{"found":true,"collection":"facts","library_url":"https://www.grokbotdb.com/library/fact.security.mcp-tokens-never-on-computer","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"fact.security.mcp-tokens-never-on-computer","subject":"security","claim":"Sign-in tokens for hosted MCP servers are held by Cursor's backend, which executes those tool calls on the computer's behalf; the computer never stores the tokens.","kind":"spec","status":"current","tier":"official","source_id":"src.docs.teams-and-enterprises","source_url":"https://docs.x.ai/grok-bot/teams-and-enterprises","quote":"Sign-in tokens for hosted MCP servers stay with Cursor's backend, which runs those tool calls on the computer's behalf. The computer never stores those tokens.","observed_at":"2026-09-03","confidence":"high","notes":"One of the sharpest architecture statements in the doc set.","first_seen":"2026-09-03","last_verified":"2026-09-03"}}