← Back to research
•·15 min read·company

Cursor

Cursor after SpaceX's acquisition: coding agents, Projects beta, self-hosted execution, current pricing, and the announced OpenAI model-access change.

Key takeaways

  • SpaceX completed its acquisition of Cursor on August 14, 2026; the product continues operating under the Cursor name.
  • OpenAI announced a proposed November 12, 2026 cutoff for its Cursor supply agreement; current model listings are not a guarantee of future access.
  • Cursor now spans its editor, cloud agents, self-hosted workers, and Projects beta, with meaningful overlap with team-agent platforms.
  • Evaluate subscription, model usage, review costs, permissions, and data flows together; self-hosted execution does not mean offline inference.

FAQ

Has SpaceX acquired Cursor?

Yes. Cursor announced the completed acquisition on August 14, 2026. SpaceX's preceding merger agreement used a $60 billion implied equity value, with consideration in SpaceX shares.

Can I still use OpenAI models in Cursor?

Cursor's September 16 documentation still lists OpenAI models, but OpenAI announced a proposed November 12, 2026 cutoff and said it would not supply future models under the agreement. Bring-your-own-key support has separate model and privacy limitations and is not a guaranteed replacement.

How much does Cursor cost?

Published monthly USD prices are Pro $20, Pro+ $60, Ultra $200, Teams Standard $40 per user, and Teams Premium $120 per user; Hobby is free and Enterprise is custom. Usage charges can add to the subscription.

Can Cursor run on my own infrastructure?

Self-Hosted Machines runs tools on your workers, with Enterprise required for Team Pools. Cursor still handles the agent loop and inference, and workers send required context and tool results to Cursor.

Executive Summary

Status, September 16, 2026: SpaceX completed its acquisition of Cursor on August 14. Cursor remains an operating product; its announcement frames the combination around access to training compute and joint model development.[1]

The consequential customer change is model supply. On August 28, OpenAI announced that it intends to end its model-supply agreement with Cursor, proposing November 12, 2026 as the cutoff and withholding future models under that agreement. This is an announced transition, not evidence that existing OpenAI access has already stopped.[2]

Cursor has also outgrown a description limited to its VS Code-derived editor. Its agent workspace combines local and cloud work, while the September Projects beta adds a coordinating agent for larger efforts.[3][4] Evaluate it as both an interactive coding tool and an increasingly integrated development platform. See AI coding assistants and cloud coding agent platforms for the broader comparisons.

Ownership and What Changed

DateVerified eventSignificance
November 13, 2025Cursor announced a $2.3 billion Series D at a $29.3 billion post-money valuation.[5]Historical financing, not its current ownership or acquisition price.
April–June 2026SpaceX obtained an acquisition option, then exercised it and signed a merger agreement. Its Q2 filing describes consideration in SpaceX shares at a $60 billion implied Cursor equity value.[6]The April partnership and June agreement preceded the completed transaction.
August 14, 2026Cursor announced that the acquisition was complete.[1]The old independent-startup fundraising outlook is obsolete.
August 28, 2026OpenAI announced its intended contract wind-down.[2]Model continuity is now a concrete procurement consideration.

The acquisition can improve access to training infrastructure, but Cursor's promise of stronger, cheaper models is a company expectation, not a measured outcome of this review.[1] My assessment is that the relevant tradeoff is tighter coordination between the product and its model supplier versus dependence on that parent's priorities and relationships with competing providers.

Model access after the acquisition

The documentation checked September 16 still lists Anthropic, Google, OpenAI, Meta, and SpaceXAI models. Cursor Grok 4.6, Grok 4.5, and Composer 2.5 occupy its first-party usage pool; third-party choices use a separate pool.[7] A model appearing in today's picker does not settle access after a supplier's announced termination date.

Bring-your-own-key access needs separate evaluation. Cursor currently documents OpenAI BYOK for standard, non-reasoning chat models; custom keys do not replace its Tab models. It also supports providers including AWS Bedrock, but provider availability and configuration still apply. Cursor's ZDR policy does not cover BYOK, and these requests still pass through Cursor's backend for prompt construction.[8] Do not assume that adding a key preserves every integrated feature or future OpenAI model. Test the specific model, workflow, billing, and data terms before relying on it for migration.

Product Overview

Cursor's original editor and newer Agents Window coexist. The latter provides a multi-repository interface, local/cloud handoff, diffs, and pull-request management; users can return to the editor for direct code work.[3] This supports a useful progression from reviewing suggestions to delegating a task, without requiring every job to become a long autonomous run.

SurfaceCurrent role and qualification
Tab and inline editsTab suggests completions and related edits across files. Cmd/Ctrl+K handles targeted changes or questions about selected code.[9][10]
Editor and AgentCode search, file edits, terminal execution, browser interaction, and checkpoints. Checkpoints are local undo aids, separate from Git history.[11]
Cloud AgentsIsolated development VMs with dependencies, tests, artifacts, and branch-based handoff. Web, desktop, Slack, API, and mobile access are documented; iOS is native, while Android uses a web/PWA experience.[12]
ProjectsBeta rollout began September 10. A coordinator plans and delegates, maintains shared context, and can subscribe to schedules, Slack, or PR activity. Treat the advertised scale as a vendor claim, not a benchmark.[4]
Self-Hosted MachinesTool execution on your hardware, including Linux/Mac computer use. Personal machines and dynamically scheduled team workers serve different operating needs.[13]
CLI and SDKThe TypeScript SDK makes the same agent used by the IDE, CLI, and web app programmable, with local and cloud runtimes. Local SDK execution still uses hosted inference.[14]
JetBrainsAgent access through ACP inside supported JetBrains IDEs requires a paid Cursor plan and the AI Assistant plugin. It is not a promise that every editor feature is identical.[15]
BugbotAutomated or manually triggered PR reviews, with findings and suggested fixes; usage billing applies.[16]
OriginCode hosting began an early beta rollout August 17. Origin-hosted repositories use Origin as their authority; mirrored GitHub repositories retain GitHub as the authority.[17]

Cloud agents gained subscriptions to events and recurring work in August, plus subagents on separate VMs. This extends Cursor into ongoing team workflows.[18] The December 2025 Graphite announcement also established a code-review acquisition agreement, while explicitly saying Graphite would continue operating independently; it did not establish that every Graphite feature was already part of Cursor.[19]

There is now a specific shipped integration to evaluate: Graphite launches Cursor Cloud Agents from its browser interface, opens draft PRs, and lets an agent commit requested changes from the PR page. Conversations can continue between Cursor and Graphite. This is a distinct review interface using Cursor execution, not an independently provisioned runtime; the cloud coding comparison evaluates that execution choice once.[20]

Grok Bot supplies another entry point. Its enterprise architecture documents a persistent computer per user and optional delegation to Cursor Cloud Agents on separate computers. Shared ownership of the products does not collapse those machine or account boundaries. Evaluate the personal-assistant workflow separately from the delegated repository task.[21] These related-product links and execution distinctions were checked September 16, alongside this profile's existing review.

Integrations and a concrete workflow

Jira is now documented for Teams and Enterprise on Jira Commercial Cloud with Rovo enabled. Assigning a work item to Cursor or mentioning it can start a cloud agent; the integration supports either team service-account or individual-user authentication. Atlassian HIPAA and FedRAMP instances are excluded in the current documentation.[22]

Bitbucket Cloud support is in public beta and covers Cloud Agents and Bugbot. Bitbucket Data Center support is documented for Bugbot; that does not establish equivalent cloud-agent support for Data Center.[23] Check the specific hosting edition when evaluating either integration.

A sensible pilot is a bounded regression ticket: specify the intended repository, expected behavior, and a reproducible failing test. Launch from the ticket, inspect the selected identity and repository, then require a test result and reviewable PR before accepting the change. Jira returns progress and a completion summary with the PR link when one is opened.[22]

Prepare the execution environment as part of that pilot. Cursor supports saved snapshots and Dockerfile-based setup, and a cloud agent can return screenshots, logs, and other artifacts. Multi-repository environments are supported, but the documentation says long-running mode is not yet available for them.[12] Use those outputs to check the result; an agent's assertion that a task is complete is not an acceptance test. This is a proposed evaluation workflow, not a deployment tested for this report.

Technical Architecture and Security

Cursor separates instructions, model selection, and tools that inspect or change the project. Its agent harness coordinates those components; the model name alone does not describe permissions, available context, or execution location.[11]

Self-Hosted Machines runs tools on customer-operated workers; Cursor retains the agent loop and inference. Checkouts and build caches stay on workers, but necessary file contents, terminal output, diffs, screenshots, and MCP results leave the network. Artifacts use Cursor-managed storage. Execution location does not establish offline operation. Team Pools require Enterprise and service-account authentication.[24]

BoundaryWhat the documentation establishes
Interactive agentWorkspace edits can be applied without approval. Sensitive actions and terminal commands require approval by default, subject to configured run modes; allowlists and auto-review are best-effort controls.[25]
Headless SDKDefault local SDK tools run without an interactive approval prompt. Configure hooks or sandbox options explicitly; do not transfer assumptions from the editor UI.[14]
Managed cloud runtimeCloud agents auto-run terminal commands and have internet access by default. Egress restrictions are configurable, but even allowlist-only mode retains necessary service domains.[26]
Privacy ModeCursor promises no training on customer data and provider ZDR arrangements, while documenting abuse-investigation exceptions and explicitly designated non-ZDR models. Disabling the mode allows broader use and storage.[27]
Enterprise administrationModel/repository controls, SCIM, audit logs, MDM, service accounts, AI Code Tracking, and Cursor Blame are documented. Attribution and logging help investigation; they do not prove generated code is correct or compliant.[28]

Cloud retention deserves its own check: conversation history is kept indefinitely by default, while environment snapshots have a rolling 90-day inactivity window. Deleting an agent's transcript does not delete its snapshots on demand. Custom conversation-retention controls are described as early access for selected Enterprise teams.[26] Privacy Mode should therefore not be read as “nothing is stored anywhere.”

For code review, requiring Bugbot's status check alone does not necessarily block a merge with findings: the documented default for findings is neutral. Organizations with the relevant option must enable failure on unresolved issues if that is the intended gate.[16] Verify branch rules and human responsibility alongside the agent settings.

Strengths and Cautions

Cursor's strongest proposition is continuity between direct editing, agent work, and review. Its local/cloud handoff lets developers choose the working mode appropriate to the task.[3] Projects adds a promising coordination layer, but remains a beta rather than evidence that large autonomous efforts reliably succeed.[4]

There is meaningful enterprise evidence, with limits. Cursor's January 21 Salesforce case study reports adoption above 75%, a PR-velocity gain above 30%, and 85% less time spent on legacy test coverage. These are customer/vendor-reported results for that deployment, not independently controlled measurements or a forecast for another team.[29]

The principal cautions are model continuity, variable usage costs, review workload, and the growing number of places where code and credentials can be used. New coordinating agents and hosting features can reduce handoffs, but also make migration more involved. Evaluate export, repository authority, and operational ownership before consolidating more of the development lifecycle into one service.[17]

What Developers Say

The April 2, 2026 Cursor 3 discussion gives useful context for the interface tradeoff. HN user whicks, identifying as a heavy daily user, valued keeping code changes visible to maintain a mental model of the system and worried that the new interface might hide that experience.[30] leerob, explicitly identifying as a Cursor engineer, replied that the new interface was a separate window and that direct code editing and the older editor experience remained available.[31] The reply is an affiliated product clarification, not independent praise.

Pricing criticism has a documented historical basis: on July 4, 2025, CEO Michael Truell acknowledged unclear plan changes and offered refunds for unexpected usage charges during a specified June–July window.[32] That episode supports checking allowances and caps carefully; it does not establish that today's billing is incorrect. These dated accounts are not a representative user survey or a hands-on assessment of the post-acquisition product.

Pricing & Licensing

Published prices checked September 16, 2026 below use monthly billing in USD before tax, except the explicitly regional Start plan. They are subscription prices, not unlimited agent-compute budgets.[33]

PlanMonthly priceRelevant distinction
HobbyFreeLimited agent requests and Composer access.[33]
Pro$20Individual subscription with Cursor Models and Other Models usage pools.[7]
Pro+$60Higher individual tier; included usage still depends on model choice.[7]
Ultra$200Highest listed individual USD tier, with both usage pools.[7]
Teams Standard$40/userTeam administration, SSO, shared context, and per-user allowances.[34]
Teams Premium$120/userFive times Standard's agent allowance.[34]
EnterpriseCustomPooled usage and additional administration/security controls.[33]
Start, India only₹649, tax inclusiveCursor Models pool; excludes the third-party pool and several features including Bugbot and SDK access.[7]

For Teams and Enterprise, third-party requests add a $0.25 per million token Cursor Token Rate, including input, output, and cached tokens and eligible BYOK requests. Grok and Composer are exempt. Teams allowances do not transfer between users, on-demand usage is enabled by default, and team-wide limits are configurable; per-member limits are Enterprise features.[34]

Bugbot uses usage billing, and its Teams usage draws from on-demand spend. Access in a plan's feature list should not be interpreted as unlimited free reviews.[16] Self-hosting also adds your machine and operating costs; managed cloud execution infrastructure is included under Cursor's documented runtime pricing.[24]

Budget against accepted changes, not prompt count. Run a representative task with the intended model and context size, include failed attempts and repeated reviews, and inspect the usage dashboard before multiplying that workload across parallel agents. Cursor is sold as a commercial service; running its worker locally does not make the hosted product free or grant control over its model supply.[33]

Competitive Positioning

The useful comparison is the workflow a team wants to operate. “Cursor is an IDE; alternatives are autonomous” is no longer a sufficient distinction.

AlternativeWhen it belongs in the evaluation
GitHub CopilotWhen retaining an existing IDE is important. GitHub documents agent mode, completion, review, and MCP support across several IDEs, with different feature coverage per editor.[35]
Claude CodeWhen Claude-based agent work and its tool ecosystem are the priority. It now spans terminal, IDE, desktop, and web, so the distinction is broader than terminal versus GUI.[36]
OpenAI CodexWhen the team wants OpenAI's own coding-agent workflow rather than depending on Cursor's supply agreement. Codex supports local repository work, command execution, automation, and cloud handoff; evaluate the complete workflow rather than treating it as a replacement model picker.[37]
DevinWhen delegating backlog tasks and reviewing returned work is central. Devin documents ticket-driven work, cloud/local handoff, and developer takeover; its own guidance emphasizes verifiable tasks and review, not operating without human oversight.[38]

Where Tembo fits

Disclosure: Ry Walker is Tembo's CEO and co-founder. Tembo is a relevant alternative and complement for teams operating coding agents across repositories and work systems. It offers shared cloud development sessions, cloud or self-hosted deployment, and triggers from Slack, Linear, GitHub, schedules, and webhooks. Its current platform explicitly includes Cursor alongside other agent harnesses.[39]

The evaluation is therefore about choosing a Cursor-centered environment versus a platform spanning multiple agent harnesses. Cursor now offers its own team context, subscriptions, and coordination, so Tembo's case should rest on the team's preferred agents, deployment, integrations, and review process rather than an assertion that Cursor cannot orchestrate work.[18][4] Tembo still introduces another platform to configure and operate; using Cursor through it does not establish an exemption from Cursor's model-access or licensing restrictions.

Viability and Recommendation

The acquisition makes product direction and supplier continuity more relevant to a buyer than speculation about another funding round. Cursor reported more than $1 billion in annualized revenue in November 2025.[5] TechCrunch subsequently reported $2 billion in annualized revenue for February 2026, citing Bloomberg; this is a historical estimate, not September revenue.[40] Historical growth and transaction value are context, not proof of future reliability or a guarantee that a preferred model will remain available.

Good fit: developers who value direct code inspection alongside delegation, and teams prepared to configure execution environments, spending controls, and review responsibilities. Pilot the stable workflows first, then assess whether Projects beta and Origin solve additional problems worth the adoption cost.

Poor fit: deployments that require entirely offline inference, a fixed long-term entitlement to every third-party model, or hands-off acceptance of generated changes. Self-hosted workers solve execution-location needs but retain outbound context flows, and OpenAI's announced change makes provider continuity a live issue.[24][2]

My recommendation is to evaluate Cursor on representative repository work and total cost per accepted change. For an existing deployment, inventory critical model dependencies before the proposed November cutoff, validate an alternative workflow, and revisit data-handling and approval settings as execution moves between local, managed cloud, and self-hosted machines.


Research by Ry Walker Research • methodology

Sources