VS Code Agent Host skips .vscode/mcp.json inputs: place Sume's entry
VS Code's Agent Host forwards your MCP config but drops entries that need input variables. Where to put Sume's entry and how to pass an API key without them.

Put Sume's entry in a workspace .mcp.json (top-level mcpServers) or in ~/.copilot/mcp-config.json, and use OAuth instead of an ${input:...} API-key prompt. VS Code's documentation says sessions that run on the Agent Host do not read .vscode/mcp.json directly: VS Code forwards your MCP configuration to the Agent Host, except servers that require interactive input such as ${input:...} variables. An API-key entry that asks for the key through an input variable is exactly such a server, so the Agent Host session would not get Sume's tools.
The VS Code facts come from its MCP server page, read on 2026-10-03. Sume's endpoint and auth rules come from the MCP quickstart and OAuth and API keys.
Which files does VS Code read?
The page lists four manual locations: .vscode/mcp.json in the workspace (a top-level servers object), .mcp.json at the workspace root (a top-level mcpServers object that works across compatible tools), the user-profile mcp.json opened by MCP: Open User Configuration, and the portable user file at $COPILOT_HOME/mcp-config.json, or ~/.copilot/mcp-config.json when that variable is unset. For new servers it says to prefer the portable destinations, and it lists .vscode/mcp.json and the user-profile file as deprecated destinations in the MCP: Add Server flow.
Its own remote example uses "type": "http" with a url, so Sume's entry takes the same shape: type http and url https://mcp.sume.com/mcp.
| File | Top-level key | Agent Host behavior |
|---|---|---|
.vscode/mcp.json | servers | Not read directly; VS Code forwards the config, except entries that need interactive input |
.mcp.json at workspace root | mcpServers | Read natively |
~/.copilot/mcp-config.json (or $COPILOT_HOME/mcp-config.json) | mcpServers | Read natively |
What does the portable entry look like for Sume?
For OAuth there is nothing secret in the file, which is why it is the better fit here. Sume's quickstart says to point an HTTP MCP client at https://mcp.sume.com/mcp and run the client's OAuth sign-in; consent happens on the MCP host, and Write is an opt-in toggle there. Commit this to the repository so the team shares it, which the VS Code page also recommends for workspace configuration.
{
"mcpServers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp"
}
}
}What if I need an API key instead?
Sume accepts Authorization: Bearer <key> or x-api-key, and an API-key session sees the full hosted tool set, while OAuth sessions are read-only until Write is granted at consent. The VS Code page warns against hardcoding keys and points to input variables or environment files. Those two choices pull in different directions here: an input variable is the case the Agent Host does not forward, and I did not find a statement on the page about environment-file support for remote servers, so check that your version reads the header value before depending on it.
The safest split is OAuth for interactive sessions and a key kept outside the repository for scripts. Whichever you use, writes and paid calls still need an idempotency_key, and dry_run previews cost first.
How do I confirm it loaded?
In chat, ask the agent to call mcp_health and check that authenticated.auth_source is mcp_oauth after OAuth sign-in, as the tools and gates page describes. If the tool is missing in an Agent Host session but present in a normal chat, compare which file the entry lives in before suspecting Sume.
Does this matter for Copilot CLI too?
The VS Code page names $COPILOT_HOME/mcp-config.json as a portable file that works across compatible Copilot tools, so the same mcpServers entry serves VS Code's Agent Host and other Copilot sessions. One file, one URL, nothing to keep in sync, which is the point of the portable format.
If the entry is still missing in one surface, check that file's top-level key. .vscode/mcp.json uses servers; the portable files use mcpServers. Pasting one into the other is a quiet way to end up with no Sume tools and no error.
Sources
Related posts
More in Integrations
- VS Code sandboxEnabled for MCP: does it cover a hosted Sume entry?
VS Code's MCP sandbox covers local stdio servers on macOS and Linux. A hosted Sume HTTP entry is outside it; scopes and spend limits are the gates.
- VS Code Restricted Mode: workspace MCP blocked, Sume tools missing
In VS Code Restricted Mode, workspace MCP config does not start. Why Sume's tools vanish in an untrusted repo and what MCP: Reset Trust changes.
- Wix Stores product video: 50 MB limit and an AI clip
Wix Stores takes AVI, MP4, MOV or MPEG product video up to 50 MB. Measure a Sume clip, then shorten it, drop audio or conform its size with video trim.
- How to add an MCP server to ChatGPT with developer mode
Turn on ChatGPT developer mode, create an app for the server's URL, and sign in with OAuth. The steps, with Sume's hosted MCP server as the example.
Written by Sume