Skip to content

third_party/glean: add remote (hosted MCP) Glean listing - #515

Open
moustafamakhlouf wants to merge 1 commit into
cursor:mainfrom
moustafamakhlouf:glean-remote-listing
Open

moustafamakhlouf wants to merge 1 commit into
cursor:mainfrom
moustafamakhlouf:glean-remote-listing

Conversation

@moustafamakhlouf

@moustafamakhlouf moustafamakhlouf commented Oct 6, 2026 •

Copy link
Copy Markdown

Why

Glean is listed in the Cursor marketplace today as plugin 734, which points at gleanwork/cursor-plugins and runs a local stdio server (node ${CLAUDE_PLUGIN_ROOT}/mcp/start.mjs). That server is a thin proxy: it does its own OAuth with a localhost callback, keeps tokens on the local disk, and forwards every tool call to Glean's hosted MCP endpoint.

On Grok Bot that process runs on the bot's computer, and every Glean failure of the last weeks comes from that:

  • plugin files missing from the bot computer's plugin index ("This plugin's files are not on Grok Bot's computer yet") — SAND-5029
  • the sign-in browser opening on the wrong virtual desktop — EXTY-1407
  • "Connected" while unauthenticated, then a silent multi-minute setup hang — EXTY-1407
  • Okta refusing the sign-in because the bot computer is an unmanaged device

A hosted-MCP listing makes Glean an ordinary HTTP connector: Cursor's backend dials the URL, OAuth completes in the user's own browser through Cursor's connector flow, tokens are stored and refreshed by Cursor, and needsAuth is a real state. None of the failure modes above can occur.

Tracking: CM-527 · SAND-5029

What's in the listing

third_party/glean/ — mcp.json, .cursor-plugin/plugin.json, README.md, CHANGELOG.md, LICENSE, assets/logo.svg, plus the entry in .cursor-plugin/marketplace.json.

{ "mcpServers": { "glean": { "type": "http", "url": "https://${GLEAN_INSTANCE}-be.glean.com/mcp/default" } } }

Glean hosts one remote MCP server per tenant at https://<instance>-be.glean.com/mcp/<server>; default is the documented default server (Glean MCP guide). It supports OAuth with dynamic client registration, so no client ID/secret variables are needed.

Setup field: one required variable, GLEAN_INSTANCE (the subdomain before -be.glean.com). Per-user URL variables are already supported by the marketplace — third_party/salesforce uses "url": "${SALESFORCE_MCP_URL}". The listing shape follows third_party/hubspot, a Cursor-owned wrapper of a vendor's hosted MCP.

Logo: Glean's mark from gleanwork/cursor-plugins (MIT; license copied as LICENSE.glean-logo).

Verified

  • node scripts/validate-plugins.mjs (the CI check) passes: "All plugins validated successfully."
  • End-to-end on a Grok Bot dev stack with a Glean-shaped OAuth test server standing in for /mcp/default: install → setup form asks for the instance → connect card → consent in the user's browser → auth wake → tool result → row Connected; all server requests originated from the backend, none from the bot computer.

What users lose vs. the stdio plugin

  • Instance lookup by work email → a one-time setup field.
  • file_args (reading local files into tool arguments).
  • The stdio bundle's own approval prompts → Cursor's connector permissions.
  • The bundle's lazy skill catalog over /mcp/gateway/proxy, if the tenant relies on it; the hosted default server exposes the admin-enabled tools directly.

Open before publishing

  1. Glean to confirm its hosted authorization server accepts dynamic client registration from Cursor's redirect URIs (http://localhost:8787/callback, https://www.cursor.com/agents/mcp/oauth/callback, cursor://anysphere.cursor-mcp/oauth/callback) and the /mcp/default resource indicator. The listing was validated against a conformant test server, not against a live Glean tenant.
  2. Repoint plugin 734 at this directory, or publish this as a new listing and deprecate 734 via replaced_by_plugin_id. Existing 734 installs get the HTTP server row only on (re)install, so an in-place repoint needs a one-off resync or a reinstall nudge.
  3. Team Bots: plugins with ${VAR} variables are badged "connect once, every member can use" (categorizeBotConnectorType). Glean permissions are per user; decide whether per-member sign-in is required there before enabling on team marketplaces.

Note

Low Risk
Adds a new third-party plugin manifest and marketplace entry only; no changes to core auth or application runtime code.

Overview
Adds a new Glean marketplace plugin under third_party/glean that connects via hosted HTTP MCP instead of a local stdio proxy.

The listing registers in .cursor-plugin/marketplace.json and wires mcp.json to https://${GLEAN_INSTANCE}-be.glean.com/mcp/default, with a required GLEAN_INSTANCE setup variable in plugin.json so each org points at its tenant backend. OAuth is expected through Cursor’s connector flow (no client ID/secret in the manifest). Packaging includes README/setup docs, changelog, MIT license, and Glean logo assets.

This is aimed at replacing the brittle stdio-based Glean listing: backend-initiated HTTP, browser sign-in, and Cursor-managed tokens rather than local plugin files and localhost OAuth on the bot machine.

Reviewed by Cursor Bugbot for commit bd348f5. Bugbot is set up for automated code reviews on this repo. Configure here.

Adds a Cursor-owned listing that points at Glean's hosted remote MCP
server (https://<instance>-be.glean.com/mcp/default) with a single
required GLEAN_INSTANCE plugin variable, following the Salesforce
(URL variable) and HubSpot (Cursor-owned wrapper of a vendor's hosted
MCP) listings.

Refs CM-527, SAND-5029.
@moustafamakhlouf
moustafamakhlouf marked this pull request as ready for review October 6, 2026 17:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant