The short answer

Plugins, also called connectors, let a Bot use services like Gmail, Slack, Notion or Linear through a structured connection instead of clicking through a website. Install one from Connect Apps (formerly Marketplace) in the sidebar, finish the sign-in in your browser, and every Bot on your account can use it. A custom MCP server must be reachable over public HTTPS.

This page follows the official docs, Cursor's help pages and the changelog as of October 7, 2026, plus Cursor staff replies on the forum, which we attribute and have not reproduced. We have not tested any connector.

Documentation: Computer and apps: connect an app ↗ Grok Bot security ↗ Cursor help: connect plugins ↗ Forum: custom connectors (staff reply, August 30) ↗

RouteUse it whenKeep in mind
A plugin from Connect AppsThe service is in the catalogAccount-wide; tokens stay on Cursor's backend; Added is not the same as signed in
A custom remote MCP serverYou run or trust an HTTPS MCP endpointMust be publicly reachable; OAuth only, no secret headers; redirect issues are open
A command (stdio) MCP server on the Bot's computerA server ships as a package you can run with npx or uvxRuns on the cloud computer, not your laptop; keep credentials out of its command and arguments
The Bot's browserThere is no plugin, or the work is visualUses your signed-in session on the shared computer; see our connectors or browser guide
A secret for a scriptAn API has no plugin sign-inUse a secure secret request; never paste a key into chat

Plugins, connectors, Marketplace, Connect Apps: the names

The docs use connector and plugin for the same thing: connectors are installed as plugins. Where you install them has moved. The changelog shows the sidebar's Marketplace button became Connect apps in 0.60.0 (September 26), Marketplace stopped listing Bots and searched only plugins in 0.63.0 (September 29), and Marketplace became Connect Apps, with category chips and Recommended for you first, in 0.67.0 (October 2). Bot templates moved to the web; see our Marketplace and templates guide.

The documentation has not caught up everywhere: docs.x.ai still says Open Marketplace from the sidebar, and Cursor's help says Plugins. A Cursor staff member's October 5 directions cover both: Marketplace (or Connect apps) at the bottom of the sidebar, or Cmd+Shift+M. GitHub is a special case; staff said on September 28 that it is now built into Grok Bot through your connected Cursor GitHub account, replacing the old marketplace plugin.

Documentation: Grok Bot changelog (Marketplace to Connect Apps, 0.60 to 0.67) ↗ Computer and apps: connect an app ↗ Cursor help: connect plugins ↗ Forum: delisted GitHub plugin, GitHub now built in (staff reply, September 28) ↗

Install and authorize a plugin

These steps combine the official docs and Cursor's help. On mobile, Cursor's help says to tap your avatar at the top left and choose Plugins.

Documentation: Computer and apps: connect an app ↗ Settings: plugins and skills ↗ Cursor help: connect plugins ↗ Cursor help: how-tos (reconnect a plugin, second accounts) ↗ Grok Bot changelog (Marketplace to Connect Apps, 0.60 to 0.67) ↗

  1. Open Connect Apps in the sidebar, or follow a Connect card in chat.
  2. Find the plugin and add it. Since 0.63.0, a plugin that needs a sign-in, such as Gmail, starts that sign-in right away.
  3. Finish the provider's sign-in in your browser within about 10 minutes. If the app shows Waiting for authorization, choose Reopen to bring the browser tab back.
  4. Confirm the plugin appears under Installed and is authorized. Added only means installed; choose Authorize if it shows Needs auth or Disconnected.
  5. In chat, type @ to attach the connector to a task. To review or switch off individual tools, open Your plugins → Manage plugins and skills.

Where tokens live, and who can use a plugin

The docs say OAuth tokens stay on Cursor's connector backend, Bots invoke tools without receiving them, and tokens are never stored on the Bot's computer. That makes a plugin sturdier than a browser login, which depends on cookies on the shared computer. A plugin can do only what the connected account can already do; it cannot raise your access or change sharing.

Installed plugins are account-wide: every Bot on your account can use every connected account. Cursor's help says some plugins, such as Notion, can add a second account, while Gmail connects one mailbox at a time. On a Cursor team, the team's connector policy decides which plugins members can use, a blocked one shows Disabled by team admin, and the MCP allowlist is Enterprise only. Blocking a plugin does not block that service's website. Team Bots treat plugins differently again; see our Team Bots guide.

Documentation: Teams and enterprises: connector policy ↗ Grok Bot security ↗ Computer and apps: connect an app ↗ Cursor help: connect plugins ↗ Cursor help: how-tos (reconnect a plugin, second accounts) ↗

Add a custom MCP server

There is no settings form for this. A Cursor staff member said on August 30 that you tell the Bot in chat to add the MCP server, and that it must be a public HTTPS URL using streamable HTTP or SSE. OAuth discovery runs from Cursor's infrastructure, so another staff answer on August 12 said the endpoint must be reachable over HTTPS from the open internet; a server behind your VPN or on localhost will not work. Staff also said on September 17 that connectors authenticate only through OAuth, with no safe way to enter a secret header.

Servers on your own laptop are not attached. Staff said on August 13 that Grok Bot does not attach MCP servers that run on your own machine, whether over stdio or on localhost. A command-style server can instead run on the Bot's cloud computer: a staff reply on September 8 suggested registering servers as npx or uvx commands or keeping wrapper scripts on the computer, and on September 28 staff explained re-pointing a custom stdio server by adding it again under the same name. The Team Bots docs warn that teammates can read a command server's command and arguments, so never put a credential in either.

Documentation: Forum: custom connectors (staff reply, August 30) ↗ Forum: custom remote MCP OAuth never starts (staff answer, August 12) ↗ Forum: custom MCP OAuth fails with redirect_uri not allowed (staff replies, September 16 to 25) ↗ Forum: does Grok Bot support local MCP? (staff reply, August 13) ↗ Forum: stdio MCP server paths on the Bot's computer (staff reply, September 8) ↗ Forum: edit a custom stdio MCP server in place (staff reply, September 28) ↗ Team Bots: plugin types ↗

Try this brief

Add a custom MCP server named [name] at [https URL] using [streamable HTTP or SSE]. Do not paste any key or token into this chat; if the server needs one, start its OAuth sign-in or ask me for a secure secret. When it is connected, list the tools it exposes and run one read-only call on [harmless test input]. Do not call any tool that creates, changes or deletes data.

Original editorial template. Replace placeholders and review access before running.

Known issues as of October 7

These are the open or recently fixed plugin problems with a Cursor staff reply or a help-page entry. Status is what the source said when we checked; later fixes may not be reflected yet.

Documentation: Forum: custom MCP OAuth fails with redirect_uri not allowed (staff replies, September 16 to 25) ↗ Cursor help: connect plugins ↗ Forum: Zoom plugin OAuth error 4700 (staff replies) ↗ Forum: Vercel plugin OAuth redirect URL invalid (staff reply, September 21) ↗ Forum: MCP shows connected but the Bot gets MCP server not found (staff fix, September 28) ↗ Forum: delisted GitHub plugin, GitHub now built in (staff reply, September 28) ↗ Grok Bot changelog (Marketplace to Connect Apps, 0.60 to 0.67) ↗

SymptomWhat Cursor saidStatus
Custom MCP OAuth fails before sign-in: redirect_uri not allowed (for example behind Cloudflare Access)Registration sends a cursor:// callback that https-only providers reject; staff called it an issue on their side and want registration to send only https and localhost callbacksOpen; no target version shared (September 25)
Zoom authorization fails with error 4700 (Invalid redirect)Cursor's help calls it a known issue with no workaroundOpen
Vercel plugin: redirect URL is invalidBroken since about September 16; staff said the team had identified the causeNo fix confirmed in the thread (September 21)
Plugin shows connected but the Bot reports MCP server not foundA server-side change left background tasks without connectors; a fix rolled outFixed (September 28)
An old GitHub plugin cannot be removed and shows 0 toolsGitHub is now built in through your Cursor GitHub account; staff removed leftovers on requestWorkaround (September 28 to October 7)
Connecting fails because another app is using the sign-in portChangelog 0.67.0: connecting an app now finishes anyway, and a failed sign-in page explains whyFixed (October 2)

Plugins in templates and Team Bots

A shared Bot template lists its first-party plugins, but each new owner reinstalls and authenticates them; xAI's template guide says templates do not carry MCP servers, custom code or scripts. On a Team Bot, a plugin that signs in with an account uses the account of whoever is talking to the Bot, while a plugin configured with a key uses the Bot's own credential for everyone, and a custom Remote HTTPS server can use either. For Gmail and Google Workspace specifics, see our Gmail guide; for the security model, see Is Grok Bot safe?.

Documentation: xAI: Templates for Grok Bot (September 8, 2026) ↗ Team Bots: plugin types ↗

Quick answers

Where did Marketplace go in Grok Bot?

It was renamed. The changelog shows the sidebar button became Connect apps in 0.60.0 (September 26), Marketplace stopped showing Bots and focused on plugins in 0.63.0 (September 29), and Marketplace became Connect Apps in 0.67.0 (October 2). Bot templates moved to the web Marketplace at x.ai/bot/marketplace. A Cursor staff member wrote on October 5: open Marketplace (or Connect apps) at the bottom of the sidebar, or press Cmd+Shift+M.

Can Grok Bot use an MCP server running on my laptop?

No. A Cursor staff member said on August 13 that Grok Bot does not attach MCP servers that run on your own machine, whether over stdio or listening on localhost, because Bots work on a cloud computer. Use a public HTTPS server, a catalog plugin, or the Bot's browser. Staff have since described running stdio servers on the Bot's own cloud computer instead.

Does the Bot see my OAuth tokens?

No, according to the docs. OAuth tokens stay on Cursor's connector backend, Bots invoke tools without receiving them, and tokens are never stored on the Bot's computer. A plugin can do only what the connected account can already do in that service.

Can I connect two accounts for the same service?

For some plugins. Cursor's help says Notion and some others can add a second account with Add Another Account, but Gmail connects one mailbox at a time. Every Bot on your account can use every connected account, so disconnect one a Bot should not use.

Do Bot templates include plugins and MCP servers?

Plugins are listed, but each new owner reinstalls and authenticates them. xAI's September 8 template guide says templates do not carry MCP servers, custom code or scripts, and suggests having the Bot write setup instructions into the template for complex setups.

Bots for this job

Directory listings that match this guide, read from each creator's public share page. They are not tested picks: check what a Bot can reach before you add it.

Browse: Bots for mcp · Bots that work with GitHub

  • Tinkabot by lauren 🎀: Turns an API into a plugin your other bots can just pick up and use
  • GitHub Steward by Lee Talley: GitHub Steward runs GitHub for you from chat: it sets up one board of your work, keeps your folders private, makes changes as drafts, and asks before
  • Compute Spread by Sam E: Cuts AI spend by preferring connectors and public data, one lean batch, and the smallest tool that still works

Sources & next steps

Capabilities are grounded in the documentation below. The workflow design and acceptance checks are editorial suggestions.

Build your own workflow brief ↗