Account Settings

Where on earth are the account settings? Why can’t I find them at all? This is ridiculous! Ever since switching to Agent Mode, the original ID interface has been hard enough to use as it is, but now I can’t even find where to go to change my account settings.

Hey @stevet

There are a couple ways to get to the settings, but the easiest would be clicking the gear icon here.

Let me know if you’re not seeing it, or if you’re working somewhere else in Cursor!

I understand that I need to click the gear icon, and I successfully switched screens after doing so. Thank you for your response. At the same time, I would like to ask: where is the option to set a new account password? I received a notification yesterday that my account had been hacked and I needed to change my password immediately. I went to the settings page but couldn’t find where to reset it, so I eventually had to log out and use the “Forgot Password” method to reset it. Also, the notification email mentioned setting up 2FA, which I also couldn’t find. Could you also tell me where to go to set up 2FA?

Hi @stevet Thanks for the post. You did the right thing by going thru the Forgot Password flow. I would just caution you to be extremely careful and suspicious of any of these types of emails. Cursor doesn’t send out emails like these so it could be spam / phishing. One legitimate case could be your password manager emailing you letting you know your password is exposed (hopefully that is what it is).

Regarding 2FA, Cursor doesn’t currently support built-in 2FA/MFA for individual Cursor accounts. The recommended workaround is to secure the identity provider you use to sign in:

  • If you sign in with Google: enable 2-Step Verification on your Google account.
  • If you sign in with GitHub: enable 2FA on your GitHub account.
  • If you’re on a team/business plan: admins can use SSO/SAML for centralized authentication on Teams/Enterprise plans.⁠⁠​

For account hygiene, review/revoke unfamiliar sessions at https://cursor.com/dashboard/settings?focus=first-name#active-sessions

Thank you for the clarification.

I am a user on a Team plan. Our Team administrator informed all team members that the payment card used for our Team subscription had been used for fraudulent transactions. As a precaution, we were asked to review our account security, so I immediately changed my password using the Forgot Password flow and signed out of all active sessions.

After reading your reply, I reviewed the notification again. I noticed that it mentioned MFA, which is why I brought it up. For security reasons, I don’t think it’s appropriate to post the full contents of the notification here.

One additional detail that may help clarify the situation: in the screenshot shared by our Team administrator, I noticed that it included an email from someone at Cursor named Ljerka, and that email mentioned MFA. I mentioned this because you said that Cursor doesn’t normally send emails like these, and I wanted to clarify where my reference to MFA came from. I wasn’t referring to a separate email that I personally received claiming to be from Cursor.

Based on your explanation, it seems that I have already completed all of the security measures currently available to me, including securing the identity provider I use to sign in and terminating all active sessions.

If there are any other security recommendations for Team users in this situation, I’d be grateful for your advice.

Thank you again for your assistance.