Operator GuideAuthenticationAgent Authentication

Grok

Register Grok accounts and authorize them for workspaces

Grok profiles use ~/.grok by default. jackin❯ scans that location on first start and imports an account only when it finds credentials in auth.json. Importing an account does not grant it to a workspace.

Register and assign a profile

Complete the agent's login flow on the host, then scan and list the imported accounts:

jackin account scan
jackin account list

To register a specific profile explicitly:

jackin account add grok-work --agent grok --directory ~/.grok
jackin workspace account assign my-app grok-work
jackin workspace account select my-app grok-work --agent grok

For an additional login, select the same directory that your host alias uses. A custom profile stays separate from the default profile. jackin❯ validates credential evidence inside the selected directory before registration.

API-key account

Register a provider key with the masked prompt, then authorize and select it:

jackin account add xai-key --provider xai --api-key
jackin workspace account assign my-app xai-key
jackin workspace account select my-app xai-key --agent grok

Use --secret-ref '$XAI_API_KEY' to reference a host environment variable, or --secret-ref 'op://Work/Grok/api-key' for a 1Password reference. The account stores the reference; jackin❯ resolves it when launching an authorized workspace.

Runtime approvals

jackin❯ launches the grok binary with --always-approve by default (see the entrypoint in the construct image). This lets Grok perform edits and tool calls autonomously without interactive approval prompts inside the jackin❯ container, consistent with the "dangerous"/"yolo" modes used for Claude Code, Codex, Amp, Kimi, and OpenCode.

Plan mode (and other Grok-specific controls) can still be enabled explicitly via role hooks (source.sh / preflight.sh) or by passing flags (e.g. --no-plan is not forced; use --permission-mode plan etc. as needed).

Additional flags (e.g. --sandbox, --rules, --system-prompt-override, --todo-gate) can be passed via role hooks or extra arguments; they are appended after the defaults.

Model selection

If the role manifest declares a model for Grok (under [grok] model = "..."), jackin❯ passes it on the CLI using -m (or --model) for every launch of that agent. This is the mechanism for per-role model overrides (the CapsuleConfig models map feeds agent_model_args, which appends the flag to the entrypoint invocation, so the command becomes grok ... -m <model>).

Models are not written into ~/.grok/config.toml; the CLI flag is used exclusively.

Check workspace access

jackin workspace account list my-app

The account must be assigned and support grok. When several assigned accounts support the same agent, select one explicitly; role-specific selection uses --role <ROLE>. An empty account allowlist forwards no coding-agent credentials.

See Account commands and Agent authentication for the registry and authorization rules.

On this page