Cursor MCP allowlist: approve Sume's URL and its read tools
Cursor enterprise admins approve remote MCP servers by URL entry and list tools per server. How to allow Sume's mcp.sume.com/mcp and which tools to list.

If your Cursor team uses the MCP Allowlist, add a URL entry that covers https://mcp.sume.com/mcp and, optionally, a tool allowlist naming Sume's read tools. Cursor's page says URL entries approve remote HTTP or SSE servers by URL entry pattern, and that remote MCP URLs are restricted to the configured pattern. Without a matching entry, a user's Sume server is blocked under that policy.
The Cursor behaviour is from Cursor Docs: Model Context Protocol, and the Sume endpoint and tool names from the MCP quickstart and tools and gates, all read 2026-10-02.
What can a Cursor admin control for an MCP server?
The page separates two jobs. Team admins distribute shared servers under Dashboard > Plugins & MCPs, and those servers are available to Cloud Agents. Enterprise admins configure MCP policy in Team Settings > MCP Configuration. Allowlisting approves a configuration; it does not install it for anyone.
| Entry type | What Cursor's page says | For Sume |
|---|---|---|
| Command entries | Approve local stdio servers by command pattern | Not used: Sume's hosted MCP is remote |
| URL entries | Approve remote HTTP/SSE servers by URL entry pattern | One entry that matches https://mcp.sume.com/mcp |
| Tool allowlists | Restrict which tools from an approved server can run automatically; empty allows all | Read tools such as tools_list, jobs_status, jobs_wait, jobs_result |
| Network controls | Remote MCP URLs are restricted to the configured URL entry pattern | Keep the entry to the one host |
Which Sume tools belong on the tool allowlist?
The page says a tool allowlist limits which tools run automatically, and that in Auto-review Run Mode allowlisted MCP tools run immediately while everything else goes through the classifier. So the list is about auto-run, not visibility. Put the read tools there: mcp_health, tools_list, tools_schema, account_me, balance_get, catalog_list, jobs_status, jobs_wait and jobs_result, all listed as read tools in Sume's docs.
Leave paid tools such as generate_image and generate_video off it. They require an idempotency_key, and routing them through the classifier or an approval prompt keeps a human in the loop for spend.
How should each person authenticate to Sume?
Sume's quickstart says to use the OAuth connector flow for interactive clients, with consent on the MCP host, and that the default grant is mcp:read. Each person signs in and chooses whether to turn Write on. Putting one shared API key into a team entry would give every user a full-tool session on one workspace, since a key resolves to its workspace and spend is wallet and admission based. Cursor's page notes a team-distributed server is configured per person after install, so prefer OAuth there.
What do I check after changing the policy?
Have a user check the Sume server in Customize and call mcp_health. Then confirm tools_list returns what you expect and that a read tool on the allowlist runs without a prompt. Cursor's page does not give the pattern syntax in the text this post read, so use the dashboard's own help for exact entry formatting. Linking a server to a team marketplace does not install or enable it for everyone, so a teammate may still need to install it.
Sources
Related posts
More in Integrations
- Cursor supports MCP roots and elicitation; Sume uses tools only
Cursor lists tools, prompts, resources, roots, elicitation and Apps as supported. Sume's hosted MCP answers only tools, so here is what you will see.
- Deno.serve webhook receiver for Sume with a KV dedupe check
A short Deno.serve receiver for Sume webhooks: verify sume-v1 over the raw body, dedupe on job_id with an atomic KV write, and acknowledge with 204.
- Devin Desktop team allowlist: Sume's MCP server blocked until listed
In Devin Desktop, once an admin allowlists any MCP server, all others are blocked for the team. Add Sume's production URL to the list before members connect.
- Devin Desktop 100-tool limit: fit Sume's MCP tools with disabledTools
Cascade in Devin Desktop (formerly Windsurf) caps total tools at 100. Sume's docs list about 75 tool ids; trim others with disabledTools.
Written by Sume