AI agents module · Grok Build by xAI

Grok Build, double-isolated on your server

Grok Build by xAI starts with the grok command in a workspace of the AI agents module and reaches its models with your xAI API key. The panel installs it behind two layers of isolation — bubblewrap and Landlock — and checks, before installing, that your server’s kernel really applies Landlock.

2 layers
of isolation: bubblewrap and Landlock
≈5 minutes
until a running agent has the new key
Linux 5.13+
kernel checked before install
01 — features

How the panel fences in Grok Build

The panel’s policy sets Grok’s key, models, telemetry and modes, and it outranks the user’s config, environment variables and command line.

01

Two layers of isolation

Grok restricts itself with Landlock on top of a bubblewrap sandbox. Before installing, the panel checks that the kernel really applies Landlock to the workspace user; if not, the install is rejected and the package is never downloaded.

02

Key swap without a restart

Left to itself, Grok would save the key in ~/.grok/auth.json; with the panel there is no such file, because the agent fetches the key from a local panel socket through a helper. Change or remove the key in the panel and the running agent notices in about 5 minutes, with no session restart.

03

New models arrive with updates

The policy lists the models from the catalogue of the installed package version. A new Grok model arrives when you update the package: Grok never updates on its own, and only the panel’s button changes the version.

04

Telemetry is off by policy

The panel’s policy switches off telemetry, trace upload and the xAI chat proxy. It overrides the user’s config, environment variables and command line, so none of them can be switched back on. Grok itself talks only to api.x.ai; commands the agent runs, such as git, npm or curl, reach the network as usual.

05

No-confirmation mode stays off

The mode that skips confirmations (bypass permissions) is disabled by the panel’s policy, and a workspace user can’t turn it on.

06

Three agents, one session

One server and one tmux session for all three: Grok Build, Claude Code and Codex can work side by side. Remove Grok Build and only its processes stop; the session and the other agents carry on.

02 — connect

Check the kernel, then run grok

Kernel first, then the module, the xAI key and a workspace.

1

Check the server kernel

Grok Build needs Linux 5.13 or newer with Landlock enabled. Older and custom kernels, and containers that filter system calls, won’t do: the panel refuses before the package is even downloaded.

2

Add Grok Build as the AI provider

If BeAdmin isn’t installed yet, install it, then add the AI agents module and tick the Grok Build provider. From there the panel installs the official @xai-official/grok package itself and, if there is no Node.js, that too (version 22 is required).

3

Issue an xAI key

Create an API key in the xAI console (console.x.ai). An xAI account or a SuperGrok or X Premium subscription won’t work: signing in to the account is closed by policy.

4

A workspace and the first grok run

Create a workspace and bind an SSH key and the xAI key to it — for the whole server or for this workspace only. After that the panel’s connection string is all you need: once in the session, type grok.

03 — use cases

What you can do with an agent on a server

From a solo developer to a team: everyone gets a workspace of their own.

From any device

The agent session lives on the server, not on your computer: connect from any device that has an SSH client and your key.

Long-running tasks

Hand the agent a big task and close the laptop: the tmux session keeps running on the server, and you can come back any time.

Teams

A separate workspace for each developer: their own user, their own SSH keys and their own session.

A server in another country

If your AI provider is unavailable in your country, set up the agent on a BeAdmin server where it is available and work with it remotely over SSH.

04 — pricing

Estimate the cost of your workspaces

The price depends on the number of workspaces and AI providers. The longer the billing period, the bigger the discount.

3

From 1 to 100 per server. The first workspace is free.

AI providers per server

From one to three AI providers: Claude Code, Codex and Grok Build.

Billing period
Currency
Your price
/mo

/mo
/mo

The more workspaces you have, the cheaper each additional one gets.

Without a licence you get one workspace and one AI provider. More workspaces and providers need a licence.

The price covers workspaces and AI providers. The API key is your own: we don’t sell tokens.

05 — partners

Don’t have a server with BeAdmin?

Vetted hosting providers with the panel ready out of the box. The module needs a plan with at least 4 GB of RAM, and you can pick a server location where your AI provider is available.

Proven over 15 years in hosting. Your VPS with BeAdmin is ready to go out of the box.

  • Germany
  • Netherlands
  • Sweden
  • Switzerland
  • Spain
  • USA
Select server

European reliability made simple. Launch BeAdmin with your VPS in just one click.

  • Germany
  • Netherlands
  • Sweden
  • Estonia
  • Romania
  • Switzerland
  • Spain
  • United Kingdom
  • USA
Sign up
06 — faq

Frequently asked questions

What people ask about Grok Build: subscription, xAI key, models, kernel, telemetry, other agents and price.

No: the panel’s policy closes signing in to an xAI account, and with it SuperGrok and X Premium subscriptions. The only way in is an xAI API key.

You issue the key in the xAI console at console.x.ai and enter it in the panel for the whole server or for a single workspace. A running agent picks up a replaced or deleted key in about 5 minutes, with no session restart. A key you put in your own config or an environment variable is overridden by the policy. Step by step: the “Where to get a key” section of the API keys article.

The ones in the catalogue of the installed package version: those are what the panel’s policy lists. New ones arrive only with a new package version, and the version changes with a button in the panel. The update steps are described in the article “Managing the module”.

The cause can be the kernel or Node.js. The panel checks that the kernel applies Landlock to the workspace user (Linux 5.13+ is required); old and custom kernels and containers that filter system calls fail the check, and the package is not even downloaded. Another possible cause is Node.js older than 22: the panel won’t touch it and will decline the install.

No. Telemetry, trace upload and the xAI chat proxy are switched off by the panel’s policy, and a user can’t bring them back with a config file, an environment variable or a command-line flag. Grok itself talks only to api.x.ai; the commands the agent runs in the workspace (git, npm, curl) reach the network as usual.

Yes. All three can live on one server in a shared tmux session, and removing Grok Build doesn’t affect the others. The first AI provider, whichever of the three, is free; each further one takes a paid licence unit, and the calculator above does the maths. Tokens aren’t part of that price: the xAI key is yours.

You need Ubuntu (20.04, 22.04, 24.04 or 26.04) or Debian (12 or 13) and at least 4 GB of RAM, as for the whole module. On top of that the kernel needs Landlock (Linux 5.13+), and the panel installs Node.js 22 itself if it is missing.

Give Grok Build a server and an xAI key

Check the kernel, install BeAdmin, paste a key from the xAI console and Grok Build is ready. The first workspace and the first AI provider cost nothing, whichever of the three you pick.