Configuration

Configuration and approvals

Full reference

8 reviewed records from the Agent CLI and the desktop app: the CLI configuration schema, settings and the sandbox and approval policy. Each entry gives the exact shipped bytes and their location; schemas are decoded or reconstructed into tables above the bytes they come from.

Configuration

CLI configuration paths

Source: index.js (Agent CLI) · bytes 4350767–4351673 · SHA-256 659658c3bd3a…

Minified Agent CLI webpack module ../cursor-config/dist/paths.js (906 characters), the code behind the CLI configuration paths. Identifiers are minified; the exact shipped code is below.

Exact shipped text
"../cursor-config/dist/paths.js"(t,e,r){"use strict";r.d(e,{WI:()=>o,Xq:()=>l,kL:()=>d,m4:()=>u,qA:()=>m});var n=r("node:crypto"),s=r("node:os"),i=r("node:path"),a=r("../utils/dist/workspace-paths.js");function o(){const t=process.env.CURSOR_CONFIG_DIR;if(t?.trim())return t;const e=process.env.XDG_CONFIG_HOME;return e?.trim()?(0,i.join)(e,"cursor"):(0,i.join)((0,s.homedir)(),".cursor")}function c(){const t=process.env.CURSOR_DATA_DIR;return t?.trim()?t:(0,i.join)((0,s.homedir)(),".cursor")}function u(){return(0,i.join)(c(),"projects")}function l(t){return(0,i.join)(u(),(0,a.r_)(t))}function d(t){let e=u();e.length>84&&(e=c(),e.length>84&&(e="/tmp/.cursor"));const r=(0,i.join)(e,(0,a.r_)(t));if(r.length>92){const t=(0,n.createHash)("sha256").update(r).digest("hex").substring(0,7);return`${r.substring(0,Math.min(84,r.length))}-${t}`}return r}function m(){return(0,i.join)(o(),"cli-config.json")}}

CLI configuration schema

Source: index.js (Agent CLI) · bytes 4352187–4356862 · SHA-256 53d4367766f0…

Minified Agent CLI webpack module ../cursor-config/dist/schema.js (4,308 characters), the code behind the CLI configuration schema. Identifiers are minified; the exact shipped code is below.

Reconstructed from the minified zod schemas in this span; approximate. Builder names are minified, so types are inferred from how each builder is used. Every key is a literal from the shipped code.

