VS Code mcp.json: servers or mcpServers key for Sume's hosted MCP?
VS Code's .vscode/mcp.json uses a top-level servers key; the portable .mcp.json uses mcpServers. Put Sume's entry under the key that matches its file.

In VS Code, the workspace file .vscode/mcp.json keeps servers under a top-level servers object, while the portable file .mcp.json at the project root keeps them under mcpServers. Paste Sume's entry under the wrong key and VS Code has no server to start, so nothing from Sume appears. For Sume's hosted MCP the entry is "type": "http" with "url": "https://mcp.sume.com/mcp".
The file formats come from VS Code's page MCP servers in VS Code, and the portable-file support is in the 1.140 notes at Visual Studio Code updates, both read on 2026-10-02. Sume's endpoint is from the MCP overview.
Which file uses which key?
VS Code's page lists four places to configure servers. Two of them are VS Code's own format and two are the portable format shared with other tools. Copying a snippet from a Cursor or Claude Code README, which use mcpServers, into .vscode/mcp.json is the usual way to end up with the wrong key.
| File | Format | Top-level key |
|---|---|---|
| .vscode/mcp.json (workspace) | VS Code format | servers |
| .mcp.json (project root) | Portable format | mcpServers |
| User profile via MCP: Open User Configuration | VS Code format | servers |
| $COPILOT_HOME/mcp-config.json or ~/.copilot/mcp-config.json | Portable format | mcpServers |
What does the Sume entry look like in each?
VS Code's page says a remote server uses type set to http, a url, and optional headers. For an API key it says to avoid hard-coding secrets and use input variables or environment files. Sume accepts x-api-key or Authorization: Bearer; send one, because Sume's authentication page says both together are rejected with 401 unauthorized.
Without a key, VS Code can use OAuth: Sume answers with a challenge and metadata, and you sign in on the consent page on the MCP host with Read locked on and Write off by default.
// .vscode/mcp.json
{
"servers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp"
}
}
}
// .mcp.json (portable)
{
"mcpServers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp"
}
}
}How do I confirm VS Code loaded it?
VS Code's command list includes MCP: List Servers, which shows what it loaded and its state. If Sume is missing there, the key or the file location is wrong. If it is listed but stopped, VS Code's page says a trust dialog appears when a server starts or its configuration changes, and that MCP: Reset Trust clears earlier decisions. Workspace servers also inherit Workspace Trust.
Once it runs, ask the agent to call mcp_health and then tools_list. A session with Write off sees read-only tools; paid tools such as generate_image return insufficient_scope until you grant mcp:write.
Should the key go in the file at all?
Not if the file is committed. .vscode/mcp.json and .mcp.json are both made to live in a repository, and VS Code's page says workspace configuration in source control lets a team share it. A URL with no secret is safe to share, and OAuth keeps the credential out of the file entirely. If you need an API key, use VS Code's input variables so the value is prompted for or read from the environment, and rotate the key if it ever lands in a commit or a chat.
Sume's docs make the same point for chat: do not paste API keys into chat, and do not store OAuth tokens in CLI config. A shared file with only the URL, plus each person signing in with OAuth, is the cleanest team setup.
What about the tool limit?
VS Code's page mentions a tool limit of 128 without detail on how it is enforced. Sume's docs inventory names roughly 75 tool ids, so Sume alone fits, but several servers together may not. Check the live number with tools_list.
What does this not cover?
VS Code can add servers through MCP: Add Server, and the 1.140 notes say the flow can write to the portable files. I have not covered that flow step by step. Where a global or workspace file wins when both define sume is VS Code's rule, so keep one entry to avoid doubt.
Sources
Related posts
More in Integrations
- Windmill webhook token in the URL: calling it from a Sume job
Windmill prefers a bearer header, but Sume's webhook_url is just a URL, so the token must ride in the query string. How to scope it and still trust the result.
- Zapier Next Gen nested loops multiply paid Sume submits
Next Gen Zaps allow nested loops. Two nested loops of 20 and 5 items are 100 paid Sume jobs: how to count, pace and pause before the first submit.
- Storage by Zapier 32-character keys: remember a Sume job id
Storage by Zapier keys are limited to 32 characters and 500 keys, and idle keys vanish after 2 months. Key by your row id, store the Sume job id as the value.
- Zed MCP: which agents use your Sume server (Panel, ACP, terminal)
Zed's own Agent uses context_servers directly, external agents get them over ACP, and terminal CLIs read their own config. Where the Sume MCP entry goes.
Written by Sume