ScreenshotNeo

BlogAI agents

What Is an MCP Server in Cursor?

An MCP server lets Cursor connect its Agent to external tools and data. Learn transports, setup, security, troubleshooting, and practical examples.

By the ScreenshotNeo team1 October 20268 min read

Short answer: An MCP server in Cursor is software that exposes tools, prompts, resources, or data through the Model Context Protocol (MCP). Cursor’s Agent connects to that server and can call its capabilities during a conversation. MCP is an integration layer; it is not a physical server that you need to purchase and it does not perform a task by itself.

Cursor describes MCP as the way it connects to external tools and data sources. The specific MCP server determines what the Agent can do, what authentication it needs, where it runs, and which permissions apply. A GitHub server might expose issue and pull-request tools, while a database server might expose read or query operations.

How MCP works in Cursor

  1. You install or configure an MCP server.
  2. Cursor starts a local process or connects to a remote endpoint using a supported transport.
  3. The server advertises its available tools, prompts, and resources.
  4. Cursor shows those capabilities to Agent when the server is enabled.
  5. Agent chooses a relevant tool, proposes arguments, and follows your approval and run-mode settings.
  6. The server executes the request and returns a result that Cursor displays in chat.

The connection can also support interactive MCP Apps in Cursor versions that provide that extension. Treat the app interface as an optional presentation layer; the underlying server still defines the capabilities and permissions.

What an MCP server provides

Capability What it means in practice
Tools Callable operations such as searching issues, reading a document, querying a service, or creating a record.
Prompts Reusable prompt templates supplied by the server.
Resources Readable context such as files, records, schemas, or generated data.
Protocol extensions Optional features implemented by a particular server or client version.
MCP Apps Interactive UI experiences supported as a progressive enhancement in compatible clients.

Installing a server does not automatically grant access to its connected service. You may still need an API key, OAuth login, network access, workspace permissions, and approval for individual tool calls.

Cursor MCP transports

Cursor documents three connection patterns. Select one based on where the server runs and how you want to authenticate it.

Transport Typical deployment Configuration shape
stdio A local process launched by Cursor Executable command, arguments, environment variables, and optionally an environment file
SSE A local or remote server with a Server-Sent Events endpoint Endpoint URL plus headers or OAuth-related settings
Streamable HTTP A local or remote HTTP server Endpoint URL plus headers or OAuth-related settings

Not every MCP server supports every transport. Check that server’s documentation before choosing a configuration.

Install an MCP server in Cursor

Option 1: one-click installation

Cursor’s Customize interface can list MCP servers. Open Customize, browse the MCP listings, select a server, and complete any authentication prompts. Team marketplaces and official plugins can provide additional distribution methods. Listings change, so verify the server’s publisher, required permissions, and supported transport before enabling it.

Option 2: project or global configuration

For manual setup, create one of these files:

  • .cursor/mcp.json in a project for a project-specific server.
  • ~/.cursor/mcp.json for a server available across your projects.

A local stdio server typically looks like this:

{
  "mcpServers": {
    "example-local": {
      "command": "npx",
      "args": ["-y", "@example/mcp-server"],
      "env": {
        "EXAMPLE_API_KEY": "${env:EXAMPLE_API_KEY}"
      }
    }
  }
}

Use the exact package name, command, and environment variable required by the server you install. The example shows the configuration shape; it is not a claim that this package exists.

A remote server configuration uses a URL. The precise key names can vary by Cursor version and server instructions, so follow Cursor’s current schema and the server’s documentation. A representative shape is:

{
  "mcpServers": {
    "example-remote": {
      "url": "https://service.example.com/mcp",
      "headers": {
        "Authorization": "Bearer ${env:EXAMPLE_TOKEN}"
      }
    }
  }
}

Keep secrets in environment variables or the supported OAuth flow. Do not commit API keys to a project-level mcp.json.

Option 3: programmatic registration

Cursor also documents an extension API for registering an MCP server without editing mcp.json. This is useful for automated or enterprise setup, where an extension or managed configuration can register servers consistently.

Use MCP tools in Cursor Agent

  1. Enable the configured server in Cursor’s MCP settings.
  2. Open an Agent conversation.
  3. Ask for the task in normal language, or name a specific tool when you need deterministic behavior.
  4. Review the proposed tool and arguments.
  5. Approve the call unless your configured run mode already allows it.
  6. Inspect the returned data and ask Agent to continue with that context.

For example, you could ask an enabled issue-tracking server to find open bugs assigned to you, ask a documentation server to locate an API example, or ask a database server to inspect a schema. The server implementation controls whether those operations are available and whether they are read-only or mutating.

Cursor requests approval by default in supported versions, and its run modes can change how approvals and allowlists work. Review the current Cursor settings before allowing automatic execution. Team and enterprise administrators can distribute servers, restrict which servers are allowed, and apply network policies. Distribution does not mean every teammate has installed or enabled a server.

