Grok Bot
Fix Zscaler SSL blocking the Grok Bot computer
Fix Zscaler SSL blocking the Grok Bot computer
Cursor staff (Colin, Sep 2, 2026) diagnosed a black loading spinner and “Can’t reach your computer” pattern where the hosted computer was healthy, yet Grok Bot still failed on both corporate LAN and an iPhone hotspot. Traffic was still leaving through Zscaler Client Connector, so switching networks alone did not help.
Confirm the path
- Fully quit Grok Bot (Task Manager on Windows, or Force Quit on macOS).
- Switch to a hotspot or home network.
- Pause or turn off Zscaler Client Connector if IT policy allows.
- Relaunch Grok Bot and wait for the computer view to load.
If the computer loads with Zscaler paused, the network path is the blocker. The computer itself does not need Recover or Reset for this case.
Ask IT for an allowlist
Staff ask for both levels of the Agent Computer host family to be allowlisted and excluded from SSL inspection:
*.cursorvm.com**.cursorvm.com
Both patterns matter. DNS or TCP reaching the host is not enough when SSL inspection still terminates the tunnel. Point IT at the Cursor domain list and verification steps linked from that forum thread.
Related fixes
- System-proxy / TUN setups that break Agent Computer reachability: Fix Grok Bot behind a system proxy or TUN VPN.
- Corporate VPN needed only for work apps (SSO, YubiKey): Reach VPN-only work apps from Grok Bot.
Pitfalls
- Hotspot tests can still fail while Zscaler Client Connector stays on. Pause the client, then relaunch Grok Bot.
api.cursor.comsucceeding over HTTPS does not prove Agent Computer traffic is clean.- Do not Recover or Reset the computer as a first move when staff say it is healthy and the pattern matches Zscaler.