Skip to main content
← Back to Articles
mcpcodadocscursoridesetup2026

Coda MCP Server Cursor IDE Setup 2026: Official Server vs. coda-mcp

Connect Coda to Cursor IDE two ways: Coda's own hosted MCP server at coda.io/apis/mcp (OAuth or a Bearer token), or the community coda-mcp npm package for local, API-key-based access to docs, tables, and rows.

By Web MCP Guide•September 17, 2026•11 min read

How do you connect Coda to Cursor IDE via MCP? You have two real options, and they're not interchangeable. Coda itself runs a hosted MCP server at coda.io/apis/mcp — add it to mcp.json as a remote URL with a Bearer token and Cursor can read and write your docs, pages, tables, and rows without you running anything locally. The alternative is coda-mcp, a community npm package that runs via npx on your machine with a Coda API key in the environment. Most people should start with the official server; the npm package earns its place when you want the process running locally instead of relying on Coda's endpoint being up.

This guide covers both, because which one is right for you depends on things the marketing copy won't tell you — whether you want OAuth-scoped access tied to your logged-in Coda account, or a simpler API-key setup you can drop into a shared dev environment.

What "Coda MCP" Actually Gets You

Coda is a docs-meets-database tool: pages that can embed live tables, and tables that behave like a lightweight spreadsheet with formulas. An MCP connection lets Cursor read a page's content as markdown, list and query rows in a table, and — this is the part people underestimate — write back. Cursor can append content to a page, create new pages, update a row's values, or push a button column (Coda's automation trigger) directly from a chat prompt. That last one matters if you use Coda buttons to fire off automations; it means an agent-driven workflow in Cursor can trigger real side effects in your workspace, not just read from it.

That write capability is also the reason to be deliberate about which token you connect. Whatever access your Coda account or API key has, the MCP connection inherits it — including any docs you can edit, not just the one you're currently thinking about.

Option 1: Coda's Official Hosted MCP Server

Coda has run a first-party MCP server since a public beta in April 2026, at coda.io/apis/mcp. It authorizes against your existing Coda account, so it sees whatever docs, tables, and rows that account already has access to — no separate scoping step. Connecting is free.

Step 1: Generate a Coda API Token

In Coda, go to your account settings and generate an API token (Coda calls this an API token in your account's API settings). Copy it — you won't see it again after leaving the page.

Step 2: Add the Server to Cursor's mcp.json

Open Cursor Settings → Tools & MCP → New MCP Server, which opens mcp.json for editing. Add:

{
  "mcpServers": {
    "coda": {
      "url": "https://coda.io/apis/mcp",
      "headers": {
        "Authorization": "Bearer ${env:CODA_API_TOKEN}"
      }
    }
  }
}

Set CODA_API_TOKEN as an environment variable rather than pasting the raw token into the file — Cursor resolves ${env:...} references in mcp.json, so the token itself never has to live in a file you might commit by accident.

Step 3: Restart and Verify

Restart Cursor. In chat, try:

List my Coda docs

If it comes back with real doc titles instead of an auth error, the connection is live.

Option 2: The Community coda-mcp Package

If you'd rather run the server locally — useful for air-gapped setups, or if you just don't want a third-party host in the auth path for a docs tool with write access — coda-mcp (published on npm, actively maintained on GitHub under orellazri/coda-mcp) does the same job through the Coda REST API instead of a hosted MCP endpoint.

Step 1: Get a Coda API Key

Same source as above: your Coda account's API settings page. This is a plain API key, not an OAuth token, so treat it like any other long-lived credential.

Step 2: Configure mcp.json

{
  "mcpServers": {
    "coda": {
      "command": "npx",
      "args": ["-y", "coda-mcp@latest"],
      "env": {
        "API_KEY": "your-coda-api-key-here"
      }
    }
  }
}

Step 3: Restart Cursor and Test

List the tables in my [doc name] Coda doc

What coda-mcp Actually Exposes

This isn't a thin wrapper — it's a fairly complete tool surface:

  • Docs & pages: coda_list_documents, coda_list_pages, coda_get_page_content, coda_create_page, coda_duplicate_page, coda_rename_page, coda_peek_page

  • Content editing: coda_replace_page_content, coda_append_page_content

  • Tables & rows: coda_list_tables, coda_list_columns, coda_list_rows, coda_get_row, coda_upsert_rows, coda_update_row, coda_delete_row, coda_delete_rows

  • Misc: coda_resolve_link (turns a Coda browser URL into structured metadata), coda_push_button
  • That coda_push_button tool is worth calling out specifically — it lets Cursor trigger any button-column automation in a table, which in practice means it can kick off whatever workflow you've wired to that button, from sending a notification to running a cross-doc sync. If you don't want an AI agent able to fire those, don't grant this server access to docs that have buttons wired to anything consequential.

    Official vs. Community: Which One to Actually Use

    The honest answer is "it depends on what you're protecting against." The official server is zero-install and inherits your account's exact permissions through OAuth-style Bearer auth — less to maintain, but every request round-trips through Coda's hosted endpoint. The community package runs on your machine, uses a static API key instead of OAuth, and its release cadence depends on one maintainer's GitHub activity rather than Coda's own SLA. If you're building something you plan to hand to teammates or run in CI, the official server's account-level auth model is easier to reason about. If you want the connection to keep working exactly as documented even if Coda changes its hosted MCP endpoint mid-beta, self-hosting the npm package gives you that control — at the cost of you being the one who has to update it.

    Either way, don't run both against the same doc set in the same Cursor session — Cursor will register two coda-named or similarly-scoped servers and you'll have no reliable way to tell which one actually served a given tool call when something goes wrong.

    Practical Workflows

    Turning a spec doc into a checklist

    Read my "Q4 Migration Plan" Coda doc and create a new page called 
    "Engineering Checklist" that breaks the plan into a table with columns 
    for Task, Owner, and Status.
    

    Auditing a tracking table before a sync

    List all rows in the "Vendors" table where the Status column is 
    "Pending Review" and summarize which ones are missing a Contact field.
    

    Keeping a doc in sync with code changes

    Append a new section to the "API Changelog" page in Coda summarizing 
    the breaking changes in this diff.
    

    Gotchas

    The official server is still labeled beta. Coda introduced it in April 2026; beta software from a vendor can change its scopes, rate limits, or auth flow with less notice than a GA product. If your workflow depends on it not changing under you, keep an eye on Coda's changelog.

    Write access means write access. Both options can create pages, edit content, and modify rows — there's no built-in read-only mode on either path. If you only want Cursor to read from Coda, that has to be a prompting discipline you enforce yourself, not something the server enforces for you.

    API keys and OAuth tokens aren't interchangeable between the two setups. The API key from your account settings works for the community coda-mcp package's API_KEY env var; the official hosted server expects a Bearer token in the Authorization header. Copying one into the other's config will fail auth, not silently degrade.

    coda_push_button can trigger real automations. Treat it the same way you'd treat handing an intern access to click any button in your workspace — fine for docs where the buttons are low-stakes, not fine for anything wired to a production system.

    Troubleshooting

    401 or "unauthorized" errors on the official server
    Confirm the header is exactly Authorization: Bearer <token> — a missing Bearer prefix is the most common mistake, and it fails silently as an auth error rather than a helpful parse error.

    npx -y coda-mcp@latest hangs or errors on first run
    Run it manually in a terminal outside Cursor first. If it fails there too, it's an environment problem (Node version, missing API_KEY), not a Cursor-specific one.

    Cursor can list docs but "List tables" comes back empty
    You're likely pointed at a doc where your account has view-only access to a locked table, or the doc genuinely has no tables — try coda_list_pages first to confirm you're looking at the right doc.

    Changes made via Cursor aren't reflecting in the Coda web app
    Coda's own UI can lag a few seconds behind API writes on busy docs. Refresh before assuming the write failed.

    Frequently Asked Questions

    Q: Is there an official, Coda-maintained MCP server?
    A: Yes — Coda has run one at coda.io/apis/mcp since a public beta in April 2026, distinct from the several community-built alternatives on npm and GitHub.

    Q: Do I need a paid Coda plan to use MCP?
    A: No — connecting the official MCP server authorizes against your existing account and its existing access; it doesn't require a specific plan tier on its own, though anything the connection can do is bounded by what your account/plan can already do inside Coda.

    Q: Can Cursor write to my Coda docs, or is this read-only?
    A: Both the official server and the coda-mcp npm package support writes — creating pages, editing content, and modifying table rows — not just reads. There's no read-only mode built into either.

    Q: What's the difference between the official server and coda-mcp?
    A: The official server is hosted by Coda and uses your account's own OAuth-style auth; coda-mcp is a community npm package you run locally via npx with a plain API key. Functionally they cover similar ground (docs, pages, tables, rows) but with different auth models and different maintenance owners.

    Q: What does coda_push_button actually do?
    A: It activates a button-column automation in a Coda table exactly as if you'd clicked it in the UI — including anything that button is wired to trigger, so it's worth restricting which docs an MCP connection can reach if any of them have consequential automations.

    Related Guides


  • Notion MCP Server: Cursor IDE Setup (2026)

  • Airtable MCP Server: Cursor IDE Setup (2026)

  • Obsidian MCP Server Setup (2026)

  • Google Calendar MCP Server: Cursor IDE Setup (2026)

  • Confluence MCP Server: Cursor IDE Setup (2026)

  • MCP Security Best Practices (2026)

  • Best MCP Servers for Developers (2026)




  • Related guides