Making an MCP Server Install Itself: Three Hosts, Three Mechanisms, Gotchas

MCP server setup still often means hand-editing a JSON file — and every host uses a different file and format. That friction keeps developers from running servers they'd otherwise use. This post breaks down three hosts, their installation mechanisms, and the gotchas that trip you up.
Three Hosts, Three Mechanisms
- VS Code: Has a real API —
registerMcpServerDefinitionProvider. Declare a provider inpackage.jsonand return the server definition at runtime. VS Code shows a consent prompt. No config file editing. Cleanest, but requires shipping a VS Code extension. - Cursor: No native API. Write
.cursor/mcp.jsondirectly with root keymcpServers. - Claude Code: Use the CLI. Do not hand-write the file. Run e.g.:
claude mcp add --transport stdio --scope <user|local> --env … <name> -- node <path>
Six Gotchas to Guard Against
- That JSON file isn't yours. Cursor's
mcp.jsonholds the user's other servers. Read, merge your entry, preserve unrelated keys — don't overwrite. - Survive a malformed file. If the file exists but is invalid JSON, do not treat it as empty and overwrite. Same for read/permission errors — rethrow. Treating “couldn't read it” as “nothing there” will corrupt configurations.
- Back up + write atomically. Copy the existing file before touching it, write to a temp file, then rename over the target. A half-written
mcp.jsonbreaks the editor. - Installing twice must be a no-op, not an error. The Claude CLI errors if the entry already exists — so
removethenadd. For file hosts, key by server name and replace in place. Re-running should converge, not duplicate. - Scope changes everything. User-level vs project-level install changes where the config lands and what the server needs (e.g., explicit data dir vs. upward-discovery). Pick deliberately.
- You own staying current. The version registered drifts from what you ship. Add a check: “is what's installed still the version I bundle?” and a clean re-install path. One button shows state: install, update, or up to date.
The meta-lesson: hand-setup fails because a human pasting a snippet doesn't know the absolute path, the right scope, env vars, or how to merge safely. The install code does.
📖 Read the full source: r/ClaudeAI
👀 See Also

How to avoid unexpected OpenRouter costs in OpenClaw automation
A developer team accidentally spent $750 in 3 days on OpenRouter by defaulting to Claude Sonnet 4.6 ($3/M tokens) across all automation tasks. They reduced costs by 97% by changing default models, locking cron jobs and subagents to cheaper options, and reserving expensive models only for sensitive work.

CLI Design Patterns for AI Agents: Misconceptions and Practical Approaches
A Reddit post clarifies that CLI for agents means a text command interface protocol, not necessarily a real shell, and outlines agent-friendly CLI design principles including Unix-style help, tips thinking, and safety mechanisms like dry-run previews and human authorization.

Camoufox Cookie Injection: Browse Reddit as Yourself While Your Agent Does the Work
A detailed walkthrough on bypassing Reddit bot detection by extracting Firefox cookies and injecting them into Camoufox via Playwright.

Practical Lessons from Building On-Device AI in React Native
A developer shares specific technical details from building a React Native app with on-device LLMs, image generation, voice transcription, and vision AI, including memory management strategies, library choices, and performance benchmarks.