Peeking Under the Hood of Cursor's API Calls
Blog post from Speedscale
An inspection of Cursor IDE network traffic using the proxymock proxy found that the VS Code-based AI editor relies on both HTTP and gRPC services for AI prompting, synchronization, telemetry, extensions, experimentation, billing, and error reporting. During an AI prompt, Cursor was observed sending the prompt along with workspace launch.json contents, selected code excerpts that appeared limited to roughly the first 4 KB of files, repository directory structure, and Git status to its API, meaning secrets stored in configuration files such as launch.json could be included. In Auto mode, Cursor appeared to select or recommend models server-side from a portfolio including Claude, Gemini, GPT-4o-mini, and DeepSeek variants, potentially based on project context, behavior, or subscription status. Other observed services included pre-signed Amazon S3 URLs for user-specific debugging-data uploads, Sentry and Microsoft telemetry endpoints, a Cursor extension marketplace, Stripe subscription validation, and a documentation catalog supporting AI context. The account frames these findings as traffic observations rather than reverse engineering and recommends safeguarding secrets, using Privacy Mode in corporate settings, and ensuring network infrastructure supports HTTP/2 and gRPC.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 4 | 1,198 | 200 | 101 | -19% |
| LLM | 2 | 4,566 | 738 | 226 | -7% |
| MCP | 2 | 4,941 | 346 | 138 | +31% |
| AI Agents | 1 | 2,986 | 597 | 186 | +11% |
| Real-time | 1 | 5,401 | 1,154 | 263 | -1% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.