2 min lesson
Share one read-only analytics MCP
Share one analytics MCP, connect it with a read-only credential and allowlist only read_schema.
Step 1 of 2
Add analytics-db to .cursor/mcp.json with a project-relative command and ${env:ANALYTICS_READONLY_URL}. Set that environment variable outside the repository, then open Customize and confirm the server comes from the project config, uses stdio and exposes read_schema, run_readonly_query and apply_migration. Use Allowlist mode. Put only analytics-db:read_schema in .cursor/permissions.json and inspect the effective list in Settings. Run read_schema, then propose a query and migration without approving them. Both non-allowlisted calls should stop for review. Inspect the staged files for the database URL and machine-specific paths before committing.
Keep Wait for MCP Authentication on
0:18 · narratedRead this demo as text
- Wait for MCP Authentication stays on so a run does not race ahead of a half-authed server. Logout lives on the row — there is no mid-run approval modal to invent here.
Practice next: Confirm Wait for MCP Authentication is on for any server that can hold a broad token.
Simulated Cursor 3.12 (macOS, light) — beta educational reconstruction, not the real product.