‹ Academy

If you are a bot, GET /api/academy/how-to-connect-plugins-to-grok-bot and /academy/how-to-connect-plugins-to-grok-bot.md.

How to connect plugins and apps to Grok Bot safely

Aug 31, 2026 · Free to read

A blue jelly and fuzzy lavender cloud connect three glowing portals while checking a golden approval shield.

Open Plugins in Grok Bot, find the service, add it, finish authorization in the provider's browser page, and confirm it appears under Installed. The connection belongs to the account used to sign in to Grok Bot, so check the provider account, workspace, and permissions before approving access.

This page was checked against Cursor's Connect plugins guide, xAI's getting-started guide, and xAI's security guide on August 31, 2026.

How do I add a Grok Bot plugin?

  • Open Plugins: use the desktop sidebar, follow an in-chat Connect card, or on iPhone open your avatar and choose Plugins.
  • Find the service: browse or search, open the plugin, and choose to add it.
  • Authorize in the browser: sign in to the intended provider account and review the requested access.
  • Return to Grok Bot: if it remains on Waiting for authorization, choose Reopen to bring the provider page back.
  • Verify installation: confirm the plugin appears under Installed before giving a Bot a real task.

For a first check, use one read-only request with an observable answer: find a named email, read one Notion page, or list one Slack channel. “Connected” proves authorization completed; it does not prove every action is available or safe.

What should I check before authorizing?

  • The Grok Bot and provider accounts are the ones you intend to connect.
  • The selected workspace, organization, or tenant is correct.
  • The requested permissions match the one workflow you want to run.
  • A scoped service account or lower-privilege test account is used where the provider supports it.
  • Sending, publishing, purchasing, deleting, permission changes, and production work remain behind approval.

The official security guide recommends connecting only the tools a workflow needs, starting with read-only work and draft outputs, and reviewing installed connectors and active routines regularly.

Where should I enter passwords and API keys?

Finish ordinary provider authentication in the browser yourself. For passwords, passkeys, two-factor codes, CAPTCHAs, and payment confirmations, take control of the Grok Bot computer, complete the sensitive step, and return control.

Do not paste a password or one-time code into chat. If Grok Bot presents a supported secure secret request, enter the value there; xAI says the value is masked, excluded from the transcript, and not shown to the model.

Does installing a plugin mean every Bot can use it?

Plugin connections belong to the signed-in Grok Bot account, not to the wording of one Bot's name. Skills can still require the relevant connection and may need to be enabled for a particular Bot. A separate Bot is not a security boundary: all Bots on the account also share one cloud computer, including its browser sessions and files.

Give each Bot only the job and approval rules it needs. Do not assume that creating another character isolates the connected account.

Why does a plugin say Disabled by team admin?

On Cursor teams, the team administrator controls which marketplace plugins are available. A member cannot repair an administrator-disabled plugin by reinstalling it; the administrator must enable it.

What if authorization fails or the plugin stays disconnected?

First confirm the provider login completed in the browser and use Reopen if Grok Bot is still waiting. Re-add the plugin and finish authorization once more. If it still shows disconnected, record the plugin name, Grok Bot account email, exact error, and the provider account or workspace used before contacting support.

Cursor currently documents some provider-specific incidents, including a Zoom desktop authorization error. Treat those as dated support facts, not permanent compatibility rules or invitations to bypass the provider flow.

Read Which apps actually work with Grok Bot? to record the exact task, path, permissions, date, and result rather than claiming a whole service works.

How do I remove a plugin safely?

Pause routines that depend on it, uninstall the connector in Grok Bot, revoke its authorization in the source service, sign out of any related browser session on the shared computer, and remove sensitive working files. Deleting one Bot does not remove shared sessions or files.

Direct answer: Add the plugin from Grok Bot, authorize the correct provider account, verify one read-only task, keep consequential actions behind approval, and revoke both the connector and provider access when the work ends.

The recipe

Hire the bots this setup runs on.