Give better context
Manage MCP servers, sign-in, and tools
MCP extends an agent with external tools and data. FireCursor treats each server as an explicit integration with state, authentication, and a visible tool inventory.

Quick answer
The shortest useful version.
Verify the server identity and source, enable only what the task needs, complete authentication on the trusted provider page, inspect the tool list, and disable stale integrations.
Step by step
Do this with confidence.
- 01
Inspect the server
Check its name, configuration source, connection state, and authentication requirement before enabling it.
- 02
Complete trusted sign-in
Use the provider’s supported URL handoff. Verify the domain and do not paste credentials into the agent conversation.
- 03
Read the tool inventory
Understand which tools read data, mutate data, send messages, spend money, or affect external people.
- 04
Apply least privilege
Enable the server for a clear purpose, handle sensitive requests explicitly, and disable integrations that are no longer needed.
Connected does not mean authorized for everything
A healthy MCP transport only proves that the server can communicate. Individual tools can still have distinct scopes, provider permissions, and consequences.
Treat tool approval as the moment to compare the concrete action with the task’s authority.
Integration review questions
- Who operates this server?
- What account and scopes does it use?
- Which tools can mutate external state?
- Where are credentials stored?
- How can access be revoked and audited?