VS Code mcp.json: put the Sume API key in a password input
In VS Code, declare a promptString input with password true and reference it as ${input:id} in the x-api-key header, so the Sume key never lands in mcp.json.

Put the Sume API key behind a VS Code input variable. Declare an inputs entry of type promptString with password: true, then write ${input:sume-key} in the server's headers. VS Code asks for the value on first connection and caches it, so mcp.json can be committed without a secret. OAuth is still the preferred path for interactive use; use a key when you need the full tool set from a script or shared setup.
The config
VS Code's MCP configuration reference (read 2026-10-08) lists type (http or sse) and url as the required fields for an HTTP server, headers as optional, and an inputs array for sensitive values. Sume's endpoint is https://mcp.sume.com/mcp, and Sume accepts either Authorization: Bearer or x-api-key, but not both on one request.
{
"inputs": [
{
"type": "promptString",
"id": "sume-key",
"description": "Sume API key",
"password": true
}
],
"servers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": { "x-api-key": "${input:sume-key}" }
}
}
}What each piece does
| Field | Meaning |
|---|---|
type: promptString | Opens an input box for free-text entry |
password: true | Hides the typed characters |
${input:sume-key} | Replaced by the value at connect time; the id must match |
headers | Optional HTTP headers sent with each request |
Key versus OAuth on Sume
Per Sume's auth matrix, an API-key session sees the full hosted tool set, and spend is wallet and admission control. Writes and paid calls must still carry an idempotency_key. OAuth defaults to read-only (mcp:read) until you switch on Write at the consent page, and there is no mcp:paid scope. An OAuth token is not an API key, and you cannot use one in place of the other, so do not paste a token into the key prompt.
- Create the key in the dashboard under API keys, and send exactly one credential header.
- If the key shows up in logs or chat history, rotate it.
- Before the first paid submit, run
dry_run=trueorgeneration_admission_preview.
Check the connection
After VS Code connects, ask the agent to call mcp_health and then tools_list. On an OAuth session authenticated.auth_source reads mcp_oauth, which is how you tell it apart from a key session. This post makes no claim about which VS Code chat modes expose MCP tools; check the VS Code page for your version.
Mistakes that leak the key
The VS Code page says to avoid hardcoding API keys and to use input variables or environment files instead. Sume's own safety rules add three more cases to avoid:
- Do not paste the key into a chat prompt, where it stays in history; if it does, rotate it.
- Do not send both
Authorization: Bearerandx-api-key. Sume's authentication page says the API then rejects the request with401 unauthorizedand the messageSend only one API key credential.; neither header wins. - Do not reuse a key created before a scope existed and expect the new scope. Scopes are fixed at creation, so create a new key and rotate to it.
- Keep the key on trusted machines and CI secret stores, not in screenshots or support tickets.
When to skip the key entirely
If a person sits at the editor, OAuth removes the secret from the picture. The client discovers the metadata, you sign in on the consent page, and the session starts read-only. Add Write only when the agent needs to create jobs. A key makes sense for shared automation, because a consent page needs a browser and a person to click it.
Sources
Related posts
More in Integrations
- VS Code mcp.json for Sume: set type http, not sse
VS Code accepts type http or sse for a remote MCP server. Sume documents a streamable HTTP endpoint at https://mcp.sume.com/mcp, so use type http and a url.
- Zapier Catch Hook URL is the same in test and live: test Sume safely
Zapier's Catch Hook URL does not change between test and live. Use Sume's webhook.test delivery to check the Zap before a real run sends a real result into it.
- Zapier MCP costs two tasks a call: batch Sume jobs_wait first
Each Zapier MCP tool call uses two tasks. When an agent uses Sume and Zapier together, wait on all jobs in one jobs_wait, then make one Zapier call.
- How to add an MCP server to ChatGPT with developer mode
Turn on ChatGPT developer mode, create an app for the server's URL, and sign in with OAuth. The steps, with Sume's hosted MCP server as the example.
Written by Sume