LIMITED STARTUP TEST · TESTED Aug 13, 2026
Does Cursor CLI phone home?
Invalid-key startup reached one Cursor host through two routes in 3/3 runs.
EXACT SCENARIO
Fresh Cursor config and data directories, ask mode, sandbox enabled, fixed prompt, deliberately invalid API key. Authentication stopped the run before model work.
default
Documented defaults
- RUNS
- 3/3
- REQUESTS
- 2 · 2 · 2
| Destination | Route | Observed | Counts | Class |
|---|---|---|---|---|
| api2.cursor.shCursor | POST /aiserver.v1.DashboardService/GetMe |
OBSERVED | 1 / 1 / 1 | first party |
| api2.cursor.shCursor | POST /auth/exchange_user_api_key |
OBSERVED | 1 / 1 / 1 | first party |
WHAT THIS SUPPORTS
Every clean-profile run called GetMe and the API-key exchange endpoint. A successful-session or privacy-mode comparison is not published yet.
WHAT IT DOES NOT SUPPORT
- The run stopped at invalid API-key validation; no model or tool traffic was measured.
- Privacy Mode is account-scoped and was not compared in this unauthenticated test.
- The test used macOS arm64 and one network path behind the operator's existing VPN.
EVIDENCE CHAIN
Hashes identify the private raw captures and public sanitized manifests.
Raw captures are withheld because they contain request and response bodies. Sanitized manifests contain route facts only.
Binary SHA-256
77d530da58cd825ed91c6a66a95730af35cb6e8e6e494649bcdc92db2d42e070Raw capture SHA-256
9e409732d7f33f3a9944d91d8460f8e3db0169109923dacb7f9efbee48728da8
1dbd8625201976923c2ba624ec60a84a91fd6d1565a3dd6a61c6fd9d330a5fd9
46540d63a9e5bff9b4905371e0dfce04a58d606d545ebe150e533eb3ffcf1044Sanitized manifest SHA-256
4379f979190becbfbaa38fb7dc2c1c2d916a98a20e5b926bbddc3fd065b60216
dc42a6abdfbbc0d3b9a956519d5c20573795e6d6234e3030d6894dd6f26952d9
1653e86adb0d11fcc9d88df0f89e222ae81f96b50ab0c8e2c9feef26f4b9da26