Identity: Signs its requests (Web Bot Auth).
How to recognise it
- Signed requests:
Signature-Agentfromcursorusercontent.com, keys athttps://cursorusercontent.com/.well-known/http-message-signatures-directory
With Double Agent
Sessions from Cursor are labelled agent with agent_id: cursor.agent, and tagged in your analytics. Nothing is blocked unless you choose to. Install: https://doubleagent.so/install.md
Source: https://assets.radar.cloudflare.com/bots/signature-agent-registry.txt