VS Code 1.140 session authorization server: what Sume issues
VS Code 1.140 proposes a field naming the authorization server behind a session. For Sume, that server is the MCP origin, mcp.sume.com.

For a Sume session over MCP in VS Code, the authorization server that issued it is the MCP origin, https://mcp.sume.com. It is not www.sume.com or app.sume.com. The VS Code 1.140 update describes a proposed API field that reports this per session.
The VS Code text is from its updates page; the Sume side is from MCP OAuth and API keys. Both were read 2026-10-01.
What does the VS Code 1.140 update add?
Under Proposed APIs, the page says the authIssuers proposal already lets an extension name the OAuth authorization server it wants to authenticate against, which VS Code introduced for MCP in 1.101. This release adds the opposite direction: an AuthenticationSession can say which authorization server issued it, "when provided by the authentication provider". The doc comment adds that this identifies the OAuth server, not a REST API endpoint or resource audience.
It is a proposed API, so it is not something to depend on in a shipped extension.
Which server issues a Sume session?
Sume's docs state it directly. Protected-resource metadata lists authorization_servers as the MCP origin, the client is sent to https://mcp.sume.com/oauth/authorize, and consent runs on the MCP host. www.sume.com remains a secondary and deprecated authorization-server surface that the metadata no longer advertises.
| Role | Value in the docs |
|---|---|
| Authorization server | The MCP origin, https://mcp.sume.com |
| Metadata | https://mcp.sume.com/.well-known/oauth-authorization-server |
| Authorize | https://mcp.sume.com/oauth/authorize |
| Resource audience | https://mcp.sume.com/mcp |
Why do the issuer and the audience differ?
The authorization server answers who issued the session; the resource audience answers which server the token is for. For Sume these are different values on the same host, which matches the VS Code comment that the new field is not a resource audience. More on that split in MCP OAuth token audience.
What should I check in an extension?
If your code compares an issuer to an expected value for Sume, compare against the MCP origin and fetch the metadata from the .well-known URL above rather than hard-coding a different host. Treat a missing issuer as unknown, since the field is only present when the provider supplies it.
Sources
Related posts
More in Integrations
- How to add an MCP server to ChatGPT with developer mode
Turn on ChatGPT developer mode, create an app for the server's URL, and sign in with OAuth. The steps, with Sume's hosted MCP server as the example.
- How to add subtitles to a video in Python
Add subtitles to a video in Python with Requests: POST the video URL to Sume's /v1/video-captions, poll the job, then read the captioned video_url.
- Add Sume to Claude as a custom connector (remote MCP)
Add Sume's hosted MCP server to Claude under Customize > Connectors, see what Sume's OAuth consent grants, and decide whether to allow paid tools.
- Airflow HTTP sensor: wait for an AI video job to finish
Submit an AI video job with Airflow's HttpOperator, then wait with an HttpSensor in reschedule mode that passes once the job's status is completed.
Written by Sume