Xcode and JetBrains Copilot: connect Sume MCP with requestInit headers

Copilot in Xcode and JetBrains sends remote MCP auth through requestInit headers. Here is the Sume API key entry, what it unlocks, and how to test it.

5 min readSume
All posts

In Xcode and JetBrains, GitHub Copilot reads remote MCP servers from a JSON file where headers go under requestInit. For Sume, put https://mcp.sume.com/mcp in url and your Sume API key in an Authorization: Bearer header. Visual Studio is different: its remote entry uses an automatic OAuth flow, so it needs no header.

Copilot MCP setup by IDE, read 2026-10-08
IDERemote auth in the Copilot docsWhat to use for Sume
XcoderequestInit headers, PAT-style bearer valueSume API key as the bearer value
JetBrainsSame structure; edit mcp.json from Agent mode, Add MCP ToolsSume API key as the bearer value
Visual StudioRemote entry with OAuth, or local stdioRemote URL with OAuth

The entry

The Copilot docs show the same shape for both IDEs: a servers object, a url, and requestInit.headers. Swap the GitHub URL and token for Sume values.

{
  "servers": {
    "sume": {
      "url": "https://mcp.sume.com/mcp",
      "requestInit": {
        "headers": {
          "Authorization": "Bearer YOUR_SUME_API_KEY"
        }
      }
    }
  }
}

What an API key unlocks

Sume accepts either OAuth access tokens or API keys on the hosted endpoint, and one cannot stand in for the other. An API-key session sees the full tool set, including write and paid tools. Those calls must still carry an idempotency_key.

OAuth sessions default to read-only. That is the safer choice for an IDE chat that you only use to look things up, so prefer Visual Studio's OAuth flow when you do not need paid tools.

Sume hosted MCP credentials, read 2026-10-08
CredentialHow it is sentTools visible
OAuth mcp:readClient OAuth flow on the MCP hostRead-only tools
OAuth mcp:read + mcp:writeWrite toggle on the consent pageFull set; paid submits need idempotency_key
API keyAuthorization: Bearer or x-api-keyFull set; same idempotency_key rule

Test the key before the IDE

Run one read-only call from a terminal first. If it answers, a failure in the IDE is a config problem, not a credential problem. mcp_health reports the endpoint, the auth source and the safety posture.

curl -sS https://mcp.sume.com/mcp \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"mcp_health","arguments":{}}}'

Handle the key as a secret

The key sits in a plain config file, so keep that file out of source control and out of chat. The Sume docs say not to paste API keys into chat and to rotate any key that appears in logs or chat history. Create and revoke keys in the dashboard.

Copilot's organization policy named MCP servers in Copilot applies only to Business and Enterprise subscriptions. On those plans an admin can block the server regardless of what your file says.

Where each IDE keeps the file

The Copilot docs describe the settings path for Xcode as Editor, then GitHub Copilot, then Open Settings and the MCP tab. For JetBrains, open the chat in Agent mode and use Add MCP Tools to edit mcp.json. Visual Studio uses a configure dialog opened from the tools icon in Agent mode.

After saving, restart the agent session so it re-lists tools. Ask it to call tools_list; the reply should include Sume's discovery tools and, with an API key, the write and paid tools as well.

If your organization is on Copilot Business or Enterprise, ask an admin whether the MCP servers policy is on, because it can block the entry. Free, Pro, Pro+ and Max plans bypass that policy, per the Copilot docs. Also decide who owns the key: a personal key in a developer's IDE file is a personal credential, and a shared one belongs in a secrets manager. Rotate it when someone leaves the team.

Sources

More in Integrations

All Integrations posts

Written by Sume