镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

feat(third_party): add Square plugin - #534

Merged
ericgyl817 merged 1 commit into
cursor:mainfrom
djiang-jq:cursor/square-plugin
Oct 10, 2026
Merged

ericgyl817 merged 1 commit into
cursor:mainfrom
djiang-jq:cursor/square-plugin

Conversation

@djiang-jq

@djiang-jq djiang-jq commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Adds a square plugin that connects to Square's official remote MCP server, hosted by Block.

What's included

  • third_party/square/mcp.json: HTTP server at https://mcp.squareup.com/mcp
  • plugin.json, README, CHANGELOG, LICENSE, and logo (Square's official mark, from the square GitHub organization)
  • Marketplace and root README entries

Auth

OAuth with dynamic client registration and PKCE. Confirmed from the server: an unauthenticated initialize returns 401 with a resource_metadata pointer, and /.well-known/oauth-authorization-server advertises a registration_endpoint and S256. There is no token or client ID to configure.

Notes for reviewers

  • The remote server reaches production data only and supports writes when *_WRITE scopes are approved. The README documents both.
  • Square keeps an allowlist of MCP clients for OAuth registration. If Cursor isn't on it, sign-in may be rejected until Square adds it. I did not test an end-to-end sign-in.
  • Square labels the server as beta.

Validation

  • node scripts/validate-plugins.mjs passes

Docs: https://developer.squareup.com/docs/mcp


Note

Low Risk
Repo changes are manifest and docs only; operational risk is users granting write scopes on live Square seller data via the remote MCP server.

Overview
Adds a new square Cursor marketplace plugin under third_party/square/ that wires agents to Square’s hosted MCP endpoint at https://mcp.squareup.com/mcp via mcp.json and plugin.json (integrations category, Cursor 3.13.0+).

Registers the plugin in .cursor-plugin/marketplace.json and the root README integrations table, with standard packaging (README, CHANGELOG, MIT LICENSE, logo). Auth is documented as OAuth 2.1 (dynamic client registration + PKCE) with no manual token setup; the README calls out production-only access, optional write scopes, beta status, and Square’s MCP client allowlist.

Reviewed by Cursor Bugbot for commit 833ac55. Bugbot is set up for automated code reviews on this repo. Configure here.

@ericgyl817
ericgyl817 merged commit d73344b into cursor:main Oct 10, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants