Skip to content

feat(third_party): add CommSync plugin - #420

Open
DevSrijit wants to merge 3 commits into
cursor:mainfrom
DevSrijit:add-commsync-plugin
Open

DevSrijit wants to merge 3 commits into
cursor:mainfrom
DevSrijit:add-commsync-plugin

Conversation

@DevSrijit

@DevSrijit DevSrijit commented Sep 23, 2026 •

Copy link
Copy Markdown

Summary

  • Add CommSync (one inbox for business SMS and email) as a third_party/ marketplace plugin, in the Attio / Clarify shape.
  • Direct submission from the CommSync team; connects to CommSync's own hosted remote MCP server over Streamable HTTP.
  • Registers the plugin in .cursor-plugin/marketplace.json and the root README table.
  • URL-only OAuth — no CLIENT_ID/CLIENT_SECRET needed; the authorization server supports dynamic client registration and client ID metadata documents.
Endpoint https://server.commsync.ai/api/mcp
Auth OAuth 2.1. Probed: 401 with WWW-Authenticate: Bearer resource_metadata=… → protected-resource metadata at /.well-known/oauth-protected-resource/api/mcp → AS https://server.commsync.ai exposes registration_endpoint, PKCE S256, authorization_code + refresh_token, client_id_metadata_document_supported, and RFC 9207 iss. The consent screen lets the user pick which phone/email lines Cursor can use.
Tools threads (list/read/search/triage), sending (SMS + email reply, compose, forward), contacts and identities, labels, search, Daily Brief, channels, webhooks. Every tool carries title + read-only/destructive/idempotent/open-world annotations; sends are destructive + open-world. The hosted runtime is the source of truth.
Registry Listed on the official MCP Registry as ai.commsync/commsync.

MCP

{
  "mcpServers": {
    "commsync": {
      "type": "http",
      "url": "https://server.commsync.ai/api/mcp"
    }
  }
}

Files

  • third_party/commsync/.cursor-plugin/plugin.json, mcp.json
  • third_party/commsync/README.md, CHANGELOG.md, LICENSE
  • third_party/commsync/assets/logo.png (192×192, CommSync's official app mark)

Verification

  • node scripts/validate-plugins.mjs → All plugins validated successfully.
  • File set mirrors third_party/attio/.

Note

Medium Risk
New integration exposes read/send messaging and contact management via a third-party hosted MCP; risk is bounded by OAuth consent and documented destructive send annotations, but outbound SMS/email still warrants careful review.

Overview
Adds CommSync as a new third_party/ marketplace plugin so Cursor can connect to CommSync’s hosted MCP server for a unified business SMS and email inbox.

The change registers commsync in .cursor-plugin/marketplace.json and the root README plugin table, and introduces third_party/commsync/ with manifest (plugin.json), URL-only mcp.json pointing at https://server.commsync.ai/api/mcp, plus README, CHANGELOG, LICENSE, and logo. Auth is documented as OAuth 2.1 with dynamic client registration and line-scoped consent—no repo secrets or client IDs.

Reviewed by Cursor Bugbot for commit 90112b6. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant