Copilot app sandbox network: Sume hosts to allow
In a sandboxed GitHub Copilot app session, allow api.sume.com, mcp.sume.com and media.sume.com outbound; send the Sume key as a header, not a git credential.

If a sandboxed Copilot app session needs Sume, allow outbound access to three hosts: api.sume.com for the REST API, mcp.sume.com for hosted MCP, and media.sume.com where result URLs live. The Sume API key goes in a request header, not in the sandbox's git credentials.
Vendor facts are from the GitHub changelog of 2026-09-23; Sume facts from the Public API and MCP docs, read 2026-10-01. For connecting Copilot's coding agent itself, see the Copilot coding agent post.
What does Copilot app sandboxing control?
Per project, the settings cover filesystem, network (outbound internet and local network) and credentials. It is off by default and in public preview. Changes apply to new sessions or when an existing one restarts, and the effective policy can be stricter when enterprise-managed settings apply. If the OS cannot enforce the policy, the sandboxed shell errors rather than running unsandboxed. The vendor page does not list per-host syntax, so check the app's settings for how to enter hosts.
Which Sume hosts does an agent reach?
| Host | Used for | Source |
|---|---|---|
api.sume.com | Developer API base https://api.sume.com/v1 | Public API |
mcp.sume.com | Hosted MCP https://mcp.sume.com/mcp | MCP overview |
media.sume.com | Public media URLs for results | MCP tools and gates |
How should the key be passed?
Sume accepts Authorization: Bearer $SUME_API_KEY or x-api-key. Provide it through whatever credential setting the sandbox offers for environment values, and never paste keys or signed URLs into chat logs, as the docs advise.
Why does a download fail while the API works?
Job results point at media.sume.com. If only the API and MCP hosts are allowed, creating and polling jobs will succeed but fetching the file will be blocked. Add the media host.
Sources
Related posts
More in Developers
- GITHUB_TOKEN can't redeliver webhooks; Sume uses jobs:write
GitHub's built-in GITHUB_TOKEN cannot redeliver webhooks. For Sume job webhooks, a jobs:write API key calls POST /v1/jobs/{job_id}/webhook/redeliver instead.
- Google Cloud TTS caps requests at 5,000 bytes; Sume counts characters
Google lists 5,000 total bytes per request and says multi-byte characters such as ja-JP count toward it. Sume TTS 1.0 counts characters: up to 20,000.
- Google Chirp 3 allows 200 requests a minute; Sume limits by plan
Google lists per-minute request quotas by voice type: Chirp 3 at 200, Studio 500, Standard 1,000. Sume TTS is limited by workspace concurrency on your plan.
- Google Play AI content policy: the in-app report button
Google Play says apps that generate content with AI need in-app reporting or flagging that works without leaving the app. What that means for an AI video app.
Written by Sume