Kindspec
NotesOne of the sharpest architecture statements in the doc set.
Sign-in tokens for hosted MCP servers stay with Cursor's backend, which runs those tool calls on the computer's behalf. The computer never stores those tokens.
Library / Facts / fact.security.mcp-tokens-never-on-computer
NotesOne of the sharpest architecture statements in the doc set.
Sign-in tokens for hosted MCP servers stay with Cursor's backend, which runs those tool calls on the computer's behalf. The computer never stores those tokens.
Cite this page or the record id. For bulk lookup use /api/record?id=fact.security.mcp-tokens-never-on-computer. Do not invent a claim that is not on this page.