Copilot CLI --mcp-github-auth: what Sume's MCP server receives
Copilot CLI's --mcp-github-auth limits GitHub auth to approved MCP origins. Sume's hosted MCP uses its own OAuth or API key, never your GitHub token.

Sume's hosted MCP server does not use your GitHub token, and Copilot CLI's new --mcp-github-auth flag is about keeping it that way. Copilot CLI v1.0.90 (September 30) and v1.0.91 (October 1, 2026) scope GitHub authentication to approved MCP server origins. Connect https://mcp.sume.com/mcp with a Sume credential: OAuth with mcp:read and optionally mcp:write, or an API key.
Credentials by server
| MCP server | Credential | Source |
|---|---|---|
| GitHub MCP origins you approve | GitHub auth via --mcp-github-auth | Copilot CLI release notes |
| https://mcp.sume.com/mcp | Sume OAuth token or Sume API key | Sume MCP docs |
Choosing OAuth or an API key
OAuth uses PKCE with consent on the MCP host. The required scope is mcp:read, which is read-only; mcp:write is opt-in. There is no separate paid scope. Under read-only, mutating tools return insufficient_scope. An API key sent as Authorization: Bearer or x-api-key sees the full tool set. OAuth tokens are not API keys, so do not paste one where a key is expected.
Per the release notes, OAuth sign-in reuses a still-valid cached token, so a repeat connect should not prompt again while the token is valid.
Safe defaults for a first session
Start with read-only and expand.
- Run
tools_list,tools_schema,mcp_healthandaccount_mefirst. - Use
catalog_listto see what can be generated before any paid call. - For paid tools pass
idempotency_key, and trydry_runwithmax_spend_usd. - Use
jobs_waitwithwait_slice_expiredhandling for long renders.
What to check if auth fails
A 401 from Sume means the credential is missing or wrong; insufficient_scope means you connected read-only and called a write tool. Neither is related to GitHub auth. If your Copilot config lists approved origins, confirm Sume is configured as its own server entry with its own header or OAuth flow.
Sources
Related posts
More in Integrations
- Crush MCP server: add Sume in crush.json with type http
Add Sume's hosted MCP to Crush in crush.json with type http, a header read from an environment variable, disabled_tools for paid tools, and a long timeout.
- Cursor CLI --approve-mcps: what it skips for paid Sume tools
Cursor CLI's --approve-mcps flag skips MCP approval prompts. How that affects paid Sume tools, plus agent mcp list-tools and login to check the connection.
- Cursor MCP allowlist: approve Sume's URL and its read tools
Cursor enterprise admins approve remote MCP servers by URL entry and list tools per server. How to allow Sume's mcp.sume.com/mcp and which tools to list.
- Cursor supports MCP roots and elicitation; Sume uses tools only
Cursor lists tools, prompts, resources, roots, elicitation and Apps as supported. Sume's hosted MCP answers only tools, so here is what you will see.
Written by Sume