VS Code 1.140 shared MCP config files: what goes in the Sume entry
VS Code 1.140 lets MCP servers live in portable config files shared across Copilot tools. For Sume the entry is one URL, and no key belongs in the file.

A shared MCP config file for Sume needs one thing: the URL https://mcp.sume.com/mcp. With OAuth, the sign-in happens in the client, so no API key has to sit in a file that several Copilot tools, and your repository, can read.
The VS Code updates page says 1.140 (Sep 30, 2026) supports MCP servers in portable config files shared across Copilot tools, on top of a Copilot harness built on the Agent Host Protocol.
What 1.140 lists
| Change | Why it matters for a media MCP server |
|---|---|
| Copilot harness on Agent Host Protocol | The agent may run outside the editor process; verify the server from there. |
| Multi-folder sessions | One session spans folders, so a single entry should serve all of them. |
| Remote task delegation | A delegated task runs with some credential; know which. |
| MCP servers in portable config files shared across Copilot tools | One Sume entry can serve several tools. |
What belongs in the file
Sume's quickstart shows the minimal remote entry for a client that uses an mcpServers map. The only required value is the URL.
{
"mcpServers": {
"sume": {
"url": "https://mcp.sume.com/mcp"
}
}
}What should stay out
Hosted OAuth is the preferred path for interactive clients. The client discovers Sume's protected-resource metadata from the endpoint, sends you to the consent page on the MCP host, and exchanges a PKCE code for a token. None of that touches the file.
An API key is the other option, sent as Authorization: Bearer or x-api-key. It sees the full tool set, so treat it as a secret and keep it out of any file that is committed or shared between tools. The docs also say an OAuth token is not an API key and must not be stored in CLI config or pasted into prompts.
Check it from each tool that reads the file
A shared file does not guarantee that each tool signs in or shows the same tools. After adding the entry, run the same read-only calls in every tool that uses it.
mcp_healthto confirm the endpoint and the auth source.tools_listto see which tools that session can use.- A paid tool with
dry_run=trueto confirm write scope without spending.
Scope is per sign-in, not per file
Each tool that completes OAuth gets its own consent. The default grants mcp:read only, and Write is a toggle on the consent page that is off by default. One tool may therefore show paid tools while another shows only read tools, even though both read the same entry.
If a tool reports insufficient_scope on generate_image, the fix is on that tool's consent, not in the shared file.
Sources
Related posts
More in Developers
- What a media MCP server should declare at server/discover
MCP 2026-07-28 adds a required server/discover call. A media server has more to say than versions: async jobs, wait limits, scopes. Where Sume documents each.
- whisper-1 or gpt-transcribe for subtitles: what OpenAI assigns to each
OpenAI recommends gpt-transcribe, gpt-4o-transcribe-diarize for speakers, whisper-1 for translation and subtitles. Plus the 25 MB limit and a chunking script.
- Windsurf now redirects to Devin Desktop: where Sume MCP setup lives
Windsurf redirects to Devin Desktop, and Cascade was removed in v3.9.19. Re-add Sume's hosted MCP URL there and verify it with mcp_health and tools_list.
- Which MCP server lets Claude Code or Cursor generate video and images?
MCP servers that let Claude Code and Cursor make video and images: Sume, fal, Replicate, Runway, Higgsfield. Endpoints, sign-in, billing, setup.
Written by Sume