← All posts

Grok Bot can now log in for you. It never sees the password

2026-09-17 · 4 min read

On Wednesday evening, the Grok Bot account posted a one-line feature note. @bot wrote that Grok Bot can now use 1Password: you share items in a vault, "approve each fill, and the secrets stay in your password manager."

That's the whole post, and it matters because of what Grok Bot is. Since its August beta, each Bot has worked on a persistent cloud computer with a browser, a file system, and a terminal, and it does its work inside your real tools rather than in a chat window. Signing into those tools has been the awkward part.

The problem it fixes

Most of the software a small business runs has no API and no connector. Think of the insurance portal, or the distributor's ordering site. An agent working in those tools has to sign in, and until this week the honest options were typing the password yourself every time or pasting it somewhere you shouldn't.

xAI's own documentation is blunt about the second option: "Do not send a password or one-time code in ordinary chat." The sanctioned route was a takeover, where you grab the Bot's screen, complete the login yourself, and hand control back.

The 1Password route changes that. You share a vault, or specific items in it, with the Bot. When the Bot reaches a login page it asks for the matching credential, you approve that one fill, and 1Password drops the credential into the Bot's browser session so the Bot can keep going. The model never holds the password.

Peter Yang raised the question on launch day. @petergyang wrote in August that the hard problem for Grok Bot is how you get regular users to "trust sharing their credentials and logins with a remote computer." Per-fill approval, with the secret staying in the vault, is xAI's first shipped answer.

The pattern is spreading

xAI didn't invent this. In July, @1Password announced the same arrangement for Claude, with the same claim: Claude can use your stored credentials "without your passwords or one-time codes ever reaching the model, its memory, or Anthropic's systems."

Meta's Muse, which this blog covered on Monday, does its own version with placeholder tokens that get swapped for real secrets at the network edge. So within two months, three consumer agent products have landed on the same rule: the agent gets to use the key, but never gets to hold it.

xAI built the money side the same way. In late August, @bot posted that you approve every spend request and the Bot gets "a secure, single-use card for each payment." Passwords now get the treatment payments already had.

What still breaks

Read xAI's docs before you get excited. All of your Bots share one cloud computer, and "files, browser sessions, and command line credentials on that computer are available across your Bot roster." xAI says it plainly: "Do not use separate Bots as a security boundary." A login you approve for one Bot becomes a session every Bot on your account can use.

Browser-driven work is also brittle in a way API work isn't. The docs say a site "can still block automation, expire a session, or require a human step," and the Bot hands those steps to you rather than working around them. Two-factor codes and CAPTCHAs still need a person.

Spain's data protection agency, meanwhile, said it had received the country's first report of a personal data breach that the affected organization attributes to an AI agent. According to that report, the agent found a way in, altered records, and reached invoice data. The agency's deputy director said attacks backed by AI "have ceased to be a theoretical risk."

My read

Per-fill approval is the right default, and I'd rather see it become boring and universal than see one vendor's version win. What I like most is where the approval happens: in the password manager, not in the chat. The model that just read a stranger's web page is not the thing deciding whether the credential gets used.

The caveat I'd stress to any owner is the shared computer. The 1Password gate protects the password. It doesn't protect the logged-in session that results, and on Grok Bot that session belongs to every Bot you've made. Treat the account as one employee with one set of keys, not a team.

What this means for your business

If you've been waiting to try an agent on tools with no API, this is the feature that makes a safe trial possible. Put the same question to any vendor: does the AI ever see the password, or does it only get to use it? Then ask what happens to the session afterward, and who else can reach it.

Before you hand any agent a vault, know which logins need an agent at all. Much of the repetitive work in a vendor portal is a weekly export a scheduled script could do with a proper API key. New Face Design's free process audit sorts your recurring tasks into what needs an agent, what needs an integration, and what needs nothing. Start here.

08 / Start here

Find your worst bottleneck. Free.

A 20 minute call. We map where your week goes and pick out the first process worth automating. You keep the map either way, and there is no deck to sit through at the end.

Email

pgorski@newfacedesign.com

Phone

+1 (773) 627-2176

Based in

Chicago area

Working with clients everywhere