22
33The extension owns one internal TAS service per activation. This infrastructure
44supports general experimentation and measurement without enabling product features.
5- Live TAS configuration remains absent until the platform owners approve the endpoint
6- and identity contract.
5+ The new assignments endpoint and parameter name are platform-owned. Live TAS
6+ configuration remains absent until VS Code provides an approved DevDeviceId API to
7+ the extension.
8+
9+ ## Settings rollout versus extension attribution
10+
11+ An ` onExP ` settings rollout does not require this service merely to apply its
12+ treatment. Declare the setting with a safe package default and the ` onExP ` tag,
13+ configure ` config.<full-setting-id> ` in ExP, and read the effective value through
14+ ` workspace.getConfiguration() ` . VS Code core retrieves the assignment and applies
15+ the treatment as a default; explicit user and workspace values still take
16+ precedence. Do not add a second TAS treatment gate for the same setting.
17+
18+ Use this service when an extension-owned experiment needs treatment variables, or
19+ when Python Environments telemetry must carry the matching assignment context for
20+ an experiment scorecard.
721
822## Publisher configuration
923
1024` initializeExperimentation() ` reads an optional top-level ` experimentation ` object
1125from the installed extension's ` package.json ` . This is publisher-owned metadata,
12- ** not** a VS Code setting: a workspace must not be able to redirect requests that
13- contain an identifier .
26+ ** not** a VS Code setting. The endpoint and identity parameter cannot be overridden
27+ by publisher or workspace configuration .
1428
15- The following is a schema illustration, not deployable configuration. Replace the
16- placeholders only with reviewed values; do not copy names from legacy ` X-* ` headers.
29+ The following is a schema illustration, not deployable configuration. The manifest
30+ entry must remain absent until the DevDeviceId provider is approved and wired.
31+ Do not copy names from legacy ` X-* ` headers.
1732
1833``` json
1934{
2035 "experimentation" : {
21- "assignmentsEndpoint" : " https://<approved-host>/api/v1/assignments" ,
2236 "targetPopulation" : " public" ,
23- "identityParameter" : " <approved-identity-parameter>" ,
2437 "assignmentParameters" : {
25- "<approved-identity-parameter>" : " machineId" ,
2638 "<approved-extension-version-parameter>" : " extensionVersion" ,
2739 "<approved-language-parameter>" : " language"
2840 }
@@ -33,19 +45,30 @@ placeholders only with reviewed values; do not copy names from legacy `X-*` head
3345Supported populations are ` public ` , ` insider ` , ` internal ` , and ` team ` . Select one
3446explicitly with the owners; an ` internal ` value is not authentication or proof of
3547employee status. Version and language bindings are optional. The identity binding
36- is mandatory and must occur exactly once. Generic SDK parameters cannot be overridden.
48+ ` "devdeviceid": "devDeviceId" ` is added by the platform configuration and cannot be
49+ overridden. Generic SDK parameters cannot be overridden.
50+
51+ The approved full endpoint is:
52+
53+ ``` text
54+ https://exp.individual.githubcopilot.com/api/v1/assignments
55+ ```
56+
57+ The host is currently fixed rather than taken from a Copilot token. Business and
58+ Enterprise networks may block the Individual endpoint; those failures must remain
59+ nonfatal and their telemetry unattributed. Validate attribution coverage before
60+ using extension events in a scorecard.
3761
38- The currently implemented identity source is VS Code's public ` env.machineId ` API.
39- It must only be used when that is the approved randomization identity. ** MachineId
40- is not DevDeviceId. ** If onboarding requires DevDeviceId or another identity, add and
41- review its provider first; unsupported sources are rejected, not silently substituted.
42- Ensure the analysis identity, and any future VS Code core setting experiment's
43- identity, agrees with this contract .
62+ The public extension API does not currently expose DevDeviceId. The service accepts
63+ an injected provider so the approved API can be connected without falling back to
64+ MachineId. Until that provider is available, configured initialization fails closed
65+ and makes no TAS request. The legacy MachineId read elsewhere in the service only
66+ namespaces cache data for the SDK's inherited legacy request; it is not the new
67+ assignments identity .
