What Oleria discovers
Once connected, Oleria continuously discovers and maps the following from your Cursor team:- Accounts - every team member, with email, name, role (owner or member), status, and admin flag.
- Roles - the two built-in Cursor team roles, Owner and Member, and which accounts hold each.
- User groups - Cursor billing groups and their membership.
- Activity - audit log events such as sign-ins, sign-outs, and member add, remove, and role-change actions.
Cursor is a developer tool, not an access-controlled resource system - it has no repositories, files, or permissions for Oleria to enumerate, so this integration does not populate Access Inventory or resource-level Access Graph data. Cursor also does not expose per-user MFA or SSO enforcement, so Oleria reports these as unavailable rather than inferring them.
Prerequisites
- Cursor Enterprise plan - the Admin API this integration uses is available only on Enterprise-tier teams.
- Team Admin or Owner access in Cursor to generate an Admin API key.
Generate an admin API key in Cursor
1
Open API Keys
Sign in to the Cursor dashboard as a team admin and go to API Keys.
2
Create a new key
Select New API Key. Cursor generates a key in the form
crsr_....The key is tied to your Cursor organization rather than to the admin who created it, so it keeps working even if that admin’s account is later disabled.Connect Cursor to Oleria
1
Open the integration
Go to your Oleria workspace, select Integrations -> select Cursor.
2
Complete the connection form
Paste your API key:
3
Save the integration
Select Authenticate to validate and save the integration. Oleria calls Cursor’s team members endpoint to confirm the key works before saving.
Verify the integration
Confirm the Cursor instance appears in your Oleria workspace’s connected integrations. After the first sync completes, you can review the discovered accounts, roles, and billing groups. Audit log activity syncs on a separate, more frequent cadence.Cursor’s Admin API rate-limits most endpoints to 20 requests per minute per team. Oleria’s sync schedule stays well within this limit, so rate limiting should not affect normal syncs.
If you rotate or revoke your Cursor API key, edit the integration in Oleria, paste the new key, and select Update. The next sync runs with the new key.

