Repository navigation
third_party/glean: add remote (hosted MCP) Glean listing - #515
Open
moustafamakhlouf wants to merge 1 commit into
Open
moustafamakhlouf wants to merge 1 commit into
moustafamakhlouf wants to merge 1 commit into
Conversation
Adds a Cursor-owned listing that points at Glean's hosted remote MCP server (https://<instance>-be.glean.com/mcp/default) with a single required GLEAN_INSTANCE plugin variable, following the Salesforce (URL variable) and HubSpot (Cursor-owned wrapper of a vendor's hosted MCP) listings. Refs CM-527, SAND-5029.
moustafamakhlouf
marked this pull request as ready for review
October 6, 2026 17:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Glean is listed in the Cursor marketplace today as plugin 734, which points at
gleanwork/cursor-pluginsand runs a local stdio server (node ${CLAUDE_PLUGIN_ROOT}/mcp/start.mjs). That server is a thin proxy: it does its own OAuth with a localhost callback, keeps tokens on the local disk, and forwards every tool call to Glean's hosted MCP endpoint.On Grok Bot that process runs on the bot's computer, and every Glean failure of the last weeks comes from that:
setuphang — EXTY-1407A hosted-MCP listing makes Glean an ordinary HTTP connector: Cursor's backend dials the URL, OAuth completes in the user's own browser through Cursor's connector flow, tokens are stored and refreshed by Cursor, and
needsAuthis a real state. None of the failure modes above can occur.Tracking: CM-527 · SAND-5029
What's in the listing
third_party/glean/—mcp.json,.cursor-plugin/plugin.json,README.md,CHANGELOG.md,LICENSE,assets/logo.svg, plus the entry in.cursor-plugin/marketplace.json.{ "mcpServers": { "glean": { "type": "http", "url": "https://${GLEAN_INSTANCE}-be.glean.com/mcp/default" } } }Glean hosts one remote MCP server per tenant at
https://<instance>-be.glean.com/mcp/<server>;defaultis the documented default server (Glean MCP guide). It supports OAuth with dynamic client registration, so no client ID/secret variables are needed.Setup field: one required variable,
GLEAN_INSTANCE(the subdomain before-be.glean.com). Per-user URL variables are already supported by the marketplace —third_party/salesforceuses"url": "${SALESFORCE_MCP_URL}". The listing shape followsthird_party/hubspot, a Cursor-owned wrapper of a vendor's hosted MCP.Logo: Glean's mark from
gleanwork/cursor-plugins(MIT; license copied asLICENSE.glean-logo).Verified
node scripts/validate-plugins.mjs(the CI check) passes: "All plugins validated successfully."/mcp/default: install → setup form asks for the instance → connect card → consent in the user's browser → auth wake → tool result → row Connected; all server requests originated from the backend, none from the bot computer.What users lose vs. the stdio plugin
file_args(reading local files into tool arguments)./mcp/gateway/proxy, if the tenant relies on it; the hosteddefaultserver exposes the admin-enabled tools directly.Open before publishing
http://localhost:8787/callback,https://www.cursor.com/agents/mcp/oauth/callback,cursor://anysphere.cursor-mcp/oauth/callback) and the/mcp/defaultresource indicator. The listing was validated against a conformant test server, not against a live Glean tenant.replaced_by_plugin_id. Existing 734 installs get the HTTP server row only on (re)install, so an in-place repoint needs a one-off resync or a reinstall nudge.${VAR}variables are badged "connect once, every member can use" (categorizeBotConnectorType). Glean permissions are per user; decide whether per-member sign-in is required there before enabling on team marketplaces.Note
Low Risk
Adds a new third-party plugin manifest and marketplace entry only; no changes to core auth or application runtime code.
Overview
Adds a new Glean marketplace plugin under
third_party/gleanthat connects via hosted HTTP MCP instead of a local stdio proxy.The listing registers in
.cursor-plugin/marketplace.jsonand wiresmcp.jsontohttps://${GLEAN_INSTANCE}-be.glean.com/mcp/default, with a requiredGLEAN_INSTANCEsetup variable inplugin.jsonso each org points at its tenant backend. OAuth is expected through Cursor’s connector flow (no client ID/secret in the manifest). Packaging includes README/setup docs, changelog, MIT license, and Glean logo assets.This is aimed at replacing the brittle stdio-based Glean listing: backend-initiated HTTP, browser sign-in, and Cursor-managed tokens rather than local plugin files and localhost OAuth on the bot machine.
Reviewed by Cursor Bugbot for commit bd348f5. Bugbot is set up for automated code reviews on this repo. Configure here.