EngineeringCodeCross Team
Harden a Cursor MVP before paid traffic (2026)
A 2026 guide for founders still shipping from Cursor Agent: rank the blast (keys in chat, .cursorignore that the terminal can still read, localhost as the ad origin, Run Everything, Cloud Agent drafts treated as a release train, a checkpoint treated as rollback), prove the doors on the live host, then decide to stay in Cursor or leave.
Engineering
13 min
- Secrets
- Host vault
- Origin
- Host you own
- Ads
- After
Not chat or git
Not localhost
Human review first
Citation-ready answer: Harden a Cursor MVP before paid traffic by moving keys out of Agent chat into the host vault and Cloud Agent Runtime Secrets. Add `.cursorignore` — then remember the terminal and MCP can still read those files. Point ads at a host you own, not localhost. Require a human review on every Cloud Agent draft pull request. Restore a prior host deploy once. Then buy ads.
This note is from CodeCross, an Austin, Texas app development company (Pakistan engineering on a US Central overlap). Other tools sit on vibe coding. Buying help is the Austin app development company page. If nobody can name a host rollback tonight, book a conversation.
Money leaves when the campaign still lists `localhost`, a laptop preview tab, or a Stripe secret that sat in Agent chat. Cursor pricing puts Individual at $20 a month and Teams at $40 per user a month. That fee buys Agent time. It does not buy a public host. Cloud Agent security says a run ends when the agent pushes a branch and opens a draft pull request. A person still has to review it. Checkpoints live on the laptop and sit outside Git. A green Agent turn is not a stranger test on the URL you would put on a billboard.
This essay is the week before you buy ads, while the app still comes from Cursor Agent. Close the risky doors while Agent still writes the tree. It expands Harden a Cursor MVP before strangers hit the app. This page is not Cursor to production, get off Cursor, migrate from Cursor, or transition from Cursor. The question here is narrower: can you buy a click while Cursor still writes the code? When secrets, the advertised origin, or the off switch is still open, book.
Stay in Cursor. Close the doors first.
Cursor is paid to finish a change tonight. Paid traffic is paid to send strangers at a public URL. Those jobs collide. A green local run can still leave a key in chat, a laptop address as the share link, or Run Everything free to push.
Cursor’s own docs draw the line. Agent edits files, runs the terminal, and can open a browser. There is no cap on how many tool calls one task can make. That is a workshop, not a host. Cursor does not give you a public `*.cursor.app` door. You still pick the host. You still pick who may merge.
Run Modes decide how much the local Agent may do without asking. Auto-review is the mode Cursor calls safest for most people. It ran as the default from Cursor 3.6 on 29 May 2026. Run Everything runs every tool call with no sandbox and no review. Cloud Agents do not use those modes at all. They auto-run inside their own machine. You do not need a new editor this week. You do need to name who can merge, who holds secrets, and which URL ads will hit.
Rank the blast. Ads make a small leak big.
Start with the blast, not a prettier Agent restyle. A stranger who dumps every order row, burns a paid API from an open route, or copies a live Stripe secret will cost more than a new landing screen. Rank those doors. Close the worst one tonight.
Blast rank — close the Cursor top layer first
Off switch and watch
A prior host deploy you have restored once — not a checkpoint on one laptop.
GitHub app mistaken for the train
The Cursor GitHub app clones and opens draft PRs. It does not replace protected main.
Unreviewed Agent diffs
Run Everything on the laptop. A Cloud Agent draft treated as already merged.
Auth and row rules on the generated backend
A hidden admin screen. An open table. A route that never asked who you are.
Localhost vs the host you own
Ads, mail, or Auth that still print localhost, a laptop preview, or a leftover Vercel preview.
Secrets in chat, rules, and git
Keys pasted into Agent, left in .cursor/rules or AGENTS.md, or committed in a .env the terminal can still read.
Put six names on paper: who owns secrets, who proves login on the advertised URL, who can merge to main, who watches spend and errors, who owns the public origin, and who can restore a prior host deploy tonight. Two red names plus a campaign date means spend stays off. If you cannot name a human for each layer, book.
Secrets: if Agent saw it, treat it as leaked
Keys are the first thing ads will leak. Agent reads what you paste. Founders then drop Stripe secrets, OpenAI keys, and webhook tokens into the same thread. A later prompt does not wipe those words from history you already shared. Rotate anything that sat in plain text.
Privacy Mode is a training lock, not a vault. When it is on, Cursor says your code is never used to train Cursor or the model vendors. Teams can force it so members cannot turn it off. That is good. It does not make a key in chat safe. The model still saw the value. Rotate it.
Ignore files is the vendor example to keep. A `.cursorignore` file can hide `.env`, `*.pem`, and `secrets.json` from Agent, Tab, Inline Edit, and @ mentions. The same page is blunt: the terminal and MCP tools cannot honor that list. A secret you hid from chat can still be `cat`’d by a command. Pair the ignore file with approvals and file permissions. Complete protection is not guaranteed.
Rules live as `.mdc` files. Root `AGENTS.md` is the plain-markdown path. Those files go with the repo. Do not put a live token in a rule. A teammate clone then holds the same secret. Team plans can enforce rules. Enforcement is steering. It is not a vault.
Cloud Agent keys have their own drawer. Secrets & Network splits three types. Environment Variables are visible to the agent. Runtime Secrets print as `[REDACTED]` in the transcript, tool output, and commits. Build Secrets stay in the Docker build. Mark money keys as Runtime Secrets. A user who opens the agent Terminal can still see them.
The host vault is the drawer you want. GitHub Actions secrets inject at run time. They do not live in the tree Agent just edited. If the app sits on Vercel, environment variables say the same: set values in the dashboard, not the repo. Secret values are write-only after you save. Stripe’s API keys guide is the split. A publishable key (`pk_…`) can sit in the browser. A secret key (`sk_…`) cannot. If the only place the key still lives is a chat you are afraid to open, book.
Localhost is the lab. The host you own is the ad target.
Cursor gives you several addresses that look live. They are not the same job.
Three live origins — only one is the ad target
01 · Laptop preview
Lab
localhost or a local port. Dies when the laptop sleeps.
02 · Preview host
Share door
A Vercel preview, a Cloud Agent demo, or a leftover share link. Not the ad.
03 · Host you own
Ads
The name on the billboard. The only public origin.
Cursor is an IDE. It does not print a vendor campaign URL. That is the trap. Founders paste the local port into Slack, then into an ad. Google Ads destination mismatch rejects an ad when the display URL domain does not match the final URL. Do not advertise your domain if clicks still land on localhost or a preview host. Google Search Central wants one preferred URL when two hosts show the same app. Link ads, mail, and in-app shares to that one name.
Search the tree for `localhost` and leftover preview hosts. Check signup redirects and “view app” links in mail. Cloud Agent demo files belong on the pull request. They are not the campaign door.
Auth and row rules: a hidden admin page is not a gate
Rows are the next thing ads will leak. Agent is good at wiring a sign-in screen. It is weaker at naming who may read a row after that screen. OWASP Top 10 2025 still ranks broken access control first. They tested apps and found some form of it in 100% of them. One of their examples is an admin check that lives only in the front end. A stranger who calls the same URL another way still gets in. Access checks belong on the server — not in the paint of the page.
If Agent stood up a hosted Postgres — often Supabase — row level security is the server gate. A table in an exposed schema without that gate is open to any role with a grant. Adding a policy does not revoke default `anon` and `authenticated` grants. Prove both.
A demo login that only works on the laptop is a costume. The advertised host must sign a stranger in. Logout must work after a hard refresh. Admin must be a server check. OAuth and reset mail must land on the host you own — not `localhost`.
Run these four checks on the advertised host. A laptop pass with your Agent session does not count:
- Every table or route that holds personal data or money checks identity, and public grants are named. A hidden admin route is not that proof.
- A stranger account cannot read another user’s row by changing an id in the URL or the API.
- Sign-up and sign-in work on the advertised host. Local success is not that proof.
- Secret, admin, or Stripe secret keys never shipped to the browser. Those keys skip row rules.
Unreviewed Agent diffs are a write path on your repo
Agent can change many files in one turn. Two people in the same folder can race. A chat undo is an editor undo. It is not branch protection.
Run Modes make that race worse if you pick Run Everything. Every shell, MCP, and Fetch call runs with no ask. Auto-review is the safer local default. It still says the classifier can make mistakes. It is not a security wall. Hooks can block a command before it runs. Use them if you stay in Cursor. They do not replace a required review on GitHub.
Cloud Agents auto-run every terminal step. They open a draft pull request. Nothing merges until a person reviews the change. That is the vendor’s own handoff. Treat a draft as a draft. Signed commits use an HSM-backed key and show a Verified badge. A verified Agent commit is still an Agent commit. It is not a human review.
The GitHub app exists so Cloud Agents and Bugbot can clone, open PRs, and read checks. It can read branch protection. It does not replace it. About protected branches is the remote lock. Require reviews. Require status checks. Keep force-push off. Restrict who can push to `main`. If the org remote still allows a direct push of whatever the laptop Agent wrote, ads wait.
Off switch: a checkpoint is not a host rollback
A bad release needs an off switch you can name tonight. Asking Agent to revert takes the draft back. It does not take the live site back by itself.
Checkpoints snapshot files before a big Agent edit. Restore puts those files back. It does not remove the chat. The same page says checkpoints are local and separate from Git. Use them to undo Agent work. Use Git for the real record. A restore on one laptop does not republish Vercel, Netlify, or a store binary.
Name the deploy owner. Prove you can restore a prior host version. A feature flag is extra. It does not replace a version you can republish in minutes. “We will open Cursor and restore the checkpoint” waits on one laptop and one agent. It is repair. It is not an off switch.
Watching: errors, spend, and a silent laptop
Watching without an off switch is half a lock. Before ads, name three signals: sign-in failures on the advertised host, 5xx after an Agent merge, and paid-API or host spend. Cursor pricing bills extra model use after the included amount. On-demand usage is billed later. Name who watches the first 24 hours. If nobody owns that, the campaign stays off.
Bugbot can review each pull request. On GitHub the check is named Cursor Bugbot. Findings default to `neutral`, so requiring the check alone does not block a merge. Autofix can spawn a Cloud Agent and push a fix. That is a review helper. It is not a merge. Keep Autofix off or on a new branch the week ads start unless a person still approves.
A clean checkout is the other watch. Clone the org remote on a machine without Cursor. Install. Build. Start with host-injected secrets. If that path fails, Agent is still the runtime. CI/CD after an AI builder is the later essay. This page only asks: does a second machine boot without an open Agent window?
Score — mark pretend vs proof
Secrets
Costume
Key in chat
Started
Moved to host env
Proof
Rotated + not in git
Public name
Costume
Ads list localhost
Started
Domain live
Proof
Ads + Auth match
Auth / rows
Costume
Hidden admin page
Started
Routes listed
Proof
Stranger cannot find rows
Review
Costume
Run Everything to main
Started
Draft PR opened
Proof
Protected main + review
CI
Costume
Only Cursor starts it
Started
Script in repo
Proof
Clean clone boots
Off / watch
Costume
“Restore checkpoint”
Started
Prior deploy named
Proof
Prior deploy restored
Score each row against the advertised URL, not the laptop. One red cell — a key in chat, localhost in ads, an open write, an open merge seat, a silent spend meter, or a rollback you have never hit — is enough to hold the spend. Move that cell. Do not greenwash the matrix.
The week before you buy ads
Treat the next seven days as operator time on the Cursor project, not a slogan. Inventory who can merge, who holds secrets, and which origin ads will hit. Then seal. Then prove.
Harden in Cursor — seven operator steps
01 →
Inventory the public path
Who can merge. Which origin ads will hit. Where secrets still live. Laptop vs host named.
02 →
Seal secrets
Drain chat, rules, and git. Rotate. Put new values in the host vault and Runtime Secrets.
03 →
Lock auth and rows
Stranger cannot find another user’s row. Login works on the advertised URL.
04 →
Lock review
Protected main. Auto-review on the laptop. Cloud Agent drafts stay drafts.
05 →
Fix the URL map
No localhost in ads. OAuth and Stripe point at the same name.
06 →
Name watch and spend
Who sees sign-in fails, 5xx after merge, and the Cursor usage bill.
07
Restore + watch, then buy
Restore a prior host deploy once in a safe window. Then spend.
Day 0 is inventory. Write five facts. The public origin. The person who can merge. Whether a live key still sits in chat or git. Whether a stranger can read another user’s row. Whether you can restore a prior host deploy tonight. If the public origin is already taking leads and you cannot name those five, stop. You do not need a new screen. You need this list.
Seal secrets first. Then rows. Then review. Bots do not wait for a nicer landing page. If a public route exists, prove it refuses the write when nobody is signed in. Then strip leftover localhost shares. Then restore a prior host deploy once in a safe window so you know the off switch works. Then spend. This page is the week you run that list.
Illustrative operator days before a Cursor ad buy
daysUnpriced Ads on a red list
3–5 wks
Campaign live. Doors still open. Cleanup later.
Illustrative operator days — not measured traffic, not a Source: Admin analytics series. Unpriced feature sprints on a public Cursor-built app often cost more than this week when the first leak hits.
Treat those bars as calendar you reserve, not a vendor promise. If you cannot name the advertised origin, who can merge, and who can restore a prior deploy, the later days will thrash. The long bar is the expensive miss: a “small” test while localhost or an open route is still the company.
Stay in Cursor, or leave. Do not mix the two jobs.
Pick one job for this week. Stay keeps Cursor as the studio, with secrets in the host vault, a host you own as the origin, protected main, and a host rollback already proved. Leave opens get-off Cursor and stops buying clicks that need that laptop window. Running both jobs at once is how teams rebuild screens they already had.
Stay or leave — pick one job
Stay (this page)
Studio still in Cursor
Agent still plans. You accept the editor and the usage bill.
Doors closed on that path
Secrets, origin, auth, review, spend, rollback.
Ads wait for green
A red layer pauses spend, not the product.
If the public origin must leave a laptop-only ship path, stop this page and open the exit. If ads are close and the origin can stay on a host you control, finish these doors first. ↓If the public origin must leave a laptop-only ship path, stop this page and open the exit. If ads are close and the origin can stay on a host you control, finish these doors first.
Leave (other pages)
Process leaves the laptop loop
Org Git plus a host you run. See get-off and migrate.
A draft PR is not the exit
The GitHub app is still that vendor path until your host serves the live app.
Kill the laptop-only ship
App still answers when the Agent window is closed.
If you only need a leave date, use when to leave an AI builder. A door that will not close belongs on rewrite vs harden. A personal Git remote belongs on GitHub handoff. A laptop-only ship path belongs on CI/CD after an AI builder. Cousin wraps: Emergent, Base44, a0, Windsurf. Those pages are not this Agent week.
Check loop — prove, then decide
01
Prove the door
One layer. One test on the advertised URL.
02
Close it
Rotate, redirect, add identity checks, protect main, or restore a prior deploy.
03
Re-check ads list
If a layer is still red, spend stays off.
04 · loops
Stay or leave
Closed doors can stay. An open laptop row opens the exit.
When the list turns red
Leave the product up. Kill the campaign if any of these are still true:
- A live key still exists only in Agent chat, a rule file, an MCP config, or a committed env file.
- A route that holds personal data or money is still readable without a named identity check.
- Ads, mail, or the sitemap still list localhost or a leftover preview host.
- Main still accepts a direct Agent push, or Run Everything can ship without a review.
- The app will not boot from a clean checkout with host-injected secrets.
- The off switch is “we will restore a checkpoint,” or you have never restored a prior host deploy.
- Two people disagree about who can merge or who holds admin.
A single red door is a miss, even if the laptop is green. Stop adding screens until secrets, row rules, protected main, and the rollback are honest. Finish those doors. Then spend — or open get-off Cursor if the laptop is still the company.
Bring a second pair of hands when the founder cannot rotate a key without pasting it back into Agent, when a stranger can still find another user’s row, or when nobody has restored a prior host deploy before the date. Hire for secrets, row locks, merge seats, and the URL map — not a prettier Agent screen. Austin app development company is the studio brief. Austin mobile app development if the next door is a store binary that still points at this Cursor-built URL.
Next steps
Walk the gates in order. Inventory the public origin, the person who can merge, and who holds workspace access. Drain chat, rules, and git secrets into the host vault. Rotate anything that appeared there. Add identity checks that refuse the write when nobody is signed in. Protect main. Strip leftover localhost shares from ads, mail, sitemap, and Auth. Prove a stranger test on the live URL. Restore a prior host deploy once in a safe window. Then buy the click — or open the exit if the process itself must leave Cursor.
CodeCross LLC is an Austin-registered product studio (1606 Headway Cir STE 9212, Austin, TX). The Cursor week we run is vaulted secrets, a host you own, auth and row locks, protected main, then a host rollback you have already hit. The Austin app development company page is the studio brief. Austin mobile app development is the store-binary door if a signed build still points at this Cursor-built URL. Company-level evidence lives on proof. When the off switch, secrets, or the advertised origin is still open, book a conversation.
Cursor is allowed to stay the studio. Ads are not allowed to treat a laptop pass, an open write, or an unreviewed Agent push as that proof. Show a prior host deploy you can restore, routes that refuse a stranger who is not signed in, and keys that never lived in chat. Most teams never need a second codebase once those three exist.
FAQ
Does the Cursor GitHub app replace a release train?
No. The GitHub app connects repos so Cloud Agents and Bugbot can clone, open pull requests, and read checks. It can read branch protection. It does not merge for you. Cloud Agent security says the handoff is a draft pull request. A person still reviews it. Protected branches are what stop a laptop push from becoming the live app. Installing the app is setup. It is not a train.
If I restore an Agent checkpoint, does the live host go back?
No. Checkpoints snapshot files on the laptop before a big Agent edit. Restore puts those files back. It does not remove the chat. The same page says checkpoints are local and separate from Git. Use them to undo Agent work. They do not republish Vercel, Netlify, or a store binary. Name the prior host deploy you would restore tonight. Hit that restore once before ads.
Does .cursorignore stop the terminal from reading a Stripe secret?
No. Ignore files hide listed paths from Agent, Tab, Inline Edit, and @ mentions. The same page says the terminal and MCP tools cannot honor that list. A `.env` you hid from chat can still be read by a command. Cursor also says complete protection is not guaranteed. Pair `.cursorignore` with approvals and file permissions. Put the live value in GitHub Actions secrets or Vercel env. Stripe says a secret key never belongs in the browser. Rotate anything that sat in chat or git.
Does Privacy Mode make a key in Agent chat safe to keep?
No. Privacy and data governance says Privacy Mode stops Cursor and the model vendors from training on your code. Teams can force it so members cannot turn it off. That is a training lock. The model still saw the value you pasted. Rotate the key at the issuer. Save the new value in the host vault. For Cloud Agents, mark money keys as Runtime Secrets so they print as `[REDACTED]` in the transcript. Do not buy ads on a red drawer.
Does Bugbot Autofix merge the fix to main by itself?
No. Bugbot reviews the diff and can spawn a Cloud Agent to draft a fix. Autofix modes are `disabled`, `newBranch`, or `existingBranch`. A repo file can lower that mode. It cannot raise it past the dashboard. The Autofix check is `success` or `neutral`. It is not a merge. Findings on the review check default to `neutral`. A person still approves.
Does Run Everything plus a green local run mean ads can use localhost?
No. Run Modes say Run Everything runs every tool call with no sandbox and no classifier. A green local turn is a lab. Google Ads destination mismatch rejects an ad when the display URL domain does not match the final URL. Do not advertise your domain if clicks still land on localhost. Google Search Central wants one preferred URL. Point ads at the host you proved.
Can a Cloud Agent skip a protected main?
Not if the lock is real. Cloud Agent security says the agent pushes a branch and opens a draft pull request. Nothing merges until a person reviews it. Signed commits satisfy a “require signed commits” rule. They do not satisfy “require a human review.” Protected branches are what stop a direct push. If main still accepts a laptop Agent push, keep spend off.
Thirty minutes with a senior teammate — honest next steps.
Ready to price an Austin build?
Bring the problem, the users, and a budget ceiling. We’ll tell you whether an app is the right next spend — and what the first year actually costs.
Prefer writing? Send project details on the contact page.