2026-08-27 · Reference

Grok Bot Login Failed: Cursor Auth, Eligibility, and Privacy Mode

Cursor took the password, the Grok Bot window came back empty, and the next hour went into reinstalling a Windows build that had already worked.

Grok Bot login failed is that sequence. The binary is fine. Sign-in runs through Cursor, then the product checks whether that Cursor identity may use Grok Bot at all (official troubleshooting). Three facts explain almost every refusal: you signed in with Cursor Hobby or a SuperGrok nobody linked, Legacy Privacy Mode is on, or you completed a personal login while the eligible seat lives on a team SSO identity.

This page is the login error only. Eligibility before you fetch the file is how to download Grok Bot. Which SKU to buy is the cheapest way in. Why the prompt says Cursor at all is the Cursor account explainer. Runtime failures after a roster exists belong on the troubleshooting hub, not here.

Read grok bot login failed as a Cursor identity check

Grok Bot uses Cursor authentication and Cursor account data settings (approvals, security, and privacy). The app is a client. The identity is a Cursor user. The entitlement is a plan name on that user, or a team membership that user belongs to.

A healthy installer proves your OS is on the client list: macOS (Apple silicon and Intel), Windows (x64 and Arm64), Linux (x64 and Arm64), iPhone on iOS 18 or later, iPad on iPadOS 18 or later, and Android 9 or later (FAQ). It does not prove access. An OS below those versions is a platform miss, not grok bot login failed. Read supported platforms if you have no supported desktop. This article assumes the app launched and then refused you.

The check is not "does this laptop belong to a company that pays Cursor." It is whether the Cursor user who just signed in holds a paid Cursor plan (Pro, Pro+, Ultra), a Cursor Teams seat, a linked individual SuperGrok, SuperGrok Plus, SuperGrok Heavy, or X Premium+, or a one-time trial (FAQ, teams and enterprises). Hobby, SuperGrok Lite, and a SuperGrok nobody linked are not that list. Confirm live SKUs on Cursor pricing and xAI pricing before you pay. Prices below were rechecked on 23 September 2026.

SpaceX acquired xAI (announced 2 February 2026) and Anysphere, the company behind Cursor (closed 14 August 2026). They are siblings under one parent, which is why Grok Bot sign-in is a Cursor flow. Eligibility widened on 21 August 2026 (xAI announcement). Launch-week posts that still describe a Mac-only Ultra product are stale.

Keep Grok Bot in the foreground while the browser finishes Cursor auth

Some refusals are a handshake that never closed. Official steps, in this order (troubleshooting): keep Grok Bot open while authentication runs in the browser, confirm the browser shows a successful Cursor sign-in, return to the app manually if it does not regain focus, try Get started or Sign In with Cursor again, then confirm the account has Grok Bot access.

If your organization uses SSO, complete the organization login rather than signing in with a different personal account. Personal Google is not the team identity.

Do not paste a password or a one-time code into ordinary chat if a later screen asks for a site login. That is a website session on the shared computer, not grok bot login failed. Take over the computer and sign that site in yourself. This page stops before that handoff.

If the browser shows a successful Cursor session and the app still has no roster, you have left the handshake. You are now in plan, privacy, or membership. Reinstalling will not promote an identity. A second Windows build from x.ai/bot will not attach you to a team seat.

Match the invoice SKU to the FAQ list before you reinstall

Open the Cursor invoice, or the xAI invoice, and read the plan name. Compare it to the FAQ list before you download a second architecture or file a ticket that says Windows is broken.

Invoice line (checked 23 Sep 2026)On the Grok Bot FAQ listWhat login will do
Cursor Hobby (free)NoSign-in can complete. Access will not.
Cursor Pro at $20Yes. Cheapest paid individual doorSucceeds if privacy and identity also match.
Cursor Pro+ at $60Yes, more weekly usage than ProSucceeds if privacy and identity also match.
Cursor Ultra at $200YesSucceeds. Ultra is not required for the bot.
Cursor TeamsYes, every memberSucceeds only on the member identity that holds the seat.
SuperGrok (individual)Yes, by linkingLink it from the Grok Bot plan screen; it grants usage and is not a Cursor plan
SuperGrok Plus or HeavyYes, by linkingSucceeds once linked to the Cursor user you sign in with.
One-time trialYes, for individualsSucceeds until the meter is gone.

