Poliogo

Connect Cursor

Run Poliogo inside Cursor. Ask your agent to check the app and it scans the workspace and lists what your documents don't yet cover.

How it connects
Model Context Protocol server, runs locally
Setup time
One command
Access
Local only — no account grant
npx poliogo-mcp init

Run this in your project, then ask your agent to check your compliance. MCP access is included from the Starter plan.

How the connection works

  1. Run one commandnpx poliogo-mcp init registers the server in your editor, once per project.
  2. Ask your agentIt calls check_compliance and scans the workspace locally.
  3. Detection on demandRe-ask any time — or wire the same tools into CI as subcommands.

What it looks like once connected

An illustration of this connection inside your Poliogo dashboard — not live data.

Local scan completeExample
~/code/acme-web · workspace

Detected in this project

  • Next.jsnext in package.json
  • Pineconesrc/lib/vectors.ts
  • OpenAIfetch to api.openai.com
  • ResendRESEND_API_KEY in .env.example
Last scan: just now3 documents up to date
Everything above was matched on your own machine. Only the service names leave it — never the files.

Exact permissions requested

Every permission this connection asks for, named as Cursor names it on its own consent screen — so you can compare this table to what you are shown.

PermissionGrantWhat it is used for
No account grantNot requestedThere is no OAuth step. The MCP server runs on your machine under your own user.
Workspace filesReadRead locally, in the folder you ran the scan in. Nothing is uploaded.
Writing documentsWriteOnly when you ask the agent to. generate_docs and install_pages write into your project, and you review the diff.

Setting it up

What you do, and what you will be looking at while you do it.

  1. Run the command in your project

    It writes the Poliogo MCP server into Cursor's config. Once per project, and there is no OAuth step — the server runs on your machine under your own user.

  2. Restart Cursor if it was open

    Cursor reads its MCP config at startup, so a running window will not see a server that was registered underneath it.

  3. Ask your agent

    “Check if my app is compliant.” It calls check_compliance, which scans your workspace locally and reports which detected services your documents do not yet describe.

  4. Ask it to fix it

    “Fix it.” The agent calls generate_docs and install_pages, which write your policies and their routes into the project as real pages in your framework. You review the diff like any other change.

  5. Keep your agent informed

    inject_rules writes a fenced compliance block into .cursorrules, so Cursor itself starts flagging compliance-relevant changes while you are still authoring them. The markers mean regeneration never clobbers your own content.

Poliogo · New projectExample

Choose how to scan your app

Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.

AI Coding EditorCursor, Claude Code, Windsurf — copy one command into your editor and it connects the project for you. No coding needed.Choose another way
CursorClaude CodeWindsurf

Generate your licence key

MCP Server Access

The licence key the poliogo-mcp package uses in Cursor, Windsurf and Claude Code. Included from Starter.

Copy it now — it is never shown again.

poliogo_••••••••••••••••••••••••

Set it as POLIOGO_API_KEY in the environment your editor launches npx poliogo-mcp with.

Generate key

Paste this into Cursor

npx poliogo-mcp initCopy

Your agent runs it and writes the server into .cursor/mcp.json — nothing else in that file is touched.

{
  "mcpServers": {
    "poliogo": {
      "command": "npx",
      "args": [
        "-y",
        "poliogo-mcp"
      ]
    }
  }
}

Ask your editor to scan

“Scan my stack with Poliogo.”Local scan complete · only the service names left this machine
Tell us what you use instead
The Poliogo setup screen for Cursor, drawn from the same catalogue the app reads. An illustration — not live data, and nothing here is clickable.

What Poliogo detects from Cursor

The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.

What it reads

  • The workspace open in your editor, scanned on your own machine.
  • Manifests and source text, exactly as a repository scan reads them.
  • Drift against the last snapshot your documents were generated from.

What it never reads

  • Your source code. It never leaves the machine — only the list of detected services is sent.
  • Anything outside the workspace you ran the scan in.
  • Any file, unless you ask the agent to write the documents.

Ready to connect Cursor?

The free plan covers one project with no credit card. You approve everything before a single document is written.

Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.