Azure DevOps remote MCP is GA: run it beside Sume's hosted MCP

Azure DevOps remote MCP went GA in sprint 278 with Foundry and Copilot Studio support. Here is how to hold it and Sume's MCP with separate credentials.

5 min readSume
All posts

Yes, an agent can use the Azure DevOps remote MCP server and Sume's hosted MCP server side by side, as two separate remote servers with two separate credentials. Microsoft's sprint 278 release notes say the Azure DevOps Remote MCP Server is now generally available, with expanded support for Microsoft Foundry and Copilot Studio. Sume's endpoint is https://mcp.sume.com/mcp.

The Microsoft facts come from the sprint 278 release notes (read 2026-10-07). The Sume facts come from the MCP overview and OAuth page.

What each server gives the agent

The two servers do different work, so an agent that holds both can turn tracker data into media.

Two remote MCP servers in one agent (read 2026-10-07)
Azure DevOps remote MCPSume hosted MCP
StatusGenerally available (sprint 278 notes)Production endpoint, OAuth or API key
ReachesWork items, repositories, pipelinesAccount, catalog, jobs, assets, generation, crawl, Avatar tools
Hosted whereMicrosoft, no local infrastructurehttps://mcp.sume.com/mcp
Listed client surfacesFoundry and Copilot Studio (expanded at GA)Any remote MCP client; see the Foundry and Copilot Studio posts

A tracker-to-video flow

A release-notes video is the obvious flow: the agent reads closed work items from Azure DevOps, drafts a script, and calls Sume to render it. Keep the paid step on its own rails.

  • Connect Sume with OAuth and leave Write off while the agent only plans. Read tools such as catalog_list and jobs_list still work.
  • When you want the render, grant mcp:write, call generation_admission_preview or send dry_run=true, then submit with an idempotency_key and max_spend_usd.
  • Wait with jobs_wait in slices of 55 seconds or less and fetch results with jobs_result.

Keep credentials apart

Do not reuse tokens across servers. The Sume docs say an MCP OAuth token is not a Sume API key, and that you should not paste tokens into prompts or forward them to third parties. Azure DevOps has its own sign-in; give each server only the credential it issued.

Admin note

In a managed setup, an admin should list both URLs separately in the client's allowlist, so that approving one does not approve the other. If a Sume tool is missing, check the credential scope first with mcp_health and tools_list.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume