VS Code Agent Host skips .vscode/mcp.json inputs: place Sume's entry

VS Code's Agent Host forwards your MCP config but drops entries that need input variables. Where to put Sume's entry and how to pass an API key without them.

4 min readSume
All posts

Put Sume's entry in a workspace .mcp.json (top-level mcpServers) or in ~/.copilot/mcp-config.json, and use OAuth instead of an ${input:...} API-key prompt. VS Code's documentation says sessions that run on the Agent Host do not read .vscode/mcp.json directly: VS Code forwards your MCP configuration to the Agent Host, except servers that require interactive input such as ${input:...} variables. An API-key entry that asks for the key through an input variable is exactly such a server, so the Agent Host session would not get Sume's tools.

The VS Code facts come from its MCP server page, read on 2026-10-03. Sume's endpoint and auth rules come from the MCP quickstart and OAuth and API keys.

Which files does VS Code read?

The page lists four manual locations: .vscode/mcp.json in the workspace (a top-level servers object), .mcp.json at the workspace root (a top-level mcpServers object that works across compatible tools), the user-profile mcp.json opened by MCP: Open User Configuration, and the portable user file at $COPILOT_HOME/mcp-config.json, or ~/.copilot/mcp-config.json when that variable is unset. For new servers it says to prefer the portable destinations, and it lists .vscode/mcp.json and the user-profile file as deprecated destinations in the MCP: Add Server flow.

Its own remote example uses "type": "http" with a url, so Sume's entry takes the same shape: type http and url https://mcp.sume.com/mcp.

Where an MCP entry lives and whether the Agent Host reads it; from the VS Code MCP page (code.visualstudio.com), read 2026-10-03.
FileTop-level keyAgent Host behavior
.vscode/mcp.jsonserversNot read directly; VS Code forwards the config, except entries that need interactive input
.mcp.json at workspace rootmcpServersRead natively
~/.copilot/mcp-config.json (or $COPILOT_HOME/mcp-config.json)mcpServersRead natively

What does the portable entry look like for Sume?

For OAuth there is nothing secret in the file, which is why it is the better fit here. Sume's quickstart says to point an HTTP MCP client at https://mcp.sume.com/mcp and run the client's OAuth sign-in; consent happens on the MCP host, and Write is an opt-in toggle there. Commit this to the repository so the team shares it, which the VS Code page also recommends for workspace configuration.

{
  "mcpServers": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp"
    }
  }
}

What if I need an API key instead?

Sume accepts Authorization: Bearer <key> or x-api-key, and an API-key session sees the full hosted tool set, while OAuth sessions are read-only until Write is granted at consent. The VS Code page warns against hardcoding keys and points to input variables or environment files. Those two choices pull in different directions here: an input variable is the case the Agent Host does not forward, and I did not find a statement on the page about environment-file support for remote servers, so check that your version reads the header value before depending on it.

The safest split is OAuth for interactive sessions and a key kept outside the repository for scripts. Whichever you use, writes and paid calls still need an idempotency_key, and dry_run previews cost first.

How do I confirm it loaded?

In chat, ask the agent to call mcp_health and check that authenticated.auth_source is mcp_oauth after OAuth sign-in, as the tools and gates page describes. If the tool is missing in an Agent Host session but present in a normal chat, compare which file the entry lives in before suspecting Sume.

Does this matter for Copilot CLI too?

The VS Code page names $COPILOT_HOME/mcp-config.json as a portable file that works across compatible Copilot tools, so the same mcpServers entry serves VS Code's Agent Host and other Copilot sessions. One file, one URL, nothing to keep in sync, which is the point of the portable format.

If the entry is still missing in one surface, check that file's top-level key. .vscode/mcp.json uses servers; the portable files use mcpServers. Pasting one into the other is a quiet way to end up with no Sume tools and no error.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume