Skip to content

feat(third_party): add CommSync plugin - #420

Open
DevSrijit wants to merge 5 commits into
cursor:mainfrom
DevSrijit:add-commsync-plugin
Open

DevSrijit wants to merge 5 commits into
cursor:mainfrom
DevSrijit:add-commsync-plugin

Conversation

@DevSrijit

@DevSrijit DevSrijit commented Sep 23, 2026 •

Copy link
Copy Markdown

Summary

  • Add CommSync (one inbox for business SMS and email) as a third_party/ marketplace plugin, in the Attio / Clarify shape.
  • Direct submission from the CommSync team; connects to CommSync's own hosted remote MCP server over Streamable HTTP.
  • Registers the plugin in .cursor-plugin/marketplace.json and the root README table.
  • URL-only OAuth — no CLIENT_ID/CLIENT_SECRET needed; the authorization server supports dynamic client registration and client ID metadata documents.
Endpoint https://server.commsync.ai/api/mcp
Auth OAuth 2.1. Probed: 401 with WWW-Authenticate: Bearer resource_metadata=… → protected-resource metadata at /.well-known/oauth-protected-resource/api/mcp → AS https://server.commsync.ai exposes registration_endpoint, PKCE S256, authorization_code + refresh_token, client_id_metadata_document_supported, and RFC 9207 iss. The consent screen lets the user pick which phone/email lines Cursor can use.
Tools threads (list/read/search/triage), sending (SMS + email reply, compose, forward), contacts and identities, labels, search, Daily Brief, channels, webhooks. Every tool carries title + read-only/destructive/idempotent/open-world annotations; sends are destructive + open-world. The hosted runtime is the source of truth.
Registry Listed on the official MCP Registry as ai.commsync/commsync.

MCP

{
  "mcpServers": {
    "commsync": {
      "type": "http",
      "url": "https://server.commsync.ai/api/mcp"
    }
  }
}

Files

  • third_party/commsync/.cursor-plugin/plugin.json, mcp.json
  • third_party/commsync/README.md, CHANGELOG.md, LICENSE
  • third_party/commsync/assets/logo.png (192×192, CommSync's official app mark)

Verification

  • node scripts/validate-plugins.mjs → All plugins validated successfully.
  • File set mirrors third_party/attio/.

Note

Medium Risk
New integration exposes inbox read/search and outbound SMS/email via OAuth; risk is bounded by user consent and Cursor prompts on destructive sends, but messaging access is inherently sensitive.

Overview
Adds CommSync as a new third_party/commsync marketplace plugin so Cursor can connect to CommSync’s hosted MCP over Streamable HTTP at https://server.commsync.ai/api/mcp.

The change is mostly packaging and discovery: plugin.json, mcp.json, README, CHANGELOG, LICENSE (and logo per PR notes), plus listing entries in .cursor-plugin/marketplace.json and the root README integrations table. Auth is documented as OAuth 2.1 with dynamic client registration—no bundled API keys—and consent lets users choose which phone/email lines agents may use; sends are described as destructive/open-world on the remote server.

No core repo logic changes beyond registering the plugin.

Reviewed by Cursor Bugbot for commit 83db5f5. Bugbot is set up for automated code reviews on this repo. Configure here.

Copilot AI balanced review requested due to automatic review settings October 9, 2026 17:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@DevSrijit

Copy link
Copy Markdown
Author

I merged the latest main and resolved the conflict in .cursor-plugin/marketplace.json. CommSync is now the last entry, after workday. scripts/validate-plugins.mjs passes. @djiang-jq, can you review this when you have time? It is a URL-only connector to CommSync's hosted MCP server (OAuth 2.1). Thank you.

# Conflicts:
#	.cursor-plugin/marketplace.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants