Xcode and JetBrains Copilot: connect Sume MCP with requestInit headers
Copilot in Xcode and JetBrains sends remote MCP auth through requestInit headers. Here is the Sume API key entry, what it unlocks, and how to test it.

In Xcode and JetBrains, GitHub Copilot reads remote MCP servers from a JSON file where headers go under requestInit. For Sume, put https://mcp.sume.com/mcp in url and your Sume API key in an Authorization: Bearer header. Visual Studio is different: its remote entry uses an automatic OAuth flow, so it needs no header.
| IDE | Remote auth in the Copilot docs | What to use for Sume |
|---|---|---|
| Xcode | requestInit headers, PAT-style bearer value | Sume API key as the bearer value |
| JetBrains | Same structure; edit mcp.json from Agent mode, Add MCP Tools | Sume API key as the bearer value |
| Visual Studio | Remote entry with OAuth, or local stdio | Remote URL with OAuth |
The entry
The Copilot docs show the same shape for both IDEs: a servers object, a url, and requestInit.headers. Swap the GitHub URL and token for Sume values.
{
"servers": {
"sume": {
"url": "https://mcp.sume.com/mcp",
"requestInit": {
"headers": {
"Authorization": "Bearer YOUR_SUME_API_KEY"
}
}
}
}
}What an API key unlocks
Sume accepts either OAuth access tokens or API keys on the hosted endpoint, and one cannot stand in for the other. An API-key session sees the full tool set, including write and paid tools. Those calls must still carry an idempotency_key.
OAuth sessions default to read-only. That is the safer choice for an IDE chat that you only use to look things up, so prefer Visual Studio's OAuth flow when you do not need paid tools.
| Credential | How it is sent | Tools visible |
|---|---|---|
OAuth mcp:read | Client OAuth flow on the MCP host | Read-only tools |
OAuth mcp:read + mcp:write | Write toggle on the consent page | Full set; paid submits need idempotency_key |
| API key | Authorization: Bearer or x-api-key | Full set; same idempotency_key rule |
Test the key before the IDE
Run one read-only call from a terminal first. If it answers, a failure in the IDE is a config problem, not a credential problem. mcp_health reports the endpoint, the auth source and the safety posture.
curl -sS https://mcp.sume.com/mcp \
-H "Authorization: Bearer $SUME_API_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"mcp_health","arguments":{}}}'Handle the key as a secret
The key sits in a plain config file, so keep that file out of source control and out of chat. The Sume docs say not to paste API keys into chat and to rotate any key that appears in logs or chat history. Create and revoke keys in the dashboard.
Copilot's organization policy named MCP servers in Copilot applies only to Business and Enterprise subscriptions. On those plans an admin can block the server regardless of what your file says.
Where each IDE keeps the file
The Copilot docs describe the settings path for Xcode as Editor, then GitHub Copilot, then Open Settings and the MCP tab. For JetBrains, open the chat in Agent mode and use Add MCP Tools to edit mcp.json. Visual Studio uses a configure dialog opened from the tools icon in Agent mode.
After saving, restart the agent session so it re-lists tools. Ask it to call tools_list; the reply should include Sume's discovery tools and, with an API key, the write and paid tools as well.
If your organization is on Copilot Business or Enterprise, ask an admin whether the MCP servers policy is on, because it can block the entry. Free, Pro, Pro+ and Max plans bypass that policy, per the Copilot docs. Also decide who owns the key: a personal key in a developer's IDE file is a personal credential, and a shared one belongs in a secrets manager. Rotate it when someone leaves the team.
Sources
More in Integrations
- Gemini CLI 0.64 preview moves settings to V2: recheck Sume
The 0.64.0 preview moves settings from V1 to V2. After you upgrade, confirm the Sume hosted MCP server still connects with a free read before any paid call.
- Gemini CLI httpUrl or url for Sume MCP: which key to use
In Gemini CLI settings, url is the SSE endpoint and httpUrl is HTTP streaming. Sume's endpoint is streamable HTTP, so use httpUrl. Config and checks inside.
- Gemini CLI includeTools for Sume MCP: expose reads, keep trust false
Gemini CLI can allowlist MCP tools with includeTools, and trust defaults to false. Use both to give an agent Sume reads without paid generation.
- Gemini CLI MCP timeout is 600000 ms; Sume jobs_wait caps at 55 s
Gemini CLI waits up to 10 minutes per MCP request, but Sume cuts jobs_wait at 55 seconds. Set the client timeout low and loop on wait_slice_expired.
Written by Sume