Cursor MCP allowlist: approve Sume's URL and its read tools

Cursor enterprise admins approve remote MCP servers by URL entry and list tools per server. How to allow Sume's mcp.sume.com/mcp and which tools to list.

5 min readSume
All posts

If your Cursor team uses the MCP Allowlist, add a URL entry that covers https://mcp.sume.com/mcp and, optionally, a tool allowlist naming Sume's read tools. Cursor's page says URL entries approve remote HTTP or SSE servers by URL entry pattern, and that remote MCP URLs are restricted to the configured pattern. Without a matching entry, a user's Sume server is blocked under that policy.

The Cursor behaviour is from Cursor Docs: Model Context Protocol, and the Sume endpoint and tool names from the MCP quickstart and tools and gates, all read 2026-10-02.

What can a Cursor admin control for an MCP server?

The page separates two jobs. Team admins distribute shared servers under Dashboard > Plugins & MCPs, and those servers are available to Cloud Agents. Enterprise admins configure MCP policy in Team Settings > MCP Configuration. Allowlisting approves a configuration; it does not install it for anyone.

Allowlist entry types from Cursor's MCP page and what they mean for Sume, read 2026-10-02.
Entry typeWhat Cursor's page saysFor Sume
Command entriesApprove local stdio servers by command patternNot used: Sume's hosted MCP is remote
URL entriesApprove remote HTTP/SSE servers by URL entry patternOne entry that matches https://mcp.sume.com/mcp
Tool allowlistsRestrict which tools from an approved server can run automatically; empty allows allRead tools such as tools_list, jobs_status, jobs_wait, jobs_result
Network controlsRemote MCP URLs are restricted to the configured URL entry patternKeep the entry to the one host

Which Sume tools belong on the tool allowlist?

The page says a tool allowlist limits which tools run automatically, and that in Auto-review Run Mode allowlisted MCP tools run immediately while everything else goes through the classifier. So the list is about auto-run, not visibility. Put the read tools there: mcp_health, tools_list, tools_schema, account_me, balance_get, catalog_list, jobs_status, jobs_wait and jobs_result, all listed as read tools in Sume's docs.

Leave paid tools such as generate_image and generate_video off it. They require an idempotency_key, and routing them through the classifier or an approval prompt keeps a human in the loop for spend.

How should each person authenticate to Sume?

Sume's quickstart says to use the OAuth connector flow for interactive clients, with consent on the MCP host, and that the default grant is mcp:read. Each person signs in and chooses whether to turn Write on. Putting one shared API key into a team entry would give every user a full-tool session on one workspace, since a key resolves to its workspace and spend is wallet and admission based. Cursor's page notes a team-distributed server is configured per person after install, so prefer OAuth there.

What do I check after changing the policy?

Have a user check the Sume server in Customize and call mcp_health. Then confirm tools_list returns what you expect and that a read tool on the allowlist runs without a prompt. Cursor's page does not give the pattern syntax in the text this post read, so use the dashboard's own help for exact entry formatting. Linking a server to a team marketplace does not install or enable it for everyone, so a teammate may still need to install it.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume