each session uses GitHub Actions minutes and AI credits, and the credits consumed depend on the model and the tokens processed.↗

How to read the table

Where GitHub Copilot cloud agent fits better

What GitHub documents

Each Copilot cloud agent session has a maximum execution time of 59 minutes, a hard limit that cannot be extended or bypassed.↗

Work happens on one branch at a time, with exactly one pull request for each assigned task.↗

Commits made in a session name the developer who assigned the task as co-author, and they are signed so they appear as Verified.↗

To limit prompt injection, text entered as an HTML comment in an issue or pull request comment is not passed to Copilot cloud agent.↗

Only Ubuntu x64 Linux and Windows 64-bit runners are supported; runners with macOS or other operating systems are not.↗

Automations ignore events from users without write access by default, and pull requests they open are attributed to the person who created the automation, who then cannot approve them.↗

How DevFlow runs the work

A DevFlow task moves from planning to a plan review, then to decomposition into at most 8 subtasks, implementation, verification and a written summary. Each task gets its own branch, named after its task ID, in a worktree under the repository's .devflow/worktrees directory.

By default, every agent invocation has a hard limit of 90 minutes and is stopped after 45 minutes without output. A workspace can also set a monthly spend cap, and a task over that cap fails with a reason before it starts.

On Pro and higher plans, finalization also runs dependency scanners for the languages DevFlow detects, such as govulncheck for Go modules and pnpm audit for Node packages, each stopped after 300 seconds by default. Scan results go into the evidence report and do not block the pipeline.

What DevFlow records along the way

A task that finishes implementation gets a merge evidence report listing the models that did the work, each subtask's verifier outcome, the build checks, the security scan summary, the final review and the people who approved the plan and clicked Mark Done. The report is added to the pull request body, and later rework refreshes it there.

Agent processes start with an allowlisted environment instead of inheriting the server's own. Provider keys and GitHub tokens are encrypted at rest with AES-256-GCM.

FAQ

Who merges pull requests opened by Copilot cloud agent?

A person does, according to GitHub's documentation: Copilot cannot approve or merge its own draft pull requests. DevFlow asks a person to approve the plan before code is written and to mark the task done before the branch is pushed.

Can Copilot cloud agent run on my own infrastructure?

Self-hosted GitHub Actions runners are documented as one place where Copilot cloud agent sessions can run. DevFlow runs at devflow.fraway.io; a self-hosted DevFlow install is not self-serve and is arranged with Fraway on request.