VS Code Settings Sync and MCP servers: keep the Sume key out
VS Code can sync MCP config when the MCP Servers sync option is on. Keep the Sume API key out of the file with an input variable, or use OAuth instead.

If you use the Sume API key in VS Code, do not paste it into an MCP config that Settings Sync can carry to other machines. The VS Code page says MCP configuration synchronizes when the "MCP Servers" option is enabled in Settings Sync, so a literal key in that file can travel with it. Use an input variable for the secret, or connect with OAuth so no key sits in the file at all.
This post covers only the sync side effect. For how Sume's two credentials differ, see the hosted MCP docs.
What the VS Code page says
The facts below come from the VS Code MCP page. Sume's own facts come from its docs.
| Topic | Fact | Source |
|---|---|---|
| Remote server entry | type http plus a url | VS Code docs |
| Secrets | The page recommends input variables for secrets | VS Code docs |
| Settings Sync | MCP configuration syncs when the MCP Servers option is enabled | VS Code docs |
| Sume server URL | https://mcp.sume.com/mcp | Sume docs |
| Sume API key header | Authorization: Bearer or x-api-key | Sume docs |
| Sume OAuth | Read-only by default; Write is an opt-in toggle on the consent page | Sume docs |
A config that carries no secret
Declare an input that VS Code prompts for, and reference it from the header. The key is then asked for on each machine rather than stored in the synced file. Check the field names against the VS Code page before you rely on this sketch.
{
"inputs": [
{"type": "promptString", "id": "sume-key", "description": "Sume API key", "password": true}
],
"servers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": {"Authorization": "Bearer ${input:sume-key}"}
}
}
}Other places a key can leak in VS Code
Settings Sync is one route. A workspace file at .vscode/mcp.json is another, because it normally sits inside a repository that teammates clone and that CI reads. The VS Code page also lists .mcp.json and a user-level ~/.copilot/mcp-config.json as locations, so check every one of them for a pasted key before you commit or enable sync.
VS Code also asks you to trust a server before it starts, and the page documents an MCP: Reset Trust command. Use it when you want the prompt to appear again for an entry you have changed.
Choosing between the key and OAuth
An API key gives the full tool set, including write and paid tools, to whoever holds it. Anything that syncs it widens that group. OAuth sessions are read-only unless the person ticks the Write toggle on the consent page, so a synced OAuth entry that has no secret in it carries less risk: each machine signs in on its own.
If a leaked key is the concern, rotate it from the dashboard and move to OAuth for editors that sync settings. Write and paid calls still need an idempotency_key whichever credential you use, and max_spend_usd is optional, enforced only when you send it.
- Turn the MCP Servers sync option off if you cannot avoid a literal key.
- Prefer one OAuth sign-in per machine over a shared key.
- After syncing, run mcp_health on the new machine to confirm which credential the session uses.
Sources
Related posts
More in Integrations
- VS Code user MCP config: a read-only and a Write Sume profile
VS Code's MCP: Open User Configuration edits per-user servers. Keep OAuth read-only Sume in your everyday setup and an API key entry only where paid jobs run.
- VS Code 1.141 background shells and a long Sume render
VS Code 1.141 tracks background shells for agent sessions. Start a Sume render, keep the job id, and use sume jobs watch instead of repeating the paid create.
- Azure Logic Apps HTTP action times out at 120 s: long Sume runs
Logic Apps HTTP actions time out at 120 s. Start a Sume Format run (202 receipt), pass a webhook URL, and set an idempotency key so retries stay safe.
- Bitbucket merged-PR webhook to a Sume Format run: verify first
Verify Bitbucket's X-Hub-Signature (sha256=) with its published test values, then start a Sume Format run on pullrequest merged with a key built from the PR.
Written by Sume