Cursor Integration
Connect NexSpace as an MCP server in Cursor to access the governed NexSpace
tool surface — workforce verbs, category tools, and connected-app actions —
from the IDE.
Setup
NexSpace is a remote MCP server, so Cursor talks to it over HTTP. Add to
your project’s .cursor/mcp.json:
Or add globally at ~/.cursor/mcp.json.
Put the key in headers, not in an env block. /mcp authenticates
exclusively from the Authorization request header — the server reads
Bearer <token> off Authorization and has no environment-variable or
query-string fallback. An env block is only meaningful for stdio (command)
MCP servers; on a remote (url) server nothing forwards it, so the connection
arrives unauthenticated and gets the 401 + WWW-Authenticate challenge
instead of a tool list.
Or skip the key entirely (OAuth)
https://mcp.nexspace365.com/mcp serves RFC 9728 protected-resource metadata
at both /.well-known/oauth-protected-resource and
/.well-known/oauth-protected-resource/mcp, pointing at the NexSpace
authorization server. An OAuth-capable MCP client can therefore drop the
headers block, self-register via Dynamic Client Registration, and run the
consent flow — no long-lived key in a config file, and the grant is revocable
per user. A 401 from the endpoint carries a WWW-Authenticate: Bearer resource_metadata="…" header so the client can bootstrap from the failure
alone.
Get an API Key
- Log in to NexSpace
- Go to Settings → API Keys
- Create a key with the scopes you need
- Paste it into the
Authorization header as Bearer <key>
Usage
Once configured, Cursor discovers the full governed tool catalog —
tools/list is not filtered by your key’s scopes. Scope is enforced when a
tool is invoked: a tools/call for a tool your credential lacks the scope
for returns -32003 FORBIDDEN with required, granted, and a suggestion
naming the missing scope. So expect to see tools you cannot yet run, and read
the catalog as “what NexSpace exposes”, not “what this key can do”. See
MCP for the scope model and the error codes.
Ask the agent naturally:
“Search for available staff at facility 12 for tomorrow”
“Show me the coverage report for all facilities this week”
“Verify credential #456 and tell me if it’s still valid”
The one exception to the unfiltered catalog is the connected-apps lane: those
tools are listed per caller, only when the credential carries apps:read /
apps:write and the bound user has an active connection to that app.
Agent skill (recommended)
Prefer the CLI skill installer — it drops the nexspace-operations skill so
Cursor follows the canonical loop (search → schema → --dry-run → execute)
and compliance walls:
Cursor Rules (legacy)
You can still copy the older rule file if you are not using the skill yet:
Available on cursor.directory
Search for “NexSpace” on cursor.directory for
one-click installation.