Copilot CLI MCP server: add Sume with copilot mcp add

Add a remote MCP server to GitHub Copilot CLI with copilot mcp add: Sume's hosted MCP, a key header or OAuth, and a timeout above 55 seconds.

5 min readSume
All posts

To add an MCP server to GitHub Copilot CLI, run copilot mcp add in your terminal, or /mcp add inside a session. A remote server takes --transport http, a name, and its URL, and the subcommand saves it to ~/.copilot/mcp-config.json. For Sume's hosted MCP server that is copilot mcp add --transport http sume https://mcp.sume.com/mcp, plus an API-key header or an OAuth sign-in, and a --timeout above the 30000 ms default, because one Sume jobs_wait call can hold for 55 seconds.

GitHub's side comes from Adding MCP servers for GitHub Copilot CLI, the CLI command reference, and Using GitHub Copilot CLI; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official Copilot CLI integration: the CLI connects to Sume's remote MCP server like any other, and Sume's basics page says hosted MCP still works but is not part of the primary path today. Copilot's cloud agent is a different client, covered in GitHub Copilot coding agent MCP.

How do I add Sume with copilot mcp add?

copilot mcp add writes to your user configuration without starting an interactive session. Pick http, the Streamable HTTP transport that Sume's docs tell remote clients to use; never sse.

Your shell expands $SUME_API_KEY, so the key itself is saved in the entry in ~/.copilot/mcp-config.json: keep that file private. The file's headers field supports variable expansion, so you can edit the entry to reference an environment variable instead. Then run copilot mcp get sume, which shows the server's type, status, and available tools, and ask Copilot to call mcp_health and tools_list, Sume's read-only discovery tools.

Options from GitHub's Adding MCP servers for GitHub Copilot CLI and CLI command reference; Sume values from MCP OAuth and API keys and Jobs and results, read 2026-09-28.
OptionWhat GitHub's docs sayFor Sume
--transportstdio, http, or sse; default stdio. http is Streamable HTTP.http
--headerAn HTTP header for remote servers; repeatable.One of Authorization: Bearer <key> or x-api-key: <key>
--tools* for all tools (the default), a comma-separated list, or "" for none.Only the Sume tools the task needs
--timeoutMilliseconds for tool discovery and tool calls; default 30000.60000, above the 55-second jobs_wait hold
copilot mcp add --transport http \
  --header "Authorization: Bearer $SUME_API_KEY" \
  --tools "mcp_health,tools_list,tools_schema,generate_image,jobs_status,jobs_wait,jobs_result" \
  --timeout 60000 \
  sume https://mcp.sume.com/mcp

What timeout should the Sume server have?

More than 55000 ms; this post uses 60000. A server entry's timeout covers tool discovery and tool calls and defaults to 30000 ms. Sume's jobs_wait holds one call open for at most 55 seconds, or 50 when its timeout_seconds is omitted, so with the CLI default a wait on an unfinished job outlasts the CLI's limit. A client-side timeout does not cancel the job; it keeps running and billing.

Long renders are waited out in slices. On wait_slice_expired, Copilot should call jobs_wait again with the same ids and never resubmit the paid create. MCP tool call timeouts on long-running video jobs covers the pattern.

Can Copilot CLI sign in to Sume with OAuth?

Leave out --header and the two sides' documented defaults line up. For remote servers the CLI's default OAuth grant is authorization_code, a browser-based flow; oauthPublicClient defaults to true; and a static oauthClientId skips dynamic registration. Sume's current server advertises a registration endpoint and the authorization_code grant with PKCE for public clients, so leave oauthClientId unset. Consent happens on Sume's MCP host with Read locked on and the Write toggle off by default; turn Write on if Copilot should generate media, because a read-only session gets insufficient_scope from paid tools such as generate_image.

Two limits come from Sume's current code: an OAuth token lasts one hour, and Sume issues no refresh token. The CLI may show a needs-auth status when a token expires, so expect that about hourly; /mcp auth sume starts a fresh OAuth flow in the browser. The CLI's headless client_credentials grant needs a confidential client, and Sume's current server offers only authorization_code, so use the API-key header in CI and copilot -p scripts. How Sume's MCP OAuth flow works has the details.

How do I stop Copilot from spending without asking?

GitHub's reference says all MCP tool invocations require explicit permission, even read-only ones. At a tool approval prompt, its guide describes a plain Yes, which asks again next time, and a Yes that approves the tool for the rest of the running session; for Sume's paid tools, pick the plain Yes.

At startup, --allow-tool and --deny-tool take SERVER-NAME(tool) patterns, several as one quoted, comma-separated list, and deny rules always take precedence, even when --allow-all is set. That matters in scripts: the reference says programmatic use requires --allow-all-tools, which runs every tool without confirmation, so deny paid Sume tools there. This session runs Sume's job reads unasked and can't start a paid image:

copilot --allow-tool='sume(jobs_status),sume(jobs_wait),sume(jobs_result)' \
  --deny-tool='sume(generate_image)'

What else should I know before relying on it?

  • Each Sume paid tool needs an idempotency_key; dry_run=true previews admission and cost without submitting; max_spend_usd caps a call only when it is sent. The model writes those arguments, so they are not a limit your configuration enforces.
  • An API-key session sees Sume's full hosted tool set, and spend resolves to the key's workspace.
  • A repository can share the server in .github/mcp.json, GitHub's place for configuration committed to the repository; .mcp.json is for local or per-checkout setups. Both load only in trusted folders. Commit the entry without the key.
  • Copilot CLI does not read VS Code's .vscode/mcp.json. VS Code remote MCP server covers that client.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume