Skip to main content

Cursor CLI

This guide explains how to deploy cx-devassist to developer machines on Cursor.

Plugin distribution is managed through Cursor Team Marketplaces (Dashboard) — this is the one marketplace-based mechanism that installs the plugin across your organization, controlled by a single install-mode setting per plugin rather than a choice between several delivery methods.

By default, the Team Marketplace can point directly to the official Checkmarx repository. Developers can then authenticate to Checkmarx One using either Browser sign-in (OAuth) or an API key. With browser sign-in, developers provide their Checkmarx One URL and tenant during initial authentication; these values are remembered for subsequent use. With API key authentication, the API key contains the URL and tenant information and should be distributed through your organization's approved secret-management process.

For organizations using Browser sign-in (OAuth), the Checkmarx One URL and tenant can also be preconfigured so developers do not need to enter them during initial authentication. This requires an internal fork or mirror of the Checkmarx repository, as described in Optional — Preconfigure the Checkmarx One URL and Tenant.

Important: There is no separate file for onboarding. The Checkmarx One URL and tenant must be baked into the plugin artifact your team marketplace serves — the plugin deliberately does not read onboarding values from environment variables, ~/.checkmarx, or any other out-of-tree path.

Prerequisites

Before deploying cx-devassist, ensure developer machines meet the plugin's host requirements (see README.md):

Requirement

Windows

macOS

Linux

Git for Windows (POSIX sh for hooks)

Required

—

—

Python 3

Required

Required

Required

Cursor (IDE and/or CLI)

Installed and managed by your organization

Same

Same

Cursor Teams or Enterprise plan

Required for Team Marketplaces

Same

Same

Windows: Verify that sh is available by running sh --version. If Git for Windows is installed but sh is not recognized, ensure that the Git bin directory is included in PATH.

Team Marketplaces require a Teams plan (one marketplace) or an Enterprise plan (unlimited marketplaces). On Enterprise, only admins can add team marketplaces.

How cx-devassist Is Distributed

There is one marketplace-based mechanism — the Team Marketplace — and one decision point: which installation mode to set for the plugin once it's added. See Optional — Alternative Deployment Paths for non-marketplace options when Team Marketplace isn't available.

Mode

Behavior

Default Off

Developers find the plugin and choose to install it

Default On

Installed by default; developers can opt out

Required

Always installed; cannot be uninstalled

Use Required to force-enable the plugin organization-wide.

Device MDM is a separate, optional layer — not a plugin-installation alternative. It enforces IDE-level policy (which Cursor team a user must sign in with, update behavior, workspace trust prompts, MCP allowlists) but does not install or manage cx-devassist itself. See Optional — Device-Level Policies.

References: Cursor plugins — Team marketplaces · Deployment patterns (MDM) · Model and integration management

Procedure

Step 1 — Configure the Team Marketplace

Add the marketplace

  1. Open Cursor Dashboard → Plugins (Enterprise admin required to add marketplaces).

  2. Under Team Marketplaces, click Add Marketplace.

  3. Choose Import from Repo and connect the official Checkmarx repository: Checkmarx/cx-agentic-ai.

  4. Confirm the marketplace picks up .cursor-plugin/marketplace.json and lists cx-devassist (Checkmarx DevAssist for Cursor).

  5. Click Add to Marketplace for the cx-devassist plugin if it is not auto-discovered.

With this configuration, the plugin is delivered directly from the official Checkmarx repository. Developers provide their Checkmarx One URL and tenant during initial authentication.

Set marketplace access

Under Marketplace Settings → Marketplace Access:

  • Default — all team members see the marketplace.

  • Restricted — limit to selected Organization Groups (SCIM-synced from your identity provider).

Team admins always retain access.

Set the plugin installation mode

Set cx-devassist to Required for mandatory deployment (see How cx-devassist Is Distributed for what each mode does).How cx-devassist Is Distributed

Enable Auto Refresh

Turn on Auto Refresh so Cursor re-indexes the marketplace when changes are pushed to the tracked branch (requires the Cursor GitHub App on the repo). Cursor re-indexes at most once every 10 minutes. Otherwise, click Refresh manually after updating onboarding values or the plugin version.

Step 2 — Wire the Security Hooks (required)

Team Marketplace installs the plugin bundle (rules, skills, MCP manifest, hook scripts), but Cursor does not automatically merge cx-devassist's security hooks into a developer's hooks.json. This is a separate, required step — without it, the security gate hooks are not active even though the plugin appears installed in Customize.

Cursor CLI (recommended for enterprise rollouts)

Instruct developers — or automate this in your onboarding docs — to run once per machine:

/cx-install-wiring

Then restart the CLI session (/exit, then agent again). Do not use Developer: Reload Window — that command is IDE-only.

This skill merges hooks into the user's or project's hooks.json, syncs rules to .cursor/rules/, and continues into cx install/auth.

IDE / silent install

For non-interactive or IDE-only deployments:

# User scope
bash plugins/cursor-devassist/scripts/install-hooks.sh

# Project scope
CX_CURSOR_HOOKS_TARGET=project CX_PROJECT_PATH=/path/to/repo \
  bash plugins/cursor-devassist/scripts/install-hooks.sh

Requires Python 3. Restart the Cursor CLI session after completion.

Include this step in your internal rollout runbook — skipping it is the most common reason the plugin looks installed but does nothing.

Step 3 — Verify the Deployment

On a test machine enrolled in your Cursor team:

  1. Confirm the team marketplace appears under Customize (sidebar).

  2. Confirm cx-devassist is installed (automatic if the mode is Required or Default On).

  3. Run /cx-install-wiring (CLI) or install-hooks.sh (IDE) if not already done.

  4. Restart the CLI session or IDE as appropriate, and verify hooks appear under Settings → Hooks.

  5. Trigger first-use authentication — for example, a scannable file write, an MCP call, or /cx-cli-setup.

  6. If authentication is required, select your organization's authentication method:

    • Browser sign-in (OAuth) — Enter the Checkmarx One URL and tenant provided by your organization, then complete authentication in the browser.

    • API key — Provide the Checkmarx One API key according to your organization's authentication process.

  7. Run another Checkmarx operation and confirm that the MCP server is connected and operational.

When using Browser sign-in (OAuth), the Checkmarx One URL and tenant are remembered after initial configuration and do not need to be entered for subsequent operations.

Audit logs, if enabled, are written to:

~/.checkmarx/agent-logs/cursor/cx-devassist.jsonl

Optional — Preconfigure the Checkmarx One URL and Tenant

When using Browser sign-in (OAuth), you can preconfigure the Checkmarx One URL and tenant so developers do not need to enter these values during initial authentication.

This requires maintaining an internal fork or mirror of the Checkmarx repository.

Important: With the standard deployment, the plugin is delivered directly from the official Checkmarx repository, so Checkmarx updates can be received directly. If your organization uses an internal fork or mirror to preconfigure the Checkmarx One URL and tenant, your organization administrator must keep the internal repository synchronized with updates from the official Checkmarx repository.

Step 1 — Create an Internal Fork or Mirror

  1. Fork or mirror Checkmarx/cx-agentic-ai into a repository controlled by your organization, for example YourOrg/cx-agentic-ai.

  2. Create a dedicated branch for the rollout, for example mdm-v1 or release/mdm-2026-08.

  3. Configure the Team Marketplace to track that branch (via Auto Refresh or re-import).

  4. Do not point the Team Marketplace at upstream master unless you maintain that branch — upstream updates will replace your onboarding configuration.

The Cursor marketplace manifest lives at .cursor-plugin/marketplace.json. Plugin id: cx-devassist · marketplace name: cx-cursor-marketplace.

Private repository access: If your fork is private, install the Cursor GitHub App on the repository so Cursor can index the marketplace. Developers also need GitHub access to clone plugin sources when Cursor resolves the marketplace locally.

Step 2 — Configure the Checkmarx One URL and Tenant

In the internal repository, edit:

plugins/cursor-devassist/config/cx-onboarding.properties

Uncomment and set both values (both are required for pre-fill to work):

cx_base_auth_uri=https://eu.ast.checkmarx.net
cx_tenant=your-org-tenant

Use the Checkmarx One base authentication URL for your region or your on-premises deployment.

