
Grok Bot
Configure Grok Bot team connector and MCP policy
Configure Grok Bot team connector and MCP policy
Grok Bot inherits your Cursor team’s connector and MCP policy. There is no separate Bot-only plugin list. Official guide: Grok Bot for teams and enterprises → Connector policy / MCP.
Any permitted connector is available to every Bot a member runs. OAuth tokens for hosted MCP stay on Cursor’s connector backend; the Bot invokes tools without holding those tokens on the computer.
Where the controls live
| Control | Where | Notes |
|---|---|---|
| Marketplace require / restrict | Teams Marketplace (Integrations) | Applies to plugins members install |
| MCP Configuration | Team Settings | Global disable, allow/deny lists, member-add toggle |
| MCP allowlist | Enterprise only | Fine-grained server URL allowlist |
| Require Team Network Allowlist | MCP Configuration (with Network Controls) | Server address must also pass the network allowlist |
Self-serve Teams configure marketplace and MCP settings that appear for their plan. The MCP allowlist itself is Enterprise only.
MCP Configuration levers
In Team Settings → MCP Configuration:
- Disable All MCP Commands Globally — turns MCP off for the whole team.
- Allowlist / denylist — which server URLs members may use.
- Members can add their own servers — on or off.
- Require Team Network Allowlist — each server address must also appear on the team network allowlist (pairs with Enterprise Network Controls).
MCP authentication is shared across Cursor and Grok Bot. Sign in once; both surfaces reuse it.
Enable a plugin for the team
- On the team plugins page, enable the plugin and set any required plugin variables/secrets.
- If you use an MCP allowlist, add the plugin’s server URL. The allowlist covers every marketplace the team uses, including the default one.
- Ask the member to restart the Grok Bot app after policy changes.
When a member sees “Disabled by team admin”
The team policy is blocking that server. Enable it in Teams Marketplace, add the URL to the MCP allowlist if you use one, then have the member restart. If a permitted plugin still fails with a vendor-side permission error, check the MCP provider — some vendors restrict endpoints to their own administrators.
Provisioning connectors as mandatory or default-on for members is not available; policy only allows or blocks.
Pitfalls
- There is no Grok Bot–only connector page that overrides Cursor team policy.
- Enterprise Network Controls are separate from this list; recreate or restart a member’s computer after network policy changes so the new allowlist applies.
- “Disabled by team admin” is a policy block, not a broken OAuth token — fix Marketplace / allowlist first.