From 833ac551b9b3a1685d21dbfcc402ec538752ec76 Mon Sep 17 00:00:00 2001 From: djiang-jq Date: Fri, 9 Oct 2026 20:02:30 -0700 Subject: [PATCH] feat(third_party): add Square plugin --- .cursor-plugin/marketplace.json | 5 ++ README.md | 1 + third_party/square/.cursor-plugin/plugin.json | 38 +++++++++++ third_party/square/CHANGELOG.md | 9 +++ third_party/square/LICENSE | 21 ++++++ third_party/square/README.md | 62 ++++++++++++++++++ third_party/square/assets/logo.png | Bin 0 -> 4200 bytes third_party/square/mcp.json | 8 +++ 8 files changed, 144 insertions(+) create mode 100644 third_party/square/.cursor-plugin/plugin.json create mode 100644 third_party/square/CHANGELOG.md create mode 100644 third_party/square/LICENSE create mode 100644 third_party/square/README.md create mode 100644 third_party/square/assets/logo.png create mode 100644 third_party/square/mcp.json diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json index a93fec22e..26e915af6 100644 --- a/.cursor-plugin/marketplace.json +++ b/.cursor-plugin/marketplace.json @@ -522,6 +522,11 @@ "name": "workday", "source": "third_party/workday", "description": "Look up workers, organizations, time off, payroll, and recruiting data in Workday." + }, + { + "name": "square", + "source": "third_party/square", + "description": "Work with payments, orders, catalog, customers, and invoices." } ] } diff --git a/README.md b/README.md index 3ce5fb51a..680205da0 100644 --- a/README.md +++ b/README.md @@ -96,6 +96,7 @@ Official Cursor plugins for popular developer tools, frameworks, and SaaS produc | `shopify-store` | [Shopify](third_party/shopify-store/) | Cursor | Integrations | Connect your Shopify store so Grok can answer questions about products, orders, customers, inventory, and sales. | | `quickbooks-online` | [QuickBooks Online](third_party/quickbooks-online/) | Cursor | Integrations | Read invoices, bills, expenses, customers, accounts, and financial reports. | | `workday` | [Workday](third_party/workday/) | Cursor | Integrations | Look up workers, organizations, time off, payroll, and recruiting data in Workday. | +| `square` | [Square](third_party/square/) | Cursor | Integrations | Work with payments, orders, catalog, customers, and invoices. | Author values match each plugin’s `plugin.json` `author.name` (Cursor lists `plugins@cursor.com` in the manifest). ## Repository structure diff --git a/third_party/square/.cursor-plugin/plugin.json b/third_party/square/.cursor-plugin/plugin.json new file mode 100644 index 000000000..f491fbaa8 --- /dev/null +++ b/third_party/square/.cursor-plugin/plugin.json @@ -0,0 +1,38 @@ +{ + "name": "square", + "displayName": "Square", + "version": "1.0.0", + "minClientVersions": { + "cursor": "3.13.0" + }, + "description": "Work with payments, orders, catalog, customers, and invoices.", + "author": { + "name": "Cursor", + "email": "plugins@cursor.com" + }, + "homepage": "https://developer.squareup.com/docs/mcp", + "repository": "https://github.com/cursor/plugins", + "license": "MIT", + "logo": "assets/logo.png", + "keywords": [ + "square", + "payments", + "point of sale", + "pos", + "orders", + "catalog", + "inventory", + "customers", + "invoices", + "commerce", + "mcp" + ], + "category": "integrations", + "tags": [ + "square", + "payments", + "commerce", + "mcp" + ], + "mcpServers": "./mcp.json" +} diff --git a/third_party/square/CHANGELOG.md b/third_party/square/CHANGELOG.md new file mode 100644 index 000000000..9b1a08b94 --- /dev/null +++ b/third_party/square/CHANGELOG.md @@ -0,0 +1,9 @@ +# Changelog + +All notable changes to this plugin will be documented here. + +## 1.0.0 — initial release + +- Added the `square` MCP server pointing at `https://mcp.squareup.com/mcp`. +- Auth uses OAuth — no access token or client ID to configure. +- Logo: Square's official mark, from the `square` GitHub organization. diff --git a/third_party/square/LICENSE b/third_party/square/LICENSE new file mode 100644 index 000000000..ca2bba771 --- /dev/null +++ b/third_party/square/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 Cursor + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/third_party/square/README.md b/third_party/square/README.md new file mode 100644 index 000000000..a5160c1bf --- /dev/null +++ b/third_party/square/README.md @@ -0,0 +1,62 @@ +# Square + +Cursor plugin that connects agents to [Square](https://squareup.com) through Square's official remote [Model Context Protocol](https://modelcontextprotocol.io/) server, hosted by Block. + +Query and manage a Square seller account — payments, orders, catalog items, inventory, customers, invoices, and more — through the Square API. + +## Install + +1. Open **Cursor Settings → Plugins**. +2. Search for **Square**. +3. Click **Install**, then complete the Square sign-in prompt. + +Or run `/add-plugin square` in chat. + +## MCP + +```json +{ + "mcpServers": { + "square": { + "type": "http", + "url": "https://mcp.squareup.com/mcp" + } + } +} +``` + +Auth is OAuth 2.1 with Dynamic Client Registration and PKCE. Cursor registers itself and prompts for Square sign-in when the plugin connects — there is no access token or client ID to configure. Square lets you approve only the permission scopes you want the connection to have. + +## What agents can do + +The server exposes a small, generic tool set that reaches the full Square API: + +| Tool | Purpose | +| --- | --- | +| `get_service_info` | Discover the methods available on a Square service (for example `catalog`, `orders`, `payments`) | +| `get_type_info` | Get the parameter requirements for a method before calling it | +| `make_api_request` | Execute a Square API call | + +Through those tools agents can reach payments and refunds, orders, catalog and inventory, customers and loyalty, invoices and subscriptions, bookings, team members and timecards, gift cards, disputes, payouts, and more — limited to the scopes you approve. + +The hosted runtime is the source of truth for tool names and schemas. + +## Notes + +- The remote server reaches **production** data only. To test against a Square Sandbox account, run Square's local server instead (`npx square-mcp-server start` with `ACCESS_TOKEN` and `SANDBOX=true`); see Square's docs. +- The server can write as well as read — including creating orders, payments, refunds, and invoices — when the matching `*_WRITE` scopes are approved. Approve only the scopes you need, and grant read-only scopes if agents should not change seller data. +- Square labels the MCP server as beta. +- Square maintains an allowlist of MCP clients for OAuth registration. If sign-in is rejected for an unregistered client, request an addition in the Square developer forum. + +## Docs + +- Square MCP server: https://developer.squareup.com/docs/mcp +- Source: https://github.com/square/square-mcp-server +- OAuth permissions reference: https://developer.squareup.com/docs/oauth-api/square-permissions +- Server URL: https://mcp.squareup.com/mcp + +Logo is Square's official mark, from the `square` GitHub organization. + +## License + +MIT diff --git a/third_party/square/assets/logo.png b/third_party/square/assets/logo.png new file mode 100644 index 0000000000000000000000000000000000000000..fe82d1787e4f70bfa2d84950a0e439b276357a44 GIT binary patch literal 4200 zcmd5;xpy20VOmkp-2-@M0!U+rC5N3jzp>gN(<796cGfa zm(Zk0Z_)`(DM6$J;XAw^-~0F8-#5lyXYRe$I^*my#~Ev`6@Ak{i-8_S4*&pzj<$v| zh|T9l3k9FXGaeT}fIKwTQUl8RdDp>%hNFd!lfFJ63hrqENTe%3bDjbk3^V|sCO`mc z5FzJ20@eRVn+eqa-k&GxD_!jY0Hz@w4OP#&!(xF;`Rw zj8h(A9kSUb`33v@y5|>r1QX?h7@`8t6g%JgHms1zGD)HF2T4B~LErMHknVeH!5jqx z^v#P8ak~*j4JSmynU@_#DRZmr`Zu$?fyZKhe;QcdC=UL;LHR`axo)EM4}w(?@*fxO zwusbU<*|=5&5@o>B6XT%@$Pb+Oo~Hbg!rb2>?k9ybLbVMJ23I7$k~p=?@!`Q8B(^b zQR45An^5M3CV0ci=Vgh+V6TQwk3mf;e|TXWe49o1#6h;1(?hPtbGn98^Kct;syoG# zSg$VA;YA%JJr!WtdQ!0bmy5;&B{_THNA}LZI3{p=E2bkZj-eW0!A1~7Ty%vSBpu`X;64kHJ_hab zDwm%IK-vCqdcx7U5>IjtVZs;QGmr?#J-VF^*;x?T?5}F{=rA?S98A8kfx9Jp1t*7J zJrZWS?@PYV)Zx}+Gnh=0FjfxA@?>2J=F1C8&kV@QTI3w%ZlJQLu)$qXRD_9WdMG6p z9p|+|yPF84iZHKTJ^#%8Gn{ms*?7A#W&l2S&V9VBV_(|%^Mqw5kouw6t~KFoC=bK_aaW&JN*~<@WKZqe4@(119wn(e zvNsT{T`|~*Q?=^N&Qg2q;L$TVs-5YDL>d{S_d;uU?LZco9{N=pz2-`zV&g1?tEW9V z-YnO>A9+Jwp!jYul8@Tv?bLI+toGO1f`(LAyk_xk*ZrRG^HGmPR%2Z;spsB?h6ba) zNVoAholYQVay2>ib7V9P8P05voftIc29j<`C!jNFjwuuq`K%rwwerPzbZ|WKY`XAz z$7v8NlSP=>#r#|85|AzpCl4;3G!OUKatXD!)&4w}g3Hx+ zJ7Ze?=1=Q&I-&QE4y3b)SrG8rNTmL>sAuxXb+os8zh)XC=uUaVy>-TU;ljNO6r}SZ794k4*yBmfncA_6=7wRwW9Ia;E*)G9b znRyD0DI2peG-Cw&mfBM81r=G!oY_S(3G}N(g=nCuT^KK&vgiF>q+Lnsdnw!I8jJpl zSbha2XF8f+^nBn{`#s=2f>p`@n}Q~?R6$bCiHu{kmo>mbrD9VVYV|-OA3x$s^8pF; zY4>P$1hF@#Z353mfZ&Cls3k$P;^!kerGrHBO7nQX28krENuicN0+*sDvArOsXhl|X zBhl1cT3?`62#`o+MSPzENT7lpYF-A!m9MrQMDWx916OzxwQHWMsZ-_DC#qXm*Qopar>L&?#W-8CO-LYl9}G#5{f!*vRt<}JF`!7YN|g)rUt*{ z%L|*UVc!i7Il7!c7i)UR+5VeyP$H}qTL>1v5*!Xk^E6FN(Vlp5pUC4?SnWPu{OgzB zt8tavA%1-(O~RvOehvgmb(9>xnGIjS(L%X|Zp4G~xaq$&^L33sWWVC!zR&(aOwl^%AUKF6sW3r-PxPtSf$ zdzB0q7_Ooi2m)G@DGKCr%PJ=iak3qYucqLz#tpZ6Z)ZS&{94v|q*EaHd(*Pa1u6yd zszlJzHxB=BgzL=l_rVqv(ja{;klc;rcM@@WZ-|!Ee8?Ak?@yy^akARW>ky?Ja)qv4 zzohMF$J5i+@IOa;UWtu@0%YdyUb3i?>ku1Isy4IQ>A4oed0BJ@zqYl78ot?jTNwTv zv#k9>>%IoBrW9JuTHM;6W{8VWkp*${xHy@SPMa%(4h#%5u&uIWJ$%s&c04B8+K$-n zBxHeGx>6GQHkGT&cAg9xY{jMy>s07+h2np0yPI&^9RFM|3R&%k$0s+>)IBsY%eKdM z+DgcwP!a!-0#N*#)Y4I&Z|*Urz~leKffcpTkCKD3ON)i51>=T>hFHy2 zJ|l%KOCfNyQ**ki4mb`C`v10Bz$aX#%Vb((N4uw&BAOhF5~7?_PROJj`= zT0I!_E{*(4N4M_O2UOnUOo7|HYOa60w>b6ZXjxNEEToJQE+(<7P76wMC^iBjR9(Ve zrR-vgJYwX3Uh*;`B0~8po5HR|>7yv0mtnXW+)w^%PfT?ZPoI8tT=Dl2in~VLHJmGK z+^uEHzR+8t9?4krk4b(Q`vL_X{}054;Z2&HtFdW=K(wD$4!w&P8&Y2TwBzHgJV$eL z&bUUAtH;m1AMkBbUtly%wApFMTIs+{QH}reH+vADhwaI6S69?|cWBkJd`-$@u3nl$ z++zMkY;0`G+~K&^Be{%1{D+;>!&}6r>pqKN$O67Mf~&#~?_exbAw)Ujr$RoPmuA6+ zKW1pBx|XP;)Qm!y#s^JpLcpz@z^dqD-2`;;=2R z!u`uNb<4X@rnw!rXWi^Crz+|L#FR9VrF2=fpGs~1(CKFQ*?&p?w_RDf~=qo&)NFPJ2f7!kt#k<={1E`o-oKXbJ>?llenI` z2$G8Wb>D=HF_u|3e7gGXt^F!=)DunBTC^6w%>9XizwCc@8YrSg<-14HADy07N~TaK z>-;h5Y?YOc}XSiHennAw~x-VrAyBM*qa1e)SC)0QW^ z@J5-@G;*}_)8EFBQ$v53-GdKf2sTyZ1uoyFS#aEQ2FJat-+296dg`p9RH;L`n4fzu z#6N@cR&1J3hn^i&S@)adky!U(H6t6HsSx0a7XC4aXQ<{;q7M7xaz>ls=qZ9bi`|-0 ztn&b)37kESnakKt=uOY^_%-tha?&5ovf=PszdQAwPxA6Od`X6Gvo^-`^6Mf$TIJ-j zpBSRmwc7fYTr-Q#5s|s*9qA(~HoAD=zbuCv^Jg-@t4PF~7Ux4gprdJ^QKn`S@_&I< Bp}GJ7 literal 0 HcmV?d00001 diff --git a/third_party/square/mcp.json b/third_party/square/mcp.json new file mode 100644 index 000000000..555a38431 --- /dev/null +++ b/third_party/square/mcp.json @@ -0,0 +1,8 @@ +{ + "mcpServers": { + "square": { + "type": "http", + "url": "https://mcp.squareup.com/mcp" + } + } +}