Skip to main content

Command Palette

Search for a command to run...

Grok Bot

Deploy Grok Bot to your organization

Your IT team installs the Grok Bot desktop app on member devices with the tools it already uses for other software: download a versioned installer, push it, and decide when devices move to a new release. Dashboard controls for turning Grok Bot on and scoping access are on Grok Bot for Teams and Enterprise, and deploying the Cursor editor is covered in Deployment patterns.

What you deploy

ComponentRuns onUpdated by
Desktop appmacOS (Apple silicon and Intel), Windows (x64 and Arm64), Linux (x64 and Arm64)The app, or your package manager for Linux .deb and .rpm installs
iPhone appiOS 18 or laterThe App Store
Android appAndroid 9 or laterGoogle Play
Hosted computerCursor's cloud, one per memberCursor

The apps are clients for chat, review, and approvals. Bots do their work on the member's hosted computer. Your device management tool reaches the apps on member devices and stops there: the hosted computer runs Linux in Cursor's cloud and isn't enrolled in MDM. To put your own tooling on hosted computers, Enterprise teams use Team Setup.

Get the installers

  • Cursor dashboard. The Download Grok Bot setup row on the Grok Bot page installs the app or copies a link you can share with members.
  • Download page. cursor.com/download/bot lists the current installer for every platform and format.
  • Release feed. For scripted packaging, read the current release from the feed below and download the file it names.
PlatformArchitecturesFormats
macOSApple silicon, Intel.dmg
Windowsx64, Arm64Setup .exe
Linuxx64, Arm64.deb, .rpm, AppImage

Read the current release from the feed

Each platform has a JSON feed at https://api2.cursor.sh/updates/api/download/stable/{platform}/sand:

{platform}Installer
darwin-arm64macOS, Apple silicon
darwin-x64macOS, Intel
win32-x64-userWindows x64
win32-arm64-userWindows Arm64
linux-x64Linux x64
linux-arm64Linux Arm64
curl -s https://api2.cursor.sh/updates/api/download/stable/darwin-arm64/sand

The fields you need:

FieldValue
versionThe current release
commitShaThe build the release comes from. Linux download URLs include it.
downloadUrlThe installer: .dmg on macOS, Setup .exe on Windows, AppImage on Linux
debUrl, rpmUrlLinux only. The .deb and .rpm packages.

The response can carry other fields. Installing the desktop app doesn't need them.

Build a versioned URL

macOS and Windows installers keep a versioned URL for each release. Replace {version} with the release you want:

InstallerURL
macOS, Apple siliconhttps://downloads.cursor.com/grokbot/stable/darwin-arm64/{version}/Grok_Bot_{version}.dmg
macOS, Intelhttps://downloads.cursor.com/grokbot/stable/darwin-x64/{version}/Grok_Bot_{version}_x64.dmg
Windows x64https://downloads.cursor.com/grokbot/stable/win32-x64/{version}/Grok_Bot_{version}_Setup.exe
Windows Arm64https://downloads.cursor.com/grokbot/stable/win32-arm64/{version}/Grok_Bot_{version}_Setup.exe

Linux packages sit under the release's commitSha, in https://downloads.cursor.com/grokbot/stable/{commitSha}/linux/x64/ or .../linux/arm64/. Copy the exact file URLs from downloadUrl, debUrl, and rpmUrl in the Linux feed.

Push the desktop app with your device management tool

  • macOS. Deploy the .dmg with the Mac management tool you run today, such as Jamf Pro, Kandji, or Microsoft Intune.
  • Windows. Deploy the Setup .exe with Intune, Configuration Manager, or another software distribution tool. Install silently with Grok_Bot_{version}_Setup.exe /S. The installer installs per user, into the member's profile under %LOCALAPPDATA%\Programs, so deploy it in user context, not as SYSTEM. Test the install on a pilot device before you push it.
  • Linux. Install the .deb or .rpm with your configuration management tool, such as Ansible, Puppet, or Chef. Prefer these packages for managed fleets: package installs update through your package manager on your schedule. See Linux package updates.
  • iPhone. Members install Grok Bot from the App Store on iOS 18 or later.
  • Android. Members install Grok Bot from Google Play on Android 9 or later. To push it to managed devices, approve it in managed Google Play from Intune or another Android device management tool.

Members sign in with their Cursor account through your normal SSO flow. Grok Bot has no separate login. To assign the Cursor app in Okta or Entra ID, see Configure identity and access.

Choose a version

  • Pin the version you tested. Download that release's installer and keep it in your own software repository or MDM package store. Deploy from your copy so every new device gets the same build. Cursor doesn't publish how long older installers stay available for download, and a pinned build works only until Cursor stops supporting it. See How desktop updates work.
  • Save the full Linux URL. Linux package URLs include the release's commitSha, so record the URL along with the version.
  • Check what a device runs. In the app, open the account menu and choose About. The dialog shows Version, and Copy version info copies the version, release track, and operating system.

How desktop updates work

InstallHow updates arrive
macOS .dmg, Windows Setup .exe, Linux AppImageThe app checks for updates automatically and offers each new version to the member. Restart to Update, in the Updates section of settings, installs it.
Linux .deb or .rpmThe app doesn't install updates. New versions arrive through your package manager.

For macOS, Windows, and AppImage installs, no device policy, installer option, or dashboard setting turns off desktop app updates. Pinning decides which version you install; the app still offers newer ones afterward.

Old builds stop working. When Cursor stops supporting a build, the app covers its whole window with Update required until the member updates. A build loses support when it falls below Cursor's minimum version, or when it passes a maximum age and a newer release is available. This applies to every install, including Linux .deb and .rpm packages. Cursor sets both limits remotely and doesn't publish them, so plan a regular cadence for moving devices to the current release.

Linux package updates

Installing the .deb adds Cursor's signed apt repository at /etc/apt/sources.list.d/grok-bot.sources. Installing the .rpm adds a signed repository at /etc/yum.repos.d/grok-bot.repo. Devices then pick up new Grok Bot versions whenever they run package upgrades.

To control when Linux devices move:

  • Hold the package. Use your package manager's hold, such as apt-mark hold grok-bot, and release it when you're ready to upgrade.
  • Turn the repository off. Set Enabled: no in grok-bot.sources, or enabled=0 in grok-bot.repo. The package rewrites these files on every install and upgrade and keeps your choice. Then ship new versions yourself from package files you've tested.

Either way, upgrade before the installed version loses support. A held package still gets the Update required screen.

Update the hosted computers

Cursor maintains the hosted computer's image, so there is no image for you to pin or supply. A computer moves to a newer image in one of three ways:

TriggerWhat happensWho starts it
New imageCursor recreates idle computers on the new image in the background, gradually and without a fixed schedule. Until then, a computer stays on its current image. Member files carry over, and Team Setup runs again.Cursor, in the background
Update Grok Bot's ComputerRebuilds the member's computer on the latest image. Scheduling it for a later time isn't available to every account yet.The member, from the Updates section of the desktop app's settings
Recreate VMsRebuilds the selected members' computers on the latest image and Team SetupOrganization admins on Enterprise, from Grok Bot Computers

Running computers pick up Team Setup manifest changes roughly once a day. To apply a change sooner, recreate the computers. On Enterprise, audit logs record computer updates, resets, recreates, and terminations as grok_bot_vm events, and operations across many members as grok_bot_vm_bulk.

Open the network path

Devices download installers and desktop updates from cursor.com and downloads.cursor.com, and the app connects to Cursor's API and the member's hosted computer on the domains in Allow these domain patterns. Allow all of them, including the nested *.*.cursorvm.com pattern, and exempt them from TLS inspection before you push the app.

Rollout checklist

1

Move off Privacy Mode (Legacy)

Privacy Mode (Legacy) blocks Grok Bot entirely. See Before you roll out.

2

Clear your network

Allow Cursor's domains on your gateway and exempt them from TLS inspection. See Configure TLS-inspecting proxies.

3

Assign the Cursor app in your identity provider

Grok Bot sign-in uses your Cursor SSO. See Assign the Cursor app.

4

Turn on Grok Bot and choose who gets it

On Enterprise, an admin turns Grok Bot on from the dashboard and scopes it with Manage Group Access. On Teams, every member already has access. See Enabling Grok Bot for your team.

5

Apply the recommended configuration

Set the admin controls in Recommended configuration before members start.

6

Pilot the installer

Install your chosen version on a few devices for each platform, sign in, and confirm the app connects to the hosted computer.

7

Push to your fleet

Deploy the tested installer to every device whose owner has access.

8

Plan updates

Pick a cadence for moving devices to new releases. For Linux, decide whether devices upgrade from Cursor's repository or from packages you ship.

FAQ

On macOS, Windows, and AppImage installs, no. The app checks for updates and offers them to members. Linux .deb and .rpm installs don't update themselves, so you control them with your package manager. See How desktop updates work.

The published installers are a .dmg for macOS, a Setup .exe for Windows, and a .deb, .rpm, or AppImage for Linux. Wrap the .dmg or .exe in your management tool's package format if it requires one.

No. The hosted computer runs Linux in Cursor's cloud and isn't enrolled in MDM. Enterprise teams install their own tooling on it with Team Setup. If your identity provider requires a managed device, see Allow sign-in to IdP apps from the computer.

No. Cursor maintains the image and moves computers to new images in the background. Enterprise organization admins can recreate computers at a time they choose from Grok Bot Computers.

Yes, unless your device policies block it. Members can download the app from the dashboard link an admin shares or from cursor.com/download/bot. Access still depends on your plan and, on Enterprise, on Manage Group Access.

Plan your Grok Bot rollout

Contact our team about Enterprise enablement, deployment planning, and security review support.

Contact Sales