GROK BOT / fix-zscaler-ssl-for-grok-bot-computer

Grok Bot

Fix Zscaler SSL blocking the Grok Bot computer

Fix Zscaler SSL blocking the Grok Bot computer

Cursor staff (Colin, Sep 2, 2026) diagnosed a black loading spinner and “Can’t reach your computer” pattern where the hosted computer was healthy, yet Grok Bot still failed on both corporate LAN and an iPhone hotspot. Traffic was still leaving through Zscaler Client Connector, so switching networks alone did not help.

Confirm the path

  1. Fully quit Grok Bot (Task Manager on Windows, or Force Quit on macOS).
  2. Switch to a hotspot or home network.
  3. Pause or turn off Zscaler Client Connector if IT policy allows.
  4. Relaunch Grok Bot and wait for the computer view to load.

If the computer loads with Zscaler paused, the network path is the blocker. The computer itself does not need Recover or Reset for this case.

Ask IT for an allowlist

Staff ask for both levels of the Agent Computer host family to be allowlisted and excluded from SSL inspection:

  • *.cursorvm.com
  • **.cursorvm.com

Both patterns matter. DNS or TCP reaching the host is not enough when SSL inspection still terminates the tunnel. Point IT at the Cursor domain list and verification steps linked from that forum thread.

Related fixes

Pitfalls

  • Hotspot tests can still fail while Zscaler Client Connector stays on. Pause the client, then relaunch Grok Bot.
  • api.cursor.com succeeding over HTTPS does not prove Agent Computer traffic is clean.
  • Do not Recover or Reset the computer as a first move when staff say it is healthy and the pattern matches Zscaler.