Copilot mcp-config.json example: a Sume remote entry
A Copilot mcp-config.json example for Sume: an http entry at mcp.sume.com/mcp with an x-api-key header and a tools list. Global file vs workspace .mcp.json.

A Sume entry in Copilot's mcp-config.json is an http server with url set to https://mcp.sume.com/mcp, an x-api-key header, and a tools list. Put it in the global file only: VS Code's MCP: Add Server flow can now save to $COPILOT_HOME/mcp-config.json (or ~/.copilot/mcp-config.json) or to a workspace .mcp.json, and a key does not belong in a file you commit.
Where do the two files live?
From the VS Code update notes, read 2026-09-30: choosing Copilot Global saves to $COPILOT_HOME/mcp-config.json, or ~/.copilot/mcp-config.json when COPILOT_HOME is not set. Choosing .mcp.json saves at the workspace root. GitHub's Copilot CLI page adds that the CLI, started inside a Git repository, walks from the working directory up to the repository root loading MCP configuration files.
| File | Scope | Put a Sume key here? |
|---|---|---|
$COPILOT_HOME/mcp-config.json or ~/.copilot/mcp-config.json | Global | If you use a key, here |
.mcp.json at workspace root | Workspace | No, it is shared with the repo |
What does the Sume entry look like?
GitHub's remote shape is type, url, headers and tools. The Sume docs give the header form x-api-key: $SUME_API_KEY and the URL. Replace the placeholder with your key; the snapshot does not say whether Copilot expands environment variables in headers, so check before relying on that.
{
"mcpServers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": { "x-api-key": "<your Sume API key>" },
"tools": ["tools_list", "tools_schema", "jobs_status", "jobs_result"]
}
}
}Which tool ids go in the allowlist?
Sume's live tool ids are underscore names such as tools_list and jobs_status. The GitHub page says tools takes "*" for all, names, or an empty value for none. Start with read tools; an API-key session can see write and paid tools, and writes need an idempotency_key. See tools and gates.
Is OAuth an alternative to the key?
Sume supports both: OAuth through consent on the MCP host, or an API key. An OAuth token is not a Sume API key, and the docs say not to store tokens in config. For the CLI walkthrough see Copilot CLI MCP server for Sume, and MCP OAuth and API keys for the auth matrix.
Sources
Related posts
More in Integrations
- Instagram Audio API for Reels ads: prepare the video side
Meta's Instagram Audio API can find royalty-free replacements for copyrighted Reels music. Sume does not call it, but can drop the audio from your video.
- Add Sume as an MCP server in Junie CLI (mcp.json)
Add Sume to Junie CLI's mcp.json as a remote server with url and headers, or leave headers out and use Authorize for OAuth. Both paths, step by step.
- Kling models in Runway MCP vs Sume: what maps to what
Runway MCP added four Kling entries on Sep 18, 2026. Sume lists a Kling v3 Pro row and a Kling motion control MCP tool; it has no Kling O3 row.
- Make webhook "Queue is full" 400: what Sume does and how to recover
When a Make webhook answers 400 Queue is full or 429, Sume retries up to 10 times at a fixed gap. If all fail, redeliver the job's event once the queue drains.
Written by Sume