VS Code --add-mcp for a remote server: add Sume with mcp.json
VS Code documents code --add-mcp only with a local command. For a remote server like Sume, put a type http entry in mcp.json and sign in with OAuth.

To add Sume to VS Code, write a type: http entry in mcp.json; do not rely on code --add-mcp, because VS Code's documentation shows that command only with a local command server. The Sume entry is one URL, https://mcp.sume.com/mcp, and sign-in happens through OAuth the first time the server starts.
What does the VS Code page say about --add-mcp?
The page (read 2026-10-03) gives this form: code --add-mcp "{\"name\":\"my-server\",\"command\": \"uvx\",\"args\": [\"mcp-server-fetch\"]}", and describes the argument as JSON in the form {"name":"server-name","command":...}. Every example is a local command-based server.
The page does not say whether the same flag accepts a remote URL. This post therefore does not give a --add-mcp one-liner for Sume. If you test one yourself, check the result in the MCP server list before you trust it.
Where does the Sume entry go?
VS Code supports several mcp.json locations according to the page. The one that fits a team repo is the workspace file, .vscode/mcp.json, which uses a top-level servers object. A portable .mcp.json at the project root uses mcpServers instead, and the user-profile file opens from the **MCP: Open User Configuration** command.
| Location | Top-level key | Shared with a team |
|---|---|---|
| .vscode/mcp.json | servers | Yes, if committed |
| .mcp.json at project root | mcpServers | Yes, if committed |
| User configuration | servers | No, per user |
| ~/.copilot/mcp-config.json | See the VS Code page | No, per user |
What is the exact Sume entry?
The VS Code page shows a remote server as "type": "http" with a url. The Sume version is below. It carries no key, so there is nothing to leak into version control.
{
"servers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp"
}
}
}How does sign-in work after the entry is saved?
Sume's OAuth and API keys page describes the flow: the client connects to the endpoint, gets a challenge and protected-resource metadata, and sends you to https://mcp.sume.com/oauth/authorize, then to a consent page on the MCP host. Read is locked on. Write is off by default and adds mcp:write when you turn it on. Paid tools are visible only with Write, and there is no mcp:paid scope.
When the server is connected, ask the agent to call mcp_health and then tools_list, as in the MCP quickstart. mcp_health shows the auth source; tools_list shows the tools this session may call.
What about secrets and the sandbox option?
The VS Code page tells you to avoid hardcoding API keys and to use input variables or environment files instead, and it describes a sandbox switch (sandboxEnabled) for macOS and Linux that is not available on Windows. The page's sandbox examples concern servers you run locally. Sume is a hosted server, so there is nothing to sandbox on your machine, and this post does not claim any effect on a remote entry.
If you need an API-key session instead of OAuth, Sume's docs say to send Authorization: Bearer or an x-api-key header, and API-key sessions see the full tool set with idempotency_key still required on paid and write calls. The VS Code excerpt I read does not show the header syntax, so take it from VS Code's own MCP configuration reference. OAuth needs none of that and is the documented default for interactive clients.
What should I do first if VS Code lists Sume but no tools?
Check three things in order. First, the URL: it must be exactly https://mcp.sume.com/mcp. Second, the top-level key: .vscode/mcp.json uses servers, while the portable .mcp.json uses mcpServers, and the wrong key means the entry is not read. Third, the sign-in: an unauthenticated server shows no tools until you complete OAuth.
If the tools appear but a paid call is refused, the grant is read-only. Sume returns insufficient_scope on a mutating tool without mcp:write. Sign in again and turn Write on at the consent page. A read-only session is a good default for exploring; add Write when you actually need to create something.
How should a team share the entry?
Commit the workspace file with the URL only. Each teammate gets their own OAuth sign-in on first use, so no credential lives in the repository. That matches the guidance on the VS Code page against hardcoding secrets, and it matches Sume's docs, which say to rotate an API key that appears in logs or chat history.
If a script or CI job needs Sume without a browser, that is the case for an API-key session, which Sume describes as the path for automation. Create the key in the dashboard and keep it out of the committed file.
Sources
Related posts
More in Integrations
- Wix Stores product video: 50 MB limit and an AI clip
Wix Stores takes AVI, MP4, MOV or MPEG product video up to 50 MB. Measure a Sume clip, then shorten it, drop audio or conform its size with video trim.
- How to add an MCP server to ChatGPT with developer mode
Turn on ChatGPT developer mode, create an app for the server's URL, and sign in with OAuth. The steps, with Sume's hosted MCP server as the example.
- How to add subtitles to a video in Python
Add subtitles to a video in Python with Requests: POST the video URL to Sume's /v1/video-captions, poll the job, then read the captioned video_url.
- Add Sume to Claude as a custom connector (remote MCP)
Add Sume's hosted MCP server to Claude under Customize > Connectors, see what Sume's OAuth consent grants, and decide whether to allow paid tools.
Written by Sume