SealGate

Grok Connectors

What Grok connectors are, which plans include them, and how to add a custom MCP connector so Grok can reach your tools through SealGate.

Grok connectors are how xAI's Grok (the chat at grok.com) reaches tools and data beyond its built-in knowledge. Grok ships with catalog connectors for popular apps and, on its paid tiers, lets you add custom MCP connectors that point at any MCP server. You add SealGate as one of those custom connectors, and Grok can then call whatever tools your gateway exposes, every call governed by SealGate policy and logged.

Like claude.ai and ChatGPT, Grok runs in xAI's cloud, not on your laptop, so you add SealGate to it once, by hand, using SealGate's public gateway URL.

What are Grok connectors?

A connector is Grok's link to an external tool or data source. There are two kinds:

  • Catalog connectors are the ready-made integrations xAI maintains, toggled on from your account.
  • Custom connectors are ones you add yourself by giving Grok the URL of an MCP server. This is how you connect SealGate.

Grok discovers the tools an MCP server exposes and offers them in conversations alongside its built-in and catalog connectors. Because SealGate fronts your whole tool surface, adding it as a single custom connector gives Grok governed access to everything behind the gateway rather than one app at a time.

Custom connectors sit on Grok's paid tiers. Confirm availability on your plan before rolling SealGate out.

How Grok connectors work

When you add a custom connector, Grok connects to the MCP server over streamable HTTP from xAI's cloud, discovers the tools it exposes, and makes them available in chat. With SealGate as the connector, every tool call Grok makes passes through SealGate's policy checks and audit log before it reaches the underlying tool, so you keep runtime control and a record of what the agent did.

Because Grok reaches your MCP server from xAI's cloud, not from your machine, your connection URL must point at SealGate's public gateway (https://mcp.sealgate.ai/...). A localhost URL from the desktop app's local injection will not work for Grok, which rejects server addresses it cannot reach over the public internet.

1. Get your SealGate connection URL

Your personal connection URL embeds your API key. For Grok, append ?client=grok so SealGate tags the session as Grok in the dashboard:

https://mcp.sealgate.ai/mcp/<your-api-key>/?client=grok

The easiest way to get this URL is from the SealGate dashboard: open Settings, find the Api key / MCP URL section, click Get MCP URL, and pick Grok from the list - the dialog gives you a ready-to-copy URL with the ?client=grok tag already appended. (Alternatively, copy the base URL from the SealGate desktop app's Copy MCP URL menu and add ?client=grok yourself.) Treat this URL like a password - anyone with it can call MCP tools as you (subject to your Access Control Levels and policies).

The ?client=grok tag matters beyond the display label - SealGate relies on it to recognize Grok and group its calls into the right session, so always include it.

The host differs per environment - release is mcp.sealgate.ai, and demo/self-hosted deployments use their own gateway host. Always copy the URL from your own desktop app rather than hardcoding the host.

2. Add SealGate as a custom MCP connector in Grok

Custom connectors are configured on your own Grok account, so each user's SealGate traffic is attributed to them - simply have every member add their own connection URL.

  1. Go to grok.com > Connectors (direct link: https://grok.com/connectors).
  2. Click New Connector, then select Custom.
  3. Under Transport, choose Streamable HTTP - SealGate's gateway speaks streamable HTTP.
  4. Paste your full connection URL from step 1 into the Server URL field, including the trailing slash and ?client=grok.
  5. Set Authentication to None. SealGate authenticates via the API key in the URL - no OAuth sign-in or separate header needed.
  6. Save the connector. Grok will connect and discover SealGate's tools.

Because every SealGate connection URL embeds a personal, per-user API key, do not share one connector's URL across a team. Distribute the SealGate desktop app so each member can copy their own connection URL and add it to their own Grok account - that keeps every member's traffic correctly attributed to them in the SealGate dashboard, where admins get org-wide visibility across all of them.

Connect Grok to your messaging apps

The same gateway fronts SealGate's messaging connectors, so Grok can read and send across WhatsApp, iMessage, Telegram, and LinkedIn under the same policy and audit log. All networks: sealgate.ai/connect.

Grok connectors FAQ

Which Grok plans include connectors?

Every Grok account can use xAI's catalog connectors, but custom connectors, the kind you need to add an MCP server like SealGate, are on Grok's paid tiers. Confirm the feature is available on your plan before rolling it out.

How do I add a custom MCP connector in Grok?

Open grok.com > Connectors, click New Connector, choose Custom, set the transport to Streamable HTTP, paste your MCP server URL, and set authentication to None if the server (like SealGate) authenticates through the URL. The full walkthrough for SealGate is in Add SealGate as a custom MCP connector in Grok above.

Do Grok connectors work with a localhost MCP server?

No. Grok connects from xAI's cloud, so it can only reach an MCP server that is available over the public internet. A localhost address will not work. SealGate solves this by exposing your tools through its public gateway (https://mcp.sealgate.ai/...) while the connectors themselves keep running locally.

What can Grok do once SealGate is connected?

Anything the tools behind your gateway allow, within your policies: read and triage your messaging apps, call enterprise MCP servers, and run other connected tools. Because SealGate is a single custom connector in front of everything, one setup governs Grok's access to your whole tool surface.

Is it safe to add SealGate as a custom connector?

The connection URL embeds a personal, per-user API key, so treat it like a password and never share one URL across a team. Every tool call still runs through SealGate's Access Control Levels, policy engine, and audit log, so you keep control of what Grok can do and a record of what it did.