Cursor mcp.json for Sume: a URL and nothing else

The Cursor entry for hosted Sume MCP is one url field with no key in the file; OAuth sign-in happens in the client and the consent page lives on the MCP host.

5 min readSume
All posts

The Cursor config for Sume is one server entry with a url and no credentials. Cursor then walks you through OAuth, and the consent page is on the MCP host, not on app.sume.com. Because no key sits in the file, committing the config to a repository exposes nothing.

Use the production URL https://mcp.sume.com/mcp. The dev host mcp.dev.sume.com is for Sume development environments, and customer configs must not use it.

{
  "mcpServers": {
    "sume": {
      "url": "https://mcp.sume.com/mcp"
    }
  }
}

After you add it

The quickstart gives this order, read 2026-10-09.

Cursor setup sequence from the MCP quickstart
StepWhat to doWhat you should see
1Add the entry in Cursor Settings, MCP, or the MCP config fileServer listed
2Complete the OAuth sign-in when Cursor promptsConsent page on the MCP host
3Leave Write off for a first runRead-only access
4Call tools_list onceOnly read tools if Write is off
5Optionally call mcp_healthauth_source of mcp_oauth

Read-only first

By default hosted OAuth grants read-only access (mcp:read). Read tools such as jobs_list, assets_get, catalog_list and crawl_scrape work; write tools such as jobs_cancel and paid tools such as generate_image return insufficient_scope. To run them, grant mcp:write by switching Write on at consent. There is no mcp:paid scope.

If you need a key-based session instead, for automation, the key goes in a header from the environment, not in the file you commit.

Before the first paid call

Cursor can run MCP tools on your behalf, so decide in advance what you will allow to run unattended. A sensible default is to keep paid tools on manual approval, require idempotency_key in the instruction, and ask the agent to run tools_schema and a dry_run first. That keeps a stray prompt in a repository file from turning into a charge.

Check that the preview matches what you expect before approving: it shows the estimate, the balance and the queue behavior.

If the sign-in does not appear

Check three things in order. The URL must be exactly the production endpoint, with no extra path. The client must support remote HTTP MCP servers with OAuth, since a client limited to local stdio servers cannot connect to a hosted endpoint at all. And the browser that opens for consent must be able to reach mcp.sume.com. The consent page is served by the MCP host, so a corporate proxy that blocks that hostname will break the flow even when the rest of Sume works.

Once connected, account_me confirms the workspace context. The workspace comes from your sign-in, so there is nothing to type and no workspace id to pass. If a teammate clones the repository, they sign in with their own account; nothing about your session travels with the file.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume