Key takeaways

  • Agent Relay lets Cursor cloud agents run on a customer’s own infrastructure.
  • Coder launched the service with SpaceXAI.
  • The model can give companies more control over code, data and access.
  • Customers may still need to manage security, compute and system updates.

Agent Relay means a way to run Cursor’s cloud coding agents inside a customer’s infrastructure. Coder launched the service with SpaceXAI. The move shifts more control from a shared cloud to each company’s own systems. That matters to firms with strict rules for private code and data.

What is Agent Relay?

Agent Relay connects Cursor’s cloud agents to computers controlled by the customer. An AI coding agent is software that can plan tasks, change files and run commands for a developer.

Under the new setup, the agent can work through a relay rather than keeping every task in Cursor’s cloud. The customer’s infrastructure may include its own cloud account, servers or protected network.

Coder builds tools for running development environments in controlled settings. SpaceXAI is part of this launch, while Cursor supplies the cloud agent experience named in the announcement. The three-part setup is clear: Cursor provides the agent, Coder provides the connection, and the customer controls the machines.

Why are companies interested in Agent Relay?

Many companies want AI help, but they don’t want sensitive source code to travel through systems they don’t control. Source code is the written instruction behind an app, much like a recipe behind a meal.

Agent Relay could help teams keep that code inside approved accounts and networks. It may also let security teams use their own login rules, logs and network checks.

That does not make the system risk-free. An agent that can edit code or run commands still needs limits. Companies must decide what it can open, change and deploy.

Agent Relay is designed to bring Cursor’s cloud agents closer to the customer’s own security boundary, while keeping the agent workflow familiar to developers.

How does the Agent Relay setup work?

The process has three basic steps. A developer gives Cursor a task, Cursor sends the job through the relay, and the customer’s system runs the work.

The relay acts like a guarded doorway between the cloud agent and the customer’s tools. It can help pass approved instructions without giving the agent unlimited access.

Access control means rules that decide who or what may use a system. In practice, a company could limit an agent to one project, one code folder or one test environment.

Cursor agent1. TaskAgent Relay2. Guarded linkCustomer systems3. Run work

This flow has two sides and one bridge. Cursor remains the place where the developer asks for work, but the customer’s environment handles the computing task.

What changes for developers?

Developers may get the same familiar agent workflow with fewer trips outside company systems. They can ask for a feature, request a bug fix or have tests run by the agent.

But the experience will depend on setup. A customer must connect its source control, build tools and rules. Source control is the system that stores and tracks changes to code.

Teams also need a clear plan for failed tasks. If an agent changes three files and breaks a test, a developer must be able to review and undo those changes.

This is where audit logs help. An audit log is a record of actions, such as which user started a job and which files the agent changed.

Agent Relay versus a normal cloud agent

Area Normal cloud agent Agent Relay model
Where work runs Provider’s cloud Customer-controlled systems
Data control Shared provider process Customer sets local rules
Setup Usually quicker Needs technical configuration
Main trade-off Less local control More work for the customer

The biggest trade-off is simple. Customers may gain control, but they also take on more work.

They must pay for computing power, keep tools updated and watch for new security problems. This differs from a fully managed service, where the provider handles more of that burden.

Why this launch matters for the AI coding market

AI coding tools are moving from simple chat windows to agents that take several steps on their own. That raises the value of strong controls around code, secrets and production systems.

Secrets are private items such as passwords, API keys and database access codes. A relay model can support tighter rules, but it cannot replace careful design.

The launch also shows how AI software is splitting into two layers. One layer supplies the smart agent. The other layer decides where that agent can work.

Readers can compare this approach with the wider push toward private AI systems in our coverage of AI infrastructure investment and lower-cost AI models.

Companies exploring the product should check the Coder platform and Cursor product site for current rollout details. Product access, supported systems and pricing can change after launch.

What should businesses check before using it?

First, teams should map every system the agent can reach. Start with a test project, not a live customer database.

Second, set approval steps for code changes and deployments. A deployment sends new code into a live app, so mistakes can affect real users.

Third, measure time saved against the cost of compute and review. A faster agent may still create extra work if people must fix many errors.

The best early test has three parts: a small codebase, a clear task and a human review. That gives a company useful evidence without opening its whole network.

FAQs

What is Agent Relay?

Agent Relay is a Coder service that lets Cursor cloud agents run work on customer-controlled infrastructure.

Why does Agent Relay matter?

It may give companies more control over private code, system access and activity records.

Who launched Agent Relay?

Coder launched Agent Relay with SpaceXAI, using Cursor’s cloud agents in the customer-infrastructure model.

What the verified record says

Agent Relay is Coder’s bridge for running the execution side of Cursor cloud agents inside infrastructure controlled by the customer. Coder’s product announcement says code, tools and credentials can remain behind the customer’s firewall while the hosted agent service coordinates work. A separate launch-partner post names SpaceXAI. The Next Web independently covered the private-preview release and its enterprise positioning.

Agent Relay: verified recordPrimary record checkedIndependent reports comparedClaims kept conditional
Agent Relay: verified record — a reporting guide, not a scale comparison.

What the headline does not prove

The phrase “self-hosted” needs precision. Agent Relay does not mean the model, reasoning stack and every control-plane component run inside the customer’s environment. The vendor cloud can still handle planning and orchestration while the relay sends approved tool actions to a local execution plane. That division may satisfy some code-residency requirements but not every sovereignty, export-control or confidential-computing policy. Organizations must map what metadata leaves the environment, how prompts are retained, which telemetry is collected and where identity decisions occur.

This distinction prevents a common news-reading error: treating an announcement, allegation, target or median as a completed result. Dates and attribution matter. Where a company, regulator or political office supplies a number, that source is named. Independent coverage helps confirm the event, but it does not turn a disputed assertion into an established fact.

Agent Relay: confidence layersConfirmed eventReported figures with attributionOutcome still developing
Agent Relay: confidence layers — a reporting guide, not a scale comparison.

Why this development matters

The architecture addresses a common enterprise AI problem: useful coding agents need repository access, build tools, tickets, secrets and sometimes production-like systems. Copying all of that into a vendor workspace can violate policy. A relay can reduce data movement by bringing execution closer to the assets. It also creates a new trust boundary. Security teams need signed requests, short-lived credentials, explicit tool allowlists, audit logs, network egress controls and a fast kill switch. Productivity gains depend on whether those controls remain usable.

For decision-makers, the practical response is to identify which facts change an action today and which ones merely deserve monitoring. Consumers should verify eligibility or device support. Businesses should preserve records and model several outcomes. Investors should read filings instead of inferring completed transactions from agendas. A disciplined reading reduces the risk of acting on a claim that later changes.

What to watch next

Because the product is in private preview, buyers should treat availability and integration breadth as evolving. Run a threat model before a pilot. Test whether an agent can reach unapproved repositories, exfiltrate through allowed tools, persist credentials or bypass review through chained actions. Measure incident response as well as coding speed. Cursor’s own product updates should be checked for the hosted-agent side, while Coder’s documentation should define the relay. The best evaluation asks exactly which component runs where and who can authorize each action.

Agent Relay: next checkpointsNew primary disclosureIndependent verificationMeasured real-world result
Agent Relay: next checkpoints — a reporting guide, not a scale comparison.

For adjacent enterprise AI questions, see AI customer-care adoption and the BQP technical platform.

Source and methodology note

This article uses a primary source where one is public and checks the central claim against at least two independently published reports. Source links are placed beside the facts they support. Interpretive passages are clearly framed as analysis. The article will be updated if a court, company, regulator or public agency releases a document that materially changes the confirmed record.

FAQs

Is the main development final?

No. The confirmed event has occurred, but the broader outcome is still developing. The article separates what has happened from what may happen next.

Why do different reports sometimes show different numbers?

Differences can come from rounding, scope, timing or the source’s methodology. Use the cited primary record and treat estimates as estimates.

What is the safest way to use this information?

Verify the latest official document before making a legal, financial, purchasing or operational decision. News explains the record; it does not replace professional advice or a current eligibility check.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.