# Connect Grok

> Add Anectico to Grok as a custom connector and read your evidence from a Grok chat. Read-only through sign-in.

Canonical page: https://anectico.com/docs/agents/connect-grok/


**Implemented from the vendor's documentation dated 2026-10-09. Not yet verified with a real Grok account.**
xAI's pages show no date of their own; 9 October 2026 is the day we read them. The steps below are
the ones xAI documents. We have not run them, and xAI's pages leave several things open. We say which.
The record for every host is on [MCP client compatibility](/docs/reference/mcp-compatibility).

## What you need

- A Grok account.
- An Anectico account. You can create it during the sign-in step below.
- A server address that anyone on the internet can reach. xAI says the server "must be reachable over
  the public internet" and rejects local and private addresses. `https://app.anectico.com/mcp` is public.
- On Grok Business or Enterprise, a team administrator must add the connector first. See below.

## Add Anectico as a custom connector

1. Open `grok.com/connectors`.
2. Select **New Connector**, then **Custom**.
3. Enter the server address `https://app.anectico.com/mcp`.
4. Complete any authentication Grok asks for. For Anectico this is a sign-in window. Sign in, choose the
   workspace, uncheck any permission the chat does not need and select **Approve**.
5. Grok then finds the tools the server offers and makes them available in conversations.

**Grok Business or Enterprise.** xAI says a team administrator must first provision a connector in the
cloud console. The administrator opens `console.x.ai`, chooses the team, then **Grok Business**, then **Connectors**,
selects **Add Connector**, chooses **Other** and enters the address. This needs the Team Read-Write
permission. Members then connect their own accounts at `grok.com/connectors`.

## What works, and what xAI does not say

- **Reading works through sign-in.** Anectico offers read permissions only. You can search for people,
  issues, logs, traces, replays, alerts and incidents, and open the proof page behind an answer.
- **Writing needs a key.** A sign-in never carries a write permission. If you want an agent to change
  something, create a key on purpose with the write permissions it needs and use it where the host
  accepts one (below).
- **How Grok signs in is not documented.** xAI says only "complete any required authentication". It does
  not say how Grok registers itself with a server, which return address it uses, or whether the
  connector form accepts an API key in a header. Anectico supports public clients with PKCE, both
  dynamic registration and client metadata documents, and an API key in a header. We cannot tell you
  which of these the Grok form uses until someone tries it.
- **No limits are published** for the number of tools, for tool annotations, or for the addresses xAI
  calls from, and xAI describes no review for a custom connector.

## Use a key instead of signing in

xAI documents two places where a header can be set. Neither has been run against Anectico.

**The xAI API.** The remote MCP tool takes the parameters `server_url`, `server_label`, `headers` and an
optional list of allowed tool names. Put the key in a header that Anectico reads:

```json
{
  "server_url": "https://app.anectico.com/mcp",
  "server_label": "anectico",
  "headers": { "X-API-Key": "<your key>" }
}
```

Add them to the remote MCP tool entry as xAI's page describes. We have not seen a complete example request, so check xAI's page for the rest.
xAI's page does not say what form its separate `authorization` field sends, and Anectico accepts only
`Authorization: Bearer an_…` or `Authorization: ApiKey an_…`. Use `headers` as above. Keep the key out of source
control.

## Grok Build

[Grok Build](https://x.ai/build) is xAI's terminal agent. Its [MCP documentation](https://docs.x.ai/build/features/mcp-servers)
describes a command and a configuration file:

```bash
grok mcp add --transport http anectico https://app.anectico.com/mcp \
  --header 'Authorization: Bearer ${ANECTICO_API_KEY}'
```

Single quotes keep your shell from filling in the key; Grok Build expands `${ANECTICO_API_KEY}` itself
when it reads its configuration. Without `--header`, a server that needs sign-in opens your browser the
first time you use it. `anectico agent bootstrap` does not write this file; the supported hosts
are listed in [Connect an AI agent with MCP](/docs/agents/connect-mcp).

Create the key with the narrowest permissions the job needs. See [Scope recipes](/docs/agents/scope-recipes).

## Grok Bot

[Grok Bot's team documentation](https://docs.x.ai/grok-bot/teams-and-enterprises)
describes MCP access through workspace connector policies. We read it on 11 October 2026.
Your administrator may need to permit the Anectico server before you can connect it to a Bot.
Use the remote MCP address above and sign in to Anectico when the permitted connection asks.

We have not verified this path with a real Grok Bot account. Grok's chat connector, Grok Build
and Grok Bot are separate clients; a connection in one is not a verification of the others.

## Try it

Ask the chat:

> Search for the most recently active customers and tell me which Anectico tools you used. Do not change anything.

## If it does not connect

| What you see | What to do |
| --- | --- |
| Grok rejects the address | The address must be public HTTPS and end in `/mcp`. A local or private address is refused by Grok. |
| The connector shows as connected but no tools appear | Remove it and add it again, and check the tool list with a question. Other companies report that Grok can show a connector as connected too early. |
| Sign-in never opens, or Grok asks for a client id | Tell us what the form showed. xAI does not document it. |
| An API key is refused | Check that the header is `X-API-Key` and the key is live and unexpired. |
| `WORKSPACE_NOT_READY` on the first question | Your first workspace is still being prepared. Wait a second and ask again. |

To stop Grok's access, revoke the connection under **Agents and keys** in the Console, or run
`anectico auth connections revoke`. See [Revoke an agent's access](/docs/agents/revoke-agent-access).
