Skip to content
| Marketplace
Sign in
Visual Studio Code>Other>NextLLMs for VS CodeNew to Visual Studio Code? Get it now.
NextLLMs for VS Code

NextLLMs for VS Code

NextLLMs

|
2 installs
| (0) | Free
Chat, plan, inspect project files, and apply targeted code changes with your NextLLMs account.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

NextLLMs for VS Code

Chat and work on code in VS Code with your existing NextLLMs account. The extension uses NextLLMs for model access, chat history, plan entitlements, and credits. It does not require you to enter a provider API key.

Sign in and chat

  1. Install the extension and open a project folder in VS Code.
  2. Click the NextLLMs icon in the editor toolbar, or run NextLLMs Code: Open Chat from the Command Palette.
  3. Choose Sign in. Your system browser opens NextLLMs so you can sign in and authorize the extension. Your password is never entered into VS Code.
  4. Send a message. Chats created by the extension are saved as remote chats in your NextLLMs account; your normal plan, model access, and credits apply. The right sidebar in VS Code lists only these remote chats. On the website, all chats remain visible and remote chats have a purple R badge. Older chats created before this origin marker existed cannot be classified reliably and therefore are not listed in the extension.
  5. To give the assistant code context, click the italic current-file chip, choose individual files with Add files, or choose a directory with Add folder. The open project's root also appears as a folder chip: click it to include the entire project directory. Selected folders cover their nested folders and eligible text files. Up to eight file contents and 48,000 characters are included directly; other discovered files remain available by path for the assistant to read as needed. Individual files are limited to 1 MB each, and content over 24,000 characters per file is truncated with a notice in the activity feed. The separate Project context option shares a limited list of file names and asks before reading each requested file in Ask First, Auto Approve, and Plan; a folder you explicitly selected can be read without another per-file prompt.
  6. For existing files, NextLLMs proposes targeted patches so only matching lines change. In Ask First and Auto Approve, inspect the side-by-side diff before applying. New files are also shown as proposals. Full Access can apply valid targeted patches and new files automatically; whole-file replacement still asks.

Connect a local project to website Project Files

With exactly one trusted local folder open, opening an existing remote chat or sending the first message automatically connects that workspace to the chat's private Project Files. Eligible text files are uploaded and then kept in sync; on the first sync, a local file replaces a same-name Project File. The connection watches the folder and checks for changes about every four seconds. Changes made through website Project Files or the website assistant arrive in VS Code, and local edits (including edits made by the extension) go back to Project Files. The website Files panel refreshes while open. You can disconnect from the extension at any time; closing the chat panel does not disconnect the background sync.

Once connected, website changes to Project Files automatically create, edit, and delete matching local files without another approval prompt, even when the chat panel is closed. Simultaneous local and remote edits are reported as conflicts and neither copy is silently overwritten. Resolve the two versions yourself, then click the retry icon. VS Code unsaved/dirty editors also pause a remote edit. Local deletions propagate to Project Files; website deletions move local files to the trash where supported.

Sync starts automatically for a remote chat when one trusted local folder is open, and is limited to supported UTF-8 text: at most 200 files, 512 KB per file, and 20 MB total. It skips ignored/build folders, likely secrets such as .env, symlinked folders, and binary files. The extension displays the number of skipped files. An unexpectedly large number of vanished local files pauses remote deletion as a safety guard. This is not a complete backup or a Git replacement; keep your own version control. The website server must run the matching sync-enabled API version. A local VSIX update alone cannot add these endpoints to an older deployed server.

Agent modes and local commands

The mode picker is beside the quota, model, and reasoning controls. It starts at Ask First whenever a panel is opened.

Mode Local commands File changes
Ask First Exact command approval each time, or Always allow exact command Review and confirm patches/files
Auto Approve Only fixed git status, git status --short, git diff, and git diff --stat forms are automatic when a trusted Git installation is found; everything else asks Review and confirm patches/files
Plan No commands or file writes; returns a plan with an Implement plan action None until you switch to Ask First and send the prepared implementation request
Full Access Proposed commands run without further prompts after a one-time warning in this panel Valid targeted patches and new files are applied; complete-file replacements still ask

The model requests at most one local action (command or project-file read) per step, and the extension returns the verified result so it can continue. An agent turn stops after four local actions, after 30 seconds per command, or when Stop is used. Command output shown in the chat is capped at 12,000 characters. Commands run only in a trusted, single local workspace, without shell expansion or stdin. The extension resolves installed executables outside the workspace so a project-local fake executable cannot replace them. On Windows only .exe programs are supported by the local runner; shell built-ins, .cmd and .bat scripts are not supported. This is not a sandbox: an approved command can read private data, access the network, or modify files.

Always allow exact command is stored per VS Code workspace and NextLLMs account. Use Reset remembered approvals in the mode menu to revoke these rules. Full Access is not persisted and must be re-enabled for each panel. In Auto Approve, Git is run from a known system installation with external diff and fsmonitor execution disabled; if that Git installation cannot be found, approval is requested instead.

Account security

See the NextLLMs Privacy Policy for how prompts, file context, and command results are processed.

  • The extension is a public OAuth client and does not contain a client secret.
  • Authorization uses the system browser, a fixed VS Code callback, exact redirect matching, S256 PKCE, account/session-bound consent, and one-use expiring authorization codes.
  • The resulting bearer token is stored with VS Code SecretStorage, not in extension settings or the webview. It is bound to the server origin used during sign-in; changing nextllms.serverUrl clears that session before any request can use it.
  • The token only authorizes the extension's chat API routes. Those routes reuse NextLLMs' normal chat, model-entitlement, and quota logic; they cannot use admin or account-management APIs.
  • Use Sign out to revoke the server session when online. If offline, it clears local credentials and you can revoke NextLLMs VS Code Extension in NextLLMs account security settings.
  • Opening or starting a remote chat automatically uploads eligible files from the single trusted local workspace and keeps them in sync until you disconnect. This project sync is separate from chat file context: the pinned active file plus up to eight directly included files have a 48,000-character total context limit. Selecting a folder makes its nested eligible files available for additional reads without another per-file prompt. Alternatively, enabling Project context shares at most 120 filtered file names (8,000 characters) per prompt and asks before each requested read in Ask First, Auto Approve, and Plan. Reads include up to 24,000 characters per file from a 1 MB maximum source file. Approved commands can still access files outside these context filters, so review their arguments carefully.
  • Generated file proposals are restricted to safe relative paths (no traversal, .git, environment secrets, or key/certificate files), capped at 12 files and 1 MB each. Targeted patches must match the exact shared file and are applied as VS Code range edits. In Full Access, eligible edits can be applied without an additional confirmation; use Git or another version-control system before enabling it.

nextllms.serverUrl defaults to https://nextllms.de. It can point to another HTTPS NextLLMs server for development; plain HTTP is accepted only for localhost, 127.0.0.1, or ::1. Changing the URL signs out the existing session.

Development and release checks

From the vscode-extension folder in the NextLLMs source repository, run:

npm run check
npx @vscode/vsce package --no-dependencies

npm run check builds the self-contained dist/ entry point and runs the extension, OAuth, policy, file-safety, and Markdown tests. vsce package runs the same checks before producing a VSIX. The package intentionally excludes the server source and tests. To debug, open the extension folder in VS Code and press F5; a second Extension Development Host window opens. This does not start or restart the NextLLMs server.

The extension's OAuth callback is tied to the Marketplace identity nextllms.nextllms-vscode. Publishing under a different publisher or extension ID requires updating both the extension and server callback registration before sign-in can work.

Every extension API request includes the version from the packaged extension manifest. The NextLLMs server accepts remote chats, Project Files, and workspace sync only from the exact current version; update from the Visual Studio Marketplace if the server reports that an update is required. Browser sign-in and normal website chats are not version-gated.

Source layout

  • package.json is the extension manifest: VS Code reads it to discover the extension, its command, and supported VS Code versions.
  • extension.js registers the authentication provider, browser sign-in, chat panel, and server API calls. The publishable entry point is generated at dist/extension.js.
  • ../lib/vscode-extension-files.js validates file context and generated file paths before any local write.
  • ../lib/vscode-agent-commands.js validates structured command requests and mode decisions.
  • ../lib/vscode-command-runner.js resolves executables, constrains the command environment, and limits runtime/output.
  • ../lib/vscode-oauth.js validates the fixed OAuth client/callback, account-bound consent, PKCE S256, expiry, and one-use code exchange.
  • ../lib/vscode-workspace-sync.js connects the trusted local folder to one chat's Project Files with change checks, version guards, automatic application, and conflict reporting.
  • ../scripts/tests/test-vscode-oauth.js covers the important authorization and PKCE invariants.
  • ../scripts/tests/test-vscode-extension-files.js covers sensitive path rejection and generated file parsing.
  • Syntax highlighting is bundled in the VSIX from the repository's pinned @highlightjs/cdn-assets dependency. Its BSD-3-Clause license is included at media/highlightjs-LICENSE.txt; no CDN is requested by the extension.
  • .vscode/launch.json tells VS Code how to launch a temporary Extension Development Host when you press F5.
  • .vscode/tasks.json runs the small syntax check before launching.
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft