cursor-relay-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CURSOR_API_KEY | No | Optional alternative authentication method. Do not use with stored login. For automation only; avoid putting it in config files or logs. | |
| CURSOR_RELAY_SETTING_SOURCES | No | Comma‑separated list of setting layers. Allowed values are 'project', 'team', 'mdm'. Invalid values are rejected. | project |
| CURSOR_RELAY_WORKSPACE_ROOTS | No | Static workspace allowlist as a comma-separated list of absolute paths. Required for unattended runs with fail‑closed security defaults. | |
| CURSOR_RELAY_ENABLE_DANGER_FULL_ACCESS | No | Optional. Set to 'true' at server startup to enable the 'danger-full-access' capability. Keep off for normal use. | |
| CURSOR_RELAY_READ_ONLY_SANDBOX_ENABLED | No | Optional. Set to 'false' to explicitly disable the sandbox on supported non‑Windows hosts. Windows always disables this. Applies only to the read‑only preset. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| doctorA | 检查 Cursor Relay 配置、认证与持久目录;不调用 Cursor 模型。 |
| list_modelsA | 从当前 Cursor 账户发现可用模型、别名与参数;start_run 前应调用。 |
| reauthenticate_cursorA | 当 Cursor SDK stored login 与用户确认的 Cursor 账户或套餐不一致时,打开系统浏览器重新登录并替换 SDK 本地凭据。不会读取或返回 API key;完成后必须重新调用 list_models 验证权限。 |
| authorize_workspaceA | 仅当用户在当前对话明确要求 Cursor Relay 读取或修改该工作区时调用。签发绑定当前 MCP 对话与精确工作区的可复用授权;read-only 与 workspace-write 均只传位置和范围,禁止传源码正文,由 Cursor 自行读取;不授予危险权限,进程结束即失效。 |
| start_runB | 在允许的本地工作区启动持久 Cursor Agent 运行。read-only 与 workspace-write 均只接受工作区、目标位置和任务范围,禁止嵌入源码正文;Cursor 自行读取所需文件。必须显式选择模型和幂等键。 |
| reply_runB | 在已结束的 Cursor Agent 会话中续接运行并保留 agentId;只传目标位置与任务范围,禁止源码正文,由 Cursor 自行读取。 |
| get_runB | 读取持久运行并重新附加事件观察;本地执行器退出后不会自动重启模型,execution.state=unknown 时需诊断。 |
| open_runA | 获取现有任务的本机只读进度链接,向用户展示可点击链接;不依赖 Codex MCP 沙箱。start_run/reply_run 成功后调用;沙箱报错时也用它查看原任务,禁止因此重复提交。 |
| read_run_progressA | 只读指定任务的持久状态与最近最多 200 条增量事件;不调用 SDK、不重连、不收敛超时。快照不是任务存活证明,实际监控仍用 wait_run。 |
| view_runA | 打开一个只读实时面板,展示指定 Cursor Relay 运行的状态、事件时间线与最终输出;不启动、续接、取消或修改运行。 |
| wait_runA | 最多等待 30 秒。mustCallAgain=true 时继续轮询;needsAttention=true 时停止无条件轮询并诊断,不能把未知执行状态当作失败或完成。 |
| cancel_runC | 取消仍在执行的 Cursor SDK 运行;重复取消具有稳定结果。 |
| list_runsB | 按创建时间倒序列出 Relay 持久运行。 |
| read_eventsC | 按递增序号读取已持久化的 Cursor SDK 流事件。事件数量有上限。 |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| cursor-relay-run-panel | 只读展示 Cursor Relay 运行状态与增量事件。 |
TDQS
Scored across 14 tools
Several tools target run observation and reading state (open_run, get_run, read_events, read_run_progress, view_run, wait_run), and their boundaries are subtle despite descriptions clarifying snapshot vs. streaming vs. live panel. Core run-control and auth tools are distinct, but the monitoring cluster invites misselection.
Almost all tools use snake_case verb_noun-style names such as list_models, start_run, and wait_run, with only doctor as a noun exception. The convention is predictable and readable.
14 tools is reasonable for auth, model discovery, workspace authorization, run lifecycle, and monitoring. The monitoring surface is somewhat heavy, but each tool maps to a defined operation.
The surface covers configuration/auth, model discovery, run creation, continuation, cancellation, listing, event reading, and progress monitoring. Explicit cleanup/prune/delete for persisted runs is missing, but the core lifecycle is otherwise covered.