Cursor (and Windsurf)
Before you start
- A running server. Examples use staging,
https://dev.nexara.ac; replace it with your own origin. Production will behttps://app.nexara.ac. - An agent key: in the app open Agents, New agent, then Create agent and key. Copy the
nxc_key (shown once) and export it:export NEXARA_KEY=nxc_.... - The MCP URL is
https://dev.nexara.ac/mcp.https://dev.nexara.ac/w/<workspace>/mcpalso works and refuses keys from other workspaces.
Configure Cursor
Save as ~/.cursor/mcp.json (or .cursor/mcp.json in a project):
{
"mcpServers": {
"nexara": {
"url": "https://dev.nexara.ac/mcp",
"headers": { "Authorization": "Bearer ${env:NEXARA_KEY}" }
}
}
}
Remote servers in Cursor do not read an envFile, so the key must be in the environment Cursor was started from.
Windsurf
Same shape in ~/.codeium/windsurf/mcp_config.json, with serverUrl instead of url:
{
"mcpServers": {
"nexara": {
"serverUrl": "https://dev.nexara.ac/mcp",
"headers": { "Authorization": "Bearer ${env:NEXARA_KEY}" }
}
}
}
Verify
Ask the agent to call context_whoami. It returns the agent name, workspace and grants. Or run:
curl -s https://dev.nexara.ac/mcp \
-H "Authorization: Bearer $NEXARA_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"context_whoami","arguments":{}}}'
Troubleshooting
| Symptom | Cause |
|---|---|
401 invalid, expired or revoked token | Wrong key, key revoked, or a workspace lockdown bumped the token epoch. Mint a new key |
401 git tokens (nxg_) are not accepted on /mcp | You pasted a git token. Use an nxc_ agent key |
403 forbidden host or origin | The server has ALLOWED_HOSTS set and your Host header is not in it |
Tool result forbidden: ... | The agent's grant does not cover that Space, action or sensitivity. Widen it on the agent page |
Tool result step_up_required | The change needs a human with step-up; it was turned into a proposal |