Configuration and approvals
Full reference8 reviewed records from the Agent CLI and the desktop app: the CLI configuration schema, settings and the sandbox and approval policy. Each entry gives the exact shipped bytes and their location; schemas are decoded or reconstructed into tables above the bytes they come from.
Configuration
CLI configuration paths
Source: index.js (Agent CLI) · bytes 4350767–4351673 · SHA-256 659658c3bd3a…
Minified Agent CLI webpack module ../cursor-config/dist/paths.js (906 characters), the code behind the CLI configuration paths. Identifiers are minified; the exact shipped code is below.
Exact shipped text
"../cursor-config/dist/paths.js"(t,e,r){"use strict";r.d(e,{WI:()=>o,Xq:()=>l,kL:()=>d,m4:()=>u,qA:()=>m});var n=r("node:crypto"),s=r("node:os"),i=r("node:path"),a=r("../utils/dist/workspace-paths.js");function o(){const t=process.env.CURSOR_CONFIG_DIR;if(t?.trim())return t;const e=process.env.XDG_CONFIG_HOME;return e?.trim()?(0,i.join)(e,"cursor"):(0,i.join)((0,s.homedir)(),".cursor")}function c(){const t=process.env.CURSOR_DATA_DIR;return t?.trim()?t:(0,i.join)((0,s.homedir)(),".cursor")}function u(){return(0,i.join)(c(),"projects")}function l(t){return(0,i.join)(u(),(0,a.r_)(t))}function d(t){let e=u();e.length>84&&(e=c(),e.length>84&&(e="/tmp/.cursor"));const r=(0,i.join)(e,(0,a.r_)(t));if(r.length>92){const t=(0,n.createHash)("sha256").update(r).digest("hex").substring(0,7);return`${r.substring(0,Math.min(84,r.length))}-${t}`}return r}function m(){return(0,i.join)(o(),"cli-config.json")}}
CLI configuration schema
Source: index.js (Agent CLI) · bytes 4352187–4356862 · SHA-256 53d4367766f0…
Minified Agent CLI webpack module ../cursor-config/dist/schema.js (4,308 characters), the code behind the CLI configuration schema. Identifiers are minified; the exact shipped code is below.
Reconstructed from the minified zod schemas in this span; approximate. Builder names are minified, so types are inferred from how each builder is used. Every key is a literal from the shipped code.
| Key | Type | Optional | Default |
|---|---|---|---|
| permissions | object | no | — |
| permissions.allow | array of string | no | — |
| permissions.deny | array of string | no | — |
| version | number | no | — |
| editor | object | no | — |
| editor.vimMode | boolean | no | — |
| editor.defaultBehavior | "ide" | "agent" | yes | — |
| display | object | no | {…} |
| display.showLineNumbers | boolean | no | false |
| display.showThinkingBlocks | boolean | no | false |
| display.showStatusIndicators | boolean | no | false |
| display.showStatusLineRunningTime | boolean | no | false |
| display.mode | "zen" | "standard" | no | "zen" |
| notifications | boolean | no | true |
| hints | boolean | no | true |
| modelSlashCommands | boolean | no | true |
| steering | boolean | no | true |
| rewind | boolean | no | true |
| statusLine | object | yes | — |
| statusLine.type | "command" | no | — |
| statusLine.command | string (min 1) | no | — |
| statusLine.padding | integer (min 0) | yes | — |
| statusLine.updateIntervalMs | integer (positive) | yes | — |
| statusLine.timeoutMs | integer (positive) | yes | — |
| channel | "static" | "prod" | "lab" | "prod-stable-internal" | yes | — |
| model | custom | yes | — |
| bedrock | object | yes | — |
| bedrock.enabled | boolean | no | false |
| bedrock.mode | "access-key" | "team-role" | no | "access-key" |
| bedrock.region | string | yes | — |
| bedrock.testModel | string | yes | — |
| bedrock.teamRoleArn | string | yes | — |
| bedrock.teamExternalId | string | yes | — |
| awsAuthRefresh | string | yes | — |
| hasChangedDefaultModel | boolean | yes | false |
| maxMode | boolean | yes | false |
| maxModeAutoEnabled | boolean | yes | — |
| modelParameters | record<string, array of object> | yes | — |
| selectedModel | object | yes | — |
| selectedModel.modelId | string | no | — |
| selectedModel.parameters | array of object | no | — |
| selectedModel.parameters[].id | string | no | — |
| selectedModel.parameters[].value | string | no | — |
| modelSelectionHistory | array of string (max 32) | yes | — |
| exploreSubagentModel | "default" | "inherit" | no | "default" |
| subagentModels | object | yes | — |
| subagentModels.explore | "default" | "inherit" | "disabled" | object | yes | — |
| privacyCache | object | yes | — |
| privacyCache.ghostMode | boolean | no | — |
| privacyCache.privacyMode | number | yes | — |
| privacyCache.updatedAt | number | no | — |
| autoReviewAvailabilityCache | object | yes | — |
| autoReviewAvailabilityCache.backendUrl | string | no | — |
| autoReviewAvailabilityCache.authCacheKey | string | no | — |
| autoReviewAvailabilityCache.teamId | number | yes | — |
| autoReviewAvailabilityCache.available | boolean | no | — |
| autoReviewAvailabilityCache.updatedAt | number | no | — |
| serverConfigCache | object | yes | — |
| serverConfigCache.backendUrl | string | no | — |
| serverConfigCache.authCacheKey | string | yes | — |
| serverConfigCache.teamId | number | yes | — |
| serverConfigCache.agentUrlConfig | object | yes | — |
| serverConfigCache.agentUrlConfig.agentUrl | string | no | — |
| serverConfigCache.agentUrlConfig.agentnUrl | string | no | — |
| serverConfigCache.cliSandboxDefaultEnabled | boolean | yes | — |
| serverConfigCache.serverHttp2Config | number | yes | — |
| serverConfigCache.updatedAt | number | no | — |
| authInfo | object | yes | — |
| authInfo.email | string | yes | — |
| authInfo.displayName | string | yes | — |
| authInfo.teamId | number | yes | — |
| authInfo.teamName | string | yes | — |
| authInfo.userId | number | yes | — |
| authInfo.authId | string | yes | — |
| authInfo.organizationId | string | yes | — |
| authInfo.activeTeamId | number | yes | — |
| network | object | no | {…} |
| network.useHttp1ForAgent | boolean | no | false |
| approvalMode | "allowlist" | "unrestricted" | "auto-review" | yes | "allowlist" |
| autoAcceptWebSearch | boolean | no | false |
| sandbox | object | yes | — |
| sandbox.mode | "disabled" | "enabled" | no | "disabled" |
| sandbox.networkAccess | "user_config_only" | "user_config_with_defaults" | "allow_all" | yes | — |
| sandbox.networkAllowlist | array of string | yes | [] |
| sandbox.readBoundary | "system" | "workspace" | yes | — |
| showSandboxIntro | boolean | yes | false |
| runEverythingSettingsPromptStreak | integer (nonnegative) | yes | — |
| runEverythingSettingsPromptCooldownUntilMs | integer (nonnegative) | yes | — |
| attribution | object | yes | — |
| attribution.attributeCommitsToAgent | boolean | no | true |
| attribution.attributePRsToAgent | boolean | no | true |
| webFetchDomainAllowlist | array of string | yes | [] |
| conversationClassificationScoredConversations | array of object | yes | — |
| conversationClassificationScoredConversations[].conversationId | string | no | — |
| conversationClassificationScoredConversations[].lastUpdatedAt | number | no | — |
Exact shipped text
"../cursor-config/dist/schema.js"(t,e,r){"use strict";r.d(e,{Kr:()=>P,R8:()=>I,cy:()=>x,r0:()=>k});var n=r("../proto/dist/generated/agent/v1/agent_pb.js"),s=r("../../../../../../../../../../<build path>"),i=r("../../../../../../../../../../<build path>");const a=s.bz().transform(((t,e)=>{if(t instanceof n.Gm)return t;try{return n.Gm.fromJson(t,{ignoreUnknownFields:!1})}catch(r){return e.addIssue({code:i.eq.custom,message:r instanceof Error?r.message:String(r)}),t}})),o=s.Ik({type:s.eu("command"),command:s.Yj().min(1),padding:s.ai().int().min(0).optional(),updateIntervalMs:s.ai().int().positive().optional(),timeoutMs:s.ai().int().positive().optional()}),c=s.Ik({allow:s.YO(s.Yj()),deny:s.YO(s.Yj())}),u=s.Ik({vimMode:s.zM(),defaultBehavior:s.k5(["ide","agent"]).optional()}),l=s.Ik({showLineNumbers:s.zM().default(!1),showThinkingBlocks:s.zM().default(!1),showStatusIndicators:s.zM().default(!1),showStatusLineRunningTime:s.zM().default(!1),mode:s.k5(["zen","standard"]).default("zen")}),d=s.Ik({enabled:s.zM().default(!1),mode:s.k5(["access-key","team-role"]).default("access-key"),region:s.Yj().optional(),testModel:s.Yj().optional(),teamRoleArn:s.Yj().optional(),teamExternalId:s.Yj().optional()}),m=s.Ik({id:s.Yj(),value:s.Yj()}),p=s.Ik({modelId:s.Yj(),parameters:s.YO(m)}),f=s.Ik({modelId:s.Yj(),parameters:s.YO(m).optional(),maxMode:s.zM().optional()}),h=s.KC([s.k5(["default","inherit","disabled"]),f]),g=s.Ik({explore:h.optional()}),A=s.Ik({ghostMode:s.zM(),privacyMode:s.ai().optional(),updatedAt:s.ai()}),b=s.Ik({backendUrl:s.Yj(),authCacheKey:s.Yj(),teamId:s.ai().optional(),available:s.zM(),updatedAt:s.ai()}),y=s.Ik({agentUrl:s.Yj(),agentnUrl:s.Yj()}),_=s.Ik({backendUrl:s.Yj(),authCacheKey:s.Yj().optional(),teamId:s.ai().optional(),agentUrlConfig:y.optional(),cliSandboxDefaultEnabled:s.zM().optional(),serverHttp2Config:s.ai().optional(),updatedAt:s.ai()}),w=s.Ik({email:s.Yj().optional(),displayName:s.Yj().optional(),teamId:s.ai().optional(),teamName:s.Yj().optional(),userId:s.ai().optional(),authId:s.Yj().optional(),organizationId:s.Yj().optional(),activeTeamId:s.ai().optional()}),C=s.Ik({useHttp1ForAgent:s.zM().default(!1)}),v=s.Ik({mode:s.k5(["disabled","enabled"]).default("disabled"),networkAccess:s.vk((t=>"allowlist"===t?"user_config_with_defaults":"enabled"===t?"allow_all":t),s.k5(["user_config_only","user_config_with_defaults","allow_all"])).optional(),networkAllowlist:s.YO(s.Yj()).default([]).optional(),readBoundary:s.k5(["system","workspace"]).optional()}),E=s.Ik({attributeCommitsToAgent:s.zM().default(!0),attributePRsToAgent:s.zM().default(!0)}),S=s.Ik({conversationId:s.Yj(),lastUpdatedAt:s.ai()}),I=s.Ik({permissions:c}),B=I.extend({version:s.ai(),editor:u,display:l.default({showLineNumbers:!1,showThinkingBlocks:!1,showStatusIndicators:!1,showStatusLineRunningTime:!1,mode:"zen"}),notifications:s.zM().default(!0),hints:s.zM().default(!0),modelSlashCommands:s.zM().default(!0),steering:s.zM().default(!0),rewind:s.zM().default(!0),statusLine:o.optional(),channel:s.eu("static").or(s.eu("prod")).or(s.eu("lab")).or(s.eu("prod-stable-internal")).optional(),model:a.optional(),bedrock:d.optional(),awsAuthRefresh:s.Yj().optional(),hasChangedDefaultModel:s.zM().default(!1).optional(),maxMode:s.zM().default(!1).optional(),maxModeAutoEnabled:s.zM().optional(),modelParameters:s.g1(s.Yj(),s.YO(m)).optional(),selectedModel:p.optional(),modelSelectionHistory:s.YO(s.Yj()).max(32).optional(),exploreSubagentModel:s.k5(["default","inherit"]).default("default"),subagentModels:g.optional(),privacyCache:A.optional(),autoReviewAvailabilityCache:b.optional(),serverConfigCache:_.optional(),authInfo:w.optional(),network:C.default({useHttp1ForAgent:!1}),approvalMode:s.k5(["allowlist","unrestricted","auto-review"]).default("allowlist").optional(),autoAcceptWebSearch:s.zM().default(!1),sandbox:v.optional(),showSandboxIntro:s.zM().default(!1).optional(),runEverythingSettingsPromptStreak:s.ai().int().nonnegative().optional(),runEverythingSettingsPromptCooldownUntilMs:s.ai().int().nonnegative().optional(),attribution:E.optional(),webFetchDomainAllowlist:s.YO(s.Yj()).default([]).optional(),conversationClassificationScoredConversations:s.YO(S).optional()}),k=I.strict().extend({}),P=B.merge(k);function x(t){return t.subagentModels?.explore??t.exploreSubagentModel}}
Project MCP configuration path (occurrence 1)
Source: out/vs/workbench/workbench.desktop.main.js (desktop) · bytes 36274133–36274149 · SHA-256 6d5c8bdb80d1…
.cursor/mcp.json
Project MCP configuration path (occurrence 2)
Source: out/vs/workbench/workbench.desktop.main.js (desktop) · bytes 36274181–36274197 · SHA-256 6d5c8bdb80d1…
.cursor/mcp.json
Host-owned session storage setting
Source: extensions/cursor-agent-host/package.json (desktop) · bytes 587–972 · SHA-256 5145ed8c09f7…
Experimental. Store new agent chats in per-session databases owned by the agent host, under the extension's global storage, mirroring every write to the renderer's store; existing chats stay where they are. Read when the agent host starts, so a change takes effect after a window reload. The CURSOR_AGENT_HOST_OWNED_SESSION_STORAGE environment variable (1 or true) turns this on too.
Remote inference route setting
Source: extensions/cursor-agent-host/package.json (desktop) · bytes 1409–1837 · SHA-256 0ef2fd74acef…
How the agent host routes AgentService on remote windows (Remote-SSH, WSL, containers). Same enum shape as remote.SSH.localServerDownload. machine-overridable so a per-remote settings.json can force always or never for one box. Local windows ignore this setting. Read once when the agent host starts; a change takes effect after a window reload. always is ignored on a private-inference remote because the local hop skips CPI.
Sandbox and approval settings
Sandbox policy schema (desktop)
Source: extensions/cursor-agent-exec/dist/main.js (desktop) · bytes 407641–407997 · SHA-256 6267e53e44c4…
Decoded from the shipped protobuf descriptor for SandboxPolicy; referenced types resolved through Cursor's own generated classes (agent.v1).
| No. | Field | Type | Label |
|---|---|---|---|
| 1 | type | enum SandboxPolicy.Type | — |
| 2 | network_access | bool | optional |
| 3 | additional_readwrite_paths | string | repeated |
| 4 | additional_readonly_paths | string | repeated |
| 5 | debug_output_dir | string | optional |
| 7 | disable_tmp_write | bool | optional |
| 8 | allowlist_escalated | bool | optional |
| 9 | enable_shared_build_cache | bool | optional |
| 10 | network_policy | NetworkPolicy | optional |
| 11 | network_policy_strict | bool | optional |
| 12 | capture_denies | bool | optional |
| 13 | skip_statsig_defaults | bool | optional |
| 14 | read_boundary | enum SandboxPolicy.ReadBoundaryMode | — |
| 15 | additional_read_paths | string | repeated |
Exact shipped text
SandboxPolicy|1 type #0|2 network_access 8?|3 additional_readwrite_paths 9*|4 additional_readonly_paths 9*|5 debug_output_dir 9?|7 disable_tmp_write 8?|8 allowlist_escalated 8?|9 enable_shared_build_cache 8?|10 network_policy #1?|11 network_policy_strict 8?|12 capture_denies 8?|13 skip_statsig_defaults 8?|14 read_boundary #2|15 additional_read_paths 9*
Sandbox policy schema (Agent CLI)
Source: index.js (Agent CLI) · bytes 5944731–5945087 · SHA-256 6267e53e44c4…
Decoded from the shipped protobuf descriptor for SandboxPolicy; referenced types resolved through Cursor's own generated classes (agent.v1).
| No. | Field | Type | Label |
|---|---|---|---|
| 1 | type | enum SandboxPolicy.Type | — |
| 2 | network_access | bool | optional |
| 3 | additional_readwrite_paths | string | repeated |
| 4 | additional_readonly_paths | string | repeated |
| 5 | debug_output_dir | string | optional |
| 7 | disable_tmp_write | bool | optional |
| 8 | allowlist_escalated | bool | optional |
| 9 | enable_shared_build_cache | bool | optional |
| 10 | network_policy | NetworkPolicy | optional |
| 11 | network_policy_strict | bool | optional |
| 12 | capture_denies | bool | optional |
| 13 | skip_statsig_defaults | bool | optional |
| 14 | read_boundary | enum SandboxPolicy.ReadBoundaryMode | — |
| 15 | additional_read_paths | string | repeated |
Exact shipped text
SandboxPolicy|1 type #0|2 network_access 8?|3 additional_readwrite_paths 9*|4 additional_readonly_paths 9*|5 debug_output_dir 9?|7 disable_tmp_write 8?|8 allowlist_escalated 8?|9 enable_shared_build_cache 8?|10 network_policy #1?|11 network_policy_strict 8?|12 capture_denies 8?|13 skip_statsig_defaults 8?|14 read_boundary #2|15 additional_read_paths 9*