Cursor MCP auth block with CLIENT_ID and CLIENT_SECRET: skip for Sume

Cursor's mcp.json supports an auth block with CLIENT_ID and CLIENT_SECRET for servers that need a fixed client. Sume's hosted OAuth does not; use just the URL.

4 min readSume
All posts

You do not need the auth block in Cursor's mcp.json for Sume. Cursor documents it as a way to supply a static OAuth client, with CLIENT_ID, optional CLIENT_SECRET and scopes, for servers that need one. Sume's hosted server registers clients dynamically as public clients, so the Sume quickstart config is just the URL. Cursor then runs the OAuth sign-in when it prompts you.

What each side documents

The Cursor column is from its own docs page. The Sume column is from the quickstart and the OAuth page. Sume's consent page lives on the MCP host, and write access is a toggle on that page.

Static OAuth settings in Cursor versus Sume's hosted OAuth (Cursor docs and Sume docs, read 2026-10-06)
ItemCursorSume hosted MCP
Config filesProject .cursor/mcp.json and global ~/.cursor/mcp.jsonQuickstart entry is a url under mcpServers
Static clientauth block with CLIENT_ID, CLIENT_SECRET, scopesNot needed
Redirect URLs listed by Cursorhttps://www.cursor.com/agents/mcp/oauth/callback and http://localhost:8787/callbackHandled by dynamic registration
ScopesWhatever you list in authmcp:read required; mcp:write opt-in at consent

When you would still touch it

If a different server needs fixed credentials, the auth block is the Cursor feature for it. For Sume, adding a made-up client id just gives the server something to reject. Sume's OAuth page also says not to mint API keys for hosted OAuth clients as a workaround.

If you want write tools, do not try to get them through the config. Turn Write on at the consent page. If you want the opposite, a read-only session, leave it off and the paid tools stay hidden from the tool list.

  • Start with only url.
  • Sign in when Cursor prompts, then call tools_list.
  • If the sign-in fails, check the host first: it must be mcp.sume.com.

The tradeoff

Dynamic registration is convenient, but it means the client identity is not pinned to you. If your organization requires a fixed, auditable client id for every connector, ask Sume whether that is possible; the docs do not describe a static-client option for hosted MCP, so this post does not claim one.

If you manage Cursor for a team, the project file .cursor/mcp.json is the one to share in a repository, and the global ~/.cursor/mcp.json is for personal servers. Neither needs a secret for Sume, which keeps the shared file safe to commit. Never put an API key in a committed file.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume