VS Code 1.140 portable MCP config: where to put the Sume server URL
VS Code 1.140 can save MCP servers to a global file or a workspace .mcp.json. Add Sume's hosted URL once and keep API keys out of the shared file.

VS Code 1.140, released September 30, 2026, lets the MCP: Add Server flow save a server to portable configuration files, so one server definition can be shared across compatible Copilot tools without hand-editing JSON (VS Code updates, read 2026-10-04). For Sume, add the hosted URL https://mcp.sume.com/mcp and sign in with OAuth, so the file holds no secret.
The two locations in 1.140
The release notes name two destinations. A global file at $COPILOT_HOME/mcp-config.json follows you across workspaces. A .mcp.json at the workspace root sits next to the project and is usually committed, so everyone who opens the repository gets the same server.
| Destination | Who sees it | What belongs in it for Sume |
|---|---|---|
| $COPILOT_HOME/mcp-config.json | You, in every workspace | The URL; OAuth sign-in, or a key referenced from your environment |
| .mcp.json in the workspace root | Everyone with the repository | The URL only; never a literal API key |
Why OAuth fits a shared file
The hosted endpoint supports MCP OAuth with protected-resource metadata, so a client can discover the sign-in flow from the URL alone. Consent defaults to read-only, with a Write toggle you turn on when you need generation. Each teammate signs in as themselves, and the committed file never carries a credential (MCP OAuth and API keys).
An API key is the alternative for automation that does not speak OAuth. Send it as Authorization: Bearer <key> or x-api-key, and keep it in an environment variable or a secret store, not in a file you commit.
Verify it after adding
Ask the agent to call mcp_health. It reports readiness, the auth source and the safety posture. With OAuth, authenticated.auth_source should read mcp_oauth. Then call tools_list to see which tools your session can use: a read-only session lists read tools only.
- Use the production URL
https://mcp.sume.com/mcpfor real work. - Do not copy an entry between environments without checking the host.
- If tools are missing, check the granted scope before editing the file.
A note on the authorization server property
The same release notes describe a proposed API that lets extensions see which OAuth server issued a credential, to avoid sending a valid token to the wrong host. It is a proposed API, not a setting you configure. For Sume, the authorization server in the protected-resource metadata is the MCP origin, not the website host.
Sources
Related posts
More in Integrations
- Workflow protections GA: keep the Sume key off fork PR runs
GitHub's workflow execution protections are GA. Pair them with a Sume workflow that only runs on push, schedule or dispatch, so a fork PR never sees the key.
- Zapier Heal mode on a failed Sume step: keep the idempotency key
Zapier's Agentic Management can fix a failed run. For a Sume step, make sure the fix keeps the Idempotency-Key, or a changed payload returns a 409.
- How to add an MCP server to ChatGPT with developer mode
Turn on ChatGPT developer mode, create an app for the server's URL, and sign in with OAuth. The steps, with Sume's hosted MCP server as the example.
- How to add subtitles to a video in Python
Add subtitles to a video in Python with Requests: POST the video URL to Sume's /v1/video-captions, poll the job, then read the captioned video_url.
Written by Sume