
Grok Bot
Store secrets securely in Grok Bot
Keep API keys and other credentials out of ordinary chat and ordinary files. After you save a secret, Grok Bot does not show the value again. A blank field later is not proof the secret was deleted. Official guide: Store secrets securely.
Add a secret from a secure card
When a Bot asks for a credential through a secure secret card, type the value in the masked field and choose Save securely. The card should say Saved, then that the value was saved securely and kept private. The value is not written into the chat transcript and is not shown to the model.
If a page asked for the secret, a filled card can say Filled into the page with the note that secret values were never shown to your Bot. If it says Could not fill into the page, the page may have moved; submit a new card when the Bot asks again. The value still was not shown to the Bot.
Add a secret on the Bot
You can also save a secret on the Bot itself:
- Open the Bot and find its Secrets section.
- Choose Add secret.
- Enter an environment variable name, a short description, and the value.
- Choose Save secret.
The description is visible to the Bot. The value is not. Secrets lists the name and description only; it never shows the value again, including in Shell.
Change or replace a value
Saved values are write-only. To change a value, choose Replace, paste the new value, and choose Replace value. You cannot read the old value back. If save fails, the form says the secret was not saved; try again. No secrets yet means this Bot has no saved names, not that a value is hidden on the card.
What Update, Recover, and Reset do
Update, Recover, and Reset remove installed apps and packages on the computer. A secret you typed into a file, a shell profile, or an installed tool can disappear with that. That path is separate from Secrets. If the name is still listed under Secrets, the value is still stored. Shell not printing it does not mean the secret was wiped.
If a name disappears and you did not choose Remove: fully quit Grok Bot and reopen it, check the same Bot on another device signed into the same Cursor account, and choose Try Again if the list errors before you add anything. If the name is still missing everywhere, add it again. Do not park a long-lived copy in a file on the computer. If names keep disappearing after you did not remove them, contact support with your account email and a screenshot of Secrets — never the secret value.
Pitfalls
- Pasting passwords, API keys, or one-time codes into ordinary chat or Shell.
- Typing credentials during Teach a task demonstrations.
- Treating a blank field as proof a secret was deleted.
- Leaving a primary login on the shared computer when every Bot on your account can reach it.