Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An MCP server in Cursor is software that exposes tools, data, prompts, or other capabilities through the Model Context Protocol (MCP), so Cursor’s Agent can use them during a conversation. It is not a physical server that you must purchase, nor a standalone Cursor feature that performs a task by itself. MCP is the integration layer; the individual server determines what Cursor can do and what account, permissions, and authentication it needs.

What MCP means in Cursor

Cursor’s documentation defines MCP this way: “MCP enables Cursor to connect to external tools and data sources.” In practice, you configure an MCP server, Cursor connects to it using a supported transport, and the server advertises capabilities that Agent may call or read.

A server might expose a GitHub issue lookup, a Linear project tool, a Notion search, a database resource, or a prompt template. MCP supplies the common protocol; it does not guarantee that every server supports the same operations, authentication method, or transport.

What an MCP server can provide

  • Tools: callable actions such as creating an issue, querying a service, or running a developer operation.
  • Resources: readable data exposed to the client.
  • Prompts: reusable prompt instructions supplied by the server.
  • Extensions and MCP Apps: Cursor’s current overview also documents protocol extensions and interactive app interfaces as progressive enhancements.

The service behind the server still controls its own data and permissions. Installing an integration does not automatically grant access to a private repository, workspace, or database.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Cursor uses an MCP server

  1. You install or configure a server in Cursor.
  2. Cursor starts a local process or connects to a remote endpoint using the configured transport.
  3. The server advertises its available tools, resources, and prompts.
  4. Those capabilities become available to Agent when the server is enabled.
  5. You ask Agent for a task. Agent can select a relevant tool, show the call and result in chat, and follow Cursor’s approval and run-mode rules.

Cursor requests approval by default in documented configurations. Depending on your version and settings, you may use review or allowlist controls. Read the proposed tool name and arguments before approving an action, especially when it can modify files, create records, send messages, or spend money.

Connection types: stdio, SSE, and Streamable HTTP

Transport Where it runs Typical configuration Important considerations
stdio A local process started by Cursor command, optional args, env, and sometimes envFile Good for a program on your computer; protect local credentials and verify the executable.
SSE Local or remote service An SSE endpoint URL, with headers or an authentication flow where supported Check endpoint trust, network policy, and whether the service is still maintained.
Streamable HTTP Local or remote service An HTTP endpoint URL, with headers or OAuth-related settings where supported Useful for hosted deployments; secure the endpoint and avoid putting secrets in shared files.

Not every implementation supports every transport. Choose based on deployment: use stdio when Cursor should launch a local command, and use SSE or Streamable HTTP when the server is exposed as a service.

Installing an MCP server in Cursor

One-click installation

  1. Open Cursor’s Customize interface.
  2. Browse the MCP listings, team marketplace, or official plugin catalog.
  3. Select a server and follow its authentication prompts.
  4. Open the server’s settings and confirm that it is enabled.
  5. Start an Agent conversation and ask for a task that requires one of its tools.

Listings can change, and an administrator-distributed server is not necessarily installed or enabled for every teammate.

Manual project configuration

Create .cursor/mcp.json in the project when the server should be available to that workspace. A typical local command entry has this shape:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
{
  "mcpServers": {
    "example-local": {
      "command": "node",
      "args": ["/absolute/path/to/server.js"],
      "env": {
        "SERVICE_TOKEN": "${env:SERVICE_TOKEN}"
      }
    }
  }
}

Keep the real token in your environment rather than committing it. Cursor documents environment-variable and workspace-path interpolation; use those mechanisms instead of hardcoding secrets.

Global configuration

Put shared personal servers in ~/.cursor/mcp.json. Project configuration is easier to review with a repository, while global configuration avoids repeating the same setup across projects. Follow your organization’s policy before placing a server in a shared project file.

Programmatic registration

Cursor also documents an extension API for registering MCP servers without editing mcp.json. This is aimed at automated or enterprise setup and can be useful when administrators need consistent configuration.

Using MCP tools in Agent chat

After a server is enabled, its tools can appear among Agent’s available tools. You can describe the outcome (“find the open authentication issues assigned to me”) or request a specific tool by name. Cursor displays calls and results in the conversation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make requests bounded and explicit. State the project, account, time range, and whether Agent may make changes. For a write operation, ask Agent to show a plan or draft first, then approve the final call.

