VS Code MCP: Reset Trust after you grant Sume the Write scope
Write on Sume's consent page changes the server's abilities, not VS Code's trust decision. MCP: Reset Trust makes VS Code ask again; mcp_health shows scopes.

Granting Write on Sume's consent page changes what the server can do, but it does not change VS Code's own trust decision for that server. The VS Code page describes trust prompts for MCP servers and a command called MCP: Reset Trust that clears them. Use it when you want VS Code to ask again before running a server whose abilities have changed, and then check the new scopes with mcp_health.
Two separate decisions
The first decision belongs to VS Code and the second to Sume. Granting one does not grant the other.
| Decision | Made where | Cleared by |
|---|---|---|
| Trust this MCP server | VS Code prompt on first start | MCP: Reset Trust |
| Allow Sume to write | Sume consent page on the MCP host | Signing in again without Write |
| Allow a given tool call | VS Code tool confirmation | Per call or per session choice |
Moving from read-only to Write
Under mcp:read, Sume hides its write tools. If a model tries one by name, it gets insufficient_scope with required_scope mcp:write. To change that, sign in again and tick Write on the consent page. Then reload the tool list and run mcp_health to confirm the scopes.
If you also want VS Code to confirm the change, run MCP: Reset Trust and let it ask. That is a sensible habit when the same entry moves from browsing models to submitting paid jobs.
Going back
To return to read-only, remove the grant by signing in again without Write; a Sume access token lasts one hour, so an old Write token ages out on its own. Paid and write calls need an idempotency_key whichever scope you use, and max_spend_usd bounds a call only when the agent sends it.
- After any scope change, call mcp_health.
- Keep tool confirmation on for paid tools.
- Use a separate VS Code profile or workspace for sessions that need Write.
Why bother with a reset
MCP: Reset Trust is the VS Code control that makes the editor ask about a server again. After a scope change on Sume, using it turns the new ability into an explicit decision in the editor, which is useful when other people use the same VS Code configuration and never saw Sume's consent page.
Sources
Related posts
More in Integrations
- VS Code Settings Sync and MCP servers: keep the Sume key out
VS Code can sync MCP config when the MCP Servers sync option is on. Keep the Sume API key out of the file with an input variable, or use OAuth instead.
- VS Code user MCP config: a read-only and a Write Sume profile
VS Code's MCP: Open User Configuration edits per-user servers. Keep OAuth read-only Sume in your everyday setup and an API key entry only where paid jobs run.
- VS Code 1.141 background shells and a long Sume render
VS Code 1.141 tracks background shells for agent sessions. Start a Sume render, keep the job id, and use sume jobs watch instead of repeating the paid create.
- Azure Logic Apps HTTP action times out at 120 s: long Sume runs
Logic Apps HTTP actions time out at 120 s. Start a Sume Format run (202 receipt), pass a webhook URL, and set an idempotency key so retries stay safe.
Written by Sume