Skip to main content
Grok Bot is xAI’s messenger for AI teammates, launched August 11, 2026. You create several named Bots (a Chief of staff, a Research lead, an Inbox manager), each with a job and its own conversation, and they all work on one persistent cloud computer that is yours. This guide builds that product on Agent37: one instance per user as the shared computer, one set of sessions per Bot, platform crons for each Bot’s routines, and a small callback so a Bot can reach the user first.
Paste this into your coding agent

grok-bot: this guide as a working app

Everything on this page, runnable: a three-pane messenger with a sidebar of Bots, streaming chat per Bot, a team chat with @mentions and handoffs, routines with an Active toggle, test runs and run history, notifications, persona and memory editors, app connections, and an optional live screen you can take over. Express plus vanilla JS, no build step. Clone it, add your key, npm start.

One computer, many Bots

In Grok Bot, every Bot on your account uses the same computer: the same files, browser, terminal, and signed-in apps. Only the conversations, the job, and the Bot’s own context differ. That maps onto Agent37 directly: A Bot is cheap because it is only words: your server keeps a brief per Bot and prepends it to that Bot’s turns, since POST /v1/responses has no system-prompt field. Different Bots are different sessions, so they work at the same time. Like in Grok Bot, Bots are not a security boundary: they share one disk and one set of connected apps, so separate people need separate instances.
1

Create the shared computer

One instance per user, created when they start their computer. The sample asks for the roomier 4 vCPU / 8 GB shape, which a workspace unlocks with its first top-up (before that it answers 403 tier_limit; leave resources out for 2 vCPU / 4 GB). Three fields matter: a budget so the managed LLM answers from the first message, auto_sleep so a computer nobody is using bills disk alone, and a random token in env that the agent later presents when it messages the user.
Every Bot shares this computer’s CPU and memory, so the 4 vCPU / 8 GB shape ($9.34 per month while awake) is the better fit once several Bots work at once; the smallest shape, 2 vCPU / 4 GB, works for trying it out (see Shapes and pricing). credit_micros: 2000000 is $2 of managed-spend headroom shared by all the user’s Bots (see Budgets). env is write-only and fixed at create, so keep only the token’s hash on your side. The 30-minute idle window keeps the computer awake through a long routine; see long requests for why it should outlast your slowest turn.The call returns 201 with status: "running" once the computer is up. Poll GET /v1/health on the instance URL until it answers "healthy": true before the first message (see Health & version).
2

Tell the computer it serves a team

~/.hermes/SOUL.md is the persona every turn loads. On a fresh computer it holds Hermes’ stock voice, so write your own with the Files API. A PUT replaces the whole file with the request body.
The persona explains the team, and it carries two rules the rest of this guide depends on:
SOUL.md (abridged)
The follow-up rule is not decoration: the gateway’s built-in instructions tell the agent it cannot follow up once a response ends, so the persona has to say plainly that it can. The notify script is step 6.
3

Add a Bot

A Bot is a row in your database: a name, a title, a description, a color, and a handle derived from the name that never changes. On create, give it a notes file on the computer, its own memory that survives across conversations. overwrite=false leaves an existing file alone and answers 409 file_exists.
The brief is what makes the Bot. Your server prepends it to the first turn of each of the Bot’s conversations, and a one-line reminder to every later turn:
the brief, prepended server-side
The fixed first and last lines let your UI strip the brief back out when it renders history from GET /v1/sessions/{id}. The agent’s own memory (~/.hermes/memories/) is shared by every Bot on the computer; the notes file is what keeps each Bot’s context its own.
4

Chat with Bots in parallel

Each Bot owns its sessions. On Hermes, a session id the harness has not seen simply starts a new thread under that id, so your server can mint the id, record it on the Bot, and only then send the first turn. Stream every reply with stream: true.
Two Bots are two sessions, and two sessions on one instance run independently: Scout can research while Chief plans your week. One session runs one turn at a time, so a second message to a Bot that is still working answers 409 session_busy with the running reply’s id in error.response_id. Follow that reply with GET /v1/responses/{id}/stream, which replays it from the start and then stays live; the same call reattaches a reply that was running when the page reloaded, found through active_response_id on GET /v1/sessions/{id}.GET /v1/sessions lists at most the 100 most recent Hermes sessions, and every routine run opens a new one, so keep your own record of which session belongs to which Bot rather than rebuilding it from that list.
5

Give each Bot routines

A routine is a platform cron: it wakes a sleeping computer, sends the prompt on a fresh session, and lets the computer sleep again. Put the Bot’s handle at the start of name, which is how your app files each cron under its Bot, and the Bot’s brief at the top of prompt, so the run stays in character.
The routine editor’s controls are one call each:agent: "hermes" names the harness that runs each firing, and every triggered run records the session_id it opened. Bots also schedule themselves: ask Chief to “remind me every weekday at 8:30 to review open pull requests” and it runs agent37 cron add --name "chief: ..." inside the computer, following the brief. That cron lands in the same list, under Chief, and its runs record their sessions too. An instance holds at most 50 crons, shared by all its Bots.
6

Let Bots message you first

Grok Bot’s Bots come back with finished work. Here that is a callback: a small script on the computer posts to your server, which checks the token and shows the user a notification. Write the script once the computer is healthy; it holds your server’s URL, so rewrite it whenever that URL changes.
~/.grokbot/notify.mjs, written by your server
GROKBOT_NOTIFY_TOKEN is the token you planted at create, and AGENT37_INSTANCE_ID is set by the platform in every container. Your endpoint finds the user by instance id and compares hashes before it trusts anything:
node
The routine brief in step 5 ends with this command, so a routine’s test run arrives as a notification from its Bot a minute later. Deliver it however your product reaches people: an in-app list (what the example does), Web Push, email, or a text.
7

