Cursor CLI
This guide explains how to deploy cx-devassist to developer machines on Cursor.
Plugin distribution is managed through Cursor Team Marketplaces (Dashboard) — this is the one marketplace-based mechanism that installs the plugin across your organization, controlled by a single install-mode setting per plugin rather than a choice between several delivery methods.
By default, the Team Marketplace can point directly to the official Checkmarx repository. Developers can then authenticate to Checkmarx One using either Browser sign-in (OAuth) or an API key. With browser sign-in, developers provide their Checkmarx One URL and tenant during initial authentication; these values are remembered for subsequent use. With API key authentication, the API key contains the URL and tenant information and should be distributed through your organization's approved secret-management process.
For organizations using Browser sign-in (OAuth), the Checkmarx One URL and tenant can also be preconfigured so developers do not need to enter them during initial authentication. This requires an internal fork or mirror of the Checkmarx repository, as described in Optional — Preconfigure the Checkmarx One URL and Tenant.
Important: There is no separate file for onboarding. The Checkmarx One URL and tenant must be baked into the plugin artifact your team marketplace serves — the plugin deliberately does not read onboarding values from environment variables,
~/.checkmarx, or any other out-of-tree path.
Prerequisites
Before deploying cx-devassist, ensure developer machines meet the plugin's host requirements (see README.md):
Requirement | Windows | macOS | Linux |
|---|---|---|---|
Git for Windows (POSIX | Required | — | — |
Python 3 | Required | Required | Required |
Cursor (IDE and/or CLI) | Installed and managed by your organization | Same | Same |
Cursor Teams or Enterprise plan | Required for Team Marketplaces | Same | Same |
Windows: Verify that
shis available by runningsh --version. If Git for Windows is installed butshis not recognized, ensure that the Gitbindirectory is included inPATH.
Team Marketplaces require a Teams plan (one marketplace) or an Enterprise plan (unlimited marketplaces). On Enterprise, only admins can add team marketplaces.
How cx-devassist Is Distributed
There is one marketplace-based mechanism — the Team Marketplace — and one decision point: which installation mode to set for the plugin once it's added. See Optional — Alternative Deployment Paths for non-marketplace options when Team Marketplace isn't available.
Mode | Behavior |
|---|---|
Default Off | Developers find the plugin and choose to install it |
Default On | Installed by default; developers can opt out |
Required | Always installed; cannot be uninstalled |
Use Required to force-enable the plugin organization-wide.
Device MDM is a separate, optional layer — not a plugin-installation alternative. It enforces IDE-level policy (which Cursor team a user must sign in with, update behavior, workspace trust prompts, MCP allowlists) but does not install or manage cx-devassist itself. See Optional — Device-Level Policies.
References: Cursor plugins — Team marketplaces · Deployment patterns (MDM) · Model and integration management
Procedure
Step 1 — Configure the Team Marketplace
Add the marketplace
Open Cursor Dashboard → Plugins (Enterprise admin required to add marketplaces).
Under Team Marketplaces, click Add Marketplace.
Choose Import from Repo and connect the official Checkmarx repository:
Checkmarx/cx-agentic-ai.Confirm the marketplace picks up
.cursor-plugin/marketplace.jsonand lists cx-devassist (Checkmarx DevAssist for Cursor).Click Add to Marketplace for the
cx-devassistplugin if it is not auto-discovered.
With this configuration, the plugin is delivered directly from the official Checkmarx repository. Developers provide their Checkmarx One URL and tenant during initial authentication.
Set marketplace access
Under Marketplace Settings → Marketplace Access:
Default — all team members see the marketplace.
Restricted — limit to selected Organization Groups (SCIM-synced from your identity provider).
Team admins always retain access.
Set the plugin installation mode
Set cx-devassist to Required for mandatory deployment (see How cx-devassist Is Distributed for what each mode does).
Enable Auto Refresh
Turn on Auto Refresh so Cursor re-indexes the marketplace when changes are pushed to the tracked branch (requires the Cursor GitHub App on the repo). Cursor re-indexes at most once every 10 minutes. Otherwise, click Refresh manually after updating onboarding values or the plugin version.
Step 2 — Wire the Security Hooks (required)
Team Marketplace installs the plugin bundle (rules, skills, MCP manifest, hook scripts), but Cursor does not automatically merge cx-devassist's security hooks into a developer's hooks.json. This is a separate, required step — without it, the security gate hooks are not active even though the plugin appears installed in Customize.
Cursor CLI (recommended for enterprise rollouts)
Instruct developers — or automate this in your onboarding docs — to run once per machine:
/cx-install-wiring
Then restart the CLI session (/exit, then agent again). Do not use Developer: Reload Window — that command is IDE-only.
This skill merges hooks into the user's or project's hooks.json, syncs rules to .cursor/rules/, and continues into cx install/auth.
IDE / silent install
For non-interactive or IDE-only deployments:
# User scope bash plugins/cursor-devassist/scripts/install-hooks.sh # Project scope CX_CURSOR_HOOKS_TARGET=project CX_PROJECT_PATH=/path/to/repo \ bash plugins/cursor-devassist/scripts/install-hooks.sh
Requires Python 3. Restart the Cursor CLI session after completion.
Include this step in your internal rollout runbook — skipping it is the most common reason the plugin looks installed but does nothing.
Step 3 — Verify the Deployment
On a test machine enrolled in your Cursor team:
Confirm the team marketplace appears under Customize (sidebar).
Confirm cx-devassist is installed (automatic if the mode is Required or Default On).
Run
/cx-install-wiring(CLI) orinstall-hooks.sh(IDE) if not already done.Restart the CLI session or IDE as appropriate, and verify hooks appear under Settings → Hooks.
Trigger first-use authentication — for example, a scannable file write, an MCP call, or
/cx-cli-setup.If authentication is required, select your organization's authentication method:
Browser sign-in (OAuth) — Enter the Checkmarx One URL and tenant provided by your organization, then complete authentication in the browser.
API key — Provide the Checkmarx One API key according to your organization's authentication process.
Run another Checkmarx operation and confirm that the MCP server is connected and operational.
When using Browser sign-in (OAuth), the Checkmarx One URL and tenant are remembered after initial configuration and do not need to be entered for subsequent operations.
Audit logs, if enabled, are written to:
~/.checkmarx/agent-logs/cursor/cx-devassist.jsonl
Optional — Preconfigure the Checkmarx One URL and Tenant
When using Browser sign-in (OAuth), you can preconfigure the Checkmarx One URL and tenant so developers do not need to enter these values during initial authentication.
This requires maintaining an internal fork or mirror of the Checkmarx repository.
Important: With the standard deployment, the plugin is delivered directly from the official Checkmarx repository, so Checkmarx updates can be received directly. If your organization uses an internal fork or mirror to preconfigure the Checkmarx One URL and tenant, your organization administrator must keep the internal repository synchronized with updates from the official Checkmarx repository.
Step 1 — Create an Internal Fork or Mirror
Fork or mirror
Checkmarx/cx-agentic-aiinto a repository controlled by your organization, for exampleYourOrg/cx-agentic-ai.Create a dedicated branch for the rollout, for example
mdm-v1orrelease/mdm-2026-08.Configure the Team Marketplace to track that branch (via Auto Refresh or re-import).
Do not point the Team Marketplace at upstream
masterunless you maintain that branch — upstream updates will replace your onboarding configuration.
The Cursor marketplace manifest lives at .cursor-plugin/marketplace.json. Plugin id: cx-devassist · marketplace name: cx-cursor-marketplace.
Private repository access: If your fork is private, install the Cursor GitHub App on the repository so Cursor can index the marketplace. Developers also need GitHub access to clone plugin sources when Cursor resolves the marketplace locally.
Step 2 — Configure the Checkmarx One URL and Tenant
In the internal repository, edit:
plugins/cursor-devassist/config/cx-onboarding.properties
Uncomment and set both values (both are required for pre-fill to work):
cx_base_auth_uri=https://eu.ast.checkmarx.net cx_tenant=your-org-tenant
Use the Checkmarx One base authentication URL for your region or your on-premises deployment.
You can find the tenant in Checkmarx One under Settings → Identity and Access Management → General Settings (Display Name), or in the Checkmarx One welcome email.
Value formats and common regions
Key | Format | Example |
|---|---|---|
| | |
| Starts with alphanumeric; then letters, digits, | |
Region | URL |
|---|---|
US | |
US2 | |
EU | |
ANZ | |
India | |
Use your on-premises URL if applicable.
If either value is missing or invalid, the plugin falls back to requesting the information from the developer rather than blocking authentication.
Commit and push the change to the branch your Team Marketplace will track.
Step 3 — Point the Team Marketplace to the Internal Repository
In Cursor Dashboard → Plugins → Team Marketplaces, update the marketplace's source repository to your fork and pinned branch (for example, YourOrg/cx-agentic-ai at mdm-v1) instead of the official repository.
Step 4 — Deploy the Updated Settings
Deploy through Step 1 — Configure the Team Marketplace and Step 2 — Wire the Security Hooks, pointed at your fork.
Step 5 — Verify Preconfigured Onboarding
Follow Step 3 — Verify the Deployment. In the authentication step, confirm the agent runs cx auth login with your pre-filled --base-auth-uri and --tenant values — the developer should not be prompted for URL or tenant.
Maintain the Internal Repository
When Checkmarx publishes a new upstream version:
Merge or cherry-pick the upstream changes into your internal fork.
Re-apply your
cx-onboarding.propertiesvalues if the merge overwrote them.Push to the branch your Team Marketplace tracks.
Wait for Auto Refresh, or click Refresh in Dashboard → Plugins.
Ask developers to restart Cursor CLI sessions. Re-run
install-hooks.shonly if hook scripts changed materially.
Do not edit cx-onboarding.properties in a user's live plugin install cache — it is overwritten on plugin update.
For Required plugins, developers cannot uninstall; Dashboard admins control the version through marketplace refresh.
Optional — Device-Level Policies
Device MDM enforces org-wide IDE behavior and does not install plugins. Use it alongside a Team Marketplace rollout, not instead of one.
Method | Platform | Location / mechanism |
|---|---|---|
Configuration profile | macOS |
|
Group Policy | Windows | Registry + ADMX from |
Policy file | Linux (Cursor 2.0+) |
|
Permissions file | All platforms |
|
Because these apply to different concerns on different platforms, they don't compete or need a precedence order among themselves.
Common policies
Policy | Purpose |
|---|---|
| Restrict login to your Cursor team — unauthorized team IDs are forcefully logged out |
| Control auto-updates ( |
| Control workspace trust prompts |
See Deployment patterns for full policy syntax.
macOS — configuration profile
Deploy a .mobileconfig with Cursor policies. Sample profiles ship inside the macOS app bundle:
/Applications/Cursor.app/Contents/Resources/app/policies/
Upload to Jamf, Kandji, or Intune as a custom configuration profile.
Windows — Group Policy
Copy the ADMX/ADML files from
%LOCALAPPDATA%\Programs\cursor\policiestoC:\Windows\PolicyDefinitions.Configure policies under Cursor in Group Policy Editor.
Computer-level policies override user-level policies.
Linux — policy file
Create ~/.cursor/policy.json (Cursor 2.0+):
{
"AllowedTeamId": "your-team-id",
"UpdateMode": "none"
}
Deploy via configuration management (Ansible, Puppet, etc.). Changes apply on Cursor restart; the file is watched for updates.
MCP allowlist (permissions.json)
cx-devassist bundles the Checkmarx MCP (cx mcp bridge). If your organization uses MCP allowlists, distribute ~/.cursor/permissions.json through MDM and include Checkmarx remediation tools as needed:
{
"mcpAllowlist": [
"Checkmarx:*"
]
}
Use the exact MCP server label shown in Customize on a test machine. Team dashboard MCP allowlists take precedence over file-based allowlists — configure both consistently. See Model and integration management — MCP Allowlist and Managing Run Mode allowlists with MDM.
Pair AllowedTeamId with your MCP allowlist so only your organization's Cursor team can use the deployment.
Optional — Alternative Deployment Paths
Use these when Team Marketplaces are unavailable — for example, individual plans, air-gapped environments, or a pre-enterprise pilot.
Cursor CLI — manual marketplace add
From a terminal:
cursor-agent plugin marketplace add https://github.com/Checkmarx/cx-agentic-ai
Then run /cx-install-wiring and restart the CLI session.
To use a preconfigured internal fork instead, point this at your fork's URL — onboarding pre-fill requires the marketplace to resolve your fork branch with the edited cx-onboarding.properties.
Local plugin install (offline / air-gapped)
Copy or symlink the plugin folder to:
~/.cursor/plugins/local/cx-devassist-cursor/ ├── .cursor-plugin/plugin.json ├── config/cx-onboarding.properties ← pre-fill here if preconfiguring onboarding ├── hooks/hooks.json ├── mcp.json └── ...
Restart Cursor, or run Developer: Reload Window (IDE). Run install-hooks.sh and /cx-cli-setup as needed.
This path is useful when no GitHub marketplace connectivity exists. You are responsible for updating the local copy when Checkmarx releases new versions.
API Key Authentication
API key authentication does not use cx-onboarding.properties. The API key contains the Checkmarx One URL and tenant information, so these values do not need to be preconfigured in the plugin.
If your organization uses API key authentication, distribute the Checkmarx One API key through your organization's approved secret-management process, separately from this deployment flow. No onboarding file is involved.
Developers select API key as the authentication method during setup.
Troubleshooting
Symptom | Likely cause | Action |
|---|---|---|
Plugin not visible in Customize | Not on Teams/Enterprise, or marketplace access restricted | Verify the plan; check Organization Group membership |
Plugin installed but the gate never runs | Hooks not wired | Run |
Checkmarx MCP server reports | | Run |
Developer is prompted for URL and tenant when using the official Checkmarx repository | This is the expected first-use flow | Enter the organization's Checkmarx One URL and tenant. They are remembered for subsequent use. |
Developer is prompted for URL and tenant when using a preconfigured internal fork | Onboarding file is empty, invalid, or only one key is set | Check both keys in your fork ( |
Wrong tenant or region at login | Marketplace tracks the wrong branch, or the fork's onboarding values are stale | Point the marketplace at your |
Marketplace refresh fails | Private repo without the Cursor GitHub App | Install the Cursor GitHub App on the fork |
MCP remediation blocked | MCP allowlist excludes Checkmarx | Add the server to the team dashboard or |
Hooks missing in Settings UI | Plugin hooks run from the manifest but the UI needs a merged | Run |
CLI session ignores new hooks | Session cache | |
Linux policy ignored | Cursor older than 2.0, or invalid JSON | Use Cursor 2.0+; check logs for |
User logged out unexpectedly | | Ensure the user's Cursor team ID is in the allowlist |
Related Documentation
Compare with other DevAssist enterprise deployment guides
GitHub Copilot CLI — three interchangeable delivery methods, official repo available by default
Claude Code CLI — three delivery methods that do not merge, official repo available by default