Cursor

Cursor browser agent: @browser, browser automation and approval modes

How do I let Cursor's Agent use the built-in browser?

Mention @browser in your Agent prompt and Agent controls a built-in browser in Cursor. It can navigate, click, type, scroll, take screenshots and read console and network output, with no extra tools to install. You choose how much it can do without asking in Agent Settings, and enterprise admins can limit which origins it may visit.

Start a browser task

Type @browser in your prompt. Agent shows its actions and screenshots in the chat.

Agent prompt

@browser open http://localhost:3000, fill out the signup form with test data, and check the console for errors

Common uses include testing your app, accessibility checks, turning designs into code, and debugging.

What Agent can do in the browser

  • Navigate: visit URLs, follow links, go back and forward, refresh.
  • Click: click, double click, right click and hover on visible elements.
  • Type: fill in forms, search boxes and text areas.
  • Scroll: reveal content on long pages.
  • Screenshot: capture pages to check layout and confirm actions.
  • Console output: read errors, logs and warnings.
  • Network traffic: inspect requests and responses. This is currently available only in the Agent panel.

Session persistence

Cookies, localStorage, sessionStorage and IndexedDB persist between Agent sessions, so logins can carry over. Browser context is isolated per workspace.

Approval modes

  • Manual approval: you approve each action. This is the recommended default.
  • Allow-listed actions: actions on your allow list run automatically, others ask first.
  • Auto-run: every action runs without approval. Avoid it with untrusted code or unfamiliar websites.

Manage the allow list and block list at Cursor Settings > Agents > Auto-Run.

Enterprise controls

  • Admins control browser access under MCP Configuration in the admin dashboard, with a browser features toggle and MCP allowlists or denylists.
  • Browser Origin Allowlist (v2.1+) limits where Agent can navigate and where browser tools run. An empty list allows all origins.
  • The origin allowlist does not stop link clicks, redirects or client side navigation from reaching other origins, but browser tools are blocked once there.

Sources

More on Cursor

Other guides

Cursor: allow all terminal commandsClaude Code: allow commands without promptsCodex CLI: approval and sandbox modesGemini CLI: YOLO mode, auto_edit and allowing specific shell commandsCursor Privacy Mode: telemetry, training and data retentionClaude Code telemetry and data retention: what is sent and how to turn it offGemini CLI: turn off usage statistics and telemetryCLAUDE.md: where it goes, how it loads, and how it works with AGENTS.mdClaude Code hooks: format on save, block risky edits, get notifiedClaude Code subagents: create one, limit its tools, and call itAdd MCP servers to Cursor with mcp.json: Keep files out of Cursor with .cursorignore: Configure Codex with config.toml: Configure Gemini CLI with settings.json: Add MCP servers to Claude Code (claude mcp add, .mcp.json, scopes): Claude Code custom slash commands and skills (SKILL.md): GitHub Copilot custom instructions: Adding MCP servers to GitHub Copilot: Claude Code settings.json: file locations, precedence, and key settingsClaude Code plugins and marketplaces: install, create, and shareGemini CLI extensions and custom commands: Configuring OpenCode with opencode.json: Cline Rules: workspace, global, and conditional rulesKiro steering files: .kiro/steering, inclusion modes, and AGENTS.mdZed agent: instruction files, MCP servers, tool permissions, and ACP agentsCursor CLI: install, headless mode, permissions and CIAider: CONVENTIONS.md, .aider.conf.yml and API keysJunie guidelines, MCP and the Action Allowlist: Amp AGENTS.md, settings.json and MCP: Configure Goose extensions, hints, recipes and permissions: Customize OpenHands with skills, AGENTS.md, setup.sh and MCP: Configure Factory Droid CLI: AGENTS.md, settings.json, autonomy, custom droids and MCPConfigure Qwen Code: settings.json, providers, QWEN.md, MCP and approval modesCursor hooks: hooks.json, beforeShellExecution, afterFileEdit and exit codesCursor sandbox: sandbox.json, network allowlist and run modesCursor settings: settings.json, Cursor Settings and the ~/.cursor config filesCursor subagents: .cursor/agents, frontmatter, built-in Explore, Bash and BrowserCursor telemetry and OpenTelemetry export (Privacy Mode, OTLP, Analytics API): Cursor rules setup: .cursor/rules, .mdc frontmatter, globs, alwaysApply and AGENTS.md

Get the weekly agent stack update

New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.

Reviewed Oct 9, 2026. Settings change often; the linked vendor docs are the source of truth.