Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Find a Cursor MCP server by starting with the task—not a popularity list. Identify the service, data, or action Cursor needs, then check whether a candidate is trustworthy, narrowly scoped, maintained, and compatible with your preferred setup. Start with Cursor’s official Marketplace and its Customize > MCPs flow when an official entry exists; treat community directories and shared install links as discovery aids, not security approval.

What an MCP server does in Cursor

MCP is the connection layer Cursor uses to reach external tools and data sources. An MCP server makes a service or capability available to Cursor through tools; depending on the server, those tools may read information, change something in an external service, or run code on your machine. The right choice is therefore the smallest server that completes the job, with no more data access or authority than that job requires.

Cursor’s security guidance is direct: “MCP servers can access external services and execute code on your behalf. Always understand what a server does before installation.” That warning applies whether you found a server in a curated listing, a code repository, or a link someone shared.

Where to find candidates

Start with Cursor’s official Marketplace

In Cursor, open Customize > MCPs to browse available servers. Where a maintained official entry exists, use its Add to Cursor flow and complete any authentication prompts. This is the most direct route for a server listed in Cursor’s own Marketplace, but installation through a listing does not remove the need to check what access the integration requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use community discovery to widen the search

Cursor also points users to cursor.directory for community discovery. Use a directory to identify candidates for the specific system you need to connect; then inspect the actual project or service behind the listing. A directory listing is not equivalent to an official Marketplace entry, and neither should substitute for reviewing tool behavior, permissions, and maintenance.

Inspect shared deeplinks before accepting

Cursor supports MCP installation deeplinks in this documented format:

cursor://anysphere.cursor-deeplink/mcp/install?name=$NAME&config=$BASE64_ENCODED_CONFIG

The link carries a server name and encoded JSON configuration into an install prompt. Treat it as a configuration payload to inspect, not as proof that the named server or its publisher is trustworthy. If you cannot determine what command, URL, credentials, or access the payload configures, do not approve it until you can.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to compare MCP servers for the same task

When several candidates appear to solve the same problem, compare them against the same checklist rather than choosing by tool count or name recognition.

Check What to establish Why it matters
Task coverage Which specific tools solve your job, and whether unrelated tools are included. A narrower server is easier to review and creates less unnecessary tool and context overhead.
Ownership and provenance Whether the listing is official, who maintains the repository, and whether ownership and source are clear. A service-owner-maintained integration gives you a clearer route to evaluate provenance than an unexplained package or reposted configuration.
Tool effects For each tool, what data it can read, what systems it can reach, and whether it can make changes. Names alone do not reveal whether a tool is read-only or has consequential side effects.
Transport Whether it runs locally over stdio or connects to a hosted endpoint using HTTP/SSE. The execution location, network boundary, and authentication model differ.
Credentials Which credentials are required, how they are supplied, and whether their access can be limited. Use a restricted key and avoid granting write access when read access is enough.
Maintenance Recent releases, issue activity, compatibility notes, and whether the project is archived or abandoned. These are practical health checks; Cursor does not publish a universal maintenance score.
Team controls Whether administrators can distribute or approve it, restrict tools, and govern network destinations. A server suitable for one developer may not fit an organization’s approval and network policies.

Choose the transport with the boundary in mind

A local stdio server runs a command on your computer with the permissions available to that process. It can keep execution local, but “local” does not mean harmless: inspect the command, arguments, and environment it needs. A remote HTTP/SSE server avoids starting that local process and can be easier to centralize, but requests go to a hosted endpoint and depend on its authentication and availability. Decide which boundary fits the task and your organization’s data-handling requirements; neither transport is automatically safer in every case.

Match access to the actual job

Map the server’s tools to the data and actions you intend to permit. Prefer read-only access if that is sufficient, use the narrowest practical API key, and keep tokens out of committed project configuration. If a server requests access unrelated to your task, choose a narrower alternative or do not install it.

Install a server in Cursor

Use the Marketplace flow for an official entry where available. For a server you have reviewed and need to configure directly, choose either project scope or user-wide scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Decide the scope. Put a project-specific configuration in .cursor/mcp.json. Use ~/.cursor/mcp.json for global configuration. Cursor merges the project and global files; if names collide, the project-level configuration takes priority.
  2. Choose the connection details. For local stdio, configure the server’s command, arguments, and environment variables. For a hosted integration, configure its URL and, where required, headers or OAuth. Get these values from the server’s official instructions and review them before saving; do not guess a command or endpoint.
  3. Protect secrets. Supply secrets using environment variables or supported authentication settings rather than hardcoding tokens in configuration that may be committed. Grant only the credential scope the integration needs.
  4. Save and authorize deliberately. Complete any authentication prompt only after you understand which account and permissions it grants. For an install deeplink, review the decoded configuration and resulting server details before accepting.
  5. Validate the connection. Check that the server appears in Cursor’s MCP interface and that its tools match the scope you expected. For command-line checks, use agent mcp list to see configured servers and status, and agent mcp list-tools <identifier> to inspect a server’s tool inventory.

Cursor’s project and global configuration files have different scopes; avoid copying a machine-specific command or secret into a project file merely to make setup easier. When a team manages MCP centrally, confirm that the configuration and permissions comply with its distribution and approval rules.

Check safety and team governance

Review a community server before running it

  • Confirm repository ownership and inspect the source code for integrations with sensitive data or consequential actions.
  • Check release activity, issue history, compatibility notes, and whether the project appears abandoned.
  • Read the startup command and arguments for local servers; identify the endpoint, headers, and authentication path for remote ones.
  • Compare the complete tool inventory with the task. Investigate tools that can write, execute, or reach data unrelated to the intended use.
  • Use restricted credentials and audit code for critical integrations before granting access.

Apply organization controls where available

Cursor’s enterprise controls can allowlist local command patterns and remote URLs, restrict tools, and set per-server network modes. Its security-hardening guidance also addresses plugin governance, network controls, secret protection, and approval of risky actions. Ask an administrator which controls apply before distributing a server to a team; an individual’s successful setup does not establish that organization-wide approval is in place.

Troubleshoot connection and tool problems

Symptom What to check Next step
Server does not appear in Cursor Whether the configuration is in the intended project or global file, and whether the server is listed in the MCP interface. Check the applicable file and Cursor’s MCP Logs. Confirm that the configuration describes the intended server and that you are looking at the right project scope.
Server is configured but not connected The local command, arguments, and required environment variables, or the remote URL and connection settings. Open MCP Logs and use agent mcp list to inspect status. Correct the failing configuration or connection detail, then reconnect.
Authentication fails Whether the server requires an authentication prompt, OAuth, headers, or a correctly supplied environment variable. Follow the server’s supported authentication flow, check the credential’s scope and availability, and replace any exposed token. Do not paste a secret into a committed file as a workaround.
Server starts and then crashes Startup details and MCP Logs for the error or crash information. Recheck the documented command, arguments, environment, and compatibility notes. If the server is community-maintained, check its issue history and release activity for related problems.
Unexpected tools or excessive access The server’s full tool list and the permissions of its credentials. Run agent mcp list-tools <identifier>, compare each tool with the task, and disable the server while reviewing it. If it is broader than necessary, remove it and choose a narrower option.

Cursor’s help guidance directs users to MCP Logs for connection errors, authentication failures, and crashes. Disable a server while troubleshooting or when its tools are not needed; re-enable it only when you are ready to use the reviewed configuration.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If the external task is taking website screenshots rather than connecting Cursor to a general-purpose data source, ScreenshotNeo is a focused alternative to try first: it is a screenshot API and MCP server with take_screenshot, get_page_info, and capture_pdf tools. Its request can return an image or PDF without setting up a browser capture workflow yourself. The API accepts a URL in one GET request; see the ScreenshotNeo API documentation for configuration details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

  • Cookie and consent banners, newsletter popups, and chat widgets are removed before the shot; each removal step can be turned off.
  • Bot checks, blank pages, and failed loads are never billed. Responses identify the page verdict and billing status in X-Page-Verdict and X-Billed headers.
  • An MCP server lets AI agents, including Claude, Cursor, and other MCP clients, take screenshots.
  • The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.

Sign up for 1,000 free screenshots a month—no card required.

Frequently Asked Questions

How often should I re-check an MCP server after installing it?

Revisit the repository’s release and issue activity when you update the server, change its credentials or permissions, or expand its use. Recheck compatibility when Cursor or the integration changes in a way that could affect the connection.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.