GROK BOT / route-grok-bot-egress-through-your-desktop

Grok Bot

Route Grok Bot egress through your desktop

Turn on Route egress through this desktop when the Grok Bot cloud computer should send its web traffic through the machine in front of you. Destinations then see that desktop's IP address, and the Bot can reach networks available from that device. Official guides: Settings and notifications → Computer, and Connect to private networks → Route through a member's desktop.

When this path fits

Use the desktop route when one member needs access through a network already available from their laptop or workstation — a VPN, office LAN, or IP allowlist that already trusts that device. Prefer it over inventing a second login on the cloud computer when the blocker is simply that shared static egress IPs are not on the allowlist.

Each member controls their own desktop route. The setting applies to one desktop installation. Enterprise admins can remove the option for the whole team with Allow Local Egress on the Grok Bot page of the Cursor dashboard. Team Setup manifests that install a networking client on every hosted computer are a separate Enterprise path — see the private-networks docs when you need fleet-wide Tailscale or Cloudflare Tunnel, not a single-member route.

Turn the route on

  1. Open the Grok Bot desktop app on the machine whose network you want to use.
  2. Open settings from the account menu or with Cmd+, (Windows and Linux use the same settings entry from the account menu).
  3. Open the Computer section.
  4. Turn on Route egress through this desktop.
  5. Ask a Bot to open a hostname or IP that only that desktop network can reach, and confirm the page or service loads.

Leave the desktop online while the Bot needs that path. Closing the laptop or turning the toggle off stops the route. If an Enterprise admin turns off Allow Local Egress, the toggle turns off and locks with a message that your team's admin has turned off local egress; any active route stops within five minutes. Your choice is preserved and takes effect again if the admin re-allows local egress.

What the route does and does not change

  • Web traffic from the Bot computer leaves through the selected desktop's network and IP.
  • The Bot still runs on the cloud computer. Files under /workspace, browser profiles on the computer, and plugins stay where they were.
  • Local execution (Shell on the machine in front of you) is a different control under General → Execution on Local Computer. Routing egress does not by itself grant local Shell.
  • Between users, computers stay isolated. You are only routing your own Bot computer through your own desktop.

For ordinary recovery when the computer is unreachable for other reasons, use the least-destructive order in Update or recover the Grok Bot computer. For VPN, SSO, or security-key issues on the client itself, see Use Grok Bot with VPN, SSO, or YubiKey.

Pitfalls

  • Enabling the toggle on the wrong desktop — only the machine where you flip the switch carries the route.
  • Expecting the route to survive after you quit the desktop app or put the laptop to sleep for a long stretch — bring the desktop back online when the Bot still needs that network.
  • Confusing this with Team Setup networking clients — those install on every Enterprise team computer from a dashboard manifest; this toggle is one member's desktop.
  • Leaving Allow Local Egress off at the admin layer and troubleshooting the client forever — if the toggle is locked, ask the admin before Reset or reinstall.