Cursor team MCP servers: share Sume's hosted MCP across a team
Cursor's docs describe project, global and team MCP servers. Where Sume's hosted MCP fits in each, how sign-in works per person, and what a shared key changes.

To share Sume's hosted MCP server across a Cursor team, add it as a team server in Cursor's dashboard, or commit it to a project's .cursor/mcp.json so everyone in the repository gets it. Each person should sign in with their own OAuth consent rather than share one API key, because a shared key gives every teammate the same spending power.
The Cursor facts come from Cursor's MCP documentation, read 2026-09-29. The Sume facts come from its MCP quickstart and OAuth pages.
Where can a Cursor MCP server live?
Cursor's page lists a project file, a global file and team-managed servers.
| Scope | Where | Who gets it |
|---|---|---|
| Project | .cursor/mcp.json | Everyone who opens the repository |
| Global | ~/.cursor/mcp.json | You, in every project |
| Team | Dashboard > Plugins & MCPs; Team Marketplace | Members of the team |
What is the Sume entry?
The entry is a url, as Sume's quickstart shows. Cursor's page says url and headers are the remote-server options.
{
"mcpServers": {
"sume": {
"url": "https://mcp.sume.com/mcp"
}
}
}How does sign-in work for each person?
With no header, Cursor starts the OAuth flow and consent appears on the MCP host. Default consent is read-only (mcp:read); a person who wants the paid tools switches Write on, which adds mcp:write. There is no mcp:paid scope. So a team can share the entry while each person decides their own access.
What changes if the team shares one API key?
A key gives the full hosted tool set, and spend goes through wallet and admission checks. Every teammate using it can start paid generations. If you do share one, keep it out of the committed file, use Cursor's header support with a secret, and ask each agent to preview with dry_run=true and pass max_spend_usd.
Sume's docs say not to store OAuth tokens as keys and to rotate an API key if it appears in logs or chat.
How do I keep the tool list manageable?
Cursor's docs say it uses MCP tools listed under Available Tools when relevant. Sume's tool set is long, so check the guidance on tool limits and keep the model's choice small for tasks that only need video.
Sources
Related posts
More in Integrations
- EventBridge API destinations: call a paid API without Lambda
An EventBridge API destination calls an HTTPS API straight from a rule, with a 5-second timeout and retries on 409, 429 and 5xx. Key every call.
- Golang HTTP POST JSON with headers and a Bearer token
http.Post can't set headers. Marshal the JSON, build it with http.NewRequest, set headers, send with a Client that has a Timeout, and close the body.
- GPT-6 Sol and Luna in Codex: keep your Sume MCP server across models
Codex added GPT-6 Sol and Luna to its model picker in late September. Your Sume MCP server is configured per Codex, not per model, so switching needs no change.
- Grok Build: add Sume's hosted MCP server with grok mcp add
Grok Build takes remote MCP servers via grok mcp add --transport http. Add mcp.sume.com, pass an API key header or use OAuth, and check with grok mcp doctor.
Written by Sume