tgcc_ key is all you need — no OAuth flow.
Configure it
Project-level config lives in.cursor/mcp.json at the repo root; global config
in ~/.cursor/mcp.json. The shape is the same.
url rather than command is what makes it a remote server;
there is no separate transport flag to set.
Check it came up
Settings → Tools & MCP lists the server and the tools it discovered. A green state and a populated tool list means the handshake andtools/list both
succeeded.
If the server connects but every tool call fails, the key is missing that
tool’s scope —
mcp:connect lists tools and calls none. That split is
deliberate; see Authentication.Use it
Ask the agent in the chat pane for something the workspace knows:Search our knowledge base for the refund window and quote it back with the source.
Upload contract.pdf, then extract the parties and the notice period.
The second one will not finish in one call, and that is correct. Uploading a
document returns success while parsing continues, and extractions answer with
a job id rather than a result. The agent has to poll. See
Tools for the two behaviours and why they exist.
Keep the key narrow
Cursor runs tools inside an editor agent loop that will happily iterate. Mint a key for it with only the scopes you want an agent reaching unattended — reading agents and searching knowledge is a very different grant from creating extractions and spending credits.What each tool demands
Every tool names its own scope, checked on every call.