SuperGrok Heavy is on the FAQ list. Its price is not published on a primary page. Do not invent one. On a self-serve Cursor Teams plan every member has Grok Bot, with no Premium seat and no admin request. A Premium seat is not a better bot.

Cursor Hobby is cause one. It is the free plan, and it does not include Grok Bot. The editor can work, the installer can finish, Sign In with Cursor can use this morning's Google account, and the product still refuses. Until September, Cursor Pro at $20 failed the same way; every paid Cursor plan now includes Grok Bot. The check is not "is this person a Cursor customer." It is "is this person on the FAQ list."

Cursor Pro at $20 a month is the cheapest documented paid path for one person. The $40 step from Pro to Pro+ buys more weekly usage, not access. A SuperGrok on your xAI account does nothing for a Hobby login until you link it from the Grok Bot plan screen, and a link is permanent. Do not buy a SuperGrok tier solely to unblock a Cursor editor seat. If you are sampling, start the one-time trial rather than buying Ultra to make login work (free trial, cheapest way in).

Holding both a Cursor subscription and a SuperGrok subscription does not give you two computers. Grok Bot uses whichever entitlement has more usage (FAQ). One persistent cloud computer is assigned to the user, not to a bot (computer and apps). There is no Grok Bot-specific spend cap, only the account-level On-demand monthly limit, and no model picker (cost, spend cap). If the invoice already says Pro, Pro+, Ultra, Teams, a linked SuperGrok, or trial, jump to privacy and SSO.

Treat Legacy Privacy Mode as a hard block no paid seat can buy through

Cause two is a setting, not a SKU. Grok Bot requires cloud data storage. Legacy Privacy Mode is not supported (FAQ, get started). Privacy Mode (Legacy) blocks Grok Bot entirely (teams and enterprises).

If that mode is on, members see "Privacy Mode (Legacy) blocks Grok Bot" and a prompt to ask an admin. Standard privacy modes work. While a member is on a team, the team's privacy mode governs. Members cannot weaken it. Buying Ultra on a personal card does not override a team Legacy setting that still wraps the identity you signed in with.

An error about Legacy Privacy Mode means the account is using a data mode that does not permit Grok Bot's required storage. Update the Cursor account data setting, or contact the organization administrator (troubleshooting). Review the setting from Cursor privacy controls. Confirm the current policy language on Cursor's privacy page rather than treating this article as a contract.

This is the refusal that wastes the most money. The invoice is eligible. The product is still blocked. Check Team Settings for Privacy Mode (Legacy) before the next cart. No Grok Bot plan buys through that toggle.

Turning Legacy off so Grok Bot can start does not isolate Gmail from a research bot. All bots on an account share one persistent cloud computer. Screens are not security boundaries. "Do not use separate Bots as a security boundary" (approvals, security, and privacy). Isolation, once you are in, is the shared computer note and least privilege. Individual accounts and self-serve Teams still have no audit view of Bot actions; Enterprise has audit logs and Action Recording. Do not wait for a log of the login failure inside Grok Bot.

Finish the organization SSO path on the member account that holds the seat

Cause three is membership. Self-serve Cursor Teams seats include Grok Bot. Enterprise access is rolling out. Availability and administrative controls can vary by organization. Contact the Cursor account team for current enterprise access (FAQ). This page will not invent an enterprise SKU.

If the organization requires SSO, complete the normal organization sign-in flow (get started, troubleshooting). Signing in with a different personal account is the documented miss. The studio can pay for Cursor Teams for twenty people. You can still grok bot login failed if the app used the Gmail you created in 2014, the one that holds Cursor Hobby for evening side projects.

Two Cursor users can share a laptop. They do not share an entitlement. The cloud computer is assigned to the user that signed in, not to the Windows device name, not to the company on the invoice.

A related trap: you signed in correctly as a member, and Legacy Privacy Mode still blocks you. That is cause two riding on cause three. You cannot weaken the team's privacy mode from a member seat. Personal Pro+ is a different user. Do not debug plugins until a roster exists. Hosted MCP sign-in tokens stay with Cursor's backend and are never stored on the computer. That is a later connector concern.

Trace Maya's Windows afternoon from a working installer to a $20 invoice

Maya is a product designer. She already pays Cursor Pro at $20 because the editor sits next to her design tools. On 27 August 2026 she wants a bot that pulls public competitor landing pages into a brief she will still art direct herself.

She opens x.ai/bot, downloads the Windows x64 build, and installs it. Sign In with Cursor uses the Google account that already opens the editor. The next screen is a refusal. She searches grok bot login failed and fetches the installer again. Windows is not the problem. The invoice still says Pro at $20. That was the right diagnosis on 27 August. Since September every paid Cursor plan includes Grok Bot, so today the same invoice would let her in, and a refusal would point at Hobby, privacy, or the wrong user.

ClockWhat Maya didWhat that actually proved
14:05Installed the official Windows x64 clientThe OS is supported. Access is not.
14:12Signed in with the Google account from the editorCursor auth can complete on a closed plan.
14:31Opened the Cursor invoicePlan name is Pro, $20, not on the August FAQ list.
14:40Started the one-time trial on that same identityLogin can succeed without buying Ultra.
Next MondayStudio admin adds her to Cursor Teams with Legacy Privacy Mode still onLogin fails again. The error names Privacy Mode, not Windows.
That afternoonAdmin leaves Legacy. Maya signs in with org SSO, not the 2014 GmailCause two and three clear. The $20 Pro side project is a different user.

The Monday failure looks like a regression. The trial worked. Then the studio added the work identity to a team that still uses Legacy Privacy Mode. Org SSO now lands her on the blocked setting. The personal trial is not the studio seat. She picks: personal identity with trial or Pro+, or work identity after an admin leaves Legacy Privacy Mode.

She should not connect studio Figma, Gmail, or analytics to celebrate. Cookies, sessions, files, and CLI credentials stay on the user computer after a bot is deleted. The first job is a public-page brief, closer to Lead Scout than to Inbox Triage.

Split every refusal into plan, privacy, or membership before you touch files

Use the exact text on the screen. Guessing "maybe Windows" is how Maya lost an hour.

What you seeWhich causeWhat will not fix it
Sign-in returns you to an empty product, invoice says HobbyCause one: closed planReinstall, architecture swap, a GitHub zip
Exact text: Privacy Mode (Legacy) blocks Grok BotCause two: Legacy Privacy ModeBuying Ultra, buying Plus, a new laptop
Browser signed into personal Google, studio already pays TeamsCause three: wrong Cursor userCompleting personal auth more thoroughly
Browser never returns, app still on Sign In with CursorHandshake, not a plan missWiping AppData as the first move
Starting your computer, progress still changingSetup, not login failedForce-killing the app mid-image
Computer cannot be reached after a roster existedRuntime. Leave this pageAnother installer

Initial setup can take several minutes. Keep the app open while Starting your computer still changes (troubleshooting). Recover and Update Agent Computer preserve durable files and logins. Reset can lose recent unsynced work. Do not reset to fix login. Exhausted usage is billing after a successful login. There is still no Grok Bot-specific spend cap, only the account-level On-demand monthly limit.

Park the download guide and the troubleshooting hub until this screen clears

Search lumps four jobs onto one query. Keep them apart.

Question in your headPage that owns itWhat this login page will not do
Which file do I fetch, and am I eligible before I fetch it?Download Grok BotWalk the progress bar
Which SKU do I buy once I accept I am on Hobby?Cheapest way inRestate the full shopping order
Why does a bot ask for a code editor account?Cursor account explainerRetell the acquisition chain
The bot is in, and a run is silent, duplicated, or stuckTroubleshooting hub on this siteFifteen runtime failures

What a bot even is, once the roster appears, is the plain explanation. Whether a paid week is worth it is the worth-it page. Those will not unblock Sign In with Cursor.

Do not follow a community "Grok Bot for Linux" wrapper. There is a Linux desktop app as of September 2026 (.deb, .rpm or AppImage). The cloud computer is a managed Linux VM where the bot runs as a non-root user. A wrapper that asks for your Cursor identity is a credential hazard, not a fix.

Write the first charter only after a roster exists

A charter pasted into a product that refused you is a note to yourself. Wait until you can create a bot, then paste a stop line before you connect a mailbox.

Maya's first bot after a successful login is a public-page brief. It never sends, never publishes, never signs into Figma, Gmail, analytics, or a bank. An approval does not reverse work already completed (approvals, security, and privacy). Read approval rules and reversibility before you widen verbs.

Name: Landing Brief
Owner: Maya
Job: Once per weekday, open the five public competitor URLs in the list I
provide. For each URL, write: current headline, primary CTA label, visible
pricing if any, and a one-line change since the last saved snapshot. Save
the brief as a dated file I own. Quote the page. If a page is behind a
login, CAPTCHA, or geo wall, write BLOCKED and stop that row.

Boundary: Never send email, never post, never comment, never create accounts,
never sign into Figma, Gmail, analytics, ads, or banking. Never store
passwords. Never click through a login wall. Never treat another Bot as
isolation. All bots on this account share one computer.

Sources: Public pages only. No authenticated app.
Deliverable: A brief with URLs I can open. Fluency without a URL is a miss.
Review: I read it before any design change. The bot does not ship UI.

That is close to Lead Scout and a read-only Chief of Staff Briefing. Mail Cleanup Assistant, Inbox Triage, Churn Watch, and Standup Scribe wait until the Cursor user on this computer is the one Maya will still want next quarter.

From the phone app (iPhone or Android) you can approve steps and pause or resume a routine, but not edit it. Editing and testing a routine still need the desktop app; the phone can now show run history and delete a routine. Teach-by-demonstration is unavailable on iPhone.

Fail the login on purpose if the Cursor email is not the one on the invoice

Verification has to be able to fail. A green window is not enough, because Maya's editor login was green too.

Check one: the email after Sign In with Cursor matches the eligible invoice or the team member list. If it is the 2014 Gmail and the invoice is the studio domain, sign out and complete organization SSO.

Check two: the plan name on that user is on the FAQ list, or the trial is active. Hobby fails. Start the trial or move to Pro. Reinstalling is not a check.

Check three: Team Settings do not show Privacy Mode (Legacy), or you are not on a team. If members see "Privacy Mode (Legacy) blocks Grok Bot," an admin changes the setting. A second seat does not skip that conversation.

Check four: you can create a bot and see a screen on the computer. If you cannot, you are still in login or setup. Wait out Starting your computer only while progress is changing. Then retry, restart, and check for an app update. Update Agent Computer is for an unreachable computer after you were already in, not for a closed plan.

Check five: you have not signed the shared browser into Gmail, the studio design file host, or a bank. If you already did, every future bot on this user can open that session. Revoke it in that site's account settings. Deleting the bot will not.

If all five pass, grok bot login failed is done. Next is a bounded first charter and the safety checklist before any inbox. Grok Build reading SKILL.md and CLAUDE.md is a different product (Grok Bot versus Grok Build). Do not debug a missing CLAUDE.md as a login error.

Answer the objection that a new binary or a new email is the real fix

The strongest case against this page is practical: wiping the app and making a fresh Cursor user has unblocked people on forums, so the three causes look like over-thinking.

Sometimes a second identity works. The one-time trial is documented per individual. A brand new email can be a new individual who still has a trial. That is not a documented second trial for the same person, and it is a bad SSO workaround. Finance then pays Teams Standard for a member who never signed in, while a personal Gmail holds the bot on a second computer with a second cookie jar the company does not admin.

A new binary works when the old install was not the official client, or when the handshake was stuck and a restart would have been enough. Official desktop path: x.ai/bot. Official phone path: iOS App Store search for Grok Bot on iPhone, iOS 18 or later, or Google Play on Android 9 or later. A second copy of that file will not change Hobby into Pro. A new laptop works when the old machine ran an unsupported OS version. That was no client, not login failed.

The objection wins in one narrow case: the browser completed Cursor auth for user A, and you needed Sign In with Cursor as user B, the member seat. That is cause three, reached with the official handshake, not a factory reset. If the screen names Legacy Privacy Mode, a new email that later joins the same team will hit the same block. Paying Ultra also looks like a fix when the old plan was Hobby on the same user. Ultra is eligible. So is Pro at $20. Check Pro first if the only goal is this login.

Keep Gmail and studio logins off the computer until the identity is known

The dangerous minute is the first success, not the failure. People unblock login and immediately connect mail so the bot feels real. Sessions live on the account computer. Every bot you add later can open that mailbox. Screens will look separate. They are not a boundary.

Gmail guidance is for after you intend to keep this Cursor user. Least privilege is the rule for every connector. Hosted MCP tokens staying on Cursor's backend is the documented exception, not a reason to treat the shared browser as empty.

Maya's studio will want the bot in Figma. Confirm current Figma rules on Figma's own site. This page will not print a third-party feature list as fact. She does not sign the studio design system into a computer she just unlocked with a personal trial she might not keep. Sessions on the trial identity do not migrate to the team identity. Sign out of anything she opened just to test. Deleting the trial bots will not.

Static egress IPs mean some services flag datacenter addresses. That is not grok bot login failed. Take over the screen. Do not paste a one-time code into chat.

End this diagnosis when the error is not a login at all

This page stops at the identity check. It does not own platform shopping beyond "the app launched," SKU shopping beyond "Hobby is closed," or a stuck checkout after you are in.

Enterprise access is rolling out. If org SSO succeeds, Legacy Privacy Mode is off, the seat is Cursor Teams, and it still refuses, that is an account team conversation. Do not take a forum's unpublished Heavy price as a workaround.

iPhone-only users can sign in and still cannot author the way the desktop can. The phone app can pause or resume a routine and approve steps, but not edit one. Missing edit controls after a successful phone sign-in is the mobile surface, not a failed login.

Cursor auth is a product choice, not a crash. Grok Bot versus Claude Cowork and Grok Bot versus ChatGPT Work will not flip Legacy Privacy Mode.

If you contact support, collect Grok Bot version, operating system, the exact error message, whether you are on Legacy Privacy Mode, the plan name on the invoice, whether org SSO was used, and whether retry changed the result. Do not include passwords, one-time codes, or secret values (troubleshooting).

Keep reading: How to Download Grok Bot and Confirm You Are Actually Eligible, The Cheapest Way Into Grok Bot Without Restating Stale Prices, Why Grok Bot Needs a Cursor Account, and How To Get Access.

Frequently Asked Questions

Why does grok bot login failed happen after a clean Windows install?

Because the installer never checks the FAQ list. Windows x64 and Arm64 are supported desktops, so a clean progress bar is the expected result on a closed plan. Sign In with Cursor then evaluates the plan (Hobby is closed), whether any SuperGrok is linked, Legacy Privacy Mode, and whether you used organization SSO or a personal Google account. Reinstalling repeats a step that already succeeded. Open the invoice, read the exact error text, and compare the Cursor user to the member list before you fetch another build from x.ai/bot.

Does upgrading to Cursor Ultra fix Legacy Privacy Mode by itself?

No. Privacy Mode (Legacy) blocks Grok Bot entirely, including on plans that are otherwise eligible. Members see a prompt to ask an admin, and they cannot weaken the team's setting. Ultra includes Grok Bot when privacy allows it. So do Pro, Pro+, Cursor Teams, a linked SuperGrok, SuperGrok Plus or SuperGrok Heavy, and the one-time trial. Change the Cursor data setting, or have an admin leave Legacy Privacy Mode, then sign in again. Confirm the live privacy language in the Cursor dashboard rather than treating a price as an override.

I already use Google to open Cursor. Why is Grok Bot still refusing the same login?

Google on a personal Gmail is not the same as organization SSO onto the member identity that holds the Teams seat. Official troubleshooting says to complete the organization login rather than signing in with a different personal account. The laptop can be the studio's. The invoice can say Cursor Teams. The app can still be looking at the Cursor Hobby user you created for evening work. Sign out, run the org SSO flow, then re-check Legacy Privacy Mode on that team. A second Google password prompt does not merge the two users.

Should I create a new Cursor email when grok bot login failed will not clear?

Only if you are starting a genuine new individual identity and you still have a one-time trial, and you accept a second cloud computer with a second cookie jar. A new email is not a documented second trial for the same person, and it is a poor SSO workaround because finance then pays for a member who never signed in. Prefer the official handshake, the invoice SKU, and an admin change to Legacy Privacy Mode. Reinstall the official client only after those checks, and only from x.ai/bot or the iPhone App Store listing.

Grok Bot Login Failed: Cursor Auth, Eligibility, and Privacy Mode