Build1 distinct publisher3 min readPublished
Agent Relay keeps Cursor's reasoning loop in Cursor's cloud and lands the tool calls in workspaces you already govern, which turns the security review's question from whether the agent is allowed into what its planner gets sent.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Look at the direction of the connection. The provider sends a resource request into Coder, Agent Relay launches a workspace, using a prebuild for a warm start, applies the correct template, and the provider's daemon inside that workspace opens a secure link back out to its external service [4]. Each Coder workspace can start a Cursor worker that dials outbound [7]. Nothing requires an inbound hole, which the network team will like, and the flow carrying agent traffic to the vendor is the one that ends up on the egress allowlist rather than under inspection. Coder says Agent Firewall, RBAC and audit logging apply automatically because the work happens inside a workspace, so there is no separate security model to build for agent traffic [5].
The split is planner remote, effectors local. Cursor continues to run the agent loop, including inference and planning, while tool calls execute in Coder environments on the customer's network, which is how Coder gets to say source code, secrets and internal services stay on machines the customer controls [6]. A planner still needs context to plan with. Both posts describe the perimeter in terms of where tool calls execute, not in terms of what the loop is sent to reason over. For the perimeter claim to hold up in a bank's review, one of two things has to be true: the remote loop plans without file contents, or the context it receives is scoped and recorded on the way out. Neither post says which.
The attribution work is the part I would pay for. Agent Relay resolves each incoming request against the organization's existing identity provider, so an agent's commits, tool calls and file access carry the same attribution as a human developer's [8]. Coder's own AI Maturity Model assessment of 100 engineering organizations found 70 percent running agents on infrastructure never designed to support them and only 31 percent at organization-wide governance, usually because nobody can say which human an agent's actions trace back to [9]. That leaves 69 of the 100 without it, and a 39-point gap between the two figures [10]. Coder assessed those organizations itself, so treat the numbers as the shape of the problem rather than its size.
The most persuasive paragraph in the launch post is the one about what failed. Coder's earlier self-hosted work used AgentAPI, an approach similar to today's Agent Client protocol, to run agent CLIs inside workspaces behind a common interface; it worked, but AgentAPI never gained traction as a standard, and wrapping CLI agents added friction when recreating their experience in a web app [13]. Registering as a compute pool in someone else's scheduler avoids re-implementing someone else's product surface, and it divides the work honestly: Coder supplies the machine, the vendor supplies the loop. Coder Agents remains the other path, running its reasoning loop in the Coder control plane while code, credentials and execution stay in customer infrastructure [14].
Both posts reach for Gartner. Forty percent of enterprise applications carrying task-specific agents by the end of 2026, up from less than 5 percent in 2025 [11], is more than eightfold in about a year [12], and that transfers to your capacity plan only if your applications get counted the way Gartner counts a task-specific agent feature. If your constraint is where commands run and which human owns them, this is the right tradeoff, and the plumbing looks well made. If your constraint is what the model sees, the relay moves execution and leaves that question where it was.
Ranked by verification strength, evidence, and original report placement.
Coder introduced Agent Relay, launching with Cursor as its first integration partner, giving enterprises a way to run cloud-hosted coding agents inside secure, self-hosted Coder workspaces instead of the agent vendor's cloud.
Coder frames the stalling question as not whether the agent is good enough but where it actually executes; by default a cloud-hosted coding agent reads the codebase, runs commands and writes files inside infrastructure the vendor controls.
When a developer starts a session, the agent provider sends a resource request, and Agent Relay launches a workspace, using prebuilt workspaces for a warm start, applies the correct template, and opens a secure connection between the agent provider's daemon inside the workspace and its external service.
Cursor continues to run the agent loop, including inference and planning, while tool calls execute in Coder environments on the customer's network, so that source code, secrets and internal services stay on machines the customer controls.
Each Coder workspace can start a Cursor worker that opens an outbound connection to Cursor.
Rob Whiteley, CEO of Coder, said enterprises never rejected AI agents but rejected the deployment model, and that the model was never the bottleneck.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Per-developer environments hit their ceiling the day one engineer ran five agents1 distinct publisher
build
Replit makes its router decide which model writes your code1 distinct publisher
build
Claude Code now outruns Copilot roughly two to one in JetBrains' survey of 15,000 developers1 distinct publisher
build
Superpowers makes spec-driven work a precondition, then ships it to twelve harnesses1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor-only, but specific enough to check
Two posts, one company, the same timestamp, and nothing else in the record. What earns Coder some credit is specificity: registering itself as a pool in the provider's scheduler, a daemon inside the workspace dialing outward, prebuilds for warm starts — these are falsifiable descriptions, and Coder volunteers the detail that costs it something, namely that inference still routes through the agent vendor rather than Coder's own gateway. What it cannot supply is anyone else's word. Cursor appears only as a quote, no one outside has run the thing, and the two posts can't agree on the partner's name.
Private preview, nobody named
Private preview with design partners is the entirety of it. No customer is identified, no preview count, no availability date, no pricing. The one hard outcome anywhere in this reporting — a global financial institution cutting compliance audit resolution from months to minutes — belongs to Coder's existing identity and audit controls, not to Agent Relay, and the institution goes unnamed. The 70%/31% survey speaks to a problem's prevalence, not to anyone using this product.
Reach oversold, mechanics honest
The framing reaches a long way past the product: an opened market of banks, defense programs and government agencies, an 'AI Operating Layer' that the modern enterprise stack supposedly lacks, all for something in private preview with design partners nobody can name. Pulling the other way, Coder is unusually candid where it counts — the reasoning loop and inference stay with the vendor, and its own earlier AgentAPI effort is described as having failed to become a standard. So the overstatement sits in the market rhetoric and the borrowed Gartner urgency, not in the engineering.
Launch material end to end
One post is Coder's product launch, the other is Coder's partnership announcement with a joint go-to-market motion and a closing link to docs and sales. The numbers establishing urgency are selected accordingly: two Gartner projections relayed without citation, and a 70%/31% governance shortfall drawn from an assessment Coder itself runs, feeding into a Coder whitepaper. None of that makes the figures wrong; it does mean every incentive in this reporting points the same direction, with no counterweight anywhere in the record.
Clear claims, one muddled source
We can say with confidence what is being claimed, who is claiming it, and how much of it is checkable later — the architecture is described in enough detail that a design partner could confirm or embarrass it. Two things cap this. The partner naming in the announcement reads like a substitution that went wrong, which makes that post a weaker record of anything it says, and the sole customer proof point arrives anonymous and, in our reading of it, partly truncated.