GROK BOT / use-grok-bot-with-vpn-sso-or-yubikey

Grok Bot

Reach VPN-only work apps from Grok Bot (SSO and YubiKey too)

Reach VPN-only work apps from Grok Bot (SSO and YubiKey too)

Grok Bot’s computer is a cloud machine with its own internet path. Cursor staff (Colin, Sep 1, 2026) stated it cannot join your corporate VPN today. Internal sites that only resolve on the VPN (for example an on-prem Jira) are unreachable from the Bot browser until private-network support lands.

What works on the cloud computer

  1. Public SaaS that loads from a normal browser off the VPN. Example: Atlassian Cloud at yourcompany.atlassian.net. Connect it from the Connectors page, or have the Bot open it and sign in.
  2. SSO / Okta (and similar). When the Bot hits a sign-in page, it pauses and asks you to take over its browser. You complete the identity-provider login yourself. The Bot continues from the signed-in page. Do not paste passwords or one-time codes into chat.
  3. Hardware keys (YubiKey) on macOS and Windows. In Grok Bot Settings, open the Security Key section and turn on Use hardware security keys. Keep the key plugged into your Mac or PC and approve each use. Staff: this works when the target org itself is reachable from the public internet.

If your org also gates logins to corporate network IPs, the same VPN limit applies for cloud-browser sessions.

Reach VPN-only hosts through your own computer

  1. Connect your Mac or Windows PC to the corporate VPN.
  2. In Grok Bot open Settings → General → Agent → Execution on Local Computer.
  3. Set Ask every time (or always-allowed only if you accept that risk).
  4. Approve each local action on the Auto-review card.

Because the command runs on your machine, the Bot can use local CLI tools or APIs that already work on the VPN. Cloud-browser tabs still cannot see VPN-only hostnames.

Do not install a VPN client on the Bot computer

Staff caution: do not ask the Bot to install a VPN client on its own cloud computer. That can knock the computer offline.

If a Bot already did that and you are stuck on Reconnecting to your computer / malformed listAgents, follow When a VPN inside Agent Computer breaks Grok Bot reconnect.

For cloud-computer reachability failures (blank screen, “Can’t reach your computer”), use Fix Grok Bot “Can’t reach your computer”. That path is the app reaching the cloud box, not the box reaching your corporate LAN.

Pitfalls

  • Local execution and cloud browsing are different permission models. A healthy cloud computer with local execution set to Never allowed still cannot hit VPN-only APIs from your PC.
  • Passkeys follow the same takeover pattern as SSO when the site prompts you. Complete the prompt on the handed-over browser session.
  • Staff labeled better private-network support as actively in progress. Until that ships, local execution on a VPN’d PC is the documented path for internal-only hosts.