Copilot mcp-config.json example: a Sume remote entry
A Copilot mcp-config.json example for Sume: an http entry at mcp.sume.com/mcp with an x-api-key header and a tools list. Global file vs workspace .mcp.json.

A Sume entry in Copilot's mcp-config.json is an http server with url set to https://mcp.sume.com/mcp, an x-api-key header, and a tools list. Put it in the global file only: VS Code's MCP: Add Server flow can now save to $COPILOT_HOME/mcp-config.json (or ~/.copilot/mcp-config.json) or to a workspace .mcp.json, and a key does not belong in a file you commit.
Where do the two files live?
From the VS Code update notes, read 2026-09-30: choosing Copilot Global saves to $COPILOT_HOME/mcp-config.json, or ~/.copilot/mcp-config.json when COPILOT_HOME is not set. Choosing .mcp.json saves at the workspace root. GitHub's Copilot CLI page adds that the CLI, started inside a Git repository, walks from the working directory up to the repository root loading MCP configuration files.
| File | Scope | Put a Sume key here? |
|---|---|---|
$COPILOT_HOME/mcp-config.json or ~/.copilot/mcp-config.json | Global | If you use a key, here |
.mcp.json at workspace root | Workspace | No, it is shared with the repo |
What does the Sume entry look like?
GitHub's remote shape is type, url, headers and tools. The Sume docs give the header form x-api-key: $SUME_API_KEY and the URL. Replace the placeholder with your key; the snapshot does not say whether Copilot expands environment variables in headers, so check before relying on that.
{
"mcpServers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": { "x-api-key": "<your Sume API key>" },
"tools": ["tools_list", "tools_schema", "jobs_status", "jobs_result"]
}
}
}Which tool ids go in the allowlist?
Sume's live tool ids are underscore names such as tools_list and jobs_status. The GitHub page says tools takes "*" for all, names, or an empty value for none. Start with read tools; an API-key session can see write and paid tools, and writes need an idempotency_key. See tools and gates.
Is OAuth an alternative to the key?
Sume supports both: OAuth through consent on the MCP host, or an API key. An OAuth token is not a Sume API key, and the docs say not to store tokens in config. For the CLI walkthrough see Copilot CLI MCP server for Sume, and MCP OAuth and API keys for the auth matrix.
Sources
Related posts
More in Integrations
- Hedra MCP for Claude, and how Sume's hosted MCP connects
Hedra's MCP and CLI let Claude and other agents generate images, video and audio. Sume's hosted MCP lives at mcp.sume.com/mcp with write and paid gates.
- HeyGen translation SRT captions vs Sume burned-in captions
HeyGen now generates caption sidecars for every translation and lipsync job. Sume burns captions into the video and does not accept SRT as input.
- Instagram Audio API for Reels ads: prepare the video side
Meta's Instagram Audio API can find royalty-free replacements for copyrighted Reels music. Sume does not call it, but can drop the audio from your video.
- Add Sume as an MCP server in Junie CLI (mcp.json)
Add Sume to Junie CLI's mcp.json as a remote server with url and headers, or leave headers out and use Authorize for OAuth. Both paths, step by step.
Written by Sume