Free guide · Grok Bot
Grok Bot: info, FAQ, and examples that actually work
Grok Bot is not the Grok model in Cursor’s picker, and it is not a Cloud Agent with a new name. It is a separate Cursor product: named AI teammates on a persistent cloud computer, with a browser, a filesystem, and a terminal of their own. This page is the orientation — what it is, how it differs from the editor, the questions people actually ask, starter prompts you can copy, and the Bot Marketplace: popular listings, how to publish your own, and a slot for Original Pages Bots as they go live.
The short version
- Download the Grok Bot app from the Grok Bot page of the Cursor dashboard. Sign in with your existing Cursor account. There is no separate Grok Bot login — install and first Bot.
- Give the Bot one job, then a task that ends at review. Do not start by letting it send mail or change production — a good first handoff.
- Every Bot on your account shares one computer. Logins and files are not a security boundary between Bots — one computer, many Bots.
- Closing your laptop does not stop the work. The desktop and iPhone apps are thin clients for chat, takeover, and approvals — FAQ.
- The Bot Marketplace is a public catalog of templates. Adding one copies the configuration, not the creator’s computer or logins — marketplace.
New to this product? Ignore the box and start below.
What Grok Bot actually is
Cursor’s own docs put it plainly: Grok Bot gives you Bots you can keep around — teammates with names, jobs, and context that compounds over time. You message a Bot the way you would message a colleague. It takes on multi-step work across apps and websites, keeps you updated in the thread, and comes back when something needs your approval.
The architectural fact that explains most of the product: the Bot does not run inside the Cursor editor, and it does not run on the Mac or Windows machine in front of you. Each user gets a dedicated cloud computer — a managed Linux virtual machine, documented as a Firecracker microVM — with a browser, a filesystem, and a terminal. The desktop app (macOS, Windows, and Linux) and the iPhone app are how you talk to it, watch it, take over the screen, and approve actions.
The name collision that wastes an afternoon: picking Grok 4.6 in Cursor’s model picker uses Grok as the model inside the editor or a Cloud Agent. Opening the Grok Bot app is a different product, with a different computer, a different security model, and no customer-facing model picker. Cursor manages which model Grok Bot uses.
Three things it is not
| Thing | What it is | What Grok Bot is instead |
|---|---|---|
Grok 4.6 in the picker | A Cursor / SpaceXAI model for coding and knowledge work in Desktop, CLI, Cloud Agents, and the SDK. | A named teammate on a persistent computer. Cursor chooses the model; you do not. |
| Cloud Agents | A remote machine that clones your git repo and runs your install script. See repo vs environment. | A standing computer with logins and files that persist. Grok Bot can delegate coding work to Cloud Agents; that spawn is a separate computer under Cloud Agent controls. |
| A workflow builder | Boxes, arrows, and a canvas you maintain. | Setup is a message: create a Bot, describe the job, grant access as it asks. Stable paths become skills and routines. |
Install, sign in, create the first Bot
Official current docs (cursor.com/docs/grok-bot, checked against the get-started page) say access is included with every paid individual Cursor plan and with the Cursor Teams plan, or by linking an individual SuperGrok, SuperGrok Plus, or SuperGrok Heavy subscription. Usage resets weekly; the plan matrix lives on Cursor’s Plans and billing page, not here. Enterprise organisations enable Grok Bot through their account team — there is an organisation-wide switch on the dashboard that self-serve Teams do not get.
Grok Bot needs cloud data storage. Accounts still on Privacy Mode (Legacy) are prompted to switch to Privacy Mode before they can start. That is documented, not a guess.
- Get the installer from the Grok Bot page of the Cursor dashboard — the Download Grok Bot setup row. If you do not have dashboard access, ask an admin for the link.
- The desktop app runs on macOS (Apple silicon and Intel), Windows (x64 and Arm64), and Linux (x64 and Arm64), and checks for updates automatically. The computers the Bots work on still run in Cursor’s cloud — the desktop app is how you talk to that machine, not where the Bot’s filesystem lives.
- Choose Get started and finish authentication in the browser. Grok Bot uses your Cursor account. Company SSO is the same Cursor SSO configuration you already have.
- Create a Bot: a short name, one primary job, and a description of how it should work. A focused Bot builds useful context; a catch-all helper does not. Cursor’s own first example:
Name: Piper
Job: Product performance
Description: Investigate product-performance questions with our
observability tools. Preserve links and screenshots, separate evidence
from hypotheses, and lead with the highest-impact issue. Never change
production settings.On iPhone, install Grok Bot from the App Store (iOS 18 or later) and sign in with the same account. You can message Bots, watch and take over the computer, approve actions, and pause or resume routines. Teaching a workflow by demonstration, editing a routine’s schedule, viewing run history, testing or deleting routines, and updating the computer stay on desktop.
A good first handoff
A strong request states the outcome, the sources that matter, the constraints, the deliverable, and where the Bot should stop for you. Cursor’s five-minute first result, with a document attached:
Summarize this document in five bullets. List every date, decision, and
open question in a separate section, and cite the section for each item.
Don't change the source file.When the Bot hits an app that needs a password or a two-factor code, it hands you the computer. Open Agent Computer, take over, type the secret yourself, and return control. The Bot does not see the password. The signed-in session persists on that cloud computer for later tasks. For supported services you can connect a plugin instead of driving the website.
Cursor’s recommended “real” first job spans a few tools and has a clear finish line:
Pull this week's pipeline review list from our CRM. Skip anyone already in
an active sequence. Research the top five accounts across the web and Slack,
pull the right contacts, draft outreach in my voice, and leave me drafts to
approve by tomorrow morning.Review the result, correct it, name lasting preferences in so many words (“always lead with the table, never the paragraph”), and only then save the path as a skill or a scheduled routine. Keep sending, publishing, purchasing, deletion, and production changes behind approval.
One computer, many Bots — not a security boundary
This is the sentence in the official docs that people skip, and it is the one that matters:
All of your Bots use the same cloud computer. They share files, browser sessions, and app logins. The computer belongs to your account, not to an individual Bot. Treat anything you place on it as available to every Bot you run. Between users, isolation is strict. Between your own Bots, it is not.
Each Bot gets its own screen on that shared machine, so several Bots can drive the browser in parallel. Screens are work surfaces, not sandboxes. If a workload needs its own computer and its own credential set, Cursor’s security FAQ is explicit: give it its own Cursor user.
Durable project files belong in /workspace on that computer, in clear project folders. Deleting a Bot does not wipe the computer’s files or browser sessions — you have to sign out of sites and remove files yourself, and revoke access in the source service.
Your laptop is a different machine. A Bot only runs commands on the local computer when that capability is enabled and you approve it. Cursor’s security page recommends setting local execution to Never unless a Bot has a specific reason to touch local files. Default is per-command approval.
Examples — starter prompts
Official use-case prompts, kept at a review point on purpose. Adapt the sources; do not skip the last line that forbids the consequential action.
Sales outbound
Owns research and review-ready outreach, not sending. Connect CRM, intent sources, and email.
Research the 25 accounts in this CRM view. Score them against our ideal
customer profile and recent intent, identify up to three relevant contacts
per account, and draft email and LinkedIn outreach in the style examples
attached. Skip anyone already in an active sequence. Return a review list;
don't send or enroll anyone.Once the output is reliable, schedule a nightly research routine that still stops at the review list.
Bug reproduction
Owns turning a report into a reproduction pack. Connect the issue tracker and staging — not production customer data. Hand test credentials over securely, not in the chat transcript.
Read this bug report and reproduce it in staging with a fresh test account.
Return exact steps, expected and actual behavior, screenshots, browser and
OS details, and a minimal test case if possible. Don't use production
customer data.Chief of staff digest
Owns a source-linked list of what changed and what needs a decision. Connect Slack, email, calendar, and the planning doc that defines “priority.”
Review activity since yesterday across my approved channels, inbox,
calendar, and meeting notes. Return only items that map to the priorities
in this document. For each item, include the source, why it matters, the
proposed next step, and whether I owe a decision. Don't send messages or
change meetings.Mark what was useful and what was noise, then schedule the digest for a time you can actually read it.
Turn a role into a durable Bot
- Put the job, source systems, output format, and standing boundaries in the Bot’s description.
- Run one real task with a safe scope.
- Correct the result until it is reviewable without you.
- Save the working process as a skill, and test it on a second input.
- Create a routine only after retries and failure cases are defined.
- Keep consequential external actions behind approval.
Cursor also documents teaching a path by demonstration: walk the Bot through a multi-step flow once, save it as a skill, and rerun it on demand or on a schedule. That flow is desktop-only.
Bot Marketplace
The official catalog lives at x.ai/bot/marketplace — currently 69 public Bots · 43 creators · 9 categories. Featured listings from the Grok Bot team sit on From Grok Bot Team. A Lambda fetches that catalog once a day and republishes the popular and latest lists on this page. New templates also appear on the live updates desk.
Cursor’s work-with-Grok-Bot docs call this sharing a Bot: you publish a public link that exposes identity, description, skills, and routines. The recipient opens a preview on x.ai and chooses Add to Grok Bot. That creates a copy on their account. It does not give them your computer, logins, or conversation history. Adding a shared Bot accepts the third-party bot terms shown at that point. Shared Bots are created by other users, not by Cursor or SpaceXAI.
This is not the Cursor editor Marketplace (plugins, skills, MCP for the IDE). A Grok Bot template is a named teammate configuration. Connect your own plugins and sign-ins after you add it. Do not expect the creator’s Ramp, Notion, or GitHub session to travel with the listing.
Popular listings
Team-featured templates first, then the rest of the live catalog order. Descriptions come from the marketplace pages. Open the link before you add anything.
dr eggbot
Designs high-quality Grok Bots. Asks a few preference questions, then creates them with CreateAgent. Coding bots get the poteto-mode bar (one job, unslopped, verified). Non-coding bots get the same tightness: one job,…
Projects Manager
Runs your team's projects from Notion: one row per project, a channel per project, and tasks your specialist bots claim. You decide, agents execute, and it never does the specialist work itself.
Outbound Prospecting
Finds prospects that match your ideal customer, then drafts a first message to each one. Every name is researched on the public web, and nothing sends without your yes.
SEO & AEO Desk
Turns your keywords into content ideas and writer-ready briefs for search and AI answers. Works from a pasted keyword list or your Search Console.
Haggle Bot
Inventories your SaaS spend from Ramp and bills, finds evidence-backed savings (unused seats, duplicates, cheaper alternatives), and drafts vendor counters for your review. Never spends, signs, or sends without you.
Recruiting Coordinator
Schedules interview loops, preps your interviewers, and chases what's stalled. Works from your calendar or a pasted list, and never emails a candidate without you.
Stills & Clips Desk
Pulls stills, thumbnails, and short clips out of your footage, sized for where they go. Cleans up screenshots for docs too, and writes the caption and alt text.
figma bro
Turns a Figma frame into a build spec, and audits your components, tokens, and motion. Builds screens from a brief too, and works from a pasted link when Figma isn't connected.
GTM Loop Closer
Finds promises, follow-ups, and customer details left behind in meetings, email, Slack, CRM, or task tools. Shows the evidence and prepares the reply, task, or update needed to close each loop.
Sales Call Coach
Scores your sales calls and tells you what to fix before the next one. Works from a pasted transcript or an uploaded recording.
Meeting Recap Deck
Turns your meeting notes into a recap deck in your slide template. Works from notes you paste or upload, and never invents a quote.
AI Search Visibility
Checks whether AI assistants and Google recommend you, and who they name instead. Starts from a handful of questions your buyers actually ask.
Latest listings
Bots the daily check has not seen before, plus the marketplace’s current featured row. After the first run, new public templates show up here the next day.
dr eggbot
Designs high-quality Grok Bots. Asks a few preference questions, then creates them with CreateAgent. Coding bots get the poteto-mode bar (one job, unslopped, verified). Non-coding bots get the same tightness: one job,…
Overheard
Watches Reddit, Hacker News, news sites, and X for third-party mentions of your name, brand, and URLs, then sends a short weekday digest when something clears the bar. Stays quiet on dead days and never posts on your…
Tradbot
Watches your personal email and calendar so school forms, bills, and RSVPs don't slip. Drafts the reply, catches the pickup clash, and never sends without you.
Projects Manager
Runs your team's projects from Notion: one row per project, a channel per project, and tasks your specialist bots claim. You decide, agents execute, and it never does the specialist work itself.
Last checked Sep 9, 2026, 06:22 PM UTC. Updated automatically once a day.
Original Pages Bots
Templates we publish ourselves will be listed here. None are live yet. The two reserved rows stay until a Bot has a public marketplace URL; then we replace the placeholder with the real name, description, and link.
Original Pages Bot — slot 1
Reserved listing. When this Bot is public, this row becomes a name, a short job description, and a link to the marketplace page.
Original Pages Bot — slot 2
Reserved listing. Same as slot 1: replace this placeholder when the share link exists, or delete the row if you do not need it.
How to create a Bot for the marketplace
Official steps, combined from Cursor’s “Share a Bot” page and SpaceXAI’s “Create and manage Bots” page:
- Make one job, not a helper. In the Grok Bot app, choose New, then Create new agent. Edit Profile: short name, a title, and a description that states the outcome, the sources, the output, and what the Bot must never do without approval.
- Prove it on a real task with a safe scope. Save the stable method as a skill. Add a routine only after retries and failure cases are defined. Keep send / spend / publish / production changes behind approval — the popular listings all say so on the tin.
- Strip anything you would not put in a public document. The share link exposes identity, description, skills, and routines. Remove API keys, internal URLs, customer data, and personal memories before you copy it. Automatic filtering is not a security boundary.
- Copy the share link from the Bot. Anyone with the URL can view the shared configuration. Preview it in a browser the way a stranger would.
- Recipients need the Grok Bot app to finish Add to Grok Bot. On Teams and Enterprise, admins control whether members can publish templates publicly; Enterprise often starts with public sharing off. If your share flow is blocked, that control is the first place to look.
After someone adds your Bot they still have to connect their own plugins, sign in to their own tools, and turn routines on. A marketplace listing is a starting roster, not a running employee.
FAQ
Does Grok Bot keep working when my laptop is closed?
Yes. Work runs on the cloud computer. Closing the app, the laptop, or the phone does not stop a background turn or a routine.
Can several Bots work at the same time?
Yes. They can reason, use plugins, work with files, and coordinate in parallel. Each Bot gets its own screen; one Bot runs one computer-use task on its screen at a time.
What does a Bot remember?
Stable preferences, role context, and summaries of prior work. Conversations and learned context stay per Bot. Shared files, browser sessions, and direct handoffs move context between Bots. For consequential decisions, ask it to check the current source instead of relying on memory.
Can a Bot use any website?
Many browser-based tools, including services with no plugin. A site can still block automation, expire a session, or require a human step. The Bot is supposed to hand those steps to you rather than work around them. Some services flag datacenter IPs; egress is shared static ranges, not dedicated per-customer IPs.
Which platforms are supported?
Desktop: macOS (Apple silicon and Intel), Windows (x64 and Arm64), and Linux (x64 and Arm64). Mobile: iPhone (iOS 18 or later). The Bot computers themselves run in Cursor’s cloud, in the United States today. Cursor’s US-only data-residency programme does not apply to Grok Bot by default — if a review needs a written residency commitment, that is an account-team conversation, not something this page can invent.
How much does it cost?
Current docs: included with every paid individual Cursor plan and with Cursor Teams, or via an individual SuperGrok account link. Usage resets weekly. See Cursor’s Plans and billing page for the matrix. The August 2026 launch post described a narrower beta (SuperGrok Heavy, Cursor Ultra, Cursor Teams Premium). Where those two disagree, this page follows the current docs page, and says so.
Is this the same as picking Grok in the Cursor editor?
No. Grok 4.6 in the editor is a model. Grok Bot is a product with its own apps and a persistent computer. There is no customer-facing model picker inside Grok Bot.
Do separate Bots isolate secrets from each other?
No. Official wording: do not use separate Bots as a security boundary. One Cursor user, one computer, one pool of sessions.
What does Auto Review actually check?
With enforcement on, an independent review model evaluates shell commands, plugin calls, computer use, automation writes (routines and event triggers), and delegation such as Cloud Agent and subagent launches. It can allow, require approval, or deny. It does not review every side effect — memory writes and most settings changes are called out as uncovered. Each member’s own setting remains the off switch; an organisation-level lock is not available.
Can we run it on-premises?
No. Grok Bot runs only on Cursor-hosted cloud computers. On-premises, inside your own perimeter, and bring-your-own-image are not supported. Cursor does not operate a VPN, tunnel, or private link into your network. Enterprise Team Setup is how you install your own networking client on every team computer if you need private services.
The computer will not finish setup on our network. Why?
A documented TLS-inspecting-gateway failure: something like Zscaler lets api2.cursor.sh through and then inspects or blocks the nested cursorvm.com hostname. Chat may still work; the computer link fails. Cursor’s fix is to allow *.cursorvm.com and *.*.cursorvm.com, exempt them from inspection, and apply that to off-network profiles too.
If we block a plugin, is the website blocked too?
No. Blocking a plugin does not block that service’s website. Connector policy and network policy are separate layers. Closing the website path takes Network Controls, which is Enterprise only. Self-serve Teams default to allow-all and cannot set a destination allowlist.
Is the Bot Marketplace the same as Cursor Marketplace?
No. Cursor Marketplace is plugins and MCP for the editor. The Bot Marketplace at x.ai/bot/marketplace is shareable Grok Bot templates. Adding one copies configuration onto your account and accepts third-party bot terms. It does not import the creator’s computer or credentials.
How do I list a Bot we built?
Create a focused Bot, prove the job, strip secrets, then copy the public share link — how to create a Bot for the marketplace. Original Pages listings belong in Original Pages Bots once that URL exists. Listings live in the marketplace content file so a new Bot is an entry, not a layout change.
How often are marketplace listings refreshed?
Once a day. A Lambda fetches the public catalog, writes popular and latest lists to marketplace.json, and this page swaps them in. Original Pages Bots on this page are hand-maintained and are not overwritten by that job.
What to read next
Browse the Original Pages Bot desk for curated starter jobs with copyable prompts. If the confusion is “the agent cannot see my file,” you are probably on Cloud Agents, not Grok Bot — start with Cursor Cloud Agents: repo vs environment. For the editor, CLI, and where config lives on disk, use Cursor setup that survives updates. Canonical product docs: the Grok Bot overview, get-started, use cases, security FAQ, Teams, and work-with pages on cursor.com/docs/grok-bot, plus the live catalog at x.ai/bot/marketplace.