Cursor CLI --approve-mcps: what it skips for paid Sume tools

Cursor CLI's --approve-mcps flag skips MCP approval prompts. How that affects paid Sume tools, plus agent mcp list-tools and login to check the connection.

5 min readSume
All posts

Cursor CLI's --approve-mcps flag skips MCP approval prompts when you run agent commands, so a paid Sume tool can run without anyone confirming it. Cursor's docs say the CLI shares the editor's MCP configuration and that the editor asks for approval before using MCP tools by default (read 2026-10-02). Use the flag only in sessions where the Sume credential cannot spend, or where you have capped the call yourself.

The CLI commands in Cursor's docs

Cursor documents a small set of MCP commands for the CLI. Because the config is shared with the editor, the Sume entry from the MCP quickstart works in both.

Cursor CLI MCP commands, read 2026-10-02 from Cursor's docs; the last column is the Sume use.
Command or flagWhat Cursor's docs sayFor Sume
agent mcp listLists configured servers with status and configuration sourceConfirm sume is connected
agent mcp list-tools <identifier>Shows a server's tools with parameter detailsCompare with tools_list
agent mcp login <identifier>Authenticates with an MCP serverThe OAuth sign-in for Sume
agent mcp enable / disableControls server activationPause Sume without deleting it
--approve-mcpsSkips approval promptsAvoid with paid tools

What skipping approval means with Sume

Sume's idempotency_key is required on paid and write tools, but the docs call it a transport and deduplication key, not human approval (MCP tools and gates). With --approve-mcps, nothing in Cursor stops a submit and nothing in Sume stops it either, except the wallet and admission checks.

What does limit the damage is the credential. OAuth with mcp:read only exposes read tools, and a paid call returns insufficient_scope. If you turn Write on at consent, or use an API key, the paid tools are visible (MCP OAuth and API keys).

A safer pattern for scripts

For unattended CLI runs, connect with OAuth and leave Write off. The agent can then read jobs, balance and assets, call catalog_list, and use crawl_scrape, and anything that spends fails with insufficient_scope rather than running. Add --approve-mcps there freely, since the worst case is a refused call.

For a run that must generate, keep approval prompts on, or have the agent call dry_run=true first and pass max_spend_usd. Sume enforces the cap only when it is provided, so it has to be in the call.

Checking what the CLI sees

Cursor's static redirect for desktop OAuth is http://localhost:8787/callback, per its MCP docs; Sume's OAuth page describes the flow from the MCP host.

  • Run agent mcp list and look for sume and its configuration source.
  • Run agent mcp list-tools sume and compare the names with what tools_list returns in a session.
  • If the OAuth token expires, run agent mcp login sume again.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume