Skip to evidence

LIMITED STARTUP TEST · TESTED Aug 13, 2026

Does Cursor CLI phone home?

Invalid-key startup reached one Cursor host through two routes in 3/3 runs.

BUILD 2026.03.30-a5d3e17 REPEATS 3/3 DECODED HOSTS 1 PLATFORM macOS 15 arm64
FOLLOW THIS BUILD FEED

Fresh Cursor config and data directories, ask mode, sandbox enabled, fixed prompt, deliberately invalid API key. Authentication stopped the run before model work.

default

Documented defaults

RUNS
3/3
REQUESTS
2 · 2 · 2
DestinationRouteObservedCountsClass
api2.cursor.shCursor POST /aiserver.v1.DashboardService/GetMe OBSERVED 1 / 1 / 1 first party
api2.cursor.shCursor POST /auth/exchange_user_api_key OBSERVED 1 / 1 / 1 first party

WHAT THIS SUPPORTS

Every clean-profile run called GetMe and the API-key exchange endpoint. A successful-session or privacy-mode comparison is not published yet.

WHAT IT DOES NOT SUPPORT

  1. The run stopped at invalid API-key validation; no model or tool traffic was measured.
  2. Privacy Mode is account-scoped and was not compared in this unauthenticated test.
  3. The test used macOS arm64 and one network path behind the operator's existing VPN.

EVIDENCE CHAIN

Hashes identify the private raw captures and public sanitized manifests.

Raw captures are withheld because they contain request and response bodies. Sanitized manifests contain route facts only.

Binary SHA-25677d530da58cd825ed91c6a66a95730af35cb6e8e6e494649bcdc92db2d42e070
Raw capture SHA-2569e409732d7f33f3a9944d91d8460f8e3db0169109923dacb7f9efbee48728da8 1dbd8625201976923c2ba624ec60a84a91fd6d1565a3dd6a61c6fd9d330a5fd9 46540d63a9e5bff9b4905371e0dfce04a58d606d545ebe150e533eb3ffcf1044
Sanitized manifest SHA-2564379f979190becbfbaa38fb7dc2c1c2d916a98a20e5b926bbddc3fd065b60216 dc42a6abdfbbc0d3b9a956519d5c20573795e6d6234e3030d6894dd6f26952d9 1653e86adb0d11fcc9d88df0f89e222ae81f96b50ab0c8e2c9feef26f4b9da26

OPEN MACHINE-READABLE MANIFEST