Copilot app sandbox network: Sume hosts to allow

In a sandboxed GitHub Copilot app session, allow api.sume.com, mcp.sume.com and media.sume.com outbound; send the Sume key as a header, not a git credential.

4 min readSume
All posts

If a sandboxed Copilot app session needs Sume, allow outbound access to three hosts: api.sume.com for the REST API, mcp.sume.com for hosted MCP, and media.sume.com where result URLs live. The Sume API key goes in a request header, not in the sandbox's git credentials.

Vendor facts are from the GitHub changelog of 2026-09-23; Sume facts from the Public API and MCP docs, read 2026-10-01. For connecting Copilot's coding agent itself, see the Copilot coding agent post.

What does Copilot app sandboxing control?

Per project, the settings cover filesystem, network (outbound internet and local network) and credentials. It is off by default and in public preview. Changes apply to new sessions or when an existing one restarts, and the effective policy can be stricter when enterprise-managed settings apply. If the OS cannot enforce the policy, the sandboxed shell errors rather than running unsandboxed. The vendor page does not list per-host syntax, so check the app's settings for how to enter hosts.

Which Sume hosts does an agent reach?

Sume hosts to allow, from docs, read 2026-10-01
HostUsed forSource
api.sume.comDeveloper API base https://api.sume.com/v1Public API
mcp.sume.comHosted MCP https://mcp.sume.com/mcpMCP overview
media.sume.comPublic media URLs for resultsMCP tools and gates

How should the key be passed?

Sume accepts Authorization: Bearer $SUME_API_KEY or x-api-key. Provide it through whatever credential setting the sandbox offers for environment values, and never paste keys or signed URLs into chat logs, as the docs advise.

Why does a download fail while the API works?

Job results point at media.sume.com. If only the API and MCP hosts are allowed, creating and polling jobs will succeed but fetching the file will be blocked. Add the media host.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume