VS Code chat.mcp.autostart newAndOutdated: Sume's first run
VS Code can start MCP servers automatically when their config changes. Learn the autostart modes and the trust dialog before you add Sume's hosted server.

VS Code reads MCP servers from an mcp.json file with a top-level servers object, and each entry has a type and a url. The VS Code MCP servers page shows type: "http" for remote servers and supports ${input:id} variables and an envFile, read 2026-10-03. For Sume's hosted server at https://mcp.sume.com/mcp, an HTTP entry with an input-prompted key avoids keeping a secret in the file.
{
"servers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": { "Authorization": "Bearer ${input:sume-key}" }
}
},
"inputs": [
{ "type": "promptString", "id": "sume-key",
"description": "Sume API key", "password": true }
]
}What autostart changes
The setting chat.mcp.autostart has three values on the page: never, onlyNew and newAndOutdated, which is the default. With the default, VS Code starts servers that are new or whose configuration changed, rather than waiting for a manual start. The page also says trust dialogs appear when a server starts or its configuration changes.
| Value | Behaviour | Fit for Sume |
|---|---|---|
never | You start servers yourself | Good for a shared machine |
onlyNew | Starts newly added servers | Good for a first connection |
newAndOutdated (default) | Also restarts after config changes | Convenient; each change re-prompts for trust |
Read the trust prompt
Starting a server means running its tools in your session. Sume's server is remote, so the relevant question is what the credential allows. The Sume OAuth page says mcp:read is required and read-only, mcp:write is opt-in, and a write or paid tool under mcp:read returns insufficient_scope. Grant the smaller scope first and widen it only when a task needs to create.
First-run checklist
The VS Code page does not say how the key prompt is stored, so check your profile's secret handling before sharing a machine.
- Add the server through
MCP: Add Server, which offers a workspace.mcp.jsonor Copilot Global. - Keep the key out of the file by using
${input:id}. - Call a read tool before any create tool.
- Send an
idempotency_keyon every paid call and treat a timeout as transport, not as a failed job. - Do not commit a file that contains a literal key.
Sources
Related posts
More in Developers
- waitForRun timeout: why SumeRunTimeoutError can arrive early
The Sume SDK's waitForRun checks its deadline before it sleeps, so SumeRunTimeoutError can fire up to one poll interval early. The run keeps going.
- waitForRun 429 and 503: the streak resets only on a clean read
Sume SDK waitForRun counts consecutive failed reads, resets only on a clean one, and retries the final result read so a late 429 cannot lose it.
- How much balance does a full Sume queue hold? By plan
A full Pro queue of 24 Seedance 2.5 clips at 720p holds $208 of wallet balance; Scale's 120 holds $1,040. Reserve by plan.
- Walmart Sponsored Videos: 15-minute upload URL, wait for AVAILABLE
Walmart's Sponsored Videos API gives an upload URL that expires in 15 minutes and needs about 30 minutes to process. How to stage a Sume clip for it safely.
Written by Sume