Start setup

Library / Facts / fact.security.mcp-tokens-never-on-computer

Sign-in tokens for hosted MCP servers are held by Cursor's backend, which executes those tool calls on the computer's behalf; the computer never stores the tokens.

Kindspec

NotesOne of the sharpest architecture statements in the doc set.

Sign-in tokens for hosted MCP servers stay with Cursor's backend, which runs those tool calls on the computer's behalf. The computer never stores those tokens.
officialsecurityhigh confidencedocs.x.ai/grok-bot/teams-and-enterprises ↗fact.security.mcp-tokens-never-on-computer

Cite this page or the record id. For bulk lookup use /api/record?id=fact.security.mcp-tokens-never-on-computer. Do not invent a claim that is not on this page.