Skip to content
Proud to collaborate with Microsoft for Startups

Cursor MCP client setup ​

Cursor is a remote Streamable HTTP client. Point it at https://mcp.orkestia.dev/mcp. Use OAuth for interactive developer sessions, or a bearer token from Settings → API tokens.

GET on that URL returns 405 — Cursor must use Streamable HTTP (POST). The server advertises OAuth at /.well-known/oauth-protected-resource/mcp.

Config ​

Project: .cursor/mcp.json. Global: ~/.cursor/mcp.json.

OAuth (Cursor discovers metadata and opens the browser):

json
{
  "mcpServers": {
    "orkestia": {
      "type": "http",
      "url": "https://mcp.orkestia.dev/mcp"
    }
  }
}

Bearer token (no browser OAuth):

json
{
  "mcpServers": {
    "orkestia": {
      "type": "http",
      "url": "https://mcp.orkestia.dev/mcp",
      "headers": {
        "Authorization": "Bearer ${env:ORKESTIA_TOKEN}"
      }
    }
  }
}

Keep ORKESTIA_TOKEN in the environment, not committed in the file.

OAuth callbacks ​

If OAuth registration fails, the redirect URI is not allowlisted. Cursor uses:

SurfaceRedirect URI
Desktophttp://localhost:8787/callback
Web / Cursor Agentshttps://www.cursor.com/agents/mcp/oauth/callback

The public MCP server must list those exact URIs in OAUTH_REDIRECT_URI_ALLOWLIST, and OAUTH_ALLOW_LOOPBACK_REDIRECT=true for desktop.

Smoke test ​

  1. Reload MCP servers in Cursor (Customize → MCP).
  2. Complete OAuth or confirm the bearer header.
  3. Confirm Cursor lists workflow tools.
  4. Run whoami first. Do not pass organization_uuid.
  5. Run list_workflow_types and get_workflow_schema.

Official docs ​