4468
4569Absent configuration reports ` notConfigured ` and makes no TAS requests. Invalid
4670configuration reports an error and also makes no requests; it does not silently
47- fall back to a legacy-only integration. No endpoint, identity value, or mapping is
48- accepted from workspace configuration.
71+ fall back to a legacy-only integration.
4972
5073## Service lifecycle and queries
5174
@@ -82,10 +105,11 @@ snapshot queries, not refresh requests.
82105
83106Cache data lives in ` context.globalState ` , namespaced by the approved configuration,
84107extension version, resolved assignment parameters, and the SDK's built-in targeting
85- values: VS Code version, application name, language, and legacy MachineId. The namespace
86- is hashed; identifiers and endpoints are not emitted in diagnostics. This prevents a
87- snapshot from being reused after its population, endpoint, version, identity, or audience
88- context changes. Malformed cache data is ignored with a warning.
108+ values: VS Code version, application name, language, and legacy MachineId. The new
109+ assignments identity is DevDeviceId. The namespace is hashed; identifiers and
110+ endpoints are not emitted in diagnostics. This prevents a snapshot from being reused
111+ after its population, endpoint, version, identity, or audience context changes.
112+ Malformed cache data is ignored with a warning.
89113
90114Revoking telemetry consent disposes the SDK, aborts outstanding requests, clears
91115shared attribution, and makes queries use defaults. Re-enabling consent creates a
@@ -98,7 +122,9 @@ New-endpoint variables take precedence when both return the same name. The commo
98122HTTPS transport supplies cancellation, a ten-second request deadline, and a two-MiB
99123response cap to both endpoints. It uses Node HTTPS like the SDK, retaining the
100124extension host's HTTP hooks; proxy behavior must still be verified in the deployment
101- environments. There is no insecure TLS or redirect fallback.
125+ environments. There is no insecure TLS or redirect fallback. New experiments must
126+ use the shared GitHub/DevDiv workspace and the assignments POST; the inherited
127+ legacy request is SDK behavior and is not a supported fallback for this extension.
102128
103129` tas-client ` requires Node 22. TypeScript 5.8 or newer is needed to type-check the
104130current wrapper's CommonJS-to-ESM declarations without disabling library checking.
@@ -177,13 +203,15 @@ Unit tests use a fake SDK for lifecycle cases. A separate contract test loads th
177203installed SDK with a fake transport to verify dual requests, assignment merging,
178204bare variable names, and shared attribution without contacting TAS.
179205
180- Before live use, confirm the endpoint, identity names/source, audience/population,
181- ExP workspace, access, and scorecard with the VS Code experimentation owners. Obtain the integration and
182- metrics reviews described in the onboarding guidance. An A/A can validate allocation,
183- attribution, data quality and baseline stability without exposing a new setting or
184- changing product behavior. A real ` tas-call ` with ` callType = assignments ` and
185- ` outcome = Success ` , a known new-endpoint assignment, and tagged subsequent telemetry
186- must all agree; a cached value alone is not proof that onboarding works.
206+ Before live use, obtain DevDeviceId access and confirm the audience/population, shared
207+ GitHub/DevDiv workspace group, access, and scorecard with the experimentation owners.
208+ The old workspace and old TAS endpoint are not supported for new experiments. Obtain
209+ the integration and metrics reviews described in the onboarding guidance. An A/A can
210+ validate allocation, attribution, data quality and baseline stability without exposing
211+ a new setting or changing product behavior. A real ` tas-call ` with
212+ ` callType = assignments ` and ` outcome = Success ` , a known new-endpoint assignment,
213+ and tagged subsequent telemetry must all agree; a cached value alone is not proof
214+ that onboarding works.
187215
188216Some older checklists still require ` vscode.abexp.features ` ; the current SDK no
189217longer maintains it. Use the current assignment-context guidance instead. The
0 commit comments