Cursor project .cursor/mcp.json or global ~/.cursor/mcp.json for Sume?

Put a URL-only Sume entry in .cursor/mcp.json to share it with a repo, and keep any API key in an env variable in the global file, not in git.

3 min readSume
All posts

Use .cursor/mcp.json in the project root when the whole repo should offer Sume, and ~/.cursor/mcp.json when only you should. Both take the same url entry. Share the OAuth form, which is just the URL, and keep anything secret out of the committed file.

The two files

Cursor's docs list project-level .cursor/mcp.json and global ~/.cursor/mcp.json. A remote entry uses a url and optional headers. Cursor resolves variables in command, args, env, url and headers, including ${env:NAME}.

{
  "mcpServers": {
    "sume": { "url": "https://mcp.sume.com/mcp" }
  }
}

OAuth first, key second

With the entry above, Cursor prompts for sign-in and the consent page appears on the MCP host. A new teammate gets mcp:read unless they switch Write on, so committing the entry does not grant anyone write access.

If you need an API-key session, for example for a headless job, the key goes in a header: "Authorization": "Bearer ${env:SUME_API_KEY}". That session sees all tools. Put it in the global file, or keep the env variable set only where it is needed, and never commit the value.

File choice for Sume, read 2026-10-07
NeedFileEntry
Whole repo uses SumeProject .cursor/mcp.jsonURL only, OAuth
Only my machineGlobal ~/.cursor/mcp.jsonURL only, OAuth
API-key sessionGlobal file or CI envBearer header from ${env:SUME_API_KEY}

Check it works

Call tools_list once after connecting. If it shows only read tools, that is the default, not a fault.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume