Skip to main content
AI client guides

Connect Cursor to StackJack

Cursor is an AI-first code editor with built-in MCP support (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). Since Cursor v1.0 it can sign in to a remote…

Written By Christopher Scaminaci

Last updated 6 days ago

Cursor is an AI-first code editor with built-in MCP support (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). Since Cursor v1.0 it can sign in to a remote server with just the URL — no headers.

Prerequisites

  • Cursor v1.0 or later for URL-only sign-in.
  • A StackJack account that is a member of your workspace. Any team member can connect — no admin-created credentials needed for the sign-in path.
  • Your StackJack MCP endpoint URL. Copy it from the MCP Setup page in the portal — that card shows the address for your workspace's region. The examples in this guide use the US address, https://mcp.stackjack.io/mcp; other regions have their own hostname. See Your region and your endpoint.
  1. Add StackJack to .cursor/mcp.json (project) or ~/.cursor/mcp.json (global) with only the URL — no headers block:

    {
      "mcpServers": {
        "stackjack": {
          "url": "https://mcp.stackjack.io/mcp"
        }
      }
    }
    
  2. Open Cursor's Settings → Tools & MCP (the pane's label varies slightly between releases — it may appear as Tools & Integrations) and click Connect (or Needs Login) next to StackJack.

  3. A browser opens to sign in. Use the same email, password, and MFA you use for the StackJack Portal.

Manual credentials (fallback)

If you can't use sign-in, an owner, co-owner, or Administrator creates an MCP client in the portal (see Managing MCP credentials).

Before you paste a credential anywhere, three things about it.

  • Base64 is encoding, not encryption. Anyone who can read the encoded string can decode it back to the client id and secret in one command. Treat the encoded value as the secret itself.
  • A typed command lands in your shell history. Produce the encoding in a way that keeps the secret out of that file, or clear the entry afterwards.
  • A config file inside a repository gets committed and shared. Keep credential-bearing config on your own machine, outside any repository. Where the client offers a secret prompt or a protected credential store, use it — the client's own documentation is what governs which of those it supports. For an automated environment, take the value from that platform's secret store rather than writing it into a file.

Base64-encode CLIENT_ID:CLIENT_SECRET and add a headers block:

{
  "mcpServers": {
    "stackjack": {
      "url": "https://mcp.stackjack.io/mcp",
      "headers": {
        "Authorization": "Basic <BASE64_OF_CLIENT_ID:CLIENT_SECRET>"
      }
    }
  }
}

If your Cursor build supports interpolating an environment variable into a header, use it so the credential stays out of the file — the form is "Authorization": "${env:STACKJACK_AUTH}". Check Cursor's own documentation for the version you are running before relying on it: if the interpolation is not supported, the literal text is sent as the header and the connection fails with a 401.

Tool limits

Cursor may limit how many MCP tools it sends to the model, and the budget is counted across every MCP server you have connected, not per server. Cursor's current official documentation states no numeric cap; the product has been observed warning about one. Treat it as one of the tightest budgets in any harness and plan accordingly.

The figure StackJack works from, with the rest of the clients, is in Client tool limits. It is an observed number rather than a documented vendor limit, so check the table rather than a figure quoted in a guide.

Because that budget is small and shared across servers, catalog mode is the primary fix: switch StackJack to minimal mode so it serves just a router tool plus a handful of catalog tools, and the model discovers any of your thousands of tools on demand — nothing is hidden and every permission still applies. (This may already be in effect: Cursor is one of the clients StackJack recognizes as capping its tool list, so if your organization has never made an explicit catalog-mode choice and your catalog exceeds that cap, this connection is already served a minimal catalog automatically. If your organization has explicitly turned catalog modes off, an admin re-enables them on the Settings page.) Trimming the client's tool selection or disabling other MCP servers you aren't using helps too. See Choosing tools for each client and managing harness tool limits.

Troubleshooting

  • Connect button never finishes — make sure the server entry has no headers block; a static header disables the sign-in flow.
  • Sign-in says no account was found — sign up in the portal first, or ask your team admin for an invite.
  • For anything else, see Connection troubleshooting.