Does Copilot's MCP policy apply to Pro+ or Max? Sume hosted MCP
GitHub's MCP servers in Copilot policy covers Business and Enterprise, off by default. Free, Pro, Pro+ and Max users can add Sume's hosted MCP server directly.

No. According to GitHub's documentation, the "MCP servers in Copilot" policy applies to Copilot Business and Copilot Enterprise, where it is disabled by default. It does not apply to Copilot Free, Pro, Pro+ or Max. Someone on one of those plans can add the Sume hosted MCP server, https://mcp.sume.com/mcp, without an administrator turning anything on.
Plan by plan
The same GitHub page says Copilot Chat can use stdio or HTTP/SSE servers, with OAuth or a personal access token. Sume is a remote server reached over HTTP, so the stdio path is not relevant.
| Plan | MCP servers policy | Suggested Sume credential |
|---|---|---|
| Free, Pro, Pro+, Max | Policy does not apply | OAuth, Write off for browsing; add Write only when needed |
| Business | Policy applies; disabled by default | Ask the admin to enable it, then OAuth |
| Enterprise | Policy applies; disabled by default | Ask the admin to enable it, then OAuth or a key held by CI |
What changes on a managed plan
On Business or Enterprise, a developer who cannot see an option to add a server usually has a policy that is still off. Ask the organization owner to enable it, and tell them what the server can do: with an API key, the full Sume tool set including paid generation; with OAuth, read-only unless the person ticks Write on the consent page.
A company that wants developers to browse Sume models and balances but never spend can standardize on OAuth with Write left off. Write and paid calls need an idempotency_key, and there is no separate paid scope, so mcp:write is the line between reading and spending.
Verify after connecting
Run mcp_health from Copilot Chat. It reports which credential the session is using and what scopes it has. If the tool list lacks write tools, that is the read scope working as designed, not a broken install.
Cost and approval still matter
A plan that lets you add servers freely also lets an agent loop call paid tools freely if you gave it an API key. Keep Copilot's tool approval on for Sume's paid tools, send max_spend_usd on every paid call, and use dry_run first when the agent is estimating cost. These parameters are optional and apply only when sent, so approval in the client is the control that does not rely on the model.
Sources
Related posts
More in Integrations
- MCP spec: token in the header on every request, never the URL
The 2025-11-25 MCP spec forbids access tokens in the URL query string and wants a Bearer header on every request. Keep the Sume key in headers, not the URL.
- MCP spec: tool annotations are untrusted. What that means for Sume
The MCP spec says clients must treat tool annotations as untrusted unless they come from a trusted server. Treat Sume as trusted only for your own workspace.
- MCP tool error or JSON-RPC error: where Sume's failures land
Sume returns tool failures as results with isError true and keeps JSON-RPC errors for protocol faults, per the 2025-11-25 MCP spec. Here is the split.
- Perplexity Agent API MCP tool: server_label rules for Sume
Perplexity MCP tool: server_label must match ^[a-zA-Z0-9_-]{1,64}$. A Sume entry that passes, with authorization, headers and allowed_tools.
Written by Sume