Copilot Studio shared agent acts as its maker: scope the Sume key
The default computer-use credentials are the maker's. A shared agent then acts with that access on the machine. Give any Sume key it holds the narrowest scope.

In Copilot Studio, computer use defaults to maker-provided credentials, and Microsoft's page warns that if you share an agent with that setting, anyone using it can act with the original author's access on the configured machine. Treat every secret the agent can reach the same way. If it also calls Sume, give it a dedicated Sume API key with only the scopes it needs, and cap each run, because the people using the shared agent inherit whatever that key can spend.
The credential behavior is from Microsoft's computer use documentation, read on 2026-10-03; Sume's scopes and caps are in MCP OAuth and API keys and Agent Completions.
What are the two credential modes?
Maker-provided credentials are the default and, per the page, suit autonomous agents. End user credentials use the person interacting with the agent, and each user needs access credentials for the machine. The page also recommends dedicated machines with least-privilege accounts.
| Mode | Acts as | Fits |
|---|---|---|
| Maker-provided (default) | The author, on the configured machine | Autonomous agents |
| End user credentials | The person chatting with the agent | Conversational agents; each user needs machine access |
What does a Sume key add to the picture?
A Sume API key sees the full hosted tool set and spend is wallet and admission based; paid tools need an idempotency_key, and max_spend_usd is enforced only when someone sends it. Those are habits of the caller, not walls. The walls are the key's scopes and the per-run cap you set in your own request.
Agent Completions need a key carrying agent_completions:write and, to read results, agent_completions:read. Completions are user-owned runs, and service-account keys are rejected with 403 insufficient_scope, so the key behind a shared agent is a user's key. Create one for the agent alone and name it for the agent so revoking it affects nothing else.
What should I set before sharing the agent?
- Create a separate Sume key, with only the scopes the tool needs, and put it in the tool's connection rather than in instructions.
- Send
generation_spend_cap_usdon every Agent Completion from the tool, at the most you would accept a single run to cost. - Prefer end user credentials when users should act as themselves on the machine.
- Keep the machine dedicated and the account least-privileged, as Microsoft recommends.
- If the key leaks, create a new key first and then revoke the old one from the dashboard.
What is the remaining risk?
A shared agent with a capped key can still be asked to spend the cap repeatedly. Cap per run limits one run; it does not limit how many runs people start. Watch the usage record for the key, and pair the cap with a plan whose concurrency you can live with.
Sources
Related posts
More in Integrations
- Dev Container devcontainer.json MCP: add Sume's hosted server
Declare Sume's hosted MCP server in devcontainer.json under customizations.vscode.mcp. Where the entry lands, what to keep out, and how to verify it.
- Devin Local server-level MCP permission: what it means for Sume
Devin Desktop 3.5.17 added two server-level options to the MCP tool permission prompt. Before approving a whole server for Sume, know which tools it exposes.
- Devin Desktop "Needs auth" and the Authenticate button for Sume
Devin Desktop shows an Authenticate button on MCP servers marked Needs auth, and it clears stored OAuth credentials. What to expect when you do it for Sume.
- Discord interaction token lasts 15 minutes: deliver a long Sume run
A Discord follow-up works for 15 minutes; a long-form Format run takes 15 to 30. Edit the original reply when young, post as the bot to the channel when not.
Written by Sume