VS Code 1.140 portable MCP config: where to put the Sume server URL

VS Code 1.140 can save MCP servers to a global file or a workspace .mcp.json. Add Sume's hosted URL once and keep API keys out of the shared file.

5 min readSume
All posts

VS Code 1.140, released September 30, 2026, lets the MCP: Add Server flow save a server to portable configuration files, so one server definition can be shared across compatible Copilot tools without hand-editing JSON (VS Code updates, read 2026-10-04). For Sume, add the hosted URL https://mcp.sume.com/mcp and sign in with OAuth, so the file holds no secret.

The two locations in 1.140

The release notes name two destinations. A global file at $COPILOT_HOME/mcp-config.json follows you across workspaces. A .mcp.json at the workspace root sits next to the project and is usually committed, so everyone who opens the repository gets the same server.

Where to save the Sume server in VS Code 1.140. Sources: VS Code release notes and Sume docs, read 2026-10-04.
DestinationWho sees itWhat belongs in it for Sume
$COPILOT_HOME/mcp-config.jsonYou, in every workspaceThe URL; OAuth sign-in, or a key referenced from your environment
.mcp.json in the workspace rootEveryone with the repositoryThe URL only; never a literal API key

Why OAuth fits a shared file

The hosted endpoint supports MCP OAuth with protected-resource metadata, so a client can discover the sign-in flow from the URL alone. Consent defaults to read-only, with a Write toggle you turn on when you need generation. Each teammate signs in as themselves, and the committed file never carries a credential (MCP OAuth and API keys).

An API key is the alternative for automation that does not speak OAuth. Send it as Authorization: Bearer <key> or x-api-key, and keep it in an environment variable or a secret store, not in a file you commit.

Verify it after adding

Ask the agent to call mcp_health. It reports readiness, the auth source and the safety posture. With OAuth, authenticated.auth_source should read mcp_oauth. Then call tools_list to see which tools your session can use: a read-only session lists read tools only.

  • Use the production URL https://mcp.sume.com/mcp for real work.
  • Do not copy an entry between environments without checking the host.
  • If tools are missing, check the granted scope before editing the file.

A note on the authorization server property

The same release notes describe a proposed API that lets extensions see which OAuth server issued a credential, to avoid sending a valid token to the wrong host. It is a proposed API, not a setting you configure. For Sume, the authorization server in the protected-resource metadata is the MCP origin, not the website host.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume