VS Code Restricted Mode: workspace MCP blocked, Sume tools missing

In VS Code Restricted Mode, workspace MCP config does not start. Why Sume's tools vanish in an untrusted repo and what MCP: Reset Trust changes.

4 min readSume
All posts

If Sume's tools disappear after you open a repository in VS Code, check whether the workspace is trusted. VS Code's MCP documentation says that in Restricted Mode, workspace MCP configuration is blocked and its servers do not start. Servers declared in .vscode/mcp.json or the workspace-root .mcp.json inherit Workspace Trust, so an untrusted clone never reaches https://mcp.sume.com/mcp, whatever the entry says.

The editor behavior is from the VS Code MCP page, read on 2026-10-03. The Sume endpoint and auth modes are from the MCP quickstart and OAuth and API keys.

What exactly does trust gate?

The page separates two decisions. Workspace servers follow Workspace Trust: when you trust the workspace, servers in .vscode/mcp.json and workspace-root .mcp.json can start without a separate server prompt, including after their configuration changes. Servers from other sources use a separate trust decision, with a dialog the first time a server starts or its configuration changes; if you decline, the server does not start and chat continues without its tools.

The documentation adds a warning that matters for shared repositories: review workspace MCP configuration before trusting a repository, because local servers can run code on your machine. A hosted HTTP entry like Sume's runs nothing locally, but the trust model does not distinguish, so a teammate's change to the file gets the same treatment.

Trust paths for an MCP entry in VS Code; from the VS Code MCP page (code.visualstudio.com), read 2026-10-03.
Where the entry livesTrust decisionIf untrusted
.vscode/mcp.json or workspace .mcp.jsonWorkspace Trust; no separate prompt once trustedBlocked in Restricted Mode; server does not start
Other sourcesSeparate dialog on first start or config changeServer does not start; chat continues without its tools
Either path, to clear saved choicesRun MCP: Reset TrustDoes not change Workspace Trust

How do I get Sume's tools in an untrusted folder?

Two honest options. Trust the folder, if you have reviewed what is in it. Or put the Sume entry where the trust model is separate: the page's user configuration (MCP: Open User Configuration) holds servers available across all workspaces. I did not find a sentence on the page saying whether user-level servers start inside a Restricted Mode window, so test that before promising it to a team.

The entry itself is the same everywhere: type http, url https://mcp.sume.com/mcp. Sume's docs say sign-in goes through the MCP host's consent page, with Read locked on and Write off until you switch it on.

{
  "servers": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp"
    }
  }
}

What does Reset Trust do to my Sume session?

MCP: Reset Trust clears the separate per-server trust decisions and, per the page, does not change Workspace Trust. After running it, the next start of a server from another source shows the dialog again. It does not touch your Sume OAuth token, which lives with the client; Sume's tokens last 3600 seconds and there is no refresh grant, so expect a fresh sign-in after an hour regardless of trust state.

To confirm the server is live afterwards, ask for mcp_health and read authenticated.auth_source; the tools and gates page lists it as the read-only readiness check.

Should a team commit the Sume entry?

Usually yes, with care. The VS Code page recommends including workspace configuration in source control so a team shares servers. For Sume that is safe when the file holds only the URL and type, with no key. Tell contributors that the first open of a fresh clone may be in Restricted Mode and that trusting the folder is what lets the entry start.

Add a line to your README that names the MCP entry and the scope you expect: read for exploration, write only when someone needs to submit generations. That keeps the consent choice deliberate instead of a default click.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume