Having the same issue.
Authorizing Self-Hosted Agent with Personal Cursor API key.
I do have My Secrets populated with proper keys and naming convention is correct. Agent also has instructions about each key in AGENTS.md file as well as team MCPs are configured correctly with ${env:FOO_BAR} keys.