News

Cloudflare Sandboxes Now Run Cursor Cloud Agents (2026)

News | 08.09.2026

Enterprises want to adopt AI coding agents without losing control over where code, build caches, and secrets actually live. Developers want to keep the tools they already use every day. Cloudflare is addressing both needs by making Cloudflare Sandboxes an execution layer for Cursor Cloud Agents, so AI coding work can run inside customer-controlled environments while preserving the familiar Cursor workflow.

What was announced

On September 2, 2026, Cloudflare announced official support for running Cursor Cloud Agents on Cloudflare Sandboxes. The integration extends Cloudflare's existing work with other AI agent platforms, including Devin Outposts and Claude Managed Agents, and positions Cloudflare Sandboxes as a secure, isolated execution layer for agentic software.

With Cursor Self-Hosted Machines, Cursor continues to run the agent loop — inference, planning, and orchestration — while tool calls execute on a customer-selected worker. That worker can now run inside a sandbox environment in the customer's Cloudflare account, keeping terminal, filesystem, and browser actions under customer control.

Developers want powerful AI tools that fit naturally into their workflows, and enterprises need those tools to run in environments they control. Bringing Cursor Cloud Agents to Cloudflare Sandboxes is another step toward making Cloudflare the execution layer for the next generation of agentic applications

Dane Knecht, Chief Technology Officer, Cloudflare

Why this matters

For CIOs, CISOs, and IT directors, agentic development introduces new questions about data residency, secrets handling, and code exposure. Traditional SaaS coding agents run in vendor-controlled infrastructure, which conflicts with strict compliance and security policies. Sandboxed execution inside the customer's own Cloudflare account gives security teams a defensible boundary while letting engineering teams keep using Cursor across desktop, web, and mobile.

Procurement leaders also gain a consolidated path: instead of provisioning separate infrastructure for AI agent workloads, teams can use Cloudflare's platform they may already have in place, reducing vendor sprawl and simplifying contracting.

Technical details

  • Execution model: Cursor runs the agent loop; tool calls execute inside customer-controlled Cloudflare Sandboxes.
  • Connectivity: Outbound-only — a Cursor worker opens a long-lived outbound HTTPS connection to Cursor's backend, no inbound access required.
  • Scope of isolation: Repositories, build caches, and secrets remain on customer machines.
  • Data uploaded: File chunks read during inference, plus Cloud Agent artifacts such as screenshots, videos, and log references for pull requests and dashboards.
  • Team scaling: Single-worker connections via My Machines, or named worker pools with pool orchestration to start and release worker capacity on demand.
  • Integration: Cloud Agents API for embedding self-hosted machine status and pool routing into existing systems.

Softprom and Cloudflare

Softprom is the official distributor of Cloudflare. Our team helps enterprises design secure architectures for AI development workloads, from Cloudflare Sandboxes and Workers to Zero Trust access for developer tooling.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.