Auto run MCP tools in Cursor: Run Modes and the allowlist
Cursor auto runs an MCP tool when it is on your allowlist or your Run Mode is Run Everything. How to set it, and which tools to keep on approval.

To auto run MCP tools in Cursor, choose a Run Mode under Settings > Agents > Approvals & Execution. In Auto-review and Allowlist modes, MCP tools on your allowlist run immediately; in Run Everything mode, every tool call runs without asking. A tool that is not allowlisted asks for approval in Allowlist mode and goes to a classifier in Auto-review.
The Cursor facts here come from its Run Modes, MCP, Agent Security, and CLI Permissions pages, read on 2026-09-28. The paid-server example uses Sume's hosted MCP server, a remote server Cursor connects to by URL, described in MCP tools and gates. Sume has no Cursor-specific connector.
Which Run Mode lets MCP tools run without asking?
Cursor's MCP page says MCP follows the same Run Modes as terminal commands. Its security page adds that after you approve an MCP connection, each tool call still needs its own approval unless you pre-approve the tool with an MCP allowlist.
- Auto-review shipped as the recommended default in Cursor 3.6 (May 29, 2026).
- Ask Every Time was deprecated in Cursor 3.5 (May 22, 2026). Cursor says to use Allowlist with an empty allowlist for the same behavior.
- Cursor calls Auto-review not a security boundary: the classifier can allow a call you would have blocked.
- Run Modes apply to local agents. Cloud Agents do not use them and never ask for approval.
| Run Mode | What runs without asking |
|---|---|
| Auto-review | Allowlisted calls run immediately. Calls that do not use the sandbox go to the Auto-review classifier, which covers shell, MCP, and Fetch calls. |
| Allowlist | Actions in your allowlist run without approval. With an empty allowlist, every call asks. |
| Run Everything | Every tool call runs automatically. |
How do I allowlist one MCP tool?
In the Cursor CLI, permissions live in ~/.cursor/cli-config.json (global) or <project>/.cursor/cli.json (one project). An MCP rule has the form Mcp(server:tool), where server is the name in mcp.json and * is a wildcard. Cursor's examples are Mcp(datadog:*) for every tool on one server and Mcp(*:*) for all MCP tools, which it says to use with caution. Deny rules take precedence over allow rules.
If you connected Sume under the name sume, as in the quickstart, this allows three read tools and nothing that spends money:
{
"permissions": {
"allow": [
"Mcp(sume:tools_list)",
"Mcp(sume:jobs_status)",
"Mcp(sume:jobs_wait)"
]
}
}Why does an allowlisted MCP tool still ask?
Cursor's docs name several settings that sit above your own allowlist:
- Team settings take precedence over individual and project configuration, and admins can override which modes are available.
- Enterprise admins can set tool allowlists per approved server; those restrict which tools can run automatically.
- If the team blocks every model the classifier uses, Auto-review is disabled and members use Allowlist instead.
- Other protections, such as Browser Protection and File-Deletion Protection, can require approval even when a mode would otherwise run automatically.
Which MCP tools should run without asking?
Allowlist tools that only read, and keep tools that create, change, or pay on approval. Sume's Authentication page gives the same rule for agents: give them read-only commands first and require explicit confirmation before write or paid generation commands. On a paid media server this matters most, because an auto-run generate_video can spend money on every call.
Sume's hosted server gives you the facts to sort its tools:
tools_listlists every tool visible in the session, with safety metadata.- Under OAuth
mcp:read, mutating and paid tools are hidden until the session hasmcp:writeor uses an API key. - Paid tools require an
idempotency_key, which is for transport and dedup, not human approval. dry_run=truepreviews admission and cost without submitting, andmax_spend_usdis enforced only when you send it.- Sume basics says hosted MCP still works but is not the primary integration path today.
Sources
Related posts
More in Integrations
- How to add MCP to Devin: connect Sume's hosted server
Add a custom MCP server to Devin in Customize > MCPs: HTTP transport, Sume's hosted MCP URL, an Authorization header or OAuth, then Test tools.
- Dify MCP client: connect Sume's hosted MCP server
Dify connects to remote MCP servers from Integrations > Tools. Add Sume's hosted MCP by URL, then sign in with OAuth or send an API-key header.
- Discord webhook send file: attach a video with files[0]
Yes: POST multipart/form-data to the webhook URL with the file as files[0] and the text in payload_json. Over 20 MiB by default, post the link.
- fal MCP server: setup for Claude Code, Cursor, and billing
fal's MCP server runs at mcp.fal.ai/mcp with a fal API key or sign-in. The server is free; model runs bill to your fal account at API prices.
Written by Sume