Use Squiid with
Cursor
Cursor needs credentials for every service your project touches. Give it one instead: SQUIID_API_KEY in .env, and every service in the catalog behind it.
What Cursor is
Cursor is an AI-first code editor built on the VS Code foundation, with inline completion, a chat sidebar and an agent mode that edits files across a project and runs commands. It is the tool most people mean by vibe coding, and because it works inside a real repository it reads your .env and your project rules the same way any editor-based workflow does.
The problem: every agent wants keys
The moment a coding agent stops writing a component and starts wiring up a product, it needs credentials. A database URL for Supabase. A deploy token for Vercel. An API key for Resend. Another for Twilio, another for Stripe, another for whichever model provider the feature calls. Each one is a signup, a dashboard, a billing relationship and a secret that has to exist somewhere Cursor can reach.
What happens next is worse than a long .env file. People paste secrets into prompts to get better answers, and keys end up in chat transcripts, in screenshots posted for help, and in committed config. Because each key belongs to a different vendor, rotating one after a leak means finding it, regenerating it and updating every place it was copied to.
The fix: one key, one convention
Squiid holds the upstream credentials for every service in the catalog. Your project gets one variable:
SQUIID_API_KEY=sq_live_xxxxxxxxxxxxxxxxxxxx
Then every call your app or your agent makes goes to the gateway with that one key:
curl https://api.squiid.io/v1/supabase/... \
-H "Authorization: Bearer $SQUIID_API_KEY"
Official SDKs take a base URL, so most integrations are a one line change rather than a rewrite:
import { createClient } from '@supabase/supabase-js';
const db = createClient(
'https://api.squiid.io/v1/supabase',
process.env.SQUIID_API_KEY,
);
That is the gateway convention: https://api.squiid.io/v1/<service>/ with Authorization: Bearer $SQUIID_API_KEY. It is the same for every service, which is why an agent only has to learn it once. Full detail is on the gateway convention page.
Setting it up in Cursor
- Cursor runs your project locally, so your app reads
.envexactly as it always did. PutSQUIID_API_KEYthere and nothing else changes. - Project rules live in
.cursor/rulesas rule files. Add a short rule stating that all third party calls go through the Squiid gateway, so the agent stops suggesting provider specific keys. Older Cursor versions used a single.cursorrulesfile at the repo root. - Cursor agent mode can run terminal commands, so it will pick up exported shell variables too. Keep secrets out of chat: paste the gateway path, never a key.
What it costs
Usage is paid from prepaid credits at par: $1 of credit is $1 at the provider, no markup. The free plan is $0/month with a 15% fee on credit top-ups and a $50 minimum top-up. Solo is $19.97/month and its top-up fee starts at 8%, falling to 6.5%, 5% and 3.5% as trailing 30-day API spend passes $100, $500 and $2,000. Team is $29.97 per seat per month for seats 1-5, $24.97 for seats 6-20 and $19.97 above that, with the same ladder one point lower. Custom pricing is 3% or less against a commitment. Subscription-priced services such as Supabase Pro at $25 a month pass through at the provider price with no fee. Credits pause at zero rather than overdrawing, with alerts at 75%, 90% and 100%. See spend controls.
Services agents ask for most
The eight services that come up first in almost every Cursor project, all reachable with the same key.
Supabase
DatabasePostgres with auth, storage and realtime.
Vercel
HostingDeploy from a git push, preview per branch.
Resend
EmailTransactional email in one POST request.
Twilio
MessagingSMS, voice and phone numbers worldwide.
Cloudflare R2
StorageR2 object storage, Workers, KV and D1.
Stripe
PaymentsCheckout, subscriptions and webhooks.
Anthropic
LLM APIClaude models for app-side generation.
OpenAI
LLM APIChat, embeddings, images and audio.
Set it up in 3 steps
Add the services in Squiid
Create a Squiid account, top up credits, and click add on the services this project needs. Squiid provisions them upstream and keeps the provider credentials.
One line in .env
Put SQUIID_API_KEY=sq_live_… in .env and remove every provider key you were carrying. That is the whole secret surface of the project.
Tell Cursor the convention
Write the base URL and the header into your project rules file so Cursor generates correct calls without being reminded.
Questions people ask
How do I stop Cursor from asking me to paste API keys?
Add a project rule under .cursor/rules saying every external service is called through https://api.squiid.io/v1/<service>/ with Authorization: Bearer $SQUIID_API_KEY. With a single key present in .env, the agent stops proposing per-provider credentials.
Does Cursor read my .env file?
Your application reads it at runtime as normal, and Cursor can read the file as part of the workspace. That is another reason to hold only one gateway key there rather than a dozen provider secrets that could end up in a chat transcript.
Can Cursor add a new service to my project on its own?
It can write the integration code. Adding the service itself is a click in the Squiid dashboard, which is deliberate: provisioning a paid upstream account is a decision a human should make, not something an agent does mid-task.
Do I pay Squiid for Cursor?
No. Cursor bills you for its own model usage. Squiid bills for the services your application uses, at provider prices from prepaid credits, plus your plan fee. The two are independent.
Give Cursor one key.
Not twelve.
One account, one API key, one bill and one dashboard for every service in the catalog your project needs.