Product and engineering

The Cursor connector.

AI coding agents that open pull requests. Connect once with your own key. Every agent your team runs reads the same 9 tools under one permission model.

How access is governed

5

Read tools

Open by default. They run when called, and every call is logged with the endpoint, tool and capability.

2

Write tools

Available through governed Slack workflows. MCP endpoints do not expose write tools.

2

Destructive tools

Admin-only in supported workflows, and never exposed over MCP.

Defaults come from the capability on each tool definition, and an admin can tighten or open any tool individually. The endpoint's capability ceiling can only tighten that policy. An endpoint scoped to read never surfaces a write tool.

Every Cursor tool

9 tools, named as the agent sees them.

  • launch_agentwrite

    Launch a Cursor background agent to write code and create a PR.

  • get_agent_statusread

    Check the current status of a Cursor agent.

  • list_agentsread

    List all Cursor agents. Shows recent and running agents.

  • add_followupwrite

    Send additional instructions to a running Cursor agent.

  • stop_agentdestructive

    Pause a running Cursor agent. Can be resumed later with add_followup.

  • delete_agentdestructive

    Permanently delete a Cursor agent.

  • get_agent_conversationread

    Get the full conversation history of a Cursor agent.

  • list_repositoriesread

    List accessible GitHub repositories. Rate-limited: 1/minute, 30/hour.

  • get_cursor_inforead

    Get information about the Cursor API key in use.

Use it from any agent

The same Cursor tools reach Claude Code, Cursor, Claude Desktop or your own agent through one MCP endpoint. The endpoint is scoped to a group, the token is issued per group and revocable from the dashboard, and an allowed-tool list and capability ceiling limit what it exposes. Reads run. Gated writes refuse unless an admin opens them. Destructive tools remain unavailable over MCP.

.mcp.json · works for Cursor and Claude Desktop too
{
  "mcpServers": {
    "growth": {
      "type": "http",
      "url": "https://app.notara.ai/mcp/g/acme/growth",
      "headers": {
        "Authorization": "Bearer ntr_mcp_xxxxxxxxxxxxxxxxxxxx"
      }
    }
  }
}

The URL and token are placeholders. Real endpoints are issued per group from the dashboard.

Setup

  1. 01

    Create a Cursor API Key in your Cursor account (where to find it). The key is yours: Notara stores it encrypted and never sees a bill.

  2. 02

    Paste it into the Notara dashboard. Credentials can be scoped to the workspace or to one person.

  3. 03

    The tools appear with their capability defaults already set. Tighten or open any of them per tool, then invite the agent to a channel or issue an MCP token.

More in product and engineering

Connect Cursor once. Use it everywhere.

Use Notara directly, or bring us the workflow that needs to be redesigned and built.