VS Code mcp.json: servers or mcpServers key for Sume's hosted MCP?

VS Code's .vscode/mcp.json uses a top-level servers key; the portable .mcp.json uses mcpServers. Put Sume's entry under the key that matches its file.

5 min readSume
All posts

In VS Code, the workspace file .vscode/mcp.json keeps servers under a top-level servers object, while the portable file .mcp.json at the project root keeps them under mcpServers. Paste Sume's entry under the wrong key and VS Code has no server to start, so nothing from Sume appears. For Sume's hosted MCP the entry is "type": "http" with "url": "https://mcp.sume.com/mcp".

The file formats come from VS Code's page MCP servers in VS Code, and the portable-file support is in the 1.140 notes at Visual Studio Code updates, both read on 2026-10-02. Sume's endpoint is from the MCP overview.

Which file uses which key?

VS Code's page lists four places to configure servers. Two of them are VS Code's own format and two are the portable format shared with other tools. Copying a snippet from a Cursor or Claude Code README, which use mcpServers, into .vscode/mcp.json is the usual way to end up with the wrong key.

VS Code MCP config files and their top-level key (read 2026-10-02)
FileFormatTop-level key
.vscode/mcp.json (workspace)VS Code formatservers
.mcp.json (project root)Portable formatmcpServers
User profile via MCP: Open User ConfigurationVS Code formatservers
$COPILOT_HOME/mcp-config.json or ~/.copilot/mcp-config.jsonPortable formatmcpServers

What does the Sume entry look like in each?

VS Code's page says a remote server uses type set to http, a url, and optional headers. For an API key it says to avoid hard-coding secrets and use input variables or environment files. Sume accepts x-api-key or Authorization: Bearer; send one, because Sume's authentication page says both together are rejected with 401 unauthorized.

Without a key, VS Code can use OAuth: Sume answers with a challenge and metadata, and you sign in on the consent page on the MCP host with Read locked on and Write off by default.

// .vscode/mcp.json
{
  "servers": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp"
    }
  }
}

// .mcp.json (portable)
{
  "mcpServers": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp"
    }
  }
}

How do I confirm VS Code loaded it?

VS Code's command list includes MCP: List Servers, which shows what it loaded and its state. If Sume is missing there, the key or the file location is wrong. If it is listed but stopped, VS Code's page says a trust dialog appears when a server starts or its configuration changes, and that MCP: Reset Trust clears earlier decisions. Workspace servers also inherit Workspace Trust.

Once it runs, ask the agent to call mcp_health and then tools_list. A session with Write off sees read-only tools; paid tools such as generate_image return insufficient_scope until you grant mcp:write.

Should the key go in the file at all?

Not if the file is committed. .vscode/mcp.json and .mcp.json are both made to live in a repository, and VS Code's page says workspace configuration in source control lets a team share it. A URL with no secret is safe to share, and OAuth keeps the credential out of the file entirely. If you need an API key, use VS Code's input variables so the value is prompted for or read from the environment, and rotate the key if it ever lands in a commit or a chat.

Sume's docs make the same point for chat: do not paste API keys into chat, and do not store OAuth tokens in CLI config. A shared file with only the URL, plus each person signing in with OAuth, is the cleanest team setup.

What about the tool limit?

VS Code's page mentions a tool limit of 128 without detail on how it is enforced. Sume's docs inventory names roughly 75 tool ids, so Sume alone fits, but several servers together may not. Check the live number with tools_list.

What does this not cover?

VS Code can add servers through MCP: Add Server, and the 1.140 notes say the flow can write to the portable files. I have not covered that flow step by step. Where a global or workspace file wins when both define sume is VS Code's rule, so keep one entry to avoid doubt.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume