Copilot mcp-config.json example: a Sume remote entry

A Copilot mcp-config.json example for Sume: an http entry at mcp.sume.com/mcp with an x-api-key header and a tools list. Global file vs workspace .mcp.json.

4 min readSume
All posts

A Sume entry in Copilot's mcp-config.json is an http server with url set to https://mcp.sume.com/mcp, an x-api-key header, and a tools list. Put it in the global file only: VS Code's MCP: Add Server flow can now save to $COPILOT_HOME/mcp-config.json (or ~/.copilot/mcp-config.json) or to a workspace .mcp.json, and a key does not belong in a file you commit.

Where do the two files live?

From the VS Code update notes, read 2026-09-30: choosing Copilot Global saves to $COPILOT_HOME/mcp-config.json, or ~/.copilot/mcp-config.json when COPILOT_HOME is not set. Choosing .mcp.json saves at the workspace root. GitHub's Copilot CLI page adds that the CLI, started inside a Git repository, walks from the working directory up to the repository root loading MCP configuration files.

Copilot MCP config locations from the VS Code and GitHub Docs pages, read 2026-09-30.
FileScopePut a Sume key here?
$COPILOT_HOME/mcp-config.json or ~/.copilot/mcp-config.jsonGlobalIf you use a key, here
.mcp.json at workspace rootWorkspaceNo, it is shared with the repo

What does the Sume entry look like?

GitHub's remote shape is type, url, headers and tools. The Sume docs give the header form x-api-key: $SUME_API_KEY and the URL. Replace the placeholder with your key; the snapshot does not say whether Copilot expands environment variables in headers, so check before relying on that.

{
  "mcpServers": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp",
      "headers": { "x-api-key": "<your Sume API key>" },
      "tools": ["tools_list", "tools_schema", "jobs_status", "jobs_result"]
    }
  }
}

Which tool ids go in the allowlist?

Sume's live tool ids are underscore names such as tools_list and jobs_status. The GitHub page says tools takes "*" for all, names, or an empty value for none. Start with read tools; an API-key session can see write and paid tools, and writes need an idempotency_key. See tools and gates.

Is OAuth an alternative to the key?

Sume supports both: OAuth through consent on the MCP host, or an API key. An OAuth token is not a Sume API key, and the docs say not to store tokens in config. For the CLI walkthrough see Copilot CLI MCP server for Sume, and MCP OAuth and API keys for the auth matrix.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume