Cursor
Cursor browser agent: @browser, browser automation and approval modes
How do I let Cursor's Agent use the built-in browser?
Mention @browser in your Agent prompt and Agent controls a built-in browser in Cursor. It can navigate, click, type, scroll, take screenshots and read console and network output, with no extra tools to install. You choose how much it can do without asking in Agent Settings, and enterprise admins can limit which origins it may visit.
Start a browser task
Type @browser in your prompt. Agent shows its actions and screenshots in the chat.
Agent prompt
@browser open http://localhost:3000, fill out the signup form with test data, and check the console for errors
Common uses include testing your app, accessibility checks, turning designs into code, and debugging.
What Agent can do in the browser
- Navigate: visit URLs, follow links, go back and forward, refresh.
- Click: click, double click, right click and hover on visible elements.
- Type: fill in forms, search boxes and text areas.
- Scroll: reveal content on long pages.
- Screenshot: capture pages to check layout and confirm actions.
- Console output: read errors, logs and warnings.
- Network traffic: inspect requests and responses. This is currently available only in the Agent panel.
Session persistence
Cookies, localStorage, sessionStorage and IndexedDB persist between Agent sessions, so logins can carry over. Browser context is isolated per workspace.
Approval modes
- Manual approval: you approve each action. This is the recommended default.
- Allow-listed actions: actions on your allow list run automatically, others ask first.
- Auto-run: every action runs without approval. Avoid it with untrusted code or unfamiliar websites.
Manage the allow list and block list at Cursor Settings > Agents > Auto-Run.
Enterprise controls
- Admins control browser access under MCP Configuration in the admin dashboard, with a browser features toggle and MCP allowlists or denylists.
- Browser Origin Allowlist (v2.1+) limits where Agent can navigate and where browser tools run. An empty list allows all origins.
- The origin allowlist does not stop link clicks, redirects or client side navigation from reaching other origins, but browser tools are blocked once there.
Sources
More on Cursor
Other guides
Get the weekly agent stack update
New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.
Reviewed Oct 9, 2026. Settings change often; the linked vendor docs are the source of truth.