Govern Cursor's MCP tools with DVARA
Cursor's agent can call any MCP server you add to it. Cursor asks before it runs a tool it thinks is risky, but that check sits with whoever clicks Run.
Put DVARA in between and Cursor sees one MCP server, DVARA. DVARA passes each tool call on only if your workspace's policy allows it, whatever was clicked in Cursor. It redacts personal data in results and records every call.
What you need
- A DVARA MCP Gateway with at least one MCP server behind it. The
MCP quickstart gives you one in
about five minutes. It runs at
http://localhost:8080/mcp, and its API key isDEMO_API_KEYin the quickstart's.env. - A DVARA workspace API key.
Add DVARA to Cursor
Cursor reads MCP servers from ~/.cursor/mcp.json for every project, or from
.cursor/mcp.json in one project. Add DVARA under mcpServers. Replace
<your-api-key> with your DVARA key:
{
"mcpServers": {
"dvara": {
"url": "http://localhost:8080/mcp",
"headers": {
"Authorization": "Bearer <your-api-key>"
}
}
}
}
Cursor picks the change up on its own. A server in ~/.cursor/mcp.json
connects straight away. A server from a project's .cursor/mcp.json stays off
until you switch it on in Cursor's settings, under MCP.
dvara should show as connected, with the tools of every MCP server behind
DVARA. DVARA lists each tool with its server's id in front, so the quickstart's
tools appear as demo-tools__get_order_status, demo-tools__lookup_customer
and demo-tools__delete_customer.
Cursor logs a 405 when it connects. That's Cursor asking for an optional
event stream DVARA doesn't offer, and it's harmless.
Try it
In Cursor's chat, in Agent mode, ask:
Look up customer C-42, then delete them.
With the quickstart's policy, the agent gets the customer record back with the email, phone number and card number redacted:
Customer C-42: Jane Doe, [REDACTED_EMAIL], [REDACTED_PHONE_NUMBER],
card on file [REDACTED_CREDIT_CARD], plan Enterprise.
Cursor then stops before the delete and asks you to approve it. Click Run. DVARA still refuses it, before it reaches the MCP server, with the policy's message:
delete_customer is irreversible and not allowed in this workspace
That's the difference: Cursor's question depends on the person clicking, and DVARA's rule doesn't. Both calls are in Flightdeck under MCP → Tool Calls.
Govern your own MCP servers
Add each MCP server to DVARA instead of to Cursor, and keep only the dvara
entry in Cursor's config. Then:
- Write the rules for what the agent may call in your workspace's policy. See Policy as Code.
- Turn on PII redaction for tool results. See PII detection.
- Hold a sensitive tool call until a person approves it in DVARA. See the MCP Gateway.
Where to go next
- MCP Gateway for everything DVARA does to a tool call.
- Other MCP clients: Claude Desktop, Claude Code, Spring AI, LangGraph.