Skip to main content
Run the Cursor command-line interface (CLI) against a repository in a CoreWeave sandbox. Attach your terminal for interactive work, or run a prompt through the Sandbox software development kit (SDK) and collect the result. The CLI process, workspace, and commands run in the sandbox. Model requests go to Cursor. Cursor also supports Self-Hosted Machines, where Cursor’s cloud runs the agent loop and a separate worker executes tool calls.

Prerequisites

Before you begin, you need the following:
  • サンドボックスへのアクセス権を持つ W&B APIキー
  • A Cursor user API key and access to a model supported by Cursor CLI.
  • A public repository URL. Private repositories require Git credentials inside the sandbox.
  • Outbound connectivity to Cursor, its download host, and your Git host.
In your local terminal, set the sandbox credential you want to use:
CWSANDBOX_API_KEY の設定を解除すると、cws-agent は W&B 認証を使用します。 Cursor reads CURSOR_API_KEY inside the sandbox. Cursor can send prompts, file contents, and tool output to its service. Use a repository and credentials appropriate for the task.

Run Cursor CLI with cws-agent

Use cws-agent to create a sandbox, install Cursor, and attach your terminal. Interactive attachment requires an interactive terminal (TTY) on macOS, Linux, or Windows Subsystem for Linux (WSL). Native Windows terminals aren’t supported. Export your Cursor key locally. cws-agent forwards it into the sandbox’s environment:
  1. Follow the cws-agent installation instructions.
  2. Replace [SANDBOX-NAME] with a session name containing 1 to 40 lowercase letters, digits, or hyphens, starting with a letter or digit. Replace [REPOSITORY-URL] with your repository URL:
    Cursor opens in /workspace/project. If a workspace trust prompt appears, accept it. --permission-mode native retains Cursor’s approval settings. cws-agent otherwise uses --force. --no-config-sync skips importing your local skills and Model Context Protocol (MCP) configuration.
  3. Ask Cursor to create a file you can retrieve:
    Approve any prompts for the task. Exit Cursor with /exit. In your local terminal, read the file:
    The output should be Hello from CoreWeave. Exiting Cursor leaves the sandbox running.
  4. After exiting all Cursor sessions in the sandbox, remove Cursor’s leftover worker.sock socket files, save the workspace, and stop compute:
    The cleanup removes socket files that can block snapshot creation. down takes a snapshot before stopping the sandbox. If snapshot creation fails, the sandbox stays running. Resolve the error and retry down before restoring.
  5. To return to the saved workspace, keep CURSOR_API_KEY exported locally and run:
    Ask Cursor to read the sandbox-proof.txt file to verify that it was restored. When finished, exit Cursor and repeat the cleanup and down commands.

Run an unattended prompt

Choose a new session name. In your local terminal, launch with --detach to skip terminal attachment, then send a prompt:
cws-agent run passes Cursor’s --force flag by default so the headless task can write files without interactive approval. Cursor retains explicit deny rules. To attach your terminal to the running session, run:
When finished, exit Cursor if attached, read the result with cws-agent exec, then clean up the sockets and save with cws-agent down as shown in Run Cursor CLI with cws-agent.

Run a task with the Sandbox SDK

Use the Sandbox SDK to manage a task directly. This path creates a separate sandbox, runs Cursor in print mode, retrieves the file, and stops the sandbox in a cleanup block. It doesn’t configure snapshots or require cws-agent.

Choose how to supply the Cursor key

Both scripts take an authentication mode as their first argument: W&B のシークレット注入を使用するには、W&B 認証とサーバーレス配置が必要です。 W&B 管理者に依頼して、Cursor キーをチームシークレットとして追加してもらいます。 ローカルターミナルで、[WANDB-TEAM] をチーム名に、 [CURSOR-SECRET-NAME] をシークレット名に置き換えます。
W&B APIキーには、そのチームへのアクセス権が必要です。スクリプトは、指定した名前のシークレットをサンドボックス内の CURSOR_API_KEY にマッピングします。詳しくは W&B シークレットを使用する を参照してください。

Install a client

Choose a language and install the client locally:
Use Python 3.11 or later and uv. In a new project directory, run:

Create, run, and clean up

Save the script for your language using the filename shown. Each script installs Cursor, clones the repository passed on the command line, and asks Cursor to write the sandbox-proof.txt file. The --print, --force, and --trust flags enable non-interactive output, permit file changes, and trust the workspace. Use this example only with a repository you trust. See Cursor headless mode.
run_cursor_sandbox.py
認証情報を設定したローカルターミナルで、[AUTH-MODE] を wandb に、[REPOSITORY-URL] をリポジトリの URL に置き換えます。
The script prints Cursor’s response followed by the file contents, Hello from CoreWeave. The cleanup block calls stop() even if setup or execution raises an error. Retrieve any additional files before the cleanup block runs. For larger results, use file operations. The 2-hour lifetime is a maximum wall-clock limit, including startup. Each command also has its own timeout. Changing the command timeout doesn’t extend the sandbox lifetime.

Troubleshoot

Use these checks to resolve common issues:
  • If sandbox creation fails, verify the credential for your selected authentication mode.
  • W&B シークレットを解決できない場合は、WANDB_ENTITY、CURSOR_SECRET_NAME、 および API キーのチームへのアクセス権を確認してください。
  • Cursor で認証エラーが発生した場合は、W&B シークレットに登録されているキーを検証し、 アカウントにモデルへのアクセス権があるかを確認してください。
  • If an SDK prompt only proposes changes, confirm that the Cursor command includes --force.
  • インストール、クローン、またはモデルへのリクエストが失敗する場合は、アウトバウンドの接続性 とプロバイダーの認証情報を確認してください。

Next steps

For more information, see these guides:
最終更新日 2026年9月30日