You can find the tenant in Checkmarx One under Settings → Identity and Access Management → General Settings (Display Name), or in the Checkmarx One welcome email.

Value formats and common regions

Key

Format

Example

cx_base_auth_uri

https://<host>[:port] — no path, query, userinfo, or trailing slash

https://eu.ast.checkmarx.net

cx_tenant

Starts with alphanumeric; then letters, digits, ., _, - only; max 64 characters

acme-corp

Region

URL

US

https://ast.checkmarx.net

US2

https://us.ast.checkmarx.net

EU

https://eu.ast.checkmarx.net

ANZ

https://anz.ast.checkmarx.net

India

https://ind.ast.checkmarx.net

Use your on-premises URL if applicable.

If either value is missing or invalid, the plugin falls back to requesting the information from the developer rather than blocking authentication.

Commit and push the change to the branch your Team Marketplace will track.

Step 3 — Point the Team Marketplace to the Internal Repository

In Cursor Dashboard → Plugins → Team Marketplaces, update the marketplace's source repository to your fork and pinned branch (for example, YourOrg/cx-agentic-ai at mdm-v1) instead of the official repository.

Step 4 — Deploy the Updated Settings

Deploy through Step 1 — Configure the Team Marketplace and Step 2 — Wire the Security Hooks, pointed at your fork.Step 1 — Configure the Team MarketplaceStep 2 — Wire the Security Hooks (required)

Step 5 — Verify Preconfigured Onboarding

Follow Step 3 — Verify the Deployment. In the authentication step, confirm the agent runs cx auth login with your pre-filled --base-auth-uri and --tenant values — the developer should not be prompted for URL or tenant.Step 3 — Verify the Deployment

Maintain the Internal Repository

When Checkmarx publishes a new upstream version:

  1. Merge or cherry-pick the upstream changes into your internal fork.

  2. Re-apply your cx-onboarding.properties values if the merge overwrote them.

  3. Push to the branch your Team Marketplace tracks.

  4. Wait for Auto Refresh, or click Refresh in Dashboard → Plugins.

  5. Ask developers to restart Cursor CLI sessions. Re-run install-hooks.sh only if hook scripts changed materially.

Do not edit cx-onboarding.properties in a user's live plugin install cache — it is overwritten on plugin update.

For Required plugins, developers cannot uninstall; Dashboard admins control the version through marketplace refresh.

Optional — Device-Level Policies

Device MDM enforces org-wide IDE behavior and does not install plugins. Use it alongside a Team Marketplace rollout, not instead of one.

Method

Platform

Location / mechanism

Configuration profile

macOS

.mobileconfig — policies such as AllowedTeamId, UpdateMode, WorkspaceTrustEnabled

Group Policy

Windows

Registry + ADMX from %LOCALAPPDATA%\Programs\cursor\policies

Policy file

Linux (Cursor 2.0+)

~/.cursor/policy.json

Permissions file

All platforms

~/.cursor/permissions.json — MCP / terminal allowlists (deploy via MDM file push)

Because these apply to different concerns on different platforms, they don't compete or need a precedence order among themselves.

Common policies

Policy

Purpose

AllowedTeamId

Restrict login to your Cursor team — unauthorized team IDs are forcefully logged out

UpdateMode

Control auto-updates (none, manual, start, silentlyApplyOnQuit)

WorkspaceTrustEnabled

Control workspace trust prompts

See Deployment patterns for full policy syntax.

macOS — configuration profile

Deploy a .mobileconfig with Cursor policies. Sample profiles ship inside the macOS app bundle:

/Applications/Cursor.app/Contents/Resources/app/policies/

Upload to Jamf, Kandji, or Intune as a custom configuration profile.

Windows — Group Policy

  1. Copy the ADMX/ADML files from %LOCALAPPDATA%\Programs\cursor\policies to C:\Windows\PolicyDefinitions.

  2. Configure policies under Cursor in Group Policy Editor.

  3. Computer-level policies override user-level policies.

Linux — policy file

Create ~/.cursor/policy.json (Cursor 2.0+):

{
  "AllowedTeamId": "your-team-id",
  "UpdateMode": "none"
}

Deploy via configuration management (Ansible, Puppet, etc.). Changes apply on Cursor restart; the file is watched for updates.

MCP allowlist (permissions.json)

cx-devassist bundles the Checkmarx MCP (cx mcp bridge). If your organization uses MCP allowlists, distribute ~/.cursor/permissions.json through MDM and include Checkmarx remediation tools as needed:

{
  "mcpAllowlist": [
    "Checkmarx:*"
  ]
}

Use the exact MCP server label shown in Customize on a test machine. Team dashboard MCP allowlists take precedence over file-based allowlists — configure both consistently. See Model and integration management — MCP Allowlist and Managing Run Mode allowlists with MDM.

Pair AllowedTeamId with your MCP allowlist so only your organization's Cursor team can use the deployment.

Optional — Alternative Deployment Paths

Use these when Team Marketplaces are unavailable — for example, individual plans, air-gapped environments, or a pre-enterprise pilot.

Cursor CLI — manual marketplace add

From a terminal:

cursor-agent plugin marketplace add https://github.com/Checkmarx/cx-agentic-ai

Then run /cx-install-wiring and restart the CLI session.

To use a preconfigured internal fork instead, point this at your fork's URL — onboarding pre-fill requires the marketplace to resolve your fork branch with the edited cx-onboarding.properties.

Local plugin install (offline / air-gapped)

Copy or symlink the plugin folder to:

~/.cursor/plugins/local/cx-devassist-cursor/
├── .cursor-plugin/plugin.json
├── config/cx-onboarding.properties   ← pre-fill here if preconfiguring onboarding
├── hooks/hooks.json
├── mcp.json
└── ...

Restart Cursor, or run Developer: Reload Window (IDE). Run install-hooks.sh and /cx-cli-setup as needed.

This path is useful when no GitHub marketplace connectivity exists. You are responsible for updating the local copy when Checkmarx releases new versions.

API Key Authentication

API key authentication does not use cx-onboarding.properties. The API key contains the Checkmarx One URL and tenant information, so these values do not need to be preconfigured in the plugin.

If your organization uses API key authentication, distribute the Checkmarx One API key through your organization's approved secret-management process, separately from this deployment flow. No onboarding file is involved.

Developers select API key as the authentication method during setup.

Troubleshooting

Symptom

Likely cause

Action

Plugin not visible in Customize

Not on Teams/Enterprise, or marketplace access restricted

Verify the plan; check Organization Group membership

Plugin installed but the gate never runs

Hooks not wired

Run /cx-install-wiring or install-hooks.sh; restart the CLI session

Checkmarx MCP server reports program not found on Windows

sh is not available on PATH

Run sh --version. If it is not recognized, ensure Git for Windows is installed and its bin directory is included in PATH, then restart the CLI session.

Developer is prompted for URL and tenant when using the official Checkmarx repository

This is the expected first-use flow

Enter the organization's Checkmarx One URL and tenant. They are remembered for subsequent use.

Developer is prompted for URL and tenant when using a preconfigured internal fork

Onboarding file is empty, invalid, or only one key is set

Check both keys in your fork (plugins/cursor-devassist/config/cx-onboarding.properties)

Wrong tenant or region at login

Marketplace tracks the wrong branch, or the fork's onboarding values are stale

Point the marketplace at your mdm-v* branch, update the values, then Refresh

Marketplace refresh fails

Private repo without the Cursor GitHub App

Install the Cursor GitHub App on the fork

MCP remediation blocked

MCP allowlist excludes Checkmarx

Add the server to the team dashboard or permissions.json allowlist

Hooks missing in Settings UI

Plugin hooks run from the manifest but the UI needs a merged hooks.json

Run install-hooks.sh

CLI session ignores new hooks

Session cache

/exit and start a new agent session — not Reload Window

Linux policy ignored

Cursor older than 2.0, or invalid JSON

Use Cursor 2.0+; check logs for policy.json parse errors

User logged out unexpectedly

AllowedTeamId MDM policy

Ensure the user's Cursor team ID is in the allowlist

Related Documentation

Compare with other DevAssist enterprise deployment guides

  • GitHub Copilot CLI — three interchangeable delivery methods, official repo available by default

  • Claude Code CLI — three delivery methods that do not merge, official repo available by default