FREELofty Health Check: connect your Lofty and see where your leads are slipping.Check my score
    Free guide · managed setup

    Grok Bot, set up safely

    By the end of this page you will have a WORKING GROKBOT: the app installed, signed in on an eligible plan or the free trial credit, a first Bot created and proven with a real task, one tool connected on purpose, and approval and privacy boundaries you chose yourself. The setup is deliberately short. Grok Bot's whole proposition is that the computer, the browser and the always-on part are run for you.

    Checked against the official Grok Bot documentation and pricing pages on 5 September 2026. Grok Bot launched in beta in August 2026 and changes weekly, and the official pages do not always agree with each other yet: if a screen does not match this page, check the official page linked below before assuming you did something wrong.

    Understand · MODEL ≠ AGENT · read this first

    MODEL is not the AGENT, and Grok Bot is not Hermes

    Grok is a model family. Grok Bot is a managed agent product built around it. Hermes Agent is open-source agent software you run yourself, into which you can plug Grok or another model.

    Each of these names is a different kind of thing. A model is the thinking: it answers, reasons and writes. An agent is the environment around a model: it has hands, holds settings and logins, and can act. Grok Bot and Hermes are both agents, but one is a hosted product you sign in to and the other is software you install and configure. Mixing them up is the fastest way to buy the wrong thing, or to expect a kind of control the product does not offer.

    Grok

    The model family (the thinking)

    • Made by xAI; available in the Grok apps, through the xAI API, and inside other products.
    • Has no hands of its own: it produces text, code and decisions, not actions.
    • Can be the model inside Hermes, which documents xAI as a supported provider.

    Grok Bot

    A managed agent product (a hosted teammate)

    • Named, persistent Bots that work on a cloud computer with a browser, a terminal and files.
    • Marketed by xAI (now SpaceXAI) and delivered through Cursor: you sign in with a Cursor account and the cloud computers are Cursor-hosted. The Grok Bot terms are published by both companies, so which terms and privacy policy apply depends on the account you hold; read the ones linked from your plan. You cannot choose the underlying model.
    • Proprietary: a hosted service with terms, not a codebase you can read, fork or self-host.

    Hermes Agent

    Open-source agent software you run yourself

    • Open-source (MIT-licensed) software from Nous Research that installs on your own Apple-silicon Mac, Windows or Linux machine; settings and secrets live in files you own.
    • You choose the model provider, including xAI, or run a local model.
    • You set and maintain the security baseline, the updates and the infrastructure.

    Grok Bot is not Grok inside Hermes

    Using Grok as the model inside a Hermes install gives you Hermes: your computer, your files, your permission rules, with Grok doing the thinking.

    Using Grok Bot gives you xAI's product: a cloud computer run by the vendor, Bots that sign in to your tools, weekly included usage, and the vendor's privacy and approval model. They are different products with different owners of the infrastructure, even though the word Grok appears in both.

    Use Grok with Hermes

    Hermes documents xAI as a supported model provider in two ways: an xAI API key in the Hermes secrets file with xAI chosen in the model selector, or a SuperGrok or X Premium+ subscription sign-in through the OAuth option. Grok then does the thinking inside your own Hermes install, subject to the same context-size floor as any other model. Hermes's own docs note that xAI has rejected some standard SuperGrok sign-ins, so the API key is the fallback.

    That is the route for people who want Grok's model with Hermes's control. The Hermes guide's model-selection section covers choosing a provider in general; the xAI-specific steps live in Hermes's own provider documentation, which that section points to.

    Open the Hermes Agent guide

    How do I know this landed?

    Nothing to install yet. Answer these out loud:

    1. Which of the three is a model, which is a hosted product, and which is software you run yourself?
    2. If you want a Bot that keeps working after you close your laptop without hosting anything, which one is that?
    3. If you want to choose the model, run it locally and keep every file on your own machine, which one is that?

    Answers: Grok is the model; Grok Bot is the hosted product; Hermes is the software you run. The always-on hosted Bot is Grok Bot. Local models and your own files are Hermes.

    Choose your agent route

    Open-source and configurable, or managed and simpler?

    Both routes end in a working agent. They differ in who runs the computer and how much you configure yourself. Keep the names apart: Grok is a model, which you can plug into Hermes; Grok Bot is xAI’s managed agent product. Realtors who want the shortest path usually start with Grok Bot; those who want to own the setup start with Hermes.

    Open-source agent environment

    Hermes Agent

    Installs on your own computer. You choose the model (Grok, Claude, Gemini and others), can run local models, and own the settings, secrets and permission rules. More control and more configuration, with a security baseline you set on purpose.

    Managed agent product

    Grok Bot

    A proprietary product from xAI, delivered through Cursor, with its own cloud computer that keeps working when your laptop is closed. Sign in, create a Bot, connect a tool. Simpler to start and less to maintain, with less to configure.

    You are here: continue below

    Neither route is the better answer for everyone. Pick by how much simplicity, control and technical comfort you want, and switch later if you like; nothing about one stops the other.

    You may stop at WORKING GROKBOT

    WORKING GROKBOT is a complete, finished outcome, not a trial. Everything past it (routines that run on a schedule, more Bots, team use, your phone) is optional and separately reversible. Finishing section 7 and closing the laptop is a success. Treat it as one.

    Plans and included usage change

    Grok Bot requires an eligible paid plan. Eligibility and included usage can change, so check the current official access and pricing page before subscribing. At the time of checking (5 September 2026) the eligible plans were Cursor Pro, Pro+ and Ultra, any seat on a self-serve Cursor Teams plan, SuperGrok, SuperGrok Plus and SuperGrok Heavy, and X Premium+ through account linking; SuperGrok Lite and the free tiers do not include it. Entry prices were Cursor Pro at $20 a month, SuperGrok at $30 a month and Cursor Teams Standard at $40 per seat a month, with higher tiers including more weekly usage. A one-time free trial credit is offered. Some official documentation pages still show an older, narrower list, which is one more reason to check before you pay.

    Check the current official Grok Bot page for plans and pricing (opens in a new tab)

    Choose your route

    Grok Bot or Hermes: how the two routes differ

    Neither route is the winner. They answer different questions about who runs the computer, who chooses the model, and how much you want to maintain. Read the row that matters most to you first.

    Open source
    GrokBotNo. A proprietary hosted service; there is no public code to read, fork or self-host.
    HermesYes. Open-source software you install; the code and the configuration files are yours to inspect.
    Proprietary or managed
    GrokBotFully managed by the vendor, from the app to the cloud computer.
    HermesSelf-managed. You install, configure and update it.
    Hosting
    GrokBotA dedicated cloud computer per account, hosted by Cursor in the United States at the time of checking.
    HermesYour own Apple-silicon Mac, Windows or Linux machine, or a server you choose.
    Setup difficulty
    GrokBotLow: install an app, sign in, create a Bot. An afternoon for most people.
    HermesModerate: a terminal install, a model connection, then a security baseline you set on purpose.
    Technical skill required
    GrokBotComfortable with apps and account sign-ins.
    HermesComfortable with a terminal, a settings file and reading an installer before running it.
    Local model capability
    GrokBotNo. The model runs at the provider and is chosen for you.
    HermesYes, optionally, on suitable hardware.
    Model and provider flexibility
    GrokBotNone at the time of checking: you cannot pick the underlying model.
    HermesHigh: choose among supported providers, including xAI, or a local model.
    Managed cloud computer
    GrokBotIncluded: a persistent computer with browser, terminal and files, shared by all Bots on the account.
    HermesNot included. The agent uses the machine you install it on.
    Always-on and background operation
    GrokBotYes by design, within your weekly usage. Work continues when your laptop or phone is closed; idle computers hibernate and resume, and routines can be paused after a long absence until you confirm them.
    HermesOnly if you set it up. An always-on service is an Advanced topic with its own security rules.
    Tool and browser access
    GrokBotPlugins (connectors) for common services plus a cloud browser that can use sites without an API; you take over for passwords, passkeys, two-factor codes, security checks and payments.
    HermesTools you connect yourself; a browser connection is an optional Go further item.
    Scheduling and routines
    GrokBotBuilt in: routines on a timetable or triggered by events, running in the cloud.
    HermesPossible through scheduled operation, an Advanced topic.
    Mobile access
    GrokBotOfficial iPhone and Android apps, with iPad added in early September 2026; some routine controls still need the desktop app.
    HermesThrough a messaging gateway such as Telegram, an optional Go further item.
    Privacy and control
    GrokBotDepends on the vendor's cloud environment, your Privacy Mode setting, the accounts you connect and current policies.
    HermesDepends on the models and providers you choose, your connectors, your configuration and whether inference is local or cloud.
    Maintenance responsibility
    GrokBotThe vendor updates the app, the computer and the models.
    HermesYou run updates and re-check the security baseline after each one.
    Cost model
    GrokBotAn eligible paid plan with weekly included usage; usage beyond that draws on your Cursor account's on-demand spend where enabled.
    HermesThe software is free; you pay a model provider for usage, or run a local model.
    Required membership
    GrokBotYes: an eligible Cursor, SuperGrok or linked X Premium+ plan at the time of checking. Check the official page.
    HermesNone. A provider account or a local model is all it needs.
    Best-fit learner
    GrokBotYou want the shortest path from sign-up to a working agent and are happy to let the vendor run the infrastructure.
    HermesYou want ownership: open source, local models, provider choice and deeper control.

    GrokBot fits you if you prioritise

    • easier setup
    • managed infrastructure
    • an included cloud computer for the agent
    • less technical maintenance
    • the fastest path from sign-up to a working agent

    Hermes fits you if you prioritise

    • open source
    • self-hosting or local operation
    • local models
    • model and provider flexibility
    • deeper configuration and control
    • owning more of the infrastructure

    Both guides are free and neither is a sales page for the other. If you are still unsure, run the shorter one first: a working Grok Bot takes an afternoon, and nothing about it stops you setting up Hermes later.

    Section 1CHECK

    1 · Check your plan

    Goal

    Confirm you have, or will get, a plan that includes Grok Bot before you install anything, so the first sign-in ends in a working app rather than a paywall.

    Prerequisites

    • An idea of what you already pay for: a Cursor plan, a SuperGrok subscription, X Premium+, or none of these.
    • Ten minutes and the official Grok Bot page open in a browser tab.

    Exact user action

    Grok Bot is included with eligible paid plans rather than sold on its own. Work out which of the three plan families you are in, then confirm on the official page that your tier is still listed.

    1. Step 1: Open the official Grok Bot page (the button in the callout above this section) and find its plan and pricing section.

      At the time of checking the entry points were Cursor Pro ($20 a month), SuperGrok ($30 a month) and Cursor Teams Standard ($40 per seat a month); higher tiers in each family include more weekly usage. SuperGrok Lite and the free tiers do not include Grok Bot.

    2. Step 2: If you already have a Cursor plan (Pro, Pro+, Ultra or a Teams seat), you are eligible through that account. Nothing more to buy.

    3. Step 3: If you already have SuperGrok, SuperGrok Plus, SuperGrok Heavy or X Premium+, note that these are linked to a Cursor account to grant usage; the Team and Enterprise SuperGrok plans cannot be linked. You will create or reuse a Cursor account in section 3.

    4. Step 4: If you have none of these, decide which family fits: a Cursor plan if you might also use Cursor's coding tools, SuperGrok if you already live in the Grok app. Do not buy yet; the app offers a free trial credit first.

    5. Step 5: Write down which account will hold Grok Bot. A SuperGrok or X link is permanent and pairs one Cursor account with one Grok or X account, so the choice is hard to undo.

    Included Grok Bot usage is its own weekly pool, separate from your normal Grok or Cursor usage, and the official pages describe tiers only relatively (higher tiers get more) without numbers. Once the weekly pool is used, further Bot work draws on your Cursor account's shared on-demand spend if that is enabled, so a plan is a ceiling on included work, not a flat fee for unlimited work.

    Where

    The official Grok Bot page now, and the plan screen inside the app later. Cursor plans are managed at cursor.com; SuperGrok in the Grok app.

    Expect to see

    A plan name that appears on the official eligibility list, or a decision to start on the free trial credit and buy afterwards.

    Save / apply

    Nothing to save on a computer. Keep the note about which account will own Grok Bot; you need it in section 3.

    Verify success

    Before moving on, say these out loud:

    1. My plan family is Cursor, SuperGrok or X Premium+, or I am starting on the trial credit.
    2. I know which single account will own Grok Bot and the link.
    3. I have seen today's eligibility list on the official page, not a screenshot from a post.

    Common friction

    Security / privacy

    What this step exposes

    Plan choice is also an identity choice: the account that owns Grok Bot owns the cloud computer, every login the Bots make, and the files they keep. If you will run Bots for your own business and for a client, plan on separate accounts from the start; section 7 explains why.

    Next safe step

    Nothing is installed yet and nothing has been paid for. Continue to section 2 to install the app.

    Safe to stop here

    How do I know this worked?

    • I can name my plan family and whether it is on today's official list.
    • I know which account will own Grok Bot and that a SuperGrok or X link is permanent.
    • I know included usage resets weekly and is separate from other Grok or Cursor usage.

    If any line is untrue, go back to Verify success and then Common friction above before continuing.

    Not yet verified3 details this guide will not guess at
    • The exact weekly included usage per plan is described only in relative terms (higher tiers get more) on the official pages, so this guide does not quote numbers.
    • X Premium+ appears as a linkable subscription on Cursor's help pages and X's Premium help page, but not on xAI's own eligibility lists; this guide follows the Cursor help wording.
    • If one account holds both a Cursor plan and a linked SuperGrok, one official page says Grok Bot uses whichever has more usage; the others do not say. This guide does not promise that the two add up.
    Section 2ACCESS

    2 · Install or open the app

    Goal

    Get the Grok Bot app onto the device you will use, downloaded from the official source and nowhere else.

    Prerequisites

    • A Mac (Apple silicon or Intel), a Windows PC (x64; Arm64 builds are listed in the docs), or a Linux machine (.deb, .rpm or AppImage builds); or an iPhone on iOS 18 or newer (iPad support was added to the iOS app in early September 2026), or an Android phone on Android 9 or newer.
    • Permission to install apps on that device.

    Exact user action

    Grok Bot is an app, not a command-line tool. Desktop is the best place to start because the computer view is easier to follow on a large screen; the phone app is for checking in later.

    1. Step 1: Desktop: open the official Grok Bot page and choose the download for your operating system; the More downloads panel lists the other platforms.

      The same builds are served from Cursor's official download page. Do not use a third-party download site.

    2. Step 2: macOS: open the downloaded file, drag Grok Bot into Applications, then open it and accept the system prompt that asks whether you want to open an app downloaded from the internet.

    3. Step 3: Windows: run the installer and follow its prompts. Linux: install the package for your distribution, or run the AppImage.

    4. Step 4: Phone or tablet: install Grok Bot from the App Store or Google Play and open it. The listing is published under xAI's company names (you may see SpaceXAI, X.AI Corp. or X Corp.), and its support and terms links point to cursor.com.

    5. Step 5: Open the app. Stop at the Get started screen; signing in is the next section.

    The app updates itself after installation, so you will not repeat this section for new versions.

    Where

    Your own computer or phone. Nothing is installed on a server: the cloud computer that Bots use is created for your account by the vendor after you sign in.

    Expect to see

    A Grok Bot window (or app screen) showing a Get started or sign-in button, and nothing asking for an API key.

    Save / apply

    Nothing to configure. The installer places the app; settings live in your account, not in local files you need to manage.

    Verify success

    The app is installed when:

    1. Grok Bot opens from Applications, the Start menu or your phone's home screen.
    2. The first screen offers Get started or sign-in rather than an error.

    Common friction

    Security / privacy

    What this step exposes

    Download only from the official page or the official app stores. An installer from anywhere else is the easiest way to hand a stranger a foothold on a machine that will soon sign in to your tools.

    Next safe step

    The app is on your device but nothing is signed in. Continue to section 3.

    Safe to stop, but unproven

    How do I know this worked?

    • The app opens on my device and shows Get started or a sign-in button.
    • I downloaded it from the official page or the official store, nowhere else.
    • I know the app updates itself and that the Bots' computer lives in the vendor's cloud, not on this device.

    If any line is untrue, go back to Verify success and then Common friction above before continuing.

    Not yet verified2 details this guide will not guess at
    • Windows Arm64 builds and Android tablets are listed on some official pages and not others; this guide does not promise either.
    • iPad support arrived in the iOS app in early September 2026 and is listed on the App Store and the official downloads panel, but xAI's own documentation still describes the app as phone-only.
    Section 3ACCESS

    3 · Sign in and attach your plan

    Goal

    Sign in with the one account you chose in section 1, and make sure the app can see a plan with Grok Bot usage on it.

    Prerequisites

    • Section 1 decided: which account owns Grok Bot.
    • A browser on the same device; sign-in completes in the browser and returns you to the app.

    Exact user action

    There is no separate Grok Bot login. The app uses a Cursor account, and a SuperGrok or X Premium+ subscription is attached to that Cursor account by linking it from the plan screen.

    1. Step 1: Choose Get started (desktop) or Login with Cursor (phone). A browser tab opens for authentication; it may also offer Sign in with Grok, which still ends in a Cursor account.

    2. Step 2: Sign in to the Cursor account that should own Grok Bot, or create one. Organizations that use single sign-on with Cursor sign in the same way.

    3. Step 3: Return to the app when the browser confirms sign-in. On desktop it usually switches back on its own.

    4. Step 4: Open the plan screen (Plans and billing, or the plan prompt during onboarding). If you have a Cursor plan, it is already applied.

    5. Step 5: If you have SuperGrok or X Premium+, choose Link Grok Account or Link X Account (offered on the Get started screen and on the plan screen), sign in to that account, and confirm. The link pairs exactly one Cursor account with one Grok or X account and cannot be moved later.

    6. Step 6: If you have no eligible plan yet, start on the free trial credit and buy after section 5, once a Bot has done real work for you.

    If your Cursor account was set to the older privacy option that keeps all data local (Legacy Privacy Mode), the app asks you to change that setting before continuing; Grok Bot needs to store data in the vendor's cloud to work at all. The current Privacy Mode still keeps your data out of model training.

    Where

    Inside the app and in the browser tab it opens. Cursor account settings live at cursor.com; the link to a Grok or X account is made from the app's plan screen.

    Expect to see

    The app shows your account, your plan name (or the trial), and an invitation to create a Bot. A linked SuperGrok or X Premium+ shows as a usage grant, not as a change to your Cursor plan.

    Save / apply

    Nothing to save by hand. The sign-in and the plan link are stored on your account and follow you to the phone app.

    Verify success

    You are signed in properly when:

    1. The app shows the account name you chose in section 1.
    2. The plan screen names a plan with Grok Bot usage, or the trial credit.
    3. You did not paste a password or a key into any chat box; sign-in happened in the browser.

    Common friction

    Security / privacy

    What this step exposes

    The account you just signed in is now the identity every Bot acts as. Bots have no identity of their own: every action, every website login, every file is attributable to this account. Use a strong password and two-factor authentication on it, and never share the account.

    Next safe step

    Signed in, plan attached, no Bot yet. Continue to section 4.

    Safe to stop, but unproven

    How do I know this worked?

    • The app shows my chosen account and a plan (or the trial) with Grok Bot usage.
    • If I use SuperGrok or X Premium+, the link is made and I understand it is permanent.
    • My Cursor account is on the current Privacy Mode, not the older local-only option, and I know what that means for training.

    If any line is untrue, go back to Verify success and then Common friction above before continuing.

    Not yet verified1 detail this guide will not guess at
    • The exact wording and position of the plan screen inside the app changes between releases; this guide describes the flow, not the pixels.
    Section 4FIRST SUCCESS

    4 · Create your first Bot

    Goal

    Create one Bot with one narrow job, so your first task has a clear owner and a clear finish line.

    Prerequisites

    • Signed in with a plan or trial (section 3).
    • One small, real, harmless job you would like done: a research summary, a weekly digest draft, a tidy-up of a document.

    Exact user action

    A Bot is a named, persistent teammate: it keeps its own conversation and working context, and it uses the account's cloud computer. Onboarding offers suggested teammates; you can also describe your own.

    1. Step 1: Choose Create a Bot, or pick a suggested teammate to edit.

    2. Step 2: Give it a short name and a one-line primary job. One job, not a list; you can create more Bots later.

      Good first jobs are read-mostly: summarize, draft, compare, monitor. Save anything that sends, buys or deletes for after section 7. Some versions of the onboarding also ask for a shape, colour and title; those are cosmetic.

    3. Step 3: Write a few sentences describing how it should work: what to look at, what a good result looks like, and what it must ask you before doing.

    4. Step 4: Finish onboarding. The app opens the Bot's conversation; the account's cloud computer is set up in the background during onboarding and may still be finishing.

    Each Bot is separate in role and conversation, but every Bot on your account shares the same cloud computer, files and website logins. Keep that in mind before you name a Bot after a client.

    Where

    The Bots list inside the app. Bot settings can be edited later from the same place.

    Expect to see

    A new Bot with its own chat, an empty working context, and a computer view that fills once you give it a task.

    Save / apply

    Bot configuration saves automatically to your account and appears on every device you sign in on.

    Verify success

    The Bot exists when:

    1. It appears in the Bots list with the name and job you gave it.
    2. Opening it shows an empty conversation ready for a first message.

    Common friction

    Security / privacy

    What this step exposes

    The description you write is instructions, not a boundary. Approvals for sensitive actions and the account's privacy settings are what actually constrain a Bot; those are section 7. Until then, give it only read-mostly work.

    Next safe step

    A Bot exists but has done nothing. Continue to section 5 for the first real task.

    Safe to stop, but unproven

    How do I know this worked?

    • My first Bot has one name and one narrow job.
    • I know every Bot on my account shares one cloud computer and its logins.
    • I have not asked it to send, buy, post or delete anything yet.

    If any line is untrue, go back to Verify success and then Common friction above before continuing.

    Section 5FIRST SUCCESS

    5 · First success: a real task, checked

    Goal

    Prove the whole chain works: your message reaches a Bot, the Bot works on its cloud computer, and a checkable result comes back.

    Prerequisites

    • A Bot from section 4.
    • A task you can check yourself in under five minutes.

    Exact user action

    Describe the outcome you want in the Bot's chat, as you would to a new colleague. You can steer or stop it at any time by sending another message. Here is a first task that produces something you can verify:

    A first task you can check

    Read the public page at [paste a URL you know well] and give me a five-bullet summary. Do not sign in to anything, do not fill in any form, and do not send anything. Tell me when you are done.
    1. Step 1: Copy the task below into the Bot's chat and send it. Watch the computer view: the Bot opens its cloud browser and works whether you watch or not; closing the app does not stop it.

    2. Step 2: When it reports back, check the result against the page yourself. The test is accuracy, not speed.

    3. Step 3: Send one follow-up that changes the result (a different focus for the summary, say) and confirm the Bot uses the earlier context.

    4. Step 4: Optional: close the laptop for a minute and reopen the app. The conversation and the result are still there; the Bot's computer keeps its files between sessions.

    A Bot proves itself with a result you can check, not with a welcome message. Only the second step of this section is the test.

    Where

    The Bot's conversation and the computer view inside the app. Files the Bot creates live in a shared workspace folder on its cloud computer, not on your device.

    Expect to see

    The Bot narrates what it is doing, opens pages on its own screen, and returns a result in the chat. If it needs something it cannot do (a password, a passkey, a code, a security check, a payment), it stops and asks you to take over rather than guessing.

    Save / apply

    Results stay in the conversation. If you want a file, ask the Bot to save one to the workspace and send it to the chat as an attachment.

    Verify success

    You have a first success when:

    1. The result matches the page you asked about.
    2. A follow-up message changed the result without you repeating the task.
    3. The conversation was still there after closing and reopening the app.

    Common friction

    Security / privacy

    What this step exposes

    Nothing sensitive should have happened here: no logins, no forms, no purchases. If you were tempted to hand it a login to make the task work, that is section 6, and the way to do it is through the app's takeover flow, never by typing a password into the chat.

    Next safe step

    This is not a stopping point. A Bot that works with default settings you have never looked at is the one genuinely unfinished state on this path. Sections 6 and 7 are short.

    Not a stopping point

    How do I know this worked?

    • I checked the result myself and it was right.
    • A follow-up used the earlier context.
    • I saw the Bot ask for a takeover, or I understand that it will for logins and payments.

    If any line is untrue, go back to Verify success and then Common friction above before continuing.

    Section 6CONNECT

    6 · Connect one tool, on purpose

    Goal

    Give a Bot access to exactly one tool you actually use, through the safer of the two available routes, and prove it works.

    Prerequisites

    • A proven Bot (section 5).
    • One tool you use every week, ideally one with a plugin: a calendar, a notes app, an inbox.

    Exact user action

    Bots reach the outside world in two ways. Plugins are structured connectors to services such as email, notes and chat tools; they belong to your account and are shared by all your Bots. Computer use is the Bot operating its cloud browser like a person, which works for sites without a plugin but is less reliable than a connector and needs you to sign it in. Prefer a plugin when one exists.

    1. Step 1: Open Plugins (in Settings, or from the sidebar) and look for the tool. If it is listed, connect it and approve the access request in the browser.

      Connector sign-in happens with the service itself in your browser. The Bot never sees your password, and the connector's access token stays on Cursor's backend rather than on the cloud computer.

    2. Step 2: If there is no plugin, open the computer view and use the takeover control to sign in to the website yourself on the Bot's screen. Complete any two-factor step yourself, then hand control back.

    3. Step 3: Ask the Bot for a read-only task using that tool: list this week's events, summarize unread messages from one sender, find one note.

    4. Step 4: Check the result in the tool yourself.

    If a Bot ever asks you for a password or a code in the chat, do not type it there. The app has a separate secure secret request for this: it masks the value, keeps it out of the transcript and hides it from the model. Use that, or sign in yourself through the takeover control.

    Where

    Settings, then Plugins for connectors; the computer view for browser sign-ins. Both are per account: connecting once makes the tool available to every Bot you own.

    Expect to see

    The plugin shows as connected, or the website shows you signed in on the Bot's screen, and the Bot's next answer contains real data from the tool.

    Save / apply

    Connections persist on your account and on the cloud computer's disk. Browser sign-ins made on the Bot's computer usually stay signed in, though they can drop if the computer is recreated; sign in again through the takeover control if a site asks.

    Verify success

    The tool is connected when:

    1. The plugin is listed as connected, or the site shows as signed in on the Bot's screen.
    2. A read-only task returns data you recognize from the tool.
    3. You never typed a password or a code into the chat.

    Common friction

    Security / privacy

    What this step exposes

    Every connection here widens what an account-level Bot can reach: the same logins are visible to all Bots you own, and the vendor's cloud computer keeps the sessions. Connect one tool, prove it, and only then decide about the next.

    Next safe step

    One tool connected and proven. Continue to section 7 before giving any Bot a task that sends, buys, posts or deletes.

    Not a stopping point

    How do I know this worked?

    • One tool is connected through a plugin or a takeover sign-in, and a read-only task returned real data.
    • I used the secure secret request or the takeover control, never the chat, for anything secret.
    • I know connections are shared by every Bot on my account.

    If any line is untrue, go back to Verify success and then Common friction above before continuing.

    Not yet verified1 detail this guide will not guess at
    • The list of available plugins changes often; this guide does not enumerate it.
    Section 7SECURE

    7 · Set approval and privacy boundaries

    Goal

    Decide on purpose what a Bot must ask before doing, what the vendor may do with your data, and which accounts must stay separate.

    Prerequisites

    • Sections 1 to 6 complete.
    • Fifteen minutes in Settings.

    Exact user action

    Grok Bot ships with sensible defaults for approvals and privacy. The baseline is not changing them blindly; it is looking at each one and knowing what it does. Four moves:

    1. Step 1: Approvals: open the settings for approvals and sensitive actions (the Auto Review controls). Confirm that sensitive actions (sending, purchasing, deleting, sharing outside your account) require your approval, and keep it that way for every Bot that touches money, clients or public channels.

    2. Step 2: Privacy Mode: confirm your Cursor account is on the current Privacy Mode, which keeps your data out of model training. Read the current data-handling page so you know what is stored in the vendor's cloud: files, browser sessions and conversations persist there.

    3. Step 3: Account separation: decide now whether your own business and any client work need separate accounts. All Bots on one account share one computer, one set of logins and one file workspace, so separating identities means separate accounts, not separate Bots.

    4. Step 4: Secrets: agree with yourself never to paste passwords, codes or keys into a chat. Use the secure secret request or the takeover sign-in, and revoke any credential that ever appears in a transcript.

    Routines that run unattended (see Go further) inherit these settings. The official guidance matches ours: keep routines for reports and digests, and keep sending, purchasing, deleting and publishing behind approval.

    Where

    Settings inside the app for approvals and plugins; your Cursor account settings for Privacy Mode and data controls; the official data-handling and security pages for what is stored and for how long.

    Expect to see

    Approval prompts appear the first time a Bot attempts a sensitive action. Privacy Mode shows as on. You have written down which account owns which identity.

    Save / apply

    Settings apply account-wide and immediately; there is no file to edit.

    Verify success

    Prove it, do not assume it:

    1. Ask a Bot to do one clearly sensitive but harmless thing and watch for the approval prompt, then decline it. If you connected an inbox in section 6, drafting and sending a message to yourself is the easiest test; otherwise ask it to delete a file it created on its own computer.
    2. Confirm Privacy Mode is on in your Cursor account settings.
    3. Confirm no second identity shares this account, or that you have created a separate account for it.

    Common friction

    Security / privacy

    What this step exposes

    Bots act as you. An approval you never look at is a decision you made by default, on an account that holds your logins. This section is the difference between a Bot you use and a Bot that uses your accounts.

    Next safe step

    That is the security baseline. If every checklist on this page is complete, you have a WORKING GROKBOT.

    Finish line

    How do I know this worked?

    • A sensitive action prompted for approval and I declined it.
    • Privacy Mode is on and I know what the vendor stores.
    • Each identity I care about has its own account, or I have kept it off Grok Bot.
    • I know where secrets go, and where they never go.

    If any line is untrue, go back to Verify success and then Common friction above before continuing.

    Not yet verified3 details this guide will not guess at
    • The exact list of actions that require approval is maintained on the official approvals page and changes; this guide does not reproduce it.
    • Data retention periods for individual accounts follow Cursor's general terms and this guide does not quote a number; Cursor's help pages do say that deleting the Cursor account removes the Grok Bot data within 30 days.
    • Marketing pages say each Bot has its own cloud computer, while the documentation says every Bot on an account shares one computer with its own screen. This guide follows the documentation, because it is the version that affects your logins.

    Milestone

    WORKING GROKBOT

    If the checklists in all seven sections are complete, you have a WORKING GROKBOT:

    • Installed from the official source on a device you control.
    • Signed in with one deliberately chosen account, on a plan or trial with Grok Bot usage.
    • A first Bot with one narrow job, proven with a result you checked yourself.
    • One tool connected on purpose, through a plugin or a takeover sign-in.
    • Approvals, Privacy Mode and account separation looked at and decided, not left to default.

    That is the finish line, not a checkpoint. Everything below is optional.

    Keeping it working

    • The app updates itself; the vendor updates the cloud computer and the models. Your job after an update is to re-check approvals and Privacy Mode, because defaults can change.
    • Usage resets weekly. If a Bot stops mid-task near the end of a week, check the usage screen before assuming a fault.
    • Idle computers hibernate. The first task after a quiet spell is slower to start; that is not a failure. After a long absence Grok Bot may ask whether to keep your routines running and pause them if you do not answer, so check for paused routines when you return.

    Nothing here requires a purchase from us. Grok Bot needs an eligible plan from its vendor, and that vendor's terms and bills are between you and them. Read both.

    Optional · after WORKING GROKBOT

    Go further: what do you want your Bot to do next?

    Optional, orderless, one at a time. Each item widens what your Bots can do; re-read section 7 after each one.

    Rules that apply to every item

    Add one capability, prove it, then decide about the next.

