Skip to main content
Version: Latest (1.9.x dev)

Govern Cursor's MCP tools with DVARA

Cursor's agent can call any MCP server you add to it. Cursor asks before it runs a tool it thinks is risky, but that check sits with whoever clicks Run.

Put DVARA in between and Cursor sees one MCP server, DVARA. DVARA passes each tool call on only if your workspace's policy allows it, whatever was clicked in Cursor. It redacts personal data in results and records every call.

What you need​

  • A DVARA MCP Gateway with at least one MCP server behind it. The MCP quickstart gives you one in about five minutes. It runs at http://localhost:8080/mcp, and its API key is DEMO_API_KEY in the quickstart's .env.
  • A DVARA workspace API key.

Add DVARA to Cursor​

Cursor reads MCP servers from ~/.cursor/mcp.json for every project, or from .cursor/mcp.json in one project. Add DVARA under mcpServers. Replace <your-api-key> with your DVARA key:

{
"mcpServers": {
"dvara": {
"url": "http://localhost:8080/mcp",
"headers": {
"Authorization": "Bearer <your-api-key>"
}
}
}
}

Cursor picks the change up on its own. A server in ~/.cursor/mcp.json connects straight away. A server from a project's .cursor/mcp.json stays off until you switch it on in Cursor's settings, under MCP.

dvara should show as connected, with the tools of every MCP server behind DVARA. DVARA lists each tool with its server's id in front, so the quickstart's tools appear as demo-tools__get_order_status, demo-tools__lookup_customer and demo-tools__delete_customer.

note

Cursor logs a 405 when it connects. That's Cursor asking for an optional event stream DVARA doesn't offer, and it's harmless.

Try it​

In Cursor's chat, in Agent mode, ask:

Look up customer C-42, then delete them.

With the quickstart's policy, the agent gets the customer record back with the email, phone number and card number redacted:

Customer C-42: Jane Doe, [REDACTED_EMAIL], [REDACTED_PHONE_NUMBER],
card on file [REDACTED_CREDIT_CARD], plan Enterprise.

Cursor then stops before the delete and asks you to approve it. Click Run. DVARA still refuses it, before it reaches the MCP server, with the policy's message:

delete_customer is irreversible and not allowed in this workspace

That's the difference: Cursor's question depends on the person clicking, and DVARA's rule doesn't. Both calls are in Flightdeck under MCP → Tool Calls.

Govern your own MCP servers​

Add each MCP server to DVARA instead of to Cursor, and keep only the dvara entry in Cursor's config. Then:

  • Write the rules for what the agent may call in your workspace's policy. See Policy as Code.
  • Turn on PII redaction for tool results. See PII detection.
  • Hold a sensitive tool call until a person approves it in DVARA. See the MCP Gateway.

Where to go next​