
Grok Bot Logs In As You: The Question SpaceXAI Hasn't Answered
- DeepSeekNEWDeepSeek: DeepSeek V4 Flash Vision (Exp)2026-08-21$0.15 / $0.29 per 1M tokens
- z-aiNEWZ.ai: GLM 5.32026-08-1860Intelligence75Coding
- obsidianNEWQwen3.8 27B2026-08-1552Intelligence68Coding
- qwenNEWQwen: Qwen3.8 27B (free)2026-08-13qwen/qwen3.8-27b-free
- deepseekNEWDeepSeek: DeepSeek V4 Pro 08132026-08-1253Intelligence69Coding
- grokNEWSpaceXAI: Grok 4.62026-08-1261Intelligence77Coding
- metaMeta: Muse Spark 1.22026-08-0557Intelligence72Coding
- qwenQwen: Qwen3.8 Max2026-08-0358Intelligence72Coding
- deepseekDeepSeek: DeepSeek V4 Flash 07312026-07-3152Intelligence69Coding
- minimaxMiniMax: MiniMax-H32026-07-31minimax/minimax-h3
- qwenQwen: Qwen3.7 Flash2026-07-27$0.03 / $0.13 per 1M tokens
- orcaOrcaDub: OrcaDub 1.02026-07-27orca/dub
- anthropicAnthropic: Claude Opus 52026-07-2463Intelligence78Coding
- googleGoogle: Gemini 3.6 Flash2026-07-2152Intelligence69Coding
- googleGoogle: Gemini 3.5 Flash-Lite2026-07-2137Intelligence49Coding
- metaMeta: Muse Spark 1.12026-07-1653Intelligence71Coding
- kimiMoonshotAI: Kimi K32026-07-1560Intelligence76Coding
- openaiOpenAI: GPT-5.6 Luna2026-07-0952Intelligence71Coding
- openaiOpenAI: GPT-5.6 Terra2026-07-0957Intelligence77Coding
- openaiOpenAI: GPT-5.6 Sol2026-07-0961Intelligence77Coding
The most quoted line from the week Grok Bot launched was not about what the bots can do. It was a criticism: the notable thing is not that the agents run, it is that they log in as you — and SpaceXAI has not published how that authentication works. That gap is the reason OrcaID exists, and it is currently in pre-registration, where you can reserve the handle an agent would carry without opening an account or starting billing.
SpaceXAI launched Grok Bot on 11 August 2026 as a beta built around "always-on" AI teammates. By the company's own description, the bots run on a cloud computer, sign into the tools you already use, and keep working after you have closed the laptop and gone to bed. They come back to you only when something needs a human decision. Bloomberg covered it the same day; MacRumors noted the macOS and iOS builds. It is a genuinely ambitious product, and every part of the description above is a capability claim from SpaceXAI rather than something a third party has verified.
"Sign into the tools you already use" is doing a lot of work
There is a sentence in SpaceXAI's own announcement that frames the whole issue better than any critic has: "Bots have their own computer. They sign into the tools you already use and work across apps, inboxes, and more."
Read those two sentences together. The bots were given their own computer — a machine in the cloud, so jobs do not stall when you step away. They were not given their own accounts. The hardware got separated from the human and the identity did not, and that asymmetry is the subject of this article.
Now read the operative phrase slowly, because it is the entire product and the entire problem.
For a bot to do sales outreach, it needs your email account. For it to run a marketing campaign, it needs your ad account. For it to handle office operations, it needs whatever you use to buy things. SpaceXAI says its own employees used Grok Bot for exactly these — sales outreach, marketing campaigns, onboarding, office operations and bug fixes. Every one of those tasks terminates in a system that knows you, bills you, and holds you responsible for what happens under your name.
There are only a few ways to give software that access, and none of them is comfortable. You can hand over a password, which means the credential now lives somewhere you do not control. You can hand over an OAuth token, which is better, but OAuth scopes were designed for apps that do one predictable thing, not for an agent that decides at runtime what it needs. You can let it drive a browser inside your logged-in session, which is the most capable option and the least bounded — a session cookie carries your full authority with no notion of a ceiling.
SpaceXAI's own page points at the third one. Under the heading "A computer of its own" it says the bots "can sign in and work across apps, tools, and websites, including platforms with no clean API or MCP, and come back with the work finished." A platform with no clean API is a platform you reach by driving its website while logged in. That is the most capable delegation mode available and the one with no ceiling in it, and it is described as a feature — correctly, because it is what makes the product work on the long tail of tools that never shipped an API.
Which credential mechanism sits behind that is, as of late August 2026, not publicly documented. That is the substance of the criticism. It is not a claim that SpaceXAI has done something insecure; it is that a product whose core function is signing into your accounts has shipped in beta without publishing its authentication model, and the wider rollout still has no announced date.

Why an always-on agent makes this worse than a chatbot did
A chat assistant that needs your credentials asks for them while you are sitting there. You watch what it does, and the session ends when you close the tab. The exposure is bounded by your attention.
Grok Bot's design deliberately removes that bound. The value proposition is that it works while you sleep and only interrupts you for judgment calls. That is useful, and it means the period during which your identity is delegated to software is now measured in days rather than minutes, with no human in the loop for most of it.
Three consequences follow, and they are structural rather than speculative:
Attribution collapses. If every action arrives at the far end wearing your login, then your mail logs, your card statement and your audit trail cannot separate what you did from what the bot did. After a month of always-on operation, that distinction is unrecoverable.
Revocation is blunt. The only reliable way to stop a delegated session you do not control is to invalidate your own credential — change the password, revoke the token, log out everywhere. You end up locking yourself out to stop your agent.
There is no natural ceiling. A logged-in session does not have a spending limit. Whatever your account can do, the agent holding that session can do, for as long as it holds it.
The multi-agent version of the same problem
Grok Bot is not one bot. SpaceXAI describes multiple bots running in parallel, one managing others, specialists for different tasks, and bots joining a group chat where they coordinate on their own — passing work, assigning ownership, and pulling the human in only for judgment calls.
Now apply the three consequences above to a team of five. If all five act under one human identity, then "which bot did this" is not a question the systems they touched can answer, because those systems only ever saw you. Ownership inside the group chat is a convention the bots maintain among themselves; it is not visible to your bank, your mail provider, or your vendor. The orchestration is real and the accountability is fictional.
This is the specific point where an issued identity stops being a nice idea and starts being the only workable design. Five agents that each hold their own handle, balance and card produce five separate ledgers by construction. You do not have to reconstruct who did what, because it was never merged in the first place.

What an issued identity changes
OrcaID's proposition is that the agent gets an account of its own: a handle in the form @name, resolving as name.orcaid.ai, with a wallet, a virtual card, an inbox spanning its whole domain and a phone number attached to it. On the site's own labelling, the wallet, card and number are marked "by verification" and the inbox "at launch" — this is a reservation stage, and it would be wrong to describe any of it as running today.
The design claim, though, is testable against the three consequences:
Actions arrive as you; attribution collapses. What an issued account does instead: Actions arrive as @name; the agent is the named party on the record.
Revocation means changing your own credentials. What an issued account does instead: A kill switch that pauses the agent in one click, leaving you untouched.
A session has no spending ceiling. What an issued account does instead: A monthly cap described as a hard stop, and a card that declines the moment it passes that cap.
Spend is spread across billing portals. What an issued account does instead: "Tokens + dollars, one ledger" — one statement covering model calls and real-world charges.
The framing on orcaid.ai is "the name is the leash": one thing to fund, one thing to cap, one thing to pull. For an agent that runs unattended for weeks, that is a materially different safety story than "we did not say how the login works".
What to actually do about it right now
Grok Bot is in beta, bundled into existing paid subscription tiers, with enterprise customers on a waitlist and no published date for a wider rollout. OrcaID is in pre-registration. Neither of those facts supports a migration plan today, so the honest advice is smaller than a strategy:
If you are running always-on agents against your own accounts, assume for now that you cannot separate their actions from yours, and scope what you delegate accordingly — a dedicated card with a low limit and a separate mail account are crude, but they are available this afternoon. Push your vendors to publish their authentication model; the fact that the question is being asked loudly about the highest-profile launch of the month is how that norm gets established. And if you expect to run agents that transact, reserving the name one would carry costs nothing and does not start billing.

The takeaway
Grok Bot's capability story is strong enough that the identity question is the one worth asking about it. Always-on agents that sign into your accounts, coordinate in teams, and run for days without supervision are not a small extension of a chatbot — they are a delegation of your identity with no ceiling, no clean attribution and no revocation short of locking yourself out. SpaceXAI has not published how it handles that, and until it does, the criticism stands on its own.
The alternative shape is not complicated: give the agent its own name, fund it, cap it, and keep one switch that turns it off. That is what OrcaID is being built to be, and it is a reservation today rather than a product. The gap it is aimed at, though, was demonstrated by the biggest agent launch of the month.
Sourcing note: Grok Bot's launch date (11 August 2026), the cloud-computer model, the "signs into the tools you already use" behaviour, the always-on framing, the multi-bot group-chat coordination, the internal use cases and the paid-tier bundling are all SpaceXAI's own claims from its launch material. The criticism that the agents log in as you and that the authentication model is undisclosed, and the absence of a published wider-rollout date, are from independent analyst and press coverage — not from SpaceXAI. Launch-day coverage: Bloomberg and MacRumors, 11 August 2026. OrcaID's handle format, capabilities, "By verification" / "At launch" status labels and governance controls are from orcaid.ai, checked 2026-08-22, and are pre-registration claims. No integration between OrcaID and Grok Bot has been announced or is implied here.