    Anything unattended (routines, event triggers) runs with the approvals you set in section 7. Set them first.

    A Bot that acts for a second identity needs a second account, not a second Bot.

    Routines on a schedule

    Verified

    A Bot runs a workflow every morning, or when something happens.

    Routines bind one workflow to one Bot on a timetable or, where an integration supports it, after an event such as a message. They run in the cloud with the laptop closed. Limits and event sources are listed on the official routines page.

    Teach a task by demonstration

    Verified

    Show a Bot a browser workflow once and let it save the steps.

    Recording a workflow on the Bot's screen produces a draft skill that you review and test before scheduling it as a routine. A test run does real work, so keep the demonstration short and read the draft before it runs.

    The cloud computer, in depth

    Verified

    Know what the Bots' computer is and what it keeps.

    One dedicated Linux computer per account, with a browser, a terminal and a workspace folder that persists between sessions. Resetting it can lose recent or unsynced work, and the official pages describe the reset differently, so read the current page before you use it.

    More plugins and browser connections

    Verified

    Reach the rest of your tools.

    Plugins for services with connectors, the cloud browser for everything else, and private networks for internal tools on Enterprise plans. Prefer plugins; expect to take over for logins.

    Several Bots and group chats

    Verified

    Split work across named teammates that can talk to each other.

    Bots can be grouped so they hand work between themselves. Remember that they share one computer and one set of logins on your account.

    Grok Bot on your phone

    Verified

    Check in, approve, and start tasks from anywhere.

    The iPhone and Android apps use the same account, and iPad support arrived in early September 2026; work continues in the cloud when the app is closed. Editing, testing and deleting routines still need the desktop app.

    Team use

    Verified

    Give each person on a team their own Bots and computer.

    Team plans give every member Grok Bot with per-person isolation; enterprise plans add admin controls. Access comes from the team's plan, not from sharing one login.

    Sharing a Bot's setup

    Verified

    Hand a colleague a copy of a Bot's configuration.

    Sharing copies the Bot's configuration to their account; it never shares your computer or logins. Share links can be public, so read what a link exposes (skills, routines and identity text) before sending one.

    Account separation

    Verified

    Keep your business and a client's business apart.

    Separate accounts are the only separation the product offers; separate Bots are not. Decide before linking a SuperGrok or X subscription, because links are permanent.

    Grok inside Hermes (a different product)

    Verified

    Use the Grok model with the Hermes agent you run yourself. This is not a Grok Bot feature.

    Hermes supports xAI as a model provider by API key or by SuperGrok and X Premium+ sign-in. That is the Hermes guide's territory: your computer, your files, your rules, with Grok doing the thinking.

    Items marked Verified are described on the official pages at the time of checking. Each becomes its own short guide as we test it.

    Read before connecting anything that matters

    Privacy and control: where the boundaries sit

    Neither route is private or exposed by itself. What differs is who controls each boundary, and therefore what you have to check and where.

    GrokBot privacy depends on

    • The managed cloud environment: your Bots' files, browser sessions and conversations are stored in the vendor's cloud, on a computer hosted by Cursor in the United States at the time of checking. Cursor's separate data-residency program does not cover Grok Bot by default.
    • The accounts and tools you connect: every login and plugin is shared by all Bots on the account.
    • The vendor's storage and processing policies: Privacy Mode governs training use, retention follows Cursor's terms, Cursor chooses which model serves each request, and the official security page says model providers do not keep prompts or outputs, though flagged content may be kept for safety review and Cursor's wider privacy pages note that a few models sit outside those retention agreements.
    • The current product configuration: approvals for sensitive actions and the privacy settings you looked at in section 7.

    Hermes privacy depends on

    • The models and providers you choose: a cloud provider sees what you send it; a local model does not leave your machine.
    • The connectors you add: an inbox or a browser profile is only as exposed as you make it.
    • Your configuration: approvals, deny rules and the write boundary are yours to set and yours to maintain.
    • Whether inference is local or cloud, which you decide per model.

    Keep your clients' accounts separate

    All Bots on a Grok Bot account share one computer, one set of logins and one workspace, and every action is attributable to the signed-in account. If you act for a client, or run a second business, that separation needs a second account. The official pages state this plainly; this guide repeats it because it is the boundary most people discover after the fact.

    Another route

    Want open-source and local-model control?

    Hermes Agent runs on your own computer, lets you choose the model provider (including xAI) or run a local model, and keeps the settings, secrets and permission rules in files you own. It takes longer to set up and you maintain it yourself.

    Explore the Hermes Agent guide

    About this guide

    This guide is based on the current official Grok Bot documentation and pricing pages, checked on 5 September 2026, and is updated as the product evolves. Where official pages disagree or a detail still needs verification, we say so clearly rather than presenting it as settled fact.