Visual Studio 18.7 MCP trust prompt and tool resets with Sume

Visual Studio resets tool approvals on tools/list_changed and shows a trust dialog when a server changes. Sume declares listChanged false, so it sends no reset.

5 min readSume
All posts

Visual Studio clears its saved tool approvals when an MCP server sends notifications/tools/list_changed, and from version 18.7 it shows a trust dialog when a server's configuration or capabilities change. Sume's hosted MCP declares tools with listChanged set to false, so Sume itself does not send that reset notification.

What Visual Studio does

Microsoft's page says Visual Studio subscribes to notifications/tools/list_changed. When one arrives it resets the earlier acceptances and permissions on that server's tools, as protection against a tool changing after you approved it, and it fetches the tool list again.

For Visual Studio 2026 18.7 and later, the page describes a trust dialog with Accept, Always Trust, and Reject, shown when the server config or capabilities change. The first time Visual Studio sees a server it saves a baseline to compare against.

Visual Studio behaviors (Microsoft Learn, read 2026-10-10) against Sume's declared capability (packages/mcp-server initialize reply)
EventVisual Studio responseSume's side
tools/list_changed arrivesResets tool approvals, refetches the listSume declares listChanged false, so it does not send it
Server config or capabilities change (18.7+)Trust dialog: Accept, Always Trust, RejectCapabilities advertise tools only
First sight of a serverBaseline savedInitial connect

What this means in practice

Because Sume does not push list changes, you should not expect Visual Studio to wipe your Sume approvals through that path. The tool list Visual Studio holds is whatever tools_list returned when it connected.

That matters after a scope change. Sume shows write and paid tools only to sessions with mcp:write or an API key. If you reconnect and grant Write on Sume's consent page, you have a new session with a different tool set, so run tools_list again and review what Visual Studio now shows. Our VS Code note on Reset Trust covers the sibling case.

  • After granting Write, reconnect and call tools_list
  • Treat a trust dialog on a Sume entry as a reason to read the diff, not to click Always Trust
  • Keep paid tools on session-level approval

Check it yourself

Sume's mcp_health tool reports the endpoint, the auth source, and the safety posture, and tools_list lists what this session can see. Run both after any trust prompt.

For why Sume has no push channel, read MCP subscriptions/listen: Sume has no push stream. The scope rules are in MCP OAuth and API keys.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume