Cursor's APIs live at https://api.cursor.com: the Admin API manages a team (with a team admin key), and the Cloud Agents API launches and lists background coding agents (with a user key).
The Admin API uses Basic auth with the team admin API key as the username and an empty password — curl's -u key:, PostTaco's Auth tab. The Cloud Agents API takes a user API key as a Bearer token. Both keys come from the Cursor dashboard.
Full reference: https://cursor.com/docs
curl https://api.cursor.com/teams/members \
-u {{CURSOR_ADMIN_KEY}}:
curl https://api.cursor.com/v0/agents \
-H "Authorization: Bearer {{CURSOR_API_KEY}}"