Skip to content

AI agents (MCP)

Cue ships a Model Context Protocol server, so AI agents — Claude, Cursor, your own agent framework — can notify people and check what happened, through the same rules, policy and audit trail as the rest of your system.

pip install cue-notify
cuectl keys create support-agent -s events:write -s messages:read

If the agent sends messages itself, register it as an agent and bind its key with --agent. It then gets a per-person attention budget, an importance ceiling, and approval for anything you want a person to check first.

Desktop agents (stdio)

Add Cue to your agent's MCP configuration, for example:

{
  "mcpServers": {
    "cue": {
      "command": "cuectl",
      "args": ["mcp"],
      "env": {
        "CUE_URL": "https://cue.example.com",
        "CUE_API_KEY": "ck_…"
      }
    }
  }
}

Remote agents (HTTP)

cuectl mcp --transport streamable-http --host 0.0.0.0 --port 8765

The endpoint is served at /mcp. Put it behind your usual authentication; the API key the server holds decides what any connected agent may do.

Tools

Tool Does Needs scope
send_event Report something that happened; rules decide what to send. events:write
send_message Send a template directly over given channels. messages:write
get_message, list_messages Delivery status, content, engagement. messages:read
get_event Per-rule outcome of an event. messages:read
review_message Approve or reject a message waiting for review. messages:write
explain Dry-run: which rules would fire and why not. admin
preview_template, list_templates Discover and render templates. admin

Read tools are annotated read-only, so agents can call them without confirmation where their host allows it; sending tools are not.

Good practice

  • Least privilege. Give agents events:write + messages:read and let your rules decide content. Grant messages:write only when the agent should choose templates.
  • Idempotency. The server instructs agents to pass an idempotency key derived from the action that triggered the notification, so a retried tool call never notifies twice.
  • Policy still applies. Caps, quiet hours and unsubscribes protect your users from an over-eager agent exactly as they do from a buggy cron job.