Visual Studio MCP tools are off by default: approve Sume per session

Visual Studio leaves MCP tools disabled until you enable them and offers session, solution, or always approval. For Sume's paid tools, choose session.

4 min readSume
All posts

In Visual Studio, tools from a newly added MCP server are disabled by default and you must enable them yourself. When a tool runs, the confirm dropdown lets you approve it for the current session, the current solution, or all future invocations. For Sume's paid tools, pick the current session so each new session asks again.

This post covers only the approval scope. For the .mcp.json entry and CodeLens sign-in, see Visual Studio MCP server: add Sume.

What Visual Studio documents

Microsoft's page says Visual Studio 2026, or Visual Studio 2022 version 17.14, is needed for MCP servers. It quotes that the tools are disabled by default and must be enabled manually, and it describes three approval scopes in the confirm dropdown.

Visual Studio approval scopes (Microsoft Learn, read 2026-10-10) and a suggested Sume use
Approval scopePersistenceSuggested Sume use
Current sessionEnds with the sessionPaid tools: generate_image, generate_video, avatars_create
Current solutionStays for that solutionRead tools only: tools_list, jobs_status, balance_get
All future invocationsStays until changedAvoid for anything that spends or writes

Why Sume's tools deserve the narrow scope

Sume's docs say write and paid tools require an idempotency_key, which is for transport and de-duplication and is not human approval. The human gate is therefore your client. If you approve a paid tool for all future invocations, an agent can submit paid jobs without another click.

Sume's optional gates still apply on top. dry_run set to true returns an admission and cost preview without submitting, and max_spend_usd is enforced only when you send it. See Tools and gates.

  • Session approval for generate_image and generate_video, and ask for dry_run first
  • Solution approval for read tools you call constantly, such as jobs_status and balance_get
  • Never approve jobs_cancel or assets_* for all future invocations

Which tools you will actually see

Sume hides write and paid tools from OAuth sessions that granted only mcp:read. With an API key, or OAuth with Write toggled on at consent, the full hosted set is listed. So the Visual Studio toolbox you review depends on how you signed in; check with tools_list after you connect.

Visual Studio supports signing in to MCP servers through any OAuth provider that follows the MCP authorization spec. Sume's consent page defaults Write to off, as documented in MCP OAuth and API keys, which gives you a read-only start.

A short routine

Connect, enable only the read tools, and run mcp_health. Enable a paid tool only when you plan to use it, approve it for the session, and begin with a dry run like the one below.

{
  "idempotency_key": "vs-image-dry-001",
  "dry_run": true,
  "max_spend_usd": 1
}

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume