Cursor MCP client setup
Cursor is a remote Streamable HTTP client. Point it at https://mcp.orkestia.dev/mcp. Use OAuth for interactive developer sessions, or a bearer token from Settings → API tokens.
GET on that URL returns 405 — Cursor must use Streamable HTTP (POST). The server advertises OAuth at /.well-known/oauth-protected-resource/mcp.
Config
Project: .cursor/mcp.json. Global: ~/.cursor/mcp.json.
OAuth (Cursor discovers metadata and opens the browser):
json
{
"mcpServers": {
"orkestia": {
"type": "http",
"url": "https://mcp.orkestia.dev/mcp"
}
}
}Bearer token (no browser OAuth):
json
{
"mcpServers": {
"orkestia": {
"type": "http",
"url": "https://mcp.orkestia.dev/mcp",
"headers": {
"Authorization": "Bearer ${env:ORKESTIA_TOKEN}"
}
}
}
}Keep ORKESTIA_TOKEN in the environment, not committed in the file.
OAuth callbacks
If OAuth registration fails, the redirect URI is not allowlisted. Cursor uses:
| Surface | Redirect URI |
|---|---|
| Desktop | http://localhost:8787/callback |
| Web / Cursor Agents | https://www.cursor.com/agents/mcp/oauth/callback |
The public MCP server must list those exact URIs in OAUTH_REDIRECT_URI_ALLOWLIST, and OAUTH_ALLOW_LOOPBACK_REDIRECT=true for desktop.
Smoke test
- Reload MCP servers in Cursor (Customize → MCP).
- Complete OAuth or confirm the bearer header.
- Confirm Cursor lists workflow tools.
- Run
whoamifirst. Do not passorganization_uuid. - Run
list_workflow_typesandget_workflow_schema.
