Does Copilot's MCP policy apply to Pro+ or Max? Sume hosted MCP

GitHub's MCP servers in Copilot policy covers Business and Enterprise, off by default. Free, Pro, Pro+ and Max users can add Sume's hosted MCP server directly.

5 min readSume
All posts

No. According to GitHub's documentation, the "MCP servers in Copilot" policy applies to Copilot Business and Copilot Enterprise, where it is disabled by default. It does not apply to Copilot Free, Pro, Pro+ or Max. Someone on one of those plans can add the Sume hosted MCP server, https://mcp.sume.com/mcp, without an administrator turning anything on.

Plan by plan

The same GitHub page says Copilot Chat can use stdio or HTTP/SSE servers, with OAuth or a personal access token. Sume is a remote server reached over HTTP, so the stdio path is not relevant.

GitHub Copilot MCP availability (GitHub Docs read 2026-10-09) and the Sume credential to choose (as of 2026-10-09)
PlanMCP servers policySuggested Sume credential
Free, Pro, Pro+, MaxPolicy does not applyOAuth, Write off for browsing; add Write only when needed
BusinessPolicy applies; disabled by defaultAsk the admin to enable it, then OAuth
EnterprisePolicy applies; disabled by defaultAsk the admin to enable it, then OAuth or a key held by CI

What changes on a managed plan

On Business or Enterprise, a developer who cannot see an option to add a server usually has a policy that is still off. Ask the organization owner to enable it, and tell them what the server can do: with an API key, the full Sume tool set including paid generation; with OAuth, read-only unless the person ticks Write on the consent page.

A company that wants developers to browse Sume models and balances but never spend can standardize on OAuth with Write left off. Write and paid calls need an idempotency_key, and there is no separate paid scope, so mcp:write is the line between reading and spending.

Verify after connecting

Run mcp_health from Copilot Chat. It reports which credential the session is using and what scopes it has. If the tool list lacks write tools, that is the read scope working as designed, not a broken install.

Cost and approval still matter

A plan that lets you add servers freely also lets an agent loop call paid tools freely if you gave it an API key. Keep Copilot's tool approval on for Sume's paid tools, send max_spend_usd on every paid call, and use dry_run first when the agent is estimating cost. These parameters are optional and apply only when sent, so approval in the client is the control that does not rely on the model.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume