VS Code remote delegation: whose Sume credit is used?

VS Code 1.140's remote delegation tools are off by default and normal approvals still apply. Sume spend follows the credential the session connects with.

4 min readSume
All posts

A remote VS Code session spends Sume credit through whichever credential its own Sume connection uses: an OAuth sign-in or an API key held on that host. VS Code 1.140 added experimental remote delegation tools, list_agent_hosts, create_remote_session and send_remote_message; they are off by default and, per the notes, normal approvals still apply. Sume is not told who delegated.

The VS Code facts are from the 1.140 release notes, read 2026-10-01. The Sume facts are from its docs on workspaces and keys.

What can the delegation tools do?

The notes describe three tools. list_agent_hosts discovers hosts, models, resource capacities and session load. create_remote_session starts a session with automatic placement. send_remote_message sends follow-up work or reports results and questions back to the originating chat. They require turning on chat.remoteSessions.tools.enabled.

How does Sume decide which workspace pays?

By the credential. Sume's safe automation page says API keys and app sessions determine the workspace. A host that connects with an API key bills the key's workspace; a host that completes OAuth bills the workspace of the account that signed in.

Credential and spend on a remote host, from the Sume docs, read 2026-10-01.
Remote host connects withTools it seesSpend lands on
OAuth, mcp:read onlyRead-only toolsNothing; it cannot submit
OAuth, mcp:read + mcp:writeFull hosted tool setThe signed-in account's workspace
API keyFull hosted tool setThe key's workspace

Should a delegated session get an API key?

Prefer OAuth read-only unless the remote session must generate. Sume's docs say API-key sessions see write and paid tools, and that keys appearing in logs or chat history should be rotated. A key written onto a remote host is a copy you have to track. Ask the delegated session to report job ids instead of media in the message it sends back.

Does the approval prompt cover Sume calls?

The notes say normal approvals still apply for remote agent sessions, so treat a paid tool call there like a local one. The call's own fields still protect you: idempotency_key is required, dry_run=true previews the cost, and max_spend_usd caps it when provided, per OAuth and API keys.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume