Auto run MCP tools in Cursor: Run Modes and the allowlist

Cursor auto runs an MCP tool when it is on your allowlist or your Run Mode is Run Everything. How to set it, and which tools to keep on approval.

5 min readSume
All posts

To auto run MCP tools in Cursor, choose a Run Mode under Settings > Agents > Approvals & Execution. In Auto-review and Allowlist modes, MCP tools on your allowlist run immediately; in Run Everything mode, every tool call runs without asking. A tool that is not allowlisted asks for approval in Allowlist mode and goes to a classifier in Auto-review.

The Cursor facts here come from its Run Modes, MCP, Agent Security, and CLI Permissions pages, read on 2026-09-28. The paid-server example uses Sume's hosted MCP server, a remote server Cursor connects to by URL, described in MCP tools and gates. Sume has no Cursor-specific connector.

Which Run Mode lets MCP tools run without asking?

Cursor's MCP page says MCP follows the same Run Modes as terminal commands. Its security page adds that after you approve an MCP connection, each tool call still needs its own approval unless you pre-approve the tool with an MCP allowlist.

  • Auto-review shipped as the recommended default in Cursor 3.6 (May 29, 2026).
  • Ask Every Time was deprecated in Cursor 3.5 (May 22, 2026). Cursor says to use Allowlist with an empty allowlist for the same behavior.
  • Cursor calls Auto-review not a security boundary: the classifier can allow a call you would have blocked.
  • Run Modes apply to local agents. Cloud Agents do not use them and never ask for approval.
From Cursor's Run Modes page, read 2026-09-28.
Run ModeWhat runs without asking
Auto-reviewAllowlisted calls run immediately. Calls that do not use the sandbox go to the Auto-review classifier, which covers shell, MCP, and Fetch calls.
AllowlistActions in your allowlist run without approval. With an empty allowlist, every call asks.
Run EverythingEvery tool call runs automatically.

How do I allowlist one MCP tool?

In the Cursor CLI, permissions live in ~/.cursor/cli-config.json (global) or <project>/.cursor/cli.json (one project). An MCP rule has the form Mcp(server:tool), where server is the name in mcp.json and * is a wildcard. Cursor's examples are Mcp(datadog:*) for every tool on one server and Mcp(*:*) for all MCP tools, which it says to use with caution. Deny rules take precedence over allow rules.

If you connected Sume under the name sume, as in the quickstart, this allows three read tools and nothing that spends money:

{
  "permissions": {
    "allow": [
      "Mcp(sume:tools_list)",
      "Mcp(sume:jobs_status)",
      "Mcp(sume:jobs_wait)"
    ]
  }
}

Why does an allowlisted MCP tool still ask?

Cursor's docs name several settings that sit above your own allowlist:

  • Team settings take precedence over individual and project configuration, and admins can override which modes are available.
  • Enterprise admins can set tool allowlists per approved server; those restrict which tools can run automatically.
  • If the team blocks every model the classifier uses, Auto-review is disabled and members use Allowlist instead.
  • Other protections, such as Browser Protection and File-Deletion Protection, can require approval even when a mode would otherwise run automatically.

Which MCP tools should run without asking?

Allowlist tools that only read, and keep tools that create, change, or pay on approval. Sume's Authentication page gives the same rule for agents: give them read-only commands first and require explicit confirmation before write or paid generation commands. On a paid media server this matters most, because an auto-run generate_video can spend money on every call.

Sume's hosted server gives you the facts to sort its tools:

  • tools_list lists every tool visible in the session, with safety metadata.
  • Under OAuth mcp:read, mutating and paid tools are hidden until the session has mcp:write or uses an API key.
  • Paid tools require an idempotency_key, which is for transport and dedup, not human approval.
  • dry_run=true previews admission and cost without submitting, and max_spend_usd is enforced only when you send it.
  • Sume basics says hosted MCP still works but is not the primary integration path today.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume