Skip to content

Bugfix/cursor signin status - #745

Open
QuanCheng-QC wants to merge 2 commits into
developfrom
bugfix/cursor-signin-status
Open

QuanCheng-QC wants to merge 2 commits into
developfrom
bugfix/cursor-signin-status

Conversation

@QuanCheng-QC

Copy link
Copy Markdown
Collaborator

What this fixes, and where it was reported

Two user reports about Cursor agents in the workspace.

Report 1: "not signed in" although the user is signed in (translated)

Cursor is installed but not signed in — run cursor-agent login on the device, or set a CURSOR_API_KEY from cursor.com/settings. Clicking Re-check returns the same sentence, followed by "Run cursor-agent login in your terminal…" and "Alternatively, configure CURSOR_API_KEY."

When I connect Cursor it keeps telling me I have no account, but I do have one and I am signed in.

Report 2: no reply on Windows (translated)

The error behind Cursor's failed reply is Workspace Trust Required. cursor-1004 received "hi", the directory C:\Users\<user> was not trusted, the CLI exited with code 1, and OpenAgents showed "No response generated".

Root cause

Sign-in. Since core 0.2.189 (3e2ff11) the readiness check reads authInfo from ~/.cursor/cli-config.json. That field is a profile the CLI caches, not the sign-in. The tokens are in the OS keychain on macOS, %APPDATA%\Cursor\auth.json on Windows and ~/.config/cursor/auth.json on Linux, and cursor-agent status answers from those alone. When authInfo is absent the core reports "not signed in", and Re-check cannot correct it, because Cursor has no live probe and the same static result comes back.

The exact output in report 1, with its three guidance lines, comes from a core older than 0.2.189, where only CURSOR_API_KEY counted. Upgrading fixes that case. This PR fixes what remains after the upgrade.

Windows. Cursor's Windows install is not an npm shim: cursor-agent.cmd → PowerShell → cursor-agent.ps1 → node.exe index.js. The adapter could not resolve it to a script, so it launched through cmd.exe /c. cmd.exe stops reading a command line at the first newline, and every prompt has carried one since the per-agent identity header was added (it ends in a blank line). Everything after it was dropped: the user's message, and --output-format, --trust, --force, --model, --workspace, --resume. The CLI ran the header alone in an untrusted directory and exited with "Workspace Trust Required". Trusting the directory by hand does not help, because the message itself never arrives.

How to reproduce

Sign-in

  1. Install the Cursor CLI and sign in with cursor-agent login. Set no CURSOR_API_KEY. cursor-agent status prints "Logged in".
  2. Have no authInfo in ~/.cursor/cli-config.json. This happens when XDG_CONFIG_HOME or CURSOR_CONFIG_DIR moves the config, or when the config was reset.
  3. Open Add agent → Cursor in the workspace, or run agn runtimes --json.

Windows

  1. Windows, Cursor CLI from the official installer (%LOCALAPPDATA%\cursor-agent), signed in.
  2. A Cursor agent whose working directory was never trusted in Cursor. The default, the user's home, is enough.
  3. Send it any message.

Before and after

Scenario Before After
Signed in, authInfo present Ready Ready, and the CLI is not started
Signed in, authInfo missing or config moved by XDG_CONFIG_HOME "installed but not signed in"; Re-check repeats it Ready
Signed out "not signed in", status unknown, Re-check gives no guidance "not signed in", status no_credentials, Re-check returns the login steps
cursor-agent status fails or times out unknown unknown, unchanged
Windows, any message "No response generated" (CLI exits 1 with Workspace Trust Required) The agent replies

Implementation

  • registry/cursor.json: check_ready gains status_args: ["status"] and logged_out_pattern. This is the rule the launcher's HOSTED_LOGIN_AGENTS.cursor already uses, so the desktop app and the workspace agree.
  • installer.js: when the env and the credential file prove nothing, _checkLoginStatus runs the resolved CLI with status_args, and loginVerdict reads the output (a port of the launcher's loginVerdict). The check is generic, and only Cursor declares it. Nothing is spawned where the caller cannot block (Electron main).
  • adapters/cursor.js: resolveCursorNodeEntry finds node.exe and index.js the way cursor-agent.ps1 does (beside the launcher, else the newest versions\<version> by date). The adapter then starts node itself and sets CURSOR_INVOKED_AS and NODE_COMPILE_CACHE as the script would.
  • Copy: the not-ready message and the Add agent hint (en-US, zh-CN) now say the CLI sign-in is separate from signing in to the Cursor editor.

Behaviour changes to note

  • A Cursor agent that really is signed out now reports no_credentials, so the chat shows the failing-health banner with the login steps. Before, the status was unknown and the banner stayed hidden.
  • When authInfo is missing, each health check starts cursor-agent status (1–3 s, cached for 10 s). Installs with authInfo pay nothing.

Testing

  • test/cursor-readiness.test.js (19 cases) and test/cursor-windows-launch.test.js (9 cases).
  • npm test in packages/agent-connector: 1875 pass, 1 fail. The failure is wsl.test.js › "an agent that only exists inside the distro", which fails the same way on develop on my machine.
  • Real cursor-agent 2026.10.01-e373342 on Linux in an isolated HOME: signed out → not ready, no_credentials; tokens present without authInfo → Ready; config under XDG_CONFIG_HOME → Ready. The signed-in state used placeholder tokens, since status only checks that both tokens exist.
  • The resolver was checked against the real Windows package (2026.10.01-e373342), laid out the way the installer leaves it.
  • Windows: the agent that answered "No response generated" replies normally after this change.
  • Not verified: the sign-in check on macOS (keychain). It runs the same status command the launcher already runs there.
  • The cmd.exe truncation was inferred from cmd's parsing rules and the symptom, not observed directly.
  • ESLint was not run: no config is picked up in packages/agent-connector.

… as not signed in

The readiness check read `authInfo` from ~/.cursor/cli-config.json, which is a
profile the CLI caches and not the sign-in. The tokens live in the OS keychain
on macOS, %APPDATA%\Cursor\auth.json on Windows and ~/.config/cursor/auth.json
on Linux, and `cursor-agent status` answers from those alone. A signed-in user
whose config had no authInfo (XDG_CONFIG_HOME or CURSOR_CONFIG_DIR set, a reset
config) read "installed but not signed in" in the workspace, and the re-check
repeated the same sentence because Cursor has no live probe.

- check_ready gains status_args and logged_out_pattern, the rule the desktop
  app already uses. When nothing on disk or in the env proves a sign-in, the
  core runs the resolved CLI with status_args and reads its output.
- Signed in gives Ready. "Not logged in" gives a definitive no_credentials, so
  the re-check returns the login guidance. No answer stays unknown.
- authInfo on disk still settles it without starting the CLI, and nothing is
  spawned where the caller cannot block (the desktop app's main thread).
- The not-ready message and the add-agent hint now say the CLI sign-in is
  separate from signing in to the Cursor editor.
…s survive

Cursor's Windows install is not an npm shim. cursor-agent.cmd hands its
arguments to PowerShell, and cursor-agent.ps1 runs the node.exe shipped under
versions\<version> on that directory's index.js. The adapter could not resolve
that to a script, so it launched through `cmd.exe /c`.

cmd.exe stops reading a command line at its first newline, and every prompt has
carried one since the identity header (which ends in a blank line) was added.
The user's message and every flag after the prompt were dropped, --trust and
--force among them. The CLI ran the header alone in an untrusted directory,
exited 1 with "Workspace Trust Required", and the chat showed "No response
generated". Trusting the directory by hand did not help, because the message
itself never arrived.

- resolveCursorNodeEntry finds the node.exe and index.js pair the way
  cursor-agent.ps1 does (beside the launcher, else the newest versions
  directory by date), and the adapter starts node itself.
- CURSOR_INVOKED_AS and NODE_COMPILE_CACHE are set as the launcher script
  would have set them.
@vercel

vercel Bot commented Oct 4, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
openagents-workspace Ready Ready Preview Oct 4, 2026 1:15pm UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — 97ca7260 Deployed Oct 4, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant