Copilot CLI --mcp-github-auth: what Sume's MCP server receives

Copilot CLI's --mcp-github-auth limits GitHub auth to approved MCP origins. Sume's hosted MCP uses its own OAuth or API key, never your GitHub token.

4 min readSume
All posts

Sume's hosted MCP server does not use your GitHub token, and Copilot CLI's new --mcp-github-auth flag is about keeping it that way. Copilot CLI v1.0.90 (September 30) and v1.0.91 (October 1, 2026) scope GitHub authentication to approved MCP server origins. Connect https://mcp.sume.com/mcp with a Sume credential: OAuth with mcp:read and optionally mcp:write, or an API key.

Credentials by server

Who gets which credential (read 2026-10-02)
MCP serverCredentialSource
GitHub MCP origins you approveGitHub auth via --mcp-github-authCopilot CLI release notes
https://mcp.sume.com/mcpSume OAuth token or Sume API keySume MCP docs

Choosing OAuth or an API key

OAuth uses PKCE with consent on the MCP host. The required scope is mcp:read, which is read-only; mcp:write is opt-in. There is no separate paid scope. Under read-only, mutating tools return insufficient_scope. An API key sent as Authorization: Bearer or x-api-key sees the full tool set. OAuth tokens are not API keys, so do not paste one where a key is expected.

Per the release notes, OAuth sign-in reuses a still-valid cached token, so a repeat connect should not prompt again while the token is valid.

Safe defaults for a first session

Start with read-only and expand.

  • Run tools_list, tools_schema, mcp_health and account_me first.
  • Use catalog_list to see what can be generated before any paid call.
  • For paid tools pass idempotency_key, and try dry_run with max_spend_usd.
  • Use jobs_wait with wait_slice_expired handling for long renders.

What to check if auth fails

A 401 from Sume means the credential is missing or wrong; insufficient_scope means you connected read-only and called a write tool. Neither is related to GitHub auth. If your Copilot config lists approved origins, confirm Sume is configured as its own server entry with its own header or OAuth flow.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume