What is Cursor Plugins? A catalogue for agent extensions
Deploying a Cursor plugin: client package, not a web server
Plan client compatibility, marketplace source and credentials for one chosen extension
What you will learn
- Resolve the distribution layers
- Handle integrations separately
- Record a release receipt
Before you start
- A disposable client profile
- One selected plugin
- The pinned repository revision
Turn a promising catalogue entry into a repeatable team decision
Key takeaways
- Marketplace and plugin manifests have different roles.
- Cross-client catalogues differ at this revision.
- A plugin can add network or hook dependencies.
Resolve the distribution layers
A marketplace entry names a source path. The plugin manifest may specify a `minClientVersions` map; the pinned GitHub integration requires Cursor 3.13.0 or later in its manifest.
The root repository is not a service that needs its own port or database. A particular plugin may start hooks or connect to an MCP server, so deployment work is defined by that plugin rather than by the repository name.
Handle integrations separately
The GitHub plugin declares a required `GITHUB_PERSONAL_ACCESS_TOKEN` variable and points its MCP configuration to an HTTP endpoint. Decide token scopes and storage before enabling it.
The `.claude-plugin/marketplace.json` at this revision lists `origin-apps`, not a mirror of every Cursor entry. Do not promise identical installation behavior across clients from a similar directory name.
Record a release receipt
Pin the repository commit, selected plugin directory, client version, manifest version and any environment variables. For shared teams, review who can add or update plugins and how to roll back a changed manifest.
This guide does not verify a live Cursor deployment, compatibility negotiation or token handling. Those require a controlled client test with no production credentials.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Pin the selected source and client version.
- 2
Keep integration tokens out of shared files.
- 3
Test update and removal in a disposable client profile.
Copy-ready example
selected_plugin: github
repository_commit: d0ef80d
client: verify_supported_version
credential: scoped_GITHUB_PERSONAL_ACCESS_TOKEN
rollback: restore_previous_plugin_versionFrequently asked questions
Does the repository need Docker?
No common server is described for the catalogue; deployment depends on the plugin selected.
Can one token serve all teams safely?
Scope and distribute each integration credential according to its actual permissions and owner.
Sources
- Cursor Plugins / .cursor-plugin/marketplace.jsonSource checked 2026-10-08
- Cursor Plugins / .claude-plugin/marketplace.jsonSource checked 2026-10-08
- Cursor Plugins / third_party/github/.cursor-plugin/plugin.jsonSource checked 2026-10-08
- Cursor Plugins / third_party/github/mcp.jsonSource checked 2026-10-08