diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json index a93fec22e..26e915af6 100644 --- a/.cursor-plugin/marketplace.json +++ b/.cursor-plugin/marketplace.json @@ -522,6 +522,11 @@ "name": "workday", "source": "third_party/workday", "description": "Look up workers, organizations, time off, payroll, and recruiting data in Workday." + }, + { + "name": "square", + "source": "third_party/square", + "description": "Work with payments, orders, catalog, customers, and invoices." } ] } diff --git a/README.md b/README.md index 3ce5fb51a..680205da0 100644 --- a/README.md +++ b/README.md @@ -96,6 +96,7 @@ Official Cursor plugins for popular developer tools, frameworks, and SaaS produc | `shopify-store` | [Shopify](third_party/shopify-store/) | Cursor | Integrations | Connect your Shopify store so Grok can answer questions about products, orders, customers, inventory, and sales. | | `quickbooks-online` | [QuickBooks Online](third_party/quickbooks-online/) | Cursor | Integrations | Read invoices, bills, expenses, customers, accounts, and financial reports. | | `workday` | [Workday](third_party/workday/) | Cursor | Integrations | Look up workers, organizations, time off, payroll, and recruiting data in Workday. | +| `square` | [Square](third_party/square/) | Cursor | Integrations | Work with payments, orders, catalog, customers, and invoices. | Author values match each plugin’s `plugin.json` `author.name` (Cursor lists `plugins@cursor.com` in the manifest). ## Repository structure diff --git a/third_party/square/.cursor-plugin/plugin.json b/third_party/square/.cursor-plugin/plugin.json new file mode 100644 index 000000000..f491fbaa8 --- /dev/null +++ b/third_party/square/.cursor-plugin/plugin.json @@ -0,0 +1,38 @@ +{ + "name": "square", + "displayName": "Square", + "version": "1.0.0", + "minClientVersions": { + "cursor": "3.13.0" + }, + "description": "Work with payments, orders, catalog, customers, and invoices.", + "author": { + "name": "Cursor", + "email": "plugins@cursor.com" + }, + "homepage": "https://developer.squareup.com/docs/mcp", + "repository": "https://github.com/cursor/plugins", + "license": "MIT", + "logo": "assets/logo.png", + "keywords": [ + "square", + "payments", + "point of sale", + "pos", + "orders", + "catalog", + "inventory", + "customers", + "invoices", + "commerce", + "mcp" + ], + "category": "integrations", + "tags": [ + "square", + "payments", + "commerce", + "mcp" + ], + "mcpServers": "./mcp.json" +} diff --git a/third_party/square/CHANGELOG.md b/third_party/square/CHANGELOG.md new file mode 100644 index 000000000..9b1a08b94 --- /dev/null +++ b/third_party/square/CHANGELOG.md @@ -0,0 +1,9 @@ +# Changelog + +All notable changes to this plugin will be documented here. + +## 1.0.0 — initial release + +- Added the `square` MCP server pointing at `https://mcp.squareup.com/mcp`. +- Auth uses OAuth — no access token or client ID to configure. +- Logo: Square's official mark, from the `square` GitHub organization. diff --git a/third_party/square/LICENSE b/third_party/square/LICENSE new file mode 100644 index 000000000..ca2bba771 --- /dev/null +++ b/third_party/square/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 Cursor + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/third_party/square/README.md b/third_party/square/README.md new file mode 100644 index 000000000..a5160c1bf --- /dev/null +++ b/third_party/square/README.md @@ -0,0 +1,62 @@ +# Square + +Cursor plugin that connects agents to [Square](https://squareup.com) through Square's official remote [Model Context Protocol](https://modelcontextprotocol.io/) server, hosted by Block. + +Query and manage a Square seller account — payments, orders, catalog items, inventory, customers, invoices, and more — through the Square API. + +## Install + +1. Open **Cursor Settings → Plugins**. +2. Search for **Square**. +3. Click **Install**, then complete the Square sign-in prompt. + +Or run `/add-plugin square` in chat. + +## MCP + +```json +{ + "mcpServers": { + "square": { + "type": "http", + "url": "https://mcp.squareup.com/mcp" + } + } +} +``` + +Auth is OAuth 2.1 with Dynamic Client Registration and PKCE. Cursor registers itself and prompts for Square sign-in when the plugin connects — there is no access token or client ID to configure. Square lets you approve only the permission scopes you want the connection to have. + +## What agents can do + +The server exposes a small, generic tool set that reaches the full Square API: + +| Tool | Purpose | +| --- | --- | +| `get_service_info` | Discover the methods available on a Square service (for example `catalog`, `orders`, `payments`) | +| `get_type_info` | Get the parameter requirements for a method before calling it | +| `make_api_request` | Execute a Square API call | + +Through those tools agents can reach payments and refunds, orders, catalog and inventory, customers and loyalty, invoices and subscriptions, bookings, team members and timecards, gift cards, disputes, payouts, and more — limited to the scopes you approve. + +The hosted runtime is the source of truth for tool names and schemas. + +## Notes + +- The remote server reaches **production** data only. To test against a Square Sandbox account, run Square's local server instead (`npx square-mcp-server start` with `ACCESS_TOKEN` and `SANDBOX=true`); see Square's docs. +- The server can write as well as read — including creating orders, payments, refunds, and invoices — when the matching `*_WRITE` scopes are approved. Approve only the scopes you need, and grant read-only scopes if agents should not change seller data. +- Square labels the MCP server as beta. +- Square maintains an allowlist of MCP clients for OAuth registration. If sign-in is rejected for an unregistered client, request an addition in the Square developer forum. + +## Docs + +- Square MCP server: https://developer.squareup.com/docs/mcp +- Source: https://github.com/square/square-mcp-server +- OAuth permissions reference: https://developer.squareup.com/docs/oauth-api/square-permissions +- Server URL: https://mcp.squareup.com/mcp + +Logo is Square's official mark, from the `square` GitHub organization. + +## License + +MIT diff --git a/third_party/square/assets/logo.png b/third_party/square/assets/logo.png new file mode 100644 index 000000000..fe82d1787 Binary files /dev/null and b/third_party/square/assets/logo.png differ diff --git a/third_party/square/mcp.json b/third_party/square/mcp.json new file mode 100644 index 000000000..555a38431 --- /dev/null +++ b/third_party/square/mcp.json @@ -0,0 +1,8 @@ +{ + "mcpServers": { + "square": { + "type": "http", + "url": "https://mcp.squareup.com/mcp" + } + } +}