
Coder has introduced Agent Relay, a self-hosted execution environment designed to let enterprises run cloud-based coding agents inside infrastructure they control.
The company announced the product on September 2, 2026, with SpaceXAI as its launch partner and Cursor as the first integration. Coder says the service is aimed particularly at organizations where security, governance and control requirements have limited the use of cloud-hosted coding agents.
With Agent Relay, developers can continue using Cursor’s existing app, web and mobile experiences. Cursor continues to operate the agent loop, including planning and inference, while the actual tool calls execute inside Coder workspaces running on infrastructure controlled by the customer.
Coder says this separation keeps source code, secrets and access to internal services inside the customer’s environment. Workspaces can run on a customer’s cloud, virtual private cloud or on-premises infrastructure.
Coder’s technical explanation of Agent Relay describes the product as a way to separate the cloud-hosted agent from the environment in which its work is executed.
The company says each Coder workspace can start a Cursor worker that establishes an outbound connection to Cursor. Platform teams can then provision and scale these environments using the same systems they already use for developer workspaces.
Coder says the arrangement allows enterprises to keep cloud agents close to private code, internal services and custom hardware without moving execution into the agent vendor’s infrastructure.
The security model is built around controls at the workspace level rather than relying entirely on the AI agent to make the correct decision.
Coder says Agent Relay uses sandboxed and ephemeral environments scoped to individual tasks. Network egress policies can be defined by platform teams and applied across workspaces.
The company also says its architecture can block unauthorized access at the environment layer. That is intended to provide protection when an agent receives instructions, including potentially malicious prompt-injection content, that attempt to reach resources outside its permitted scope.
Agent activity is also logged. According to Coder, each run records what the agent accessed, executed, changed and was prevented from doing, allowing organizations to retain an audit trail of automated development activity.
The approach builds on Coder’s existing work on controlled AI development environments. In May 2026, the company introduced Coder Agents, a native AI coding system designed to run its agent loop on Coder’s own control plane while keeping code, credentials and execution on customer infrastructure.
Agent Relay is different. Instead of replacing a company’s preferred cloud agent with Coder’s own agent, it allows organizations to keep using an external cloud-hosted agent while moving its execution environment under enterprise control.
Coder said its earlier work with AgentAPI also influenced the design. The company said AgentAPI did not gain enough traction as a standard and that wrapping command-line agents created difficulties when reproducing their native experiences in web applications.
The company now says the broader goal is to separate the agent itself from the infrastructure in which it operates, allowing enterprises to adopt different AI coding tools without rebuilding their security and governance model each time.
That approach reflects a growing number of organizations using multiple AI coding agents rather than relying on a single provider. Coder cited a Gartner projection that 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from less than 5% in 2025.
In a separate announcement, Coder cited another Gartner projection that 80% of enterprise software engineers will need to upskill for generative AI by 2027.
Coder is positioning Agent Relay particularly for banks, government agencies, defense organizations and other large enterprises with strict requirements around source-code access, data protection and auditability.
The company said these organizations have often faced a deployment problem rather than a lack of interest in AI coding tools. Developers may want the same agents available elsewhere, while security teams need execution to remain within controlled environments.
Agent Relay is intended to address that divide by leaving Cursor’s user experience and cloud-based agent operation in place while transferring execution to customer-controlled infrastructure.
The launch also comes shortly after Cursor became part of SpaceX. Cursor announced on August 14, 2026, that SpaceX had completed its acquisition of Cursor. Cursor said the deal would give the company access to SpaceX’s large GPU infrastructure as it works to develop more capable and economical models.
Coder identified SpaceXAI as the first agent provider working with Agent Relay and said it plans to extend the technology to additional providers over time.
The partnership arrives during a period of change for Cursor’s model ecosystem as well. On August 28, OpenAI said it intended to wind down its contract providing OpenAI models to Cursor, with a proposed shutdown date of November 12, 2026.
In its announcement, OpenAI said the decision followed Cursor’s acquisition by SpaceX and concerns about compliance with its terms of service. OpenAI said it would continue providing access to its models through the contract’s remaining period but would not provide future models to Cursor under the arrangement.
The OpenAI decision is separate from Coder’s Agent Relay launch, but it highlights the changing relationships among AI model providers, coding-agent companies and the infrastructure enterprises use to deploy them.
Coder says Agent Relay is currently in private preview with design partners. The company has not opened the Cursor integration for general availability.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

