Cursor CLI --approve-mcps: what it skips for paid Sume tools
Cursor CLI's --approve-mcps flag skips MCP approval prompts. How that affects paid Sume tools, plus agent mcp list-tools and login to check the connection.

Cursor CLI's --approve-mcps flag skips MCP approval prompts when you run agent commands, so a paid Sume tool can run without anyone confirming it. Cursor's docs say the CLI shares the editor's MCP configuration and that the editor asks for approval before using MCP tools by default (read 2026-10-02). Use the flag only in sessions where the Sume credential cannot spend, or where you have capped the call yourself.
The CLI commands in Cursor's docs
Cursor documents a small set of MCP commands for the CLI. Because the config is shared with the editor, the Sume entry from the MCP quickstart works in both.
| Command or flag | What Cursor's docs say | For Sume |
|---|---|---|
agent mcp list | Lists configured servers with status and configuration source | Confirm sume is connected |
agent mcp list-tools <identifier> | Shows a server's tools with parameter details | Compare with tools_list |
agent mcp login <identifier> | Authenticates with an MCP server | The OAuth sign-in for Sume |
agent mcp enable / disable | Controls server activation | Pause Sume without deleting it |
--approve-mcps | Skips approval prompts | Avoid with paid tools |
What skipping approval means with Sume
Sume's idempotency_key is required on paid and write tools, but the docs call it a transport and deduplication key, not human approval (MCP tools and gates). With --approve-mcps, nothing in Cursor stops a submit and nothing in Sume stops it either, except the wallet and admission checks.
What does limit the damage is the credential. OAuth with mcp:read only exposes read tools, and a paid call returns insufficient_scope. If you turn Write on at consent, or use an API key, the paid tools are visible (MCP OAuth and API keys).
A safer pattern for scripts
For unattended CLI runs, connect with OAuth and leave Write off. The agent can then read jobs, balance and assets, call catalog_list, and use crawl_scrape, and anything that spends fails with insufficient_scope rather than running. Add --approve-mcps there freely, since the worst case is a refused call.
For a run that must generate, keep approval prompts on, or have the agent call dry_run=true first and pass max_spend_usd. Sume enforces the cap only when it is provided, so it has to be in the call.
Checking what the CLI sees
Cursor's static redirect for desktop OAuth is http://localhost:8787/callback, per its MCP docs; Sume's OAuth page describes the flow from the MCP host.
- Run
agent mcp listand look forsumeand its configuration source. - Run
agent mcp list-tools sumeand compare the names with whattools_listreturns in a session. - If the OAuth token expires, run
agent mcp login sumeagain.
Sources
Related posts
More in Integrations
- Cursor MCP allowlist: approve Sume's URL and its read tools
Cursor enterprise admins approve remote MCP servers by URL entry and list tools per server. How to allow Sume's mcp.sume.com/mcp and which tools to list.
- Cursor supports MCP roots and elicitation; Sume uses tools only
Cursor lists tools, prompts, resources, roots, elicitation and Apps as supported. Sume's hosted MCP answers only tools, so here is what you will see.
- Deno.serve webhook receiver for Sume with a KV dedupe check
A short Deno.serve receiver for Sume webhooks: verify sume-v1 over the raw body, dedupe on job_id with an atomic KV write, and acknowledge with 204.
- Devin Desktop team allowlist: Sume's MCP server blocked until listed
In Devin Desktop, once an admin allowlists any MCP server, all others are blocked for the team. Add Sume's production URL to the list before members connect.
Written by Sume