Inspect MCP servers with the Cursor CLI

The Cursor CLI shares MCP configuration with the editor. These commands help diagnose what is configured:

# List configured servers
agent mcp list

# List tools exposed by one configured server
agent mcp list-tools <identifier>

# Use the CLI's documented login, enable, and disable commands
# for servers that support those operations.

Run the commands in the environment where the Cursor CLI is installed. The identifier is the server name from your configuration.

Security and permission model

  • Credentials: Treat an MCP configuration as access to the connected service. Use environment-variable interpolation, an environment file, or OAuth rather than hardcoding secrets.
  • Tool arguments: Read the tool name and arguments before approval. A tool that creates, deletes, sends, or modifies data needs stronger review than a read-only lookup.
  • Local trust: A stdio server runs code on the same machine as Cursor. Install only servers you trust and understand.
  • Remote trust: A remote endpoint receives the requests and credentials you send to it. Check its owner, transport security, data handling, and authentication method.
  • Workspace scope: Project configuration can affect anyone who opens the repository. Keep shared configuration free of personal secrets and document required environment variables.
  • Administration: Team and enterprise controls may limit distribution, execution, allowlists, and network access. A marketplace listing is not a security review.

Common MCP errors and fixes

Error or symptom Likely cause Fix
Server does not appear Invalid JSON, wrong file path, or the server is disabled Validate mcp.json, confirm you used .cursor/mcp.json or ~/.cursor/mcp.json, then enable the server and restart Cursor if needed.
Command not found The executable is not installed or is missing from Cursor’s PATH Install the required runtime/package and use an absolute command path when appropriate.
Server starts then exits Missing environment variable, invalid argument, incompatible runtime, or an application error Run the command manually, check its logs, verify every required variable, and compare arguments with the server documentation.
Unauthorized or forbidden Missing, expired, or insufficient credentials Repeat the server’s login/OAuth flow or rotate the token; confirm the account has access to the requested resource.
Remote connection times out Incorrect URL, firewall, proxy, DNS, or a server outage Open the endpoint from the same network, verify the transport path, and check proxy and enterprise network rules.
Tool is unavailable to Agent The server did not advertise it, the tool is disabled, or policy blocks it Use agent mcp list-tools, inspect Cursor’s enabled-server and allowlist settings, and confirm the server version supports the tool.
Tool call is repeatedly rejected Approval or run-mode policy requires manual confirmation Review the proposed arguments and approve the call, or adjust the relevant Cursor policy only if your team permits it.
Wrong or stale results External data changed, the server cached a response, or Agent supplied an ambiguous argument Ask for a fresh lookup, specify identifiers and time ranges, and verify the returned record in the source service.

Performance, reliability, and cost considerations

Performance

  • Local stdio avoids a network hop but still depends on process startup and the server’s dependencies.
  • Remote SSE and Streamable HTTP add network latency and can be affected by DNS, proxies, TLS, and endpoint load.
  • Keep tool results focused. Large responses consume context and make Agent reasoning slower; prefer server-side filters, pagination, and explicit fields.
  • For repeated work, ask the server for a narrow resource or query rather than loading an entire project or database.

Reliability

Failures can occur in Cursor, the MCP transport, the server process, authentication, or the downstream service. Log the tool name, request identifier if provided, transport, and error message. Retry only idempotent reads automatically; confirm before repeating a mutation that may have succeeded even if the response was lost.

Cost

MCP itself does not define a universal price. Costs may come from Cursor, the connected API, a hosted MCP provider, infrastructure, or database usage. Check each service’s pricing and rate limits. A free server can still call a paid downstream API.

Or skip the browser setup

If your Agent needs website screenshots, ScreenshotNeo provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. It removes cookie and consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and each response reports the page verdict and billing status in headers.

You can also call its HTTP API directly. See the ScreenshotNeo API documentation for configuration details.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo supports full-page and element captures, device presets, custom viewports, retina scale, dark mode, PDF output, custom CSS and JavaScript, selectors to hide, waits, request blocking, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, caching, signed links, asynchronous jobs, webhooks, bulk capture, usage information, and an OpenAPI specification. Its plans include 1,000 free shots per month without a card; paid plans start at $5 for 3,000 shots.

Create a free ScreenshotNeo account and start with 1,000 screenshots per month at no cost.

FAQ

Is an MCP server the same as an API?

No. An API is an interface exposed by a service. An MCP server adapts capabilities to the Model Context Protocol so an MCP client such as Cursor can discover and call them in a standard way.

Do I need to host an MCP server myself?

No. A server may be a local process, a remote service, or a hosted integration. Your choice depends on trust, deployment, authentication, and maintenance requirements.

Can Cursor call MCP tools without asking?

Approval behavior depends on Cursor’s version and run-mode settings. Review the current approval and allowlist controls, especially for tools that change external data.

Can one project use several MCP servers?

Yes. Configure multiple entries and enable the servers you need. Give each one a clear name and limit overlapping tools when you want predictable Agent behavior.

Are MCP servers available in the Cursor CLI?

Yes. The CLI uses the editor’s MCP configuration and provides commands to list servers and inspect their tools.