VS Code 1.140 session authorization server: what Sume issues

VS Code 1.140 proposes a field naming the authorization server behind a session. For Sume, that server is the MCP origin, mcp.sume.com.

4 min readSume
All posts

For a Sume session over MCP in VS Code, the authorization server that issued it is the MCP origin, https://mcp.sume.com. It is not www.sume.com or app.sume.com. The VS Code 1.140 update describes a proposed API field that reports this per session.

The VS Code text is from its updates page; the Sume side is from MCP OAuth and API keys. Both were read 2026-10-01.

What does the VS Code 1.140 update add?

Under Proposed APIs, the page says the authIssuers proposal already lets an extension name the OAuth authorization server it wants to authenticate against, which VS Code introduced for MCP in 1.101. This release adds the opposite direction: an AuthenticationSession can say which authorization server issued it, "when provided by the authentication provider". The doc comment adds that this identifies the OAuth server, not a REST API endpoint or resource audience.

It is a proposed API, so it is not something to depend on in a shipped extension.

Which server issues a Sume session?

Sume's docs state it directly. Protected-resource metadata lists authorization_servers as the MCP origin, the client is sent to https://mcp.sume.com/oauth/authorize, and consent runs on the MCP host. www.sume.com remains a secondary and deprecated authorization-server surface that the metadata no longer advertises.

Where each OAuth role lives for Sume, from the docs read 2026-10-01: https://docs.sume.com/mcp/oauth
RoleValue in the docs
Authorization serverThe MCP origin, https://mcp.sume.com
Metadatahttps://mcp.sume.com/.well-known/oauth-authorization-server
Authorizehttps://mcp.sume.com/oauth/authorize
Resource audiencehttps://mcp.sume.com/mcp

Why do the issuer and the audience differ?

The authorization server answers who issued the session; the resource audience answers which server the token is for. For Sume these are different values on the same host, which matches the VS Code comment that the new field is not a resource audience. More on that split in MCP OAuth token audience.

What should I check in an extension?

If your code compares an issuer to an expected value for Sume, compare against the MCP origin and fetch the metadata from the .well-known URL above rather than hard-coding a different host. Treat a missing issuer as unknown, since the field is only present when the provider supplies it.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume