Cursor cloud agents and Sume MCP: HTTP, redacted headers
Cursor cloud agents run MCP over HTTP or stdio. Sume's hosted server is HTTP, so the key stays in Cursor's backend and OAuth is per user. What to set.

Yes, a Cursor cloud agent can use Sume's hosted MCP server, because Cursor's cloud agents accept HTTP MCP servers and Sume's endpoint, https://mcp.sume.com/mcp, is a remote HTTP server. Add it through the MCP dropdown at cursor.com/agents (personal) or under Dashboard, Plugins & MCPs (team), then pick OAuth or an API-key header. The choice matters more here than in the IDE, because a cloud agent runs without you watching it.
Cursor's side of this comes from its Cloud Agent capabilities page (read 2026-10-10). Sume's side comes from the MCP pages on docs.sume.com. This post does not claim a tested cloud run; it lines up what each page promises so you can set the right limits before the first paid call.
What Cursor says about cloud-agent MCP
Per Cursor's page, cloud agents use MCP servers configured for your team or added personally. Custom servers can use HTTP or stdio, while SSE and mcp-remote are not supported. Sume's hosted server does not need either of the unsupported paths: the Sume quickstart tells clients to set a streamable HTTP URL.
The most useful detail is where the credentials live. Cursor recommends HTTP and says that for HTTP servers the configuration is never present in the cloud agent's VM, that the agent has no access to refresh tokens or headers, and that tool calls are proxied through Cursor's backend. Headers and the OAuth client secret are redacted after saving and cannot be read back.
| Topic | What Cursor documents |
|---|---|
| Transports | HTTP and stdio; SSE and mcp-remote not supported |
| HTTP server config | Never in the VM; calls proxied through the backend |
| Stdio server config | Runs inside the VM; agent can see its environment variables |
| Redacted after save | env, headers, and CLIENT_SECRET |
| OAuth | Supported; per user, including servers shared at team level |
Pick the Sume credential for an unattended run
Sume gives two credentials for the same endpoint, and they behave differently. OAuth gives mcp:read by default, and the user opts into mcp:write with the Write toggle on the consent page. There is no mcp:paid scope. An API key sees the full hosted tool set.
For a cloud agent that means: with read-only OAuth, generate_image or avatars_create return insufficient_scope and nothing is billed, which is a safe default for research runs. With a write grant or an API key the agent can submit paid work, and Sume's own spend gate is the wallet and admission, not a prompt. Cursor's per-user OAuth also means a teammate who has not signed in to Sume cannot borrow your grant.
| Credential | What the cloud agent can call | Spend control |
|---|---|---|
| OAuth, Write off | Read tools such as tools_list, jobs_list, crawl_scrape | None needed; paid tools return insufficient_scope |
| OAuth, Write on | Full hosted tool set | Wallet and admission; idempotency_key required on paid calls |
| API key in a header | Full hosted tool set | Same; Authorization: Bearer or x-api-key |
Put the guardrails in the prompt and the task
Sume's docs list three gates for paid and write tools: a required idempotency_key, an optional dry_run=true that previews cost without submitting, and an optional max_spend_usd that Sume enforces only when you pass it. A cloud agent will not add the optional ones unless told to, so write them into the task.
A prompt that works as a standing instruction: call mcp_health and tools_list first; before any paid call run dry_run=true and report the estimate; set max_spend_usd on every paid call; never re-use an idempotency_key for a different request; poll with jobs_wait rather than re-submitting.
- Start the task with
mcp_health; Sume documents it as the check for endpoint, auth source and safety posture. - Ask for
dry_run=trueon the first paid call, then review the estimate before the real submit. - Keep Write off for any run whose job is only to read
catalog_list,balance_getorjobs_list. - Rotate the API key if it was ever pasted into a prompt or chat; the header field is for it.
Network access is a separate switch
Cursor's settings page (read 2026-10-10) lets users, admins and environment owners choose allow all network access, default plus an allowlist, or an allowlist only. Because Cursor says HTTP MCP calls are proxied through its backend, the MCP request itself is not made from the VM. Downloading a result file is a different step: if the agent fetches a media URL from Sume inside the VM, that request is subject to your network mode, so add the host from the result URL if you run allowlist-only. That last point is our reading of the two pages, not a Cursor statement, so confirm it with one small test job.
Sume's docs say integrations should store the Sume media URL, not provider URLs, so the host to allow is the one that appears in your own job results.
Sources
Related posts
More in Integrations
- Cursor remote MCP has no envFile: where the Sume key goes
Cursor's envFile works for stdio servers only. For Sume's remote MCP, read the key from your shell with a headers entry, or skip keys and use OAuth.
- Docker Agent YAML: add Sume as a remote MCP toolset
Docker Agent takes a remote MCP URL, headers and a tools allowlist. Here is the Sume entry with a Bearer key from the environment and a read-only tool list.
- Framer looping video: keep it under 5 MB, Framer won't compress
Framer says keep looping videos under 5 MB, uses H.264 MP4, and serves a 4K upload at full size. Render and trim a Sume clip small before you upload.
- Freshdesk Trigger Webhook: 1000 calls an hour and Sume bulk runs
Freshdesk automations cap webhook calls at 1000 an hour and retry failures every 30 minutes. Here is how a relay maps ticket bursts onto Sume bulk runs.
Written by Sume