Skip to content
FunCoding

Search

Search docs, Skills and MCP

Origin App 认证与安装

验证安装回执,签发短期 token,并区分 REST、Git 和用户 CLI 凭据。

This page has not been translated into English yet. The original Chinese version is shown below.

Origin REST base 为 https://api.cursor.com/v1/origin,early beta。应用使用 Ed25519 app JWT 换取 installation access token;用户通过 Origin CLI 登录。Cursor API key 不是可直接放到 Origin Authorization header 的 bearer token。

注册和安装

在 codebase Apps 注册应用,仅上传公钥,私钥留在 secret manager。应用最多 10 个 active signing keys:

openssl genpkey -algorithm ED25519 -out origin-app-private.pem
openssl pkey -in origin-app-private.pem -pubout -out origin-app-public.pem

安装 URL 的 client_id、空格分隔 scope、精确匹配已注册的 redirect_uri 确定请求;随机 state 用于回调校验。重新授权可用 include_granted_scopes=true 保留已有范围、请求增量。

workspace admin 选择 owner、scopes 和 all/selected repositories,应用不能自行扩大批准范围。repository:metadata:read 自动加入。

安装回执不是 token

回调携带 installation_receipt JWT。按 JWKS 验签,要求 EdDSA、typ=origin-installation-receipt+jwt,检查 iss、aud、exp 和签名中的 state。sub 是安装 i_… ID,回执五分钟到期;不要将其用于 REST Bearer。

Origin issuer 为 https://api.cursor.com/v1/origin,JWKS 在 /keys。缓存有效期 600 秒,刷新失败最多再用 600 秒;无法验签时刷新密钥,不能无限沿用过期缓存。

App JWT 与 installation token

App JWT 的 alg=EdDSA,iss/kid 为 app ID,aud=origin-apps。通常约五分钟寿命。POST /app/installations/{installationId}/access_tokens 使用该 JWT 换取 token,返回 expiresAt。

token 最长 15 分钟,且不能超过签发 JWT 的 exp,因此五分钟 JWT 只得到至多五分钟 token。需要完整 15 分钟的 CI 参考 CloneKit 的较长 JWT 配方;总是读取 expiresAt,重新 mint,不按 GitHub token 周期缓存。

scopes/repositoryIds 可缩小授权,省略或空数组继承完整安装范围,不是零权限。删除 app 或卸载会在 expiresAt 前使既有 installation token 失效。

REST 与 Git

REST 使用 Bearer。Git HTTPS 用 Basic,用户名 x-access-token、密码 installation token,拒绝 REST Bearer 方式。clone/fetch/pull 需 contents:read,push 需 contents:write 和仓库 owner 写入资格。

用户自动化可让 origin api 用个人 CURSOR_API_KEY 换短期 user access token;应用集成仍使用 app/install 凭据。不要把 token 嵌入长期 remote URL,具体 CI helper 支持按CloneKit的当前流程。

镜像仓库对 installation token 限于 metadata/members/contents/mirror read 和 mirror sync;PR、review、checks、push 等不允许。用户 UI 可评审 GitHub PR 不表示应用 token 也具有此能力。