Add a team chat with @mentions

Grok Bot’s group chats hold several Bots; you @mention one to hand it work, and Bots hand work to each other. On Agent37 your server is the orchestrator. Give each Bot one extra session for the team chat, forward each mention to it, and post the answer back to the group:
node
Mentions to different Bots run at once, one session each. Queue mentions to the same Bot, since its group session also runs one turn at a time. A hop limit of two lets Chief ask Scout and Scout answer Chief without a loop, and skipping Bots the user already mentioned keeps a Bot from forwarding the user’s own request. Tell each Bot in its group brief to @mention another Bot only when it needs it to do something.
8

Show memory and connect apps

Memory is files too. Hermes keeps what it learns in ~/.hermes/memories/USER.md (about the user) and ~/.hermes/memories/MEMORY.md (everything else), each a list of entries separated by a line holding §. Read them with GET /v1/files/content, and write the whole list back with PUT after the user edits or deletes an entry; new conversations see the change. Each Bot’s ~/bots/<handle>/notes.md gets a plain editor of its own.Connected apps belong to the computer, so every Bot can use them. List the catalog, start a connection, and send the user to the returned link:
Sign-in happens on the app’s own page and the OAuth tokens stay with the managed integration, so no Bot ever sees a password. Open the link in a new tab and point callbackUrl at a plain “you’re connected” page that needs no sign-in, so the return works whichever address the user opened your app on (in local dev, localhost and the tunnel are different sites with different cookies). The tab that opened the link polls the connections list until the account reads ACTIVE. See App integrations for listing and disconnecting accounts.

Watch and take over its computer

In Grok Bot you can watch a Bot work on its computer, and take control when a site needs you: a password, a 2FA code, a CAPTCHA. On Agent37 that is a desktop image with a screen you can stream, plus a short-lived signed URL for it. The example turns it on when DESKTOP_TEMPLATE is set in its .env, and runs exactly as above without it.
1

Build the desktop template

The hermes-vnc-desktop recipe is the stock Hermes image plus a visible Chromium, which the agent’s browser tool drives, and a noVNC server for that screen on port 6901. Build it into a workspace template once. The build runs in the cloud, so you don’t need Docker:
Create each user’s computer from it with the same call as in Create the shared computer, changing only "template": "hermes-vnc-desktop". Everything else on this page works unchanged, because the image is the stock one plus the screen. Add a line to SOUL.md so the Bots use it: the user can watch this computer’s screen and take it over, so when a site needs a login, a 2FA code, or a CAPTCHA, leave the page open, ask the user to take over, and carry on when they are done.
2

Mint a token for each connection

Your server mints a signed URL for port 6901 and hands the browser only a WebSocket URL built from it. The token rides in that URL’s query string, so the connection needs no cookie and works from your own origin: the browser connects straight to the instance from your page, with no proxy.
Treat the token as the keys to the computer:
  • It grants full control. Watching versus controlling is a setting in your page, not a permission: anyone holding the token can connect a VNC client that clicks and types. Mint it only for the computer’s owner.
  • It cannot be revoked, so keep it short. 60 seconds, the minimum, is enough: the token only has to be valid while the socket opens, an open view keeps working after it expires, and every reconnect mints a fresh one.
3

Show the screen, then take over

In the browser, noVNC draws the screen. noVNC is plain ES modules, so the page can import a pinned release straight from a CDN, with no install and no build step. Start in view-only mode; Take over turns view-only off and Give back turns it on again:
The user and the Bots share one browser, so a Bot picks up where the user left off: the page open after a takeover is the one it sees on its next turn.Connect the view only while it is on screen. It streams continuously, close to 1 MB a minute even when nothing on the screen changes, and that traffic counts as activity, so an open view keeps an auto-sleep computer awake. The example closes it when the tab is hidden or the pane is closed, and opens it again when the user comes back; opening the socket wakes a sleeping computer.
On a workspace template, a cron that names no agent records its run’s session_id only once the turn finishes. Name it, "agent": "hermes", and the run links its session from the moment it fires, so you can open a routine while it is still working. The calls in Give each Bot routines already set it, but agent37 cron add has no flag for it, so PATCH the crons a Bot schedules for itself with { "agent": "hermes" }. The example does that when it lists routines. Don’t put the signed URL itself in an iframe on your site: its auth rides a SameSite=Lax cookie, which a cross-site frame does not send. Connecting noVNC to the WebSocket, as above, avoids the cookie altogether.

Worth knowing

  • Bots share everything on the computer. Files, the browser, the terminal, connected apps, and Hermes’ own memory are common to all of a user’s Bots, exactly as in Grok Bot. The per-Bot parts are the sessions, the brief, and the notes file.
  • Cost follows use. With auto_sleep, a computer nobody is using bills its disk alone, and chats and crons wake it. Awake, the 2 vCPU / 4 GB shape is $4.76 per month and 4 vCPU / 8 GB is $9.34 per month, metered per minute (see Billing).
  • Purchases go back to the user. The persona tells every Bot to stop and hand over anything that needs a payment.
  • Routines count per computer. The 50-cron limit is shared by every Bot on the instance.
  • Texting a Bot is its own guide: Text your agent on iMessage.
  • Left out of this guide: approvals before an action, masked secret requests, teach-by-demonstration, voice, Slack event triggers and Team Bots, and sharing Bots.
  • Chat, streaming, and sessions are the standard chat app wiring, and the token-checked callback is the same pattern as the website builder’s publish endpoint.
Not affiliated with xAI.