Inspecting servers with the Cursor CLI

Cursor’s CLI shares MCP configuration with the editor. These documented commands help diagnose setup:

agent mcp list
agent mcp list-tools <identifier>

The CLI also provides commands to log in, enable, or disable a server. If a server appears in the editor but not in the CLI, check that both use the same user profile and configuration scope.

Security, authentication, and administration

Credentials are service access

Treat an MCP configuration as access to the connected service. Use environment-variable interpolation, an environment file excluded from version control, or the server’s supported OAuth flow. Do not paste long-lived production tokens into a project file or chat.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Approval is a safety boundary

Approval settings reduce accidental actions, but they do not make an untrusted server safe. Before enabling one, inspect its source, command, network destinations, requested scopes, and update process. Review every sensitive tool call and its arguments.

Team and enterprise controls

Team administrators can distribute MCP servers. Enterprise administrators can configure allowlists and network restrictions. Distribution and permission are separate controls: a server can be listed or distributed without being installed, enabled, or authorized for every user.

Local versus remote trust

  • A local stdio server can read files and environment variables available to its process.
  • A remote server can receive the requests and credentials you send to its endpoint and may be subject to different network logging and retention policies.
  • Use the least-privileged account and scopes that satisfy the task.

Common problems and fixes

The server does not appear

Confirm the file is named exactly mcp.json, is in the intended project or home directory, and contains valid JSON. Restart or reload Cursor after changing configuration, then check the MCP settings and agent mcp list.

“Command not found” or immediate process exit

Use an absolute executable path or ensure the runtime is on Cursor’s PATH. Run the same command in a terminal, verify the server’s required Node, Python, or other runtime version, and inspect its stderr output.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authentication fails

Check that the environment variable is present in the process Cursor actually launches. Confirm token scope, expiration, account, and endpoint URL. For OAuth, complete the server’s sign-in flow rather than substituting a personal token unless its documentation explicitly supports that method.

Tools are listed but calls fail

Read the returned error and validate required arguments, workspace identifiers, and permissions. A tool can be visible while the connected account lacks access to the requested resource.

Agent never chooses the tool

Make the request specific, mention the service or tool, and verify that the server is enabled. Check whether approval or an administrator allowlist is blocking execution. You can ask Agent to list the relevant available tools before retrying.

A remote connection times out

Test the endpoint from the same network, check proxy and firewall rules, confirm the transport expected by the server, and verify that required headers are configured. A browser opening the URL does not prove that the MCP endpoint is reachable or speaks the correct protocol.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing an MCP server

Compare candidates on the dimensions that affect real operation:

  • Transport and deployment: local stdio, remote SSE, or Streamable HTTP.
  • Capabilities: the exact tools, resources, prompts, and write actions exposed.
  • Authentication: OAuth, API key, environment variable, or another method.
  • Maintenance and trust: source availability, update process, and requested permissions.
  • Approval and administration: whether your Cursor settings or organization allow it.
  • Operational fit: latency, network requirements, logging, and failure behavior.

Examples named in Cursor’s materials include GitHub, Linear, Notion, Sentry, Figma, Playwright, DuckDB, Vercel, and GitLab. Availability and marketplace listings can change, so verify the current entry and permissions before relying on one.

ScreenshotNeo as an MCP example

ScreenshotNeo is a website screenshot API and MCP server for developers. Its MCP tools—take_screenshot, get_page_info, and capture_pdf—illustrate the model: an AI client such as Cursor can call a specialized external capability instead of implementing browser automation itself.

Or skip the browser setup

For a direct API call, see the ScreenshotNeo documentation. cURL:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server lets AI agents take screenshots; 1,000 screenshots per month are free with no card, and paid plans start at $5 for 3,000. Sign up for the free plan.

Frequently Asked Questions

Is an MCP server the same thing as an API?

Not exactly. An MCP server can call APIs internally, but it presents capabilities through the Model Context Protocol so an MCP client such as Cursor can discover and use them in context.

Do I need to host an MCP server myself?

No. Cursor can start a local stdio server, or connect to a hosted SSE or Streamable HTTP endpoint. Hosting responsibility depends on the server you choose.

Can an MCP server read my whole computer?

Only if the process and its configured tools have that access. Review the command, environment, filesystem scope, network permissions, and tool definitions before enabling it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.