Copilot CLI sandbox network bypass prompt: allow Sume hosts
Copilot CLI 1.0.92-3 offers a network bypass prompt when the sandbox proxy blocks a destination. Which Sume hosts to expect and when to approve.

When a sandboxed shell command in Copilot CLI hits a destination the sandbox proxy blocks, version 1.0.92-3 (2026-10-02) now offers a network bypass prompt instead of just failing. If the destination is one of Sume's documented hosts, approving it for that command is reasonable; for everything else, read the host first.
This applies to shell commands such as curl against Sume's API, not to the MCP connection Copilot CLI itself holds.
What the prompt covers
The release notes say sandboxed commands offer a bypass whenever the proxy blocks a destination. Sandbox CA commands arrived earlier, in v1.0.91.
At a glance
| Host | Purpose |
|---|---|
| mcp.sume.com | Hosted MCP server at /mcp |
| api.sume.com | REST API and Agent Completions |
| Unlisted hosts | Review before approving |
Sume hosts you may see
Sume's documented endpoints are https://mcp.sume.com/mcp for MCP and https://api.sume.com for the REST API, including Agent Completions at /v1/agent/completions. Results can also be hosted on Sume media domains.
Approve per command, not permanently, and confirm that the API key in the command is the one you intend to use.
- mcp.sume.com for MCP.
- api.sume.com for REST and agent runs.
- Treat any other host in a Sume-related command as unexpected.
Limits and what is not verified
I did not verify which media hostnames a given result URL will use, so check the host in the prompt rather than trusting this table for downloads. The prompt wording in the release notes is brief and I did not capture its exact text.
Sources
Related posts
More in Integrations
- Dev Container devcontainer.json MCP: add Sume's hosted server
Declare Sume's hosted MCP server in devcontainer.json under customizations.vscode.mcp. Where the entry lands, what to keep out, and how to verify it.
- Devin Local server-level MCP permission: what it means for Sume
Devin Desktop 3.5.17 added two server-level options to the MCP tool permission prompt. Before approving a whole server for Sume, know which tools it exposes.
- Devin Desktop "Needs auth" and the Authenticate button for Sume
Devin Desktop shows an Authenticate button on MCP servers marked Needs auth, and it clears stored OAuth credentials. What to expect when you do it for Sume.
- Etsy two videos per listing: is_multi_video and the Oct 21 date
Etsy's API now lets a listing hold 2 active videos: send is_multi_video=true, one upload per call; a third gets 409. Plan two Sume clips for the slots.
Written by Sume