Grok Build
Run Grok Build in a secure E2B sandbox with full filesystem, terminal, and git access.
Grok Build is xAI’s coding agent and CLI. E2B provides a pre-built grok template with Grok Build already installed.
CLI
Create a sandbox with the E2B CLI.
e2b sbx create grokOnce inside the sandbox, start Grok Build.
grokRun headless
Use -p for non-interactive mode and --always-approve to auto-approve all tool calls. The sandbox isolates the agent from your host machine, but sandboxes can reach the open internet by default — restrict outbound traffic with network rules. Grok Build authenticates with an API key from the xAI console via the XAI_API_KEY environment variable.
Auto-approving tool calls is contained by the sandbox: the agent cannot touch your host machine, local files, or credentials. It can still make outbound network requests — internet access is enabled by default. To limit where an auto-approved agent can connect, configure outbound network rules (allowInternetAccess, plus allow/deny lists by CIDR or hostname). Hostname rules apply to HTTP(S) traffic only; use CIDR rules for other protocols.
import { Sandbox } from 'e2b'
const sandbox = await Sandbox.create('grok', {
envs: { XAI_API_KEY: process.env.XAI_API_KEY },
})
const result = await sandbox.commands.run(
`grok --always-approve -p "Create a hello world HTTP server in Go"`
)
console.log(result.stdout)
await sandbox.kill()Example: work on a cloned repository
import { Sandbox } from 'e2b'
const sandbox = await Sandbox.create('grok', {
envs: { XAI_API_KEY: process.env.XAI_API_KEY },
timeoutMs: 600_000,
})
await sandbox.git.clone('https://github.com/your-org/your-repo.git', {
path: '/home/user/repo',
username: 'x-access-token',
password: process.env.GITHUB_TOKEN,
depth: 1,
})
const result = await sandbox.commands.run(
`cd /home/user/repo && grok --always-approve -p "Add error handling to all API endpoints"`,
{ onStdout: (data) => process.stdout.write(data) }
)
const diff = await sandbox.commands.run('cd /home/user/repo && git diff')
console.log(diff.stdout)
await sandbox.kill()Build a custom template
If you need to customize the environment (e.g. pre-install dependencies, add config files), build your own template on top of the pre-built grok template.
// template.ts
import { Template } from 'e2b'
export const template = Template()
.fromTemplate('grok')// build.ts
import { Template, defaultBuildLogger } from 'e2b'
import { template as grokTemplate } from './template'
await Template.build(grokTemplate, 'my-grok', {
cpuCount: 2,
memoryMB: 2048,
onBuildLogs: defaultBuildLogger(),
})Run the build script to create the template.
npx tsx build.ts