Key Type Optional Default
permissions object no —
permissions.allow array of string no —
permissions.deny array of string no —
version number no —
editor object no —
editor.vimMode boolean no —
editor.defaultBehavior "ide" | "agent" yes —
display object no {…}
display.showLineNumbers boolean no false
display.showThinkingBlocks boolean no false
display.showStatusIndicators boolean no false
display.showStatusLineRunningTime boolean no false
display.mode "zen" | "standard" no "zen"
notifications boolean no true
hints boolean no true
modelSlashCommands boolean no true
steering boolean no true
rewind boolean no true
statusLine object yes —
statusLine.type "command" no —
statusLine.command string (min 1) no —
statusLine.padding integer (min 0) yes —
statusLine.updateIntervalMs integer (positive) yes —
statusLine.timeoutMs integer (positive) yes —
channel "static" | "prod" | "lab" | "prod-stable-internal" yes —
model custom yes —
bedrock object yes —
bedrock.enabled boolean no false
bedrock.mode "access-key" | "team-role" no "access-key"
bedrock.region string yes —
bedrock.testModel string yes —
bedrock.teamRoleArn string yes —
bedrock.teamExternalId string yes —
awsAuthRefresh string yes —
hasChangedDefaultModel boolean yes false
maxMode boolean yes false
maxModeAutoEnabled boolean yes —
modelParameters record<string, array of object> yes —
selectedModel object yes —
selectedModel.modelId string no —
selectedModel.parameters array of object no —
selectedModel.parameters[].id string no —
selectedModel.parameters[].value string no —
modelSelectionHistory array of string (max 32) yes —
exploreSubagentModel "default" | "inherit" no "default"
subagentModels object yes —
subagentModels.explore "default" | "inherit" | "disabled" | object yes —
privacyCache object yes —
privacyCache.ghostMode boolean no —
privacyCache.privacyMode number yes —
privacyCache.updatedAt number no —
autoReviewAvailabilityCache object yes —
autoReviewAvailabilityCache.backendUrl string no —
autoReviewAvailabilityCache.authCacheKey string no —
autoReviewAvailabilityCache.teamId number yes —
autoReviewAvailabilityCache.available boolean no —
autoReviewAvailabilityCache.updatedAt number no —
serverConfigCache object yes —
serverConfigCache.backendUrl string no —
serverConfigCache.authCacheKey string yes —
serverConfigCache.teamId number yes —
serverConfigCache.agentUrlConfig object yes —
serverConfigCache.agentUrlConfig.agentUrl string no —
serverConfigCache.agentUrlConfig.agentnUrl string no —
serverConfigCache.cliSandboxDefaultEnabled boolean yes —
serverConfigCache.serverHttp2Config number yes —
serverConfigCache.updatedAt number no —
authInfo object yes —
authInfo.email string yes —
authInfo.displayName string yes —
authInfo.teamId number yes —
authInfo.teamName string yes —
authInfo.userId number yes —
authInfo.authId string yes —
authInfo.organizationId string yes —
authInfo.activeTeamId number yes —
network object no {…}
network.useHttp1ForAgent boolean no false
approvalMode "allowlist" | "unrestricted" | "auto-review" yes "allowlist"
autoAcceptWebSearch boolean no false
sandbox object yes —
sandbox.mode "disabled" | "enabled" no "disabled"
sandbox.networkAccess "user_config_only" | "user_config_with_defaults" | "allow_all" yes —
sandbox.networkAllowlist array of string yes []
sandbox.readBoundary "system" | "workspace" yes —
showSandboxIntro boolean yes false
runEverythingSettingsPromptStreak integer (nonnegative) yes —
runEverythingSettingsPromptCooldownUntilMs integer (nonnegative) yes —
attribution object yes —
attribution.attributeCommitsToAgent boolean no true
attribution.attributePRsToAgent boolean no true
webFetchDomainAllowlist array of string yes []
conversationClassificationScoredConversations array of object yes —
conversationClassificationScoredConversations[].conversationId string no —
conversationClassificationScoredConversations[].lastUpdatedAt number no —
Exact shipped text
"../cursor-config/dist/schema.js"(t,e,r){"use strict";r.d(e,{Kr:()=>P,R8:()=>I,cy:()=>x,r0:()=>k});var n=r("../proto/dist/generated/agent/v1/agent_pb.js"),s=r("../../../../../../../../../../<build path>"),i=r("../../../../../../../../../../<build path>");const a=s.bz().transform(((t,e)=>{if(t instanceof n.Gm)return t;try{return n.Gm.fromJson(t,{ignoreUnknownFields:!1})}catch(r){return e.addIssue({code:i.eq.custom,message:r instanceof Error?r.message:String(r)}),t}})),o=s.Ik({type:s.eu("command"),command:s.Yj().min(1),padding:s.ai().int().min(0).optional(),updateIntervalMs:s.ai().int().positive().optional(),timeoutMs:s.ai().int().positive().optional()}),c=s.Ik({allow:s.YO(s.Yj()),deny:s.YO(s.Yj())}),u=s.Ik({vimMode:s.zM(),defaultBehavior:s.k5(["ide","agent"]).optional()}),l=s.Ik({showLineNumbers:s.zM().default(!1),showThinkingBlocks:s.zM().default(!1),showStatusIndicators:s.zM().default(!1),showStatusLineRunningTime:s.zM().default(!1),mode:s.k5(["zen","standard"]).default("zen")}),d=s.Ik({enabled:s.zM().default(!1),mode:s.k5(["access-key","team-role"]).default("access-key"),region:s.Yj().optional(),testModel:s.Yj().optional(),teamRoleArn:s.Yj().optional(),teamExternalId:s.Yj().optional()}),m=s.Ik({id:s.Yj(),value:s.Yj()}),p=s.Ik({modelId:s.Yj(),parameters:s.YO(m)}),f=s.Ik({modelId:s.Yj(),parameters:s.YO(m).optional(),maxMode:s.zM().optional()}),h=s.KC([s.k5(["default","inherit","disabled"]),f]),g=s.Ik({explore:h.optional()}),A=s.Ik({ghostMode:s.zM(),privacyMode:s.ai().optional(),updatedAt:s.ai()}),b=s.Ik({backendUrl:s.Yj(),authCacheKey:s.Yj(),teamId:s.ai().optional(),available:s.zM(),updatedAt:s.ai()}),y=s.Ik({agentUrl:s.Yj(),agentnUrl:s.Yj()}),_=s.Ik({backendUrl:s.Yj(),authCacheKey:s.Yj().optional(),teamId:s.ai().optional(),agentUrlConfig:y.optional(),cliSandboxDefaultEnabled:s.zM().optional(),serverHttp2Config:s.ai().optional(),updatedAt:s.ai()}),w=s.Ik({email:s.Yj().optional(),displayName:s.Yj().optional(),teamId:s.ai().optional(),teamName:s.Yj().optional(),userId:s.ai().optional(),authId:s.Yj().optional(),organizationId:s.Yj().optional(),activeTeamId:s.ai().optional()}),C=s.Ik({useHttp1ForAgent:s.zM().default(!1)}),v=s.Ik({mode:s.k5(["disabled","enabled"]).default("disabled"),networkAccess:s.vk((t=>"allowlist"===t?"user_config_with_defaults":"enabled"===t?"allow_all":t),s.k5(["user_config_only","user_config_with_defaults","allow_all"])).optional(),networkAllowlist:s.YO(s.Yj()).default([]).optional(),readBoundary:s.k5(["system","workspace"]).optional()}),E=s.Ik({attributeCommitsToAgent:s.zM().default(!0),attributePRsToAgent:s.zM().default(!0)}),S=s.Ik({conversationId:s.Yj(),lastUpdatedAt:s.ai()}),I=s.Ik({permissions:c}),B=I.extend({version:s.ai(),editor:u,display:l.default({showLineNumbers:!1,showThinkingBlocks:!1,showStatusIndicators:!1,showStatusLineRunningTime:!1,mode:"zen"}),notifications:s.zM().default(!0),hints:s.zM().default(!0),modelSlashCommands:s.zM().default(!0),steering:s.zM().default(!0),rewind:s.zM().default(!0),statusLine:o.optional(),channel:s.eu("static").or(s.eu("prod")).or(s.eu("lab")).or(s.eu("prod-stable-internal")).optional(),model:a.optional(),bedrock:d.optional(),awsAuthRefresh:s.Yj().optional(),hasChangedDefaultModel:s.zM().default(!1).optional(),maxMode:s.zM().default(!1).optional(),maxModeAutoEnabled:s.zM().optional(),modelParameters:s.g1(s.Yj(),s.YO(m)).optional(),selectedModel:p.optional(),modelSelectionHistory:s.YO(s.Yj()).max(32).optional(),exploreSubagentModel:s.k5(["default","inherit"]).default("default"),subagentModels:g.optional(),privacyCache:A.optional(),autoReviewAvailabilityCache:b.optional(),serverConfigCache:_.optional(),authInfo:w.optional(),network:C.default({useHttp1ForAgent:!1}),approvalMode:s.k5(["allowlist","unrestricted","auto-review"]).default("allowlist").optional(),autoAcceptWebSearch:s.zM().default(!1),sandbox:v.optional(),showSandboxIntro:s.zM().default(!1).optional(),runEverythingSettingsPromptStreak:s.ai().int().nonnegative().optional(),runEverythingSettingsPromptCooldownUntilMs:s.ai().int().nonnegative().optional(),attribution:E.optional(),webFetchDomainAllowlist:s.YO(s.Yj()).default([]).optional(),conversationClassificationScoredConversations:s.YO(S).optional()}),k=I.strict().extend({}),P=B.merge(k);function x(t){return t.subagentModels?.explore??t.exploreSubagentModel}}

Project MCP configuration path (occurrence 1)

Source: out/vs/workbench/workbench.desktop.main.js (desktop) · bytes 36274133–36274149 · SHA-256 6d5c8bdb80d1…

.cursor/mcp.json

Project MCP configuration path (occurrence 2)

Source: out/vs/workbench/workbench.desktop.main.js (desktop) · bytes 36274181–36274197 · SHA-256 6d5c8bdb80d1…

.cursor/mcp.json

Host-owned session storage setting

Source: extensions/cursor-agent-host/package.json (desktop) · bytes 587–972 · SHA-256 5145ed8c09f7…

Experimental. Store new agent chats in per-session databases owned by the agent host, under the extension's global storage, mirroring every write to the renderer's store; existing chats stay where they are. Read when the agent host starts, so a change takes effect after a window reload. The CURSOR_AGENT_HOST_OWNED_SESSION_STORAGE environment variable (1 or true) turns this on too.

Remote inference route setting

Source: extensions/cursor-agent-host/package.json (desktop) · bytes 1409–1837 · SHA-256 0ef2fd74acef…

How the agent host routes AgentService on remote windows (Remote-SSH, WSL, containers). Same enum shape as remote.SSH.localServerDownload. machine-overridable so a per-remote settings.json can force always or never for one box. Local windows ignore this setting. Read once when the agent host starts; a change takes effect after a window reload. always is ignored on a private-inference remote because the local hop skips CPI.

Sandbox and approval settings

Sandbox policy schema (desktop)

Source: extensions/cursor-agent-exec/dist/main.js (desktop) · bytes 407641–407997 · SHA-256 6267e53e44c4…

Decoded from the shipped protobuf descriptor for SandboxPolicy; referenced types resolved through Cursor's own generated classes (agent.v1).

No. Field Type Label
1 type enum SandboxPolicy.Type —
2 network_access bool optional
3 additional_readwrite_paths string repeated
4 additional_readonly_paths string repeated
5 debug_output_dir string optional
7 disable_tmp_write bool optional
8 allowlist_escalated bool optional
9 enable_shared_build_cache bool optional
10 network_policy NetworkPolicy optional
11 network_policy_strict bool optional
12 capture_denies bool optional
13 skip_statsig_defaults bool optional
14 read_boundary enum SandboxPolicy.ReadBoundaryMode —
15 additional_read_paths string repeated
Exact shipped text
SandboxPolicy|1 type #0|2 network_access 8?|3 additional_readwrite_paths 9*|4 additional_readonly_paths 9*|5 debug_output_dir 9?|7 disable_tmp_write 8?|8 allowlist_escalated 8?|9 enable_shared_build_cache 8?|10 network_policy #1?|11 network_policy_strict 8?|12 capture_denies 8?|13 skip_statsig_defaults 8?|14 read_boundary #2|15 additional_read_paths 9*

Sandbox policy schema (Agent CLI)

Source: index.js (Agent CLI) · bytes 5944731–5945087 · SHA-256 6267e53e44c4…

Decoded from the shipped protobuf descriptor for SandboxPolicy; referenced types resolved through Cursor's own generated classes (agent.v1).

No. Field Type Label
1 type enum SandboxPolicy.Type —
2 network_access bool optional
3 additional_readwrite_paths string repeated
4 additional_readonly_paths string repeated
5 debug_output_dir string optional
7 disable_tmp_write bool optional
8 allowlist_escalated bool optional
9 enable_shared_build_cache bool optional
10 network_policy NetworkPolicy optional
11 network_policy_strict bool optional
12 capture_denies bool optional
13 skip_statsig_defaults bool optional
14 read_boundary enum SandboxPolicy.ReadBoundaryMode —
15 additional_read_paths string repeated
Exact shipped text
SandboxPolicy|1 type #0|2 network_access 8?|3 additional_readwrite_paths 9*|4 additional_readonly_paths 9*|5 debug_output_dir 9?|7 disable_tmp_write 8?|8 allowlist_escalated 8?|9 enable_shared_build_cache 8?|10 network_policy #1?|11 network_policy_strict 8?|12 capture_denies 8?|13 skip_statsig_defaults 8?|14 read_boundary #2|15 additional_read_paths 9*