Cursor MCP servers and Dome
Cursor reaches your tools. Each developer signs in.
Put your Gateway in mcp.json and Cursor's first tool call opens a browser. Each developer signs in with their own Dome account. Every sign-in is a grant you can list and revoke, and a refused one is recorded against the person who tried.
How Dome helps
Dome provides governed MCP access for Cursor
A URL, no headers
The Gateway goes into mcp.json as a URL alone. Nothing secret sits in the file.
One repository or all of them
Use .cursor/mcp.json for one project, or ~/.cursor/mcp.json for every project. Both reach the same Gateway and the same rules.
Grants you can see
Every sign-in is a grant, listed in Dome. Revoke a contractor's on their last day and their token stops renewing.
Get started
Cursor on a Gateway in three steps
Allow your developers, permit the tools, and add one URL to Cursor's mcp.json.
01
Turn on interactive access
Choose who may sign in from Cursor: exact emails or identity provider subjects. Enabling access gives the Gateway one managed agent.
$ dome gateways interactive enable eng-gateway \--email lena@example.com \--email omar@example.com02
Permit what it may call
Cursor's calls run as that managed agent, so the rule below is applied to it. Find its name with dome gateways get.
$ dome rules apply interactive-access.cedar \--agent gateway-interactive-<gateway-id> \--name interactive-access03
Add the Gateway to Cursor
Put it in the project's .cursor/mcp.json, or ~/.cursor/mcp.json for every project. The first tool call opens a browser to sign in.
$ cat > .cursor/mcp.json <<'EOF'$ {"mcpServers": {"dome": {"url": "https://<gateway-host>/gateways/<gateway-id>/mcp"}}$ }$ EOF
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Cursor itself, see Anysphere's documentation.
Rules
A rule for the managed agent
Anyone signed in can see the tools and use GitHub from Cursor. Merging stays with lena.
permit ( principal is Dome::Agent, action == Dome::Action::"mcp:discover", resource); permit ( principal is Dome::Agent, action == Dome::Action::"mcp:call", resource is Dome::MCPTool) when { resource.connection_name == "github" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "github" && resource.tool_name == "merge_pull_request"}unless { principal has act_as && principal.act_as.email == "lena@example.com"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Signed in as
- Sign-inlena@example.com is on the allow-list
- TokenInteractive token for eng-gateway, still valid
- RuleMerges are open to lena
Agent workflow
Bringing it together
Connecting Cursor to registered tools and models in Dome completes a governed agent application.
Acting for
Agent
Client
Cursor
This page
Client
Claude Code
See how
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
FAQ
Common questions
How do I add a remote MCP server to Cursor?
Add its URL under mcpServers in .cursor/mcp.json, or in Cursor's MCP settings. For a Dome Gateway, leave out the headers block.
Does Cursor need an API key for the Gateway?
No. The first tool call opens a browser to sign in, and Cursor renews its short-lived token on its own.
Can my team share the Cursor MCP config?
Yes. Commit .cursor/mcp.json with the code. It holds the Gateway URL and nothing else.
Is a refused sign-in recorded?
Yes. Dome files the refusal in audit against the person who tried, with the reason it was refused.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreMCP server
Atlassian
The Atlassian Rovo MCP server behind the Tool Gateway, with rules that decide each Jira and Confluence call on its tool and site.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
Claude Code, Cursor and Codex: governed MCP access for your people
People connect Claude Code, Cursor or Codex to a Gateway and sign in with their own Dome account. Nobody holds a shared key, and every call is audited under the person who made it.
See them all