Choose the reviewed Cursor config path and keep credentials in the client environment or secret store.
Prerequisite
Use a Cursor version with Settings -> MCP or marketplace support. Cursor has a reviewed OAuth path and a direct XMEMO_KEY fallback for headless use.
- Endpoint: https://xmemo.dev/mcp.
- Preferred auth mode: browser OAuth.
- Fallback auth mode: direct bearer token for headless use.
Install / setup
Open Cursor Settings -> MCP or install the reviewed server from the marketplace. For headless operation, use the existing direct configuration block on this page instead of the browser flow.
- OAuth path: configure the hosted URL only and let first use open browser consent.
- Direct fallback: keep the token in XMEMO_KEY, not in the settings file.
- Do not mix the OAuth entry with an Authorization header.
Set the credential
OAuth path: no key — complete browser OAuth. Direct headless fallback: set XMEMO_KEY in the environment and never paste its value into Cursor settings.
# OAuth path: no XMEMO_KEY
# Direct fallback:
export XMEMO_KEY='<your-xmemo-token>'
Generate / confirm XMEMO_AGENT_INSTANCE_ID
The reviewed Cursor OAuth and direct snippets do not require a client-side instance header. Confirm that the selected path has no identity header to add; if a headless wrapper supplies XMEMO_AGENT_INSTANCE_ID, generate it once per local profile and reuse it.
Preserve the existing config block
Use the existing Cursor XMemo configuration block rendered on this page. Preserve the OAuth URL-only shape for the interactive path and the Authorization environment reference for the direct fallback.
Restart the client
Restart Cursor after changing MCP settings or the direct environment so it reloads the selected authentication mode.
Test with a real recall call
Make the first MCP call read-only. This is an actual recall invocation, not a health-check placeholder, and it does not write memory.
recall({ query: "connection check", limit: 1 })
Expected response (literal shape)
A successful call returns the public ranked text shape below; the reference and content are real values from the authorized memory space.
### XMemo Memory Results:
1. Reference: <opaque-memory-id> | Location: <location>
> <memory content>
Common Errors
Cursor can fail on either its OAuth path or its direct headless fallback.
- invalid_grant — the OAuth authorization code is invalid, expired, or already used: reconnect Cursor and authorize again.
- 401 invalid_token — the direct fallback token is missing, expired, revoked, or otherwise invalid: verify XMEMO_KEY in the headless environment.
- 403 insufficient_scope — the credential does not grant memory:read: approve the required scope or issue a token with it.
Headless fallback reference
Only use the direct fallback when the OAuth path cannot complete; the existing environment-backed Authorization block is the reviewed fallback.