Dome Systems

Cursor MCP servers and Dome

Cursor reaches your tools. Each developer signs in.

Put your Gateway in mcp.json and Cursor's first tool call opens a browser. Each developer signs in with their own Dome account. Every sign-in is a grant you can list and revoke, and a refused one is recorded against the person who tried.

Developers in CursorAgentsDomeTools & modelsCallersDevelopers in CursorAgentsgateway-interactive-1d85Agentscode-reviewerAgentsdocs-writerGatewayseng-gatewayGitHubMCP serverInternal toolsMCP serversclaude-opus-5-5Model poolRulesGuardsAuditsaudit-trail
gateway-interactive-1d85→github/merge_pull_request· as lena@example.comAllowed

How Dome helps

Dome provides governed MCP access for Cursor

A URL, no headers

The Gateway goes into mcp.json as a URL alone. Nothing secret sits in the file.

One repository or all of them

Use .cursor/mcp.json for one project, or ~/.cursor/mcp.json for every project. Both reach the same Gateway and the same rules.

Grants you can see

Every sign-in is a grant, listed in Dome. Revoke a contractor's on their last day and their token stops renewing.

Get started

Cursor on a Gateway in three steps

Allow your developers, permit the tools, and add one URL to Cursor's mcp.json.

  1. 01

    Turn on interactive access

    Choose who may sign in from Cursor: exact emails or identity provider subjects. Enabling access gives the Gateway one managed agent.

    $ dome gateways interactive enable eng-gateway \
    --email lena@example.com \
    --email omar@example.com
  2. 02

    Permit what it may call

    Cursor's calls run as that managed agent, so the rule below is applied to it. Find its name with dome gateways get.

    $ dome rules apply interactive-access.cedar \
    --agent gateway-interactive-<gateway-id> \
    --name interactive-access
  3. 03

    Add the Gateway to Cursor

    Put it in the project's .cursor/mcp.json, or ~/.cursor/mcp.json for every project. The first tool call opens a browser to sign in.

    $ cat > .cursor/mcp.json <<'EOF'
    $ {
    "mcpServers": {
    "dome": {
    "url": "https://<gateway-host>/gateways/<gateway-id>/mcp"
    }
    }
    $ }
    $ EOF

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Cursor itself, see Anysphere's documentation.

Rules

A rule for the managed agent

Anyone signed in can see the tools and use GitHub from Cursor. Merging stays with lena.

permit (
principal is Dome::Agent,
action == Dome::Action::"mcp:discover",
resource
);
 
permit (
principal is Dome::Agent,
action == Dome::Action::"mcp:call",
resource is Dome::MCPTool
) when { resource.connection_name == "github" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "github" &&
resource.tool_name == "merge_pull_request"
}
unless {
principal has act_as &&
principal.act_as.email == "lena@example.com"
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Signed in as

agent gateway-interactive-1d85 · acting as lena@example.com
github/merge_pull_request(owner: "acme", repo: "app", pullNumber: 905)
  1. Sign-inlena@example.com is on the allow-list
  2. TokenInteractive token for eng-gateway, still valid
  3. RuleMerges are open to lena
DecisionAllowed

Agent workflow

Bringing it together

Connecting Cursor to registered tools and models in Dome completes a governed agent application.

Dome

Agent

Client

Cursor

This page

Client

Claude Code

See how

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How do I add a remote MCP server to Cursor?

Add its URL under mcpServers in .cursor/mcp.json, or in Cursor's MCP settings. For a Dome Gateway, leave out the headers block.

Does Cursor need an API key for the Gateway?

No. The first tool call opens a browser to sign in, and Cursor renews its short-lived token on its own.

Can my team share the Cursor MCP config?

Yes. Commit .cursor/mcp.json with the code. It holds the Gateway URL and nothing else.

Is a refused sign-in recorded?

Yes. Dome files the refusal in audit against the person who tried, with the reason it was refused.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.