Cursor iOS remote control for local agents: keep paid Sume calls safe
Cursor can now show and answer local agents from its iOS app. If one holds Sume MCP, grant read-only, send dry_run first, and cap max_spend_usd.

Yes, you can answer a Cursor agent from your phone, and if that agent has Sume's hosted MCP it can reach paid tools, so set the limits on the Sume side. Cursor's October 6, 2026 changelog entry says you can now see and reply to the local agents running on your computer from the Cursor iOS app, available by default except for Enterprise organizations. Sume's spend gates do not depend on which screen you reply from.
The Cursor facts come from the Cursor changelog (read 2026-10-07). The Sume facts come from the OAuth page and MCP tools and gates.
What protects you
Replying from a phone makes quick approvals easy, which is the moment a paid call slips through. The table lists the controls Sume gives you.
| Control | What it does | Required? |
|---|---|---|
OAuth mcp:read only | Read-only tools; writes and paid tools return insufficient_scope | Default grant |
OAuth mcp:write | Adds write and paid tools; Write is off by default at consent | Opt-in |
idempotency_key | Dedup for transport retries; not human approval | Required on write and paid calls |
dry_run=true | Cost and admission preview; does not submit | Optional |
max_spend_usd | Spend ceiling, enforced only when you send it | Optional |
Start read-only
An agent that only has mcp:read can list models, read jobs, and preview costs, but cannot create anything. For work you step away from, that is the safest grant. Reconnect with Write on only for the session where you want renders to start.
Treat the phone reply as the gate
The Sume docs are explicit that idempotency_key is a deduplication key and not a consent step. A phone approval inside Cursor is your gate; Sume will accept a paid call that carries a key and enough balance. Ask the agent to send dry_run=true first, read the estimate, and then send the real call with max_spend_usd set at or just above the estimate.
Config stays the same
Because the call to Sume is the same wherever you reply from, there is nothing to configure in the iOS app. Keep the Sume entry in your Cursor MCP config as a plain URL for OAuth (https://mcp.sume.com/mcp), as shown in the quickstart, and avoid pasting an API key into a chat you read on a phone.
Sources
Related posts
More in Agents
- Build a run status chip from the Format events phase timeline
Sume has no SSE stream for Format runs. Poll status_url and events_url to show queued, preparing, running and finalizing in your UI without faking progress.
- Stop an AI video agent overspending: the four Sume spend gates
An unattended Sume agent can only spend what four gates allow: the wallet, a per-run cap, a schedule ceiling, and a Format cap. Values and failure codes inside.
- MCP wants a human in the loop: Sume gates for unattended agents
MCP says a human SHOULD be able to deny tool calls. For unattended agents, Sume adds scopes, idempotency keys and a required Agent Completions cap.
- Auditing agent tool calls: MCP log advice, Sume script_run journal
The MCP spec tells clients to log tool usage for audit. For Sume's script_run, the response includes a calls[] journal and child jobs[] to use with jobs_wait.
Written by Sume