An AI agent that can only chat can only be wrong on screen. Give it your email and your files, and it can be wrong in your life. That is the upgrade in this guide, and the reason to do it carefully.
In part one we built the agent itself: a name, instructions and a tone. It stopped there and said nothing about connecting apps. This part covers how Grok reaches your calendar, files and own tools, and how to keep that reach small. You need a Grok account and one app to connect. Google Calendar is the easiest.
Tool, connector, MCP: three words in plain English

Tool. A tool is one action the AI can ask for, such as searching the web, running code or looking up a calendar event. SpaceXAI’s tools documentation says tools let Grok do more than generate text, including querying your data and calling your own functions. The Model Context Protocol specification calls tools “model-controlled”: the AI can find and use them on its own, based on your request.
Connector. Grok’s word for a ready-made link to an app. SpaceXAI’s connectors page says connectors let Grok reach your tools and data inside a chat: search email, browse cloud files, check a calendar. There are three kinds. Built-in ones cover Gmail and Google Calendar, Google Drive, OneDrive, Outlook, Teams, SharePoint and Salesforce. A catalogue covers other popular services. Custom ones are servers you bring yourself.
MCP. Model Context Protocol is an open standard for connecting AI apps to outside systems. Its own site compares it to a USB-C port: one standard plug instead of a different cable for every device. Our MCP explainer goes deeper.
Put together: the connector is the plug, tools are what the plug lets Grok do, and MCP is the standard shape of the plug when you build your own.
Step by step: your first safe connection

Start with a read-only job. A calendar summary is useful and low-risk.
- Open the connectors page. Go to grok.com/connectors, click New Connector and choose Google Calendar, as the Gmail and Google Calendar docs describe. SpaceXAI’s launch post gives a second route: on the web, the + button, then Connectors, then + Add connector; on iOS and Android, Settings, then Connectors. Menus move, so if yours differ, follow the docs page.
- Read the Google consent screen before clicking Allow. The docs say Calendar’s base connection is read-only, and event changes are requested only “when write tools are enabled”. The launch post, though, says the Google Workspace connector can read and write. Grok’s own pages describe it two ways, so let the consent screen decide. If it asks to change events and you only want to read, stop there.
- Ask a read-only question. For example: “Using my calendar only, list what I have on Monday and Tuesday. Do not create, change or delete anything.” That sentence is a request. The permission you granted on the consent screen is the lock.
- Check what it did. Compare the answer with your real calendar. Did it touch anything else?
- Know the exit. The docs say you can disconnect from the connectors page, or revoke access at myaccount.google.com/permissions. Do this for anything you stop using.
Google Drive works differently. Its docs list read permissions plus an optional write permission, and say Grok “can only access files that the signed-in Google account has access to”. If you want Grok to see only some files, one practical option is a separate Google account that holds only those files.
Then put the rules in your agent. Part one’s tip about constraints applies here. Add lines such as: “Use a connector only when I ask. Never send, delete or change anything. Tell me which connector you used and what you looked at.” The connector docs do not say whether a connector can be tied to one custom agent or applies to your whole account, so treat it as account-wide until you see otherwise.
Going further: connect your own MCP server
If your data lives somewhere the catalogue does not cover, a custom connector lets you plug in your own MCP server. The connectors docs give three steps: go to grok.com/connectors, click New Connector and select Custom, then enter the server URL and complete any authentication. Grok then discovers the tools that server offers.
Some rules from the docs:
- The server must be reachable on the public internet. Addresses such as localhost, 127.0.0.1, 10.x, 172.16.x and 192.168.x are rejected. For a server on your own machine, the tunnelling page suggests a tunnel such as ngrok or Cloudflare Tunnel. Free tunnel URLs usually change on restart, so you must remove the connector and add it again. The tunnel only gets traffic through; your server’s own sign-in still applies.
- On Grok Business and Enterprise, an admin adds the connector first in console.x.ai (Grok Business, Connectors, + Add Connector, Other).
- If you use the API, the remote MCP docs say that without an allow-list the model gets every tool the server offers. Use
allowed_toolsto name only the read-only ones. The docs also say the OpenAI-stylerequire_approvalsetting is not supported, so the allow-list is your main control there.
A good model to copy is TSN’s look at Flux Cloud’s MCP server: 15 tools, most of which only look, and two that can spend money only when a call carries an explicit confirm flag. Reading by default, acting only on request.
What can go wrong

Too much access. An agent with write power can do damage by honest mistake, not just attack. The MCP specification says there should always be a human in the loop with the ability to deny tool calls.
Prompt injection. OWASP describes indirect prompt injection as what happens when an AI takes input from outside sources such as websites or files, and hidden content in that input changes its behaviour. Your inbox and shared documents are exactly that kind of input. Constructed example, not a real incident: a newsletter contains invisible text telling the assistant to forward your last ten emails to an address. You ask for a summary. If your connector can send mail, the instruction has a path to act. OWASP says it is unclear whether fool-proof prevention exists and recommends least-privilege access plus human approval for high-risk actions. For real-world reports, see our AI agent security roundup.
Untrusted servers. The MCP specification says clients must treat tool annotations, the properties that describe what a tool does, as untrusted unless they come from a trusted server. Only add servers you run or trust.
Safety checklist
- Start read-only. Add write access only for a task that needs it.
- Connect one app at a time.
- Read every consent screen. If it asks for more than the job needs, decline.
- Use a separate account or folder for experiments.
- Never let the agent send, delete or pay without approving each action.
- Treat anything from outside (emails, web pages, shared files) as possibly hostile text.
- Add only MCP servers you run or trust, and prefer ones that separate read tools from write tools.
- Review your connected apps monthly and disconnect what you do not use.
- Check what the agent says it did against the source.
Not to be confused with Grok Bot, SpaceXAI’s separate product of persistent cloud-computer teammates. The Grok FAQ says it is not the same as Grok on grok.com. For that, see our Grok Bot guide.
Sources
- SpaceXAI docs, “Connectors” (built-in, catalogue and custom MCP connectors; how to connect). https://docs.x.ai/grok/connectors
- SpaceXAI docs, “Gmail & Google Calendar” (permission tiers, disconnecting). https://docs.x.ai/grok/connectors/gmail-google-calendar
- SpaceXAI docs, “Google Drive” (scopes, account access). https://docs.x.ai/grok/connectors/google-drive
- SpaceXAI docs, “Custom MCP Server Tunneling”. https://docs.x.ai/grok/connectors/custom-mcp-tunneling
- SpaceXAI docs, “Connector Management” (Business and Enterprise admins). https://docs.x.ai/grok/connector-management
- SpaceXAI docs, “Remote MCP Tools” (API; allowed_tools, require_approval). https://docs.x.ai/developers/tools/remote-mcp
- SpaceXAI docs, “Tools overview”. https://docs.x.ai/docs/guides/tools/overview
- SpaceXAI news, “Connectors in web, iOS, and Android” (launch post, menu route, Bring Your Own MCP). https://x.ai/news/grok-connectors
- SpaceXAI docs, “Help & FAQ” (Grok Bot is a separate product). https://docs.x.ai/grok/faq
- Model Context Protocol, “What is MCP?” https://modelcontextprotocol.io/docs/getting-started/intro
- Model Context Protocol specification, “Tools” (model-controlled tools, human in the loop, security considerations). https://modelcontextprotocol.io/specification/latest/server/tools
- OWASP Gen AI Security Project, “LLM01:2025 Prompt Injection”. https://genai.owasp.org/llmrisk/llm01-prompt-injection/

