Grok
Register Grok accounts and authorize them for workspaces
Grok profiles use ~/.grok by default. jackin❯ scans that location on first start and imports an account only when it finds credentials in auth.json. Importing an account does not grant it to a workspace.
Register and assign a profile
Complete the agent's login flow on the host, then scan and list the imported accounts:
jackin account scan
jackin account listTo register a specific profile explicitly:
jackin account add grok-work --agent grok --directory ~/.grok
jackin workspace account assign my-app grok-work
jackin workspace account select my-app grok-work --agent grokFor an additional login, select the same directory that your host alias uses. A custom profile stays separate from the default profile. jackin❯ validates credential evidence inside the selected directory before registration.
API-key account
Register a provider key with the masked prompt, then authorize and select it:
jackin account add xai-key --provider xai --api-key
jackin workspace account assign my-app xai-key
jackin workspace account select my-app xai-key --agent grokUse --secret-ref '$XAI_API_KEY' to reference a host environment variable, or --secret-ref 'op://Work/Grok/api-key' for a 1Password reference. The account stores the reference; jackin❯ resolves it when launching an authorized workspace.
Runtime approvals
jackin❯ launches the grok binary with --always-approve by default (see the entrypoint in the construct image). This lets Grok perform edits and tool calls autonomously without interactive approval prompts inside the jackin❯ container, consistent with the "dangerous"/"yolo" modes used for Claude Code, Codex, Amp, Kimi, and OpenCode.
Plan mode (and other Grok-specific controls) can still be enabled explicitly via role hooks (source.sh / preflight.sh) or by passing flags (e.g. --no-plan is not forced; use --permission-mode plan etc. as needed).
Additional flags (e.g. --sandbox, --rules, --system-prompt-override, --todo-gate) can be passed via role hooks or extra arguments; they are appended after the defaults.
Model selection
If the role manifest declares a model for Grok (under [grok] model = "..."), jackin❯ passes it on the CLI using -m (or --model) for every launch of that agent. This is the mechanism for per-role model overrides (the CapsuleConfig models map feeds agent_model_args, which appends the flag to the entrypoint invocation, so the command becomes grok ... -m <model>).
Models are not written into ~/.grok/config.toml; the CLI flag is used exclusively.
Check workspace access
jackin workspace account list my-appThe account must be assigned and support grok. When several assigned accounts support the same agent, select one explicitly; role-specific selection uses --role <ROLE>. An empty account allowlist forwards no coding-agent credentials.
See Account commands and Agent authentication for the registry and authorization rules.