الأكاديمية ← أدلة تطبيقيةتوثيق رسمي · إرشاد عربي

تسجيل الدخول إلى xAI Grok

xAI Grok OAuth (SuperGrok / X Premium+)

متوسط9 دقائق قراءةالدرس 265 أسئلة✓ 2026-08-18
قبل أن تقرأ

ما هذه الصفحة، وماذا تحتوي.

الأسرار والمفاتيح: كلمات السر ومفاتيح الخدمات التي يحتاجها Hermes ليدخل إلى حساباتك. تُحفظ في مكان واحد محمي، فلا تظهر في المحادثات ولا في الملفات التي تشاركها. الصفحة فيها تحذير من المصدر، و9 دقائق قراءة. انتبه: لا تكتب مفتاحًا داخل محادثة ولا داخل ملف إعداد تشاركه. استعمل متغيرات البيئة أو مدير أسرار.

13أقسام
12أمثلة برمجية
3جداول
8أوامر
1,579كلمة من المصدر
الوصف الرسمي في سطر

Sign in with your SuperGrok or X Premium+ subscription to use Grok models in Hermes Agent — no API key required

ماذا ستستطيع بعدها

نتائج مأخوذة من هذه الصفحة، لا من قالب.

  • تعرف ما الأسرار والمفاتيح ولماذا قد تحتاجه.
  • تنفّذ hermes auth add xai-oauth وhermes model وتفهم ما يحدث بعدها.
  • تقرأ الجدول وتأخذ منه السطر الذي يخصّك فقط.
  • تضبط XAI_API_KEY في المكان الصحيح.
ما ستقابله من أسماء

كما تظهر تمامًا داخل Hermes.

الأوامر
  • hermes auth add xai-oauth
  • hermes model
  • hermes tools
  • hermes config set model
  • hermes auth logout xai-oauth
  • hermes setup
  • hermes doctor
  • hermes auth list xai-oauth
متغيرات البيئة
  • XAI_API_KEY
خريطة الصفحة

انتقل مباشرة إلى ما تحتاجه.

  1. 01Overview
  2. 02Prerequisites
  3. 03Quick Start
  4. 04Logging In Manually
  5. 05How the Login Works
  6. 06Checking Login Status
  7. 07Switching Models
  8. 08Configuration Reference
  9. 09Direct-to-xAI Tools (TTS / Image / Video / Transcription / X Search)
  10. 10Environment Variables
  11. 11Troubleshooting
  12. 12Logging Out
  13. 13See Also
الصفحة الرسمية كاملة

بلا اختصار أو حذف.

النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.

Hermes Agent supports xAI Grok through a browser-based OAuth device-code login flow against accounts.x.ai ↗, using either a SuperGrok subscription (grok.com ↗) or an X Premium+ subscription (linked X account). No XAI_API_KEY is required — log in once and Hermes automatically refreshes your session in the background.

When you sign in with an X account that has Premium+, xAI automatically links the subscription status to your xAI session, so the OAuth flow works the same as it does for direct SuperGrok subscribers.

The transport reuses the codex_responses adapter (xAI exposes a Responses-style endpoint), so reasoning, tool-calling, streaming, and prompt caching work without any adapter changes.

The same OAuth bearer token is also reused by every direct-to-xAI surface in Hermes — TTS, image generation, video generation, and transcription — so a single login covers all four.

Overview

جدول مرجعي. لا تقرأه كله، ابحث عن السطر الذي يخصّك فقط.

ItemValue
Provider IDxai-oauth
Display namexAI Grok OAuth (SuperGrok / X Premium+)
Auth typeBrowser OAuth 2.0 device code
TransportxAI Responses API (codex_responses)
Default modelgrok-4.6
Endpointhttps://api.x.ai/v1
Auth serverhttps://accounts.x.ai
Requires env varNo (XAI_API_KEY is not used for this provider)
SubscriptionSuperGrok ↗ or X Premium+ ↗ — see note below

Prerequisites

فيه تحذير مهم. اقرأه قبل أن تنفّذ أي شيء من هذا القسم. نصّ التحذير من المصدر مذكور أسفل هذا الشرح.

  • Python 3.9+
  • Hermes Agent installed
  • An active SuperGrok subscription on your xAI account, or an X Premium+ subscription on the X account you sign in with (xAI links the subscription automatically)
  • A browser available anywhere you can open the printed verification URL

Quick Start

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية. الأوامر هنا: hermes model.

Shell9 أسطر
# Launch the provider and model picker
hermes model
# → Select "xAI Grok OAuth (SuperGrok / X Premium+)" from the provider list
# → Hermes opens or prints an accounts.x.ai verification URL
# → Enter the displayed code if prompted, then approve access in the browser
# → Pick a model (grok-4.6 is at the top)
# → Start chatting

hermes

After the first login, credentials are stored under ~/.hermes/auth.json and refreshed automatically before they expire.

Logging In Manually

أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes auth add xai-oauth.

You can trigger a login without going through the model picker:

Shellسطر واحد
hermes auth add xai-oauth

Remote / headless sessions

On servers, containers, browser-only consoles (Cloud Shell, Codespaces, EC2 Instance Connect), or SSH sessions where Hermes cannot open a browser locally, Hermes prints the xAI verification URL and user code. Open the URL in any browser on your laptop or in the cloud console, enter the code if prompted, and Hermes will keep polling until xAI approves the login. No SSH tunnel or local callback listener is required.

Shellسطران
hermes auth add xai-oauth --no-browser
# Open the printed verification URL in your browser.

The same device-code flow applies when you sign in from the web dashboard or the desktop app: Hermes shows the verification URL and user code, then polls in the background until you approve access.

How the Login Works

أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes auth logout xai-oauth.

  1. Hermes requests a device code from auth.x.ai.
  2. You open the verification URL, sign in, enter the displayed code if prompted, and approve access.
  3. Hermes polls xAI until approval, then saves tokens to ~/.hermes/auth.json.
  4. From then on, Hermes refreshes the access token in the background — you stay signed in until you hermes auth logout xai-oauth or revoke access from your xAI account settings.

Checking Login Status

أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes doctor.

Shellسطر واحد
hermes doctor

The ◆ Auth Providers section will show the current state of every provider, including xai-oauth.

Switching Models

أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes config set model، hermes model.

Shell3 أسطر
hermes model
# → Select "xAI Grok OAuth (SuperGrok / X Premium+)"
# → Pick from the model list (grok-4.6 is pinned to the top)

Or set the model directly:

Shellسطران
hermes config set model.default grok-4.6
hermes config set model.provider xai-oauth

Configuration Reference

إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير.

After login, ~/.hermes/config.yaml will contain:

YAML4 أسطر
model:
  default: grok-4.6
  provider: xai-oauth
  base_url: https://api.x.ai/v1

Provider aliases

All of the following resolve to xai-oauth:

Shell4 أسطر
hermes --provider xai-oauth        # canonical
hermes --provider grok-oauth       # alias
hermes --provider x-ai-oauth       # alias
hermes --provider xai-grok-oauth   # alias

Environment Variables

أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes setup.

VariableEffect
XAI_BASE_URLOverride the default https://api.x.ai/v1 endpoint (rarely needed).

To select xAI as the active provider, set model.provider: xai-oauth in config.yaml (use hermes setup for the guided flow) or pass --provider xai-oauth for a single invocation.

Troubleshooting

قسم لحل المشكلات. ابحث فيه عن العطل الذي يشبه حالتك بدل قراءته كاملًا. الأوامر هنا: hermes auth add xai-oauth، hermes model.

Token expired — not re-logging in automatically

Hermes refreshes the token before each session and again reactively on a 401. If refresh fails with invalid_grant (the refresh token was revoked, or the account was rotated), Hermes surfaces a typed re-auth message instead of crashing.

When the refresh failure is terminal (HTTP 4xx, invalid_grant, revoked grant, etc.), Hermes marks the refresh token as dead and quarantines it locally — subsequent calls skip the