Skip to main content
← Back to Articles
mcpcursorjenkinsci-cdsetup2026

Jenkins MCP Server Cursor IDE Setup 2026 (Official Plugin)

Connect Cursor to Jenkins with the official jenkinsci/mcp-server-plugin: install steps, the /mcp-server/mcp endpoint, Basic Auth with an API token, exposed tools, and troubleshooting.

By Web MCP Guide•September 19, 2026•11 min read

How do you connect Cursor to Jenkins over MCP? Install the official MCP Server plugin (jenkinsci/mcp-server-plugin) from the Jenkins plugin manager — it needs no configuration to start working. Then in Cursor's mcp.json, add a streamableHttp entry pointed at <your-jenkins-url>/mcp-server/mcp with an Authorization: Basic <base64 user:token> header built from a Jenkins API token. Restart Cursor, confirm the green dot, then ask it to list your Jenkins jobs as a first test.

Unlike most MCP servers on this site, Jenkins MCP isn't an npm package or a Docker image you run locally — it's a server-side Jenkins plugin. Jenkins itself becomes the MCP server; Cursor is just another HTTP client talking to it, the same way its own UI or REST API clients do.

Quick reference

MaintainerJenkins project (official, jenkinsci org)
Install asJenkins plugin, not a local process
Streamable HTTP endpoint<jenkins-url>/mcp-server/mcp
SSE endpoint<jenkins-url>/mcp-server/sse
Stateless endpoint<jenkins-url>/mcp-server/stateless
AuthHTTP Basic — Jenkins username + API token, base64-encoded
Config needed after installNone — endpoints are live immediately

Prerequisites


  • A Jenkins instance you administer, reachable over HTTPS from wherever Cursor runs.

  • Permission to install plugins (Manage Jenkins → Plugins) and to generate a personal API token.

  • Cursor with Streamable HTTP MCP support for the recommended transport.
  • Step 1: Install the MCP Server plugin

    1. Manage Jenkins → Plugins → Available plugins.
    2. Search for MCP Server and install it. No restart-time configuration screen appears — the plugin wires up its endpoints automatically as soon as it's active.
    3. Confirm it loaded by hitting <jenkins-url>/mcp-health in a browser while logged in; a response means the plugin is live.

    If your Jenkins instance is locked down behind a corporate proxy or VPN, Cursor needs the same network path to reach it that your browser uses for the Jenkins UI — there's no separate allowlisting step specific to the MCP endpoints beyond that.

    Step 2: Generate a Jenkins API token

    The plugin authenticates over standard Jenkins HTTP Basic Auth, not a bespoke MCP credential.

    1. Click your username (top right) → Security.
    2. Under API Token, click Add new Token, give it a name like cursor-mcp, and generate it.
    3. Copy the token immediately — Jenkins shows it once.
    4. Base64-encode username:token:

    echo -n "yourusername:11a2b3c4d5e6f7890" | base64
    

    Use the output as the value after Basic in the Authorization header. Scope this to a Jenkins account with the narrowest role that can still do what you want Cursor to do — a service account with read-only job/build permissions if you only want status and log lookups, a broader one if you also want it triggering builds.

    Step 3: Add Jenkins to Cursor's mcp.json

    Cursor reads MCP servers from ~/.cursor/mcp.json (global) or .cursor/mcp.json (project). The Streamable HTTP endpoint is the one to reach for first:

    {
      "mcpServers": {
        "jenkins": {
          "type": "streamableHttp",
          "url": "https://your-jenkins-host/mcp-server/mcp",
          "headers": {
            "Authorization": "Basic <base64-encoded-user:token>"
          }
        }
      }
    }
    

    If your Cursor build doesn't recognize streamableHttp, or you're behind infrastructure that mishandles long-lived HTTP/2 connections, the SSE endpoint is the fallback:

    {
      "mcpServers": {
        "jenkins": {
          "type": "sse",
          "url": "https://your-jenkins-host/mcp-server/sse",
          "headers": {
            "Authorization": "Basic <base64-encoded-user:token>"
          }
        }
      }
    }
    

    There's also a /mcp-server/stateless endpoint for clients or proxies that can't hold session state between calls — most Cursor setups don't need it, but it exists if you're routing through a load balancer that round-robins requests across Jenkins controllers.

    Save the file, restart Cursor, and check Settings → Tools & Integrations → MCP Tools for a green dot next to jenkins.

    Step 4: Verify the connection

    Ask Cursor something that requires a real call against your Jenkins instance:

    List my Jenkins jobs and tell me which ones failed on their last build.
    

    or

    Show me the console log for the most recent build of <job-name> and summarize any errors.
    

    A real, specific answer confirms the token and endpoint are working. An HTTP 401 means the Basic Auth header is wrong; a connection failure usually means the URL or network path is wrong, not the plugin itself.

    What tools does it expose?

    The plugin ships a fixed set of tools — there's no toolset-picker like some of the SaaS MCP servers on this site use, since Jenkins is a single self-hosted product rather than a multi-product API surface.

    Job management: getJob, getJobs, triggerBuild, getQueueItem

    Build information: getBuild, updateBuild, getBuildLog, searchBuildLog, rebuildBuild, getReplayScripts, replayBuild, getTestResults

    SCM integration: getJobScm, getBuildScm, getBuildChangeSets, findJobsWithScmUrl

    Management: whoAmI, getStatus

    triggerBuild, rebuildBuild, and replayBuild are the write-capable tools here — the rest are read-only lookups. Cursor prompts for approval before running a write tool by default; treat that prompt as a real checkpoint rather than something to reflexively approve, especially on a Jenkins instance wired to production deploys.

    Tuning the plugin with system properties

    The plugin needs no configuration to start, but a handful of Java system properties control its behavior once it's running. Set these on the Jenkins controller's startup flags (-D<property>=<value>):

    PropertyPurposeDefault
    io.jenkins.plugins.mcp.server.extensions.BuildLogsExtension.limit.maxHard cap on log lines returned per call10000
    io.jenkins.plugins.mcp.server.Endpoint.disableMcpStatelessTurn off the stateless endpointfalse
    io.jenkins.plugins.mcp.server.Endpoint.disableMcpSseTurn off the SSE endpointfalse
    io.jenkins.plugins.mcp.server.Endpoint.disableMcpStreamableTurn off the Streamable HTTP endpointfalse
    io.jenkins.plugins.mcp.server.Endpoint.keepAliveIntervalSSE keep-alive interval, seconds30
    io.jenkins.plugins.mcp.server.Endpoint.requireOriginMatchReject requests whose Origin header doesn't match Jenkins' root URLtrue
    io.jenkins.plugins.mcp.server.Endpoint.requireOriginHeaderReject requests with no Origin header at allfalse

    If you're only using one transport, disabling the other two shrinks the attack surface without losing anything Cursor needs — set the two disableMcp* flags for whichever endpoints you're not pointing mcp.json at.

    Security notes specific to a self-hosted MCP server

    Every other guide on this site covers a hosted SaaS MCP endpoint or a process you run locally. Jenkins MCP is different: it's a live endpoint on infrastructure you already run, reachable by anyone who can reach your Jenkins URL and has valid credentials.

  • Put it behind HTTPS. Basic Auth sends the encoded credential on every request — over plain HTTP that's a plaintext-equivalent password on the wire.

  • requireOriginMatch defaults to true, which blocks a class of cross-origin request forgery against the endpoint. Don't disable it unless you understand exactly what's calling in from outside Jenkins' own origin.

  • The plugin currently authenticates only via Basic Auth with a username and API token — there's no OAuth 2.1 authorization flow yet, though one is under open discussion in the project's GitHub issues. Until that lands, treat the API token exactly like a password: rotate it if it leaks, and don't paste it into a shared or committed mcp.json.

  • Scope the Jenkins account behind the token to the minimum role needed. A token from an admin account gives Cursor admin-equivalent reach into your CI/CD system.
  • Common mistakes

    Pointing at the Jenkins UI URL instead of the MCP path. https://jenkins.example.com and https://jenkins.example.com/mcp-server/mcp are different things — the plugin only answers on the /mcp-server/* paths.

    Using a Jenkins password instead of an API token. Basic Auth here expects username:api-token, not username:password. A raw account password will usually fail even if it "should" work, and shouldn't be used here regardless.

    Forgetting to base64-encode the credential pair. The header value is Basic <base64 of user:token>, not Basic user:token in plain text.

    Assuming a toolset picker exists. Unlike GitHub's or other multi-product MCP servers, Jenkins MCP doesn't have an env-var or header-based toolset filter — all the tools listed above are always available to any client that authenticates successfully. Access control happens at the Jenkins-account level, not the MCP-config level.

    Troubleshooting

    Connection refused or timeout. Confirm the exact hostname and port Cursor is using match what resolves from wherever Cursor runs — a Jenkins instance only reachable over a VPN needs that VPN active on the Cursor machine too.

    401 Unauthorized. Regenerate the API token and re-encode the user:token string. A stray newline from copy-pasting the base64 output is a common cause of a header that looks right but isn't.

    Tools list is empty in Cursor. Confirm you're hitting /mcp-server/mcp (or /sse) exactly — a trailing slash mismatch or a typo in the path returns a generic error rather than a helpful one on some Jenkins reverse-proxy setups.

    Plugin installed but /mcp-health 404s. The plugin didn't fully activate — check Manage Jenkins → Plugins → Installed for a warning icon next to MCP Server, and check the Jenkins system log for a startup exception.

    Origin-related rejections from a reverse proxy setup. If Jenkins sits behind a reverse proxy that rewrites or strips headers, requireOriginMatch can reject legitimate Cursor requests. Confirm the proxy passes the Origin header through unchanged, or set requireOriginMatch=false only if you understand the tradeoff.

    Frequently Asked Questions

    Is there an official Jenkins MCP server? Yes — jenkinsci/mcp-server-plugin, maintained under the official jenkinsci GitHub organization and distributed through the standard Jenkins plugin manager, not a third-party npm or PyPI package.

    Do I need Docker to run Jenkins MCP? No. It's a Jenkins plugin that runs inside your existing Jenkins controller process — there's no separate container or local command to run.

    Does Jenkins MCP support OAuth? Not yet. It authenticates via HTTP Basic Auth with a Jenkins username and API token. An OAuth 2.1 authorization flow has been proposed and is under active discussion in the plugin's GitHub repository, but it isn't shipped.

    Can Cursor trigger a Jenkins build, not just read status? Yes — triggerBuild, rebuildBuild, and replayBuild are write-capable tools the plugin exposes. Cursor will prompt for approval before calling them by default; review the specific job and parameters before approving on any pipeline tied to a production deploy.

    Which endpoint should I use — Streamable HTTP, SSE, or stateless? Streamable HTTP (/mcp-server/mcp) is the current default recommendation and what most MCP clients, including Cursor, expect. Use SSE (/mcp-server/sse) if your client or network path doesn't handle Streamable HTTP well, and stateless (/mcp-server/stateless) only if you're routing through infrastructure that can't preserve session state between requests, like a load balancer spreading calls across multiple Jenkins nodes.

    Related guides


  • CircleCI MCP Server: Cursor IDE Setup (2026)

  • Buildkite MCP Server: Cursor IDE Setup (2026) — an official, OAuth-hosted remote MCP server if you don't want to self-host

  • GitLab MCP Server: Cursor IDE Setup (2026)

  • Kubernetes MCP Server: Cursor IDE Setup (2026)

  • Terraform MCP Server: Cursor IDE Setup (2026)

  • Docker MCP Server Setup Guide (2026)

  • MCP Deployment Automation & DevOps Guide

  • How to Authenticate MCP Servers: OAuth and API Keys

  • Debug MCP Server Issues

  • MCP Security Best Practices (2026)
  • Official docs cited


  • MCP Server plugin (plugins.jenkins.io)

  • jenkinsci/mcp-server-plugin (GitHub)

  • Extension Points defined in MCP Server Plugin (jenkins.io)

  • Cursor MCP reference

  • Related guides