Grok CLI
Operating Grok CLI on workers — sign-in or XAI_API_KEY, the prompt file, the session id, and what it cannot do.
Install
npm install -g @xai-official/grokThe worker looks for grok on the worker user's PATH.
Sign-in
Run grok login once as the worker's user (grok login --device-code on a machine without a browser), or put
XAI_API_KEY in the task's environment profile. Without either a run ends with "Not signed in".
How it runs
grok --prompt-file <file> --output-format streaming-json --always-approve --session-id <uuid> [--model <model>]
- Grok reads the task from the prompt file itself, so nothing of the task is on the command line.
--always-approveapproves every tool call; without it a headless run waits.- The worker assigns each session its id.
streaming-jsonis one session update per line.
Add-on models
Grok CLI cannot use add-on models or providers configured on the worker. When it reaches its limit, the task moves to another compatible agent, or waits, as the fallback policy says.
Sessions
Resume is not claimed for Grok CLI: no resume command could be verified without an account. After a crash, recovery starts a fresh session from the checkpoint.
What was verified
Checked against Grok CLI 1.0.46 on 2026-10-06: its --help, and a real run without credentials through the
worker's session runtime. A task with the vendor's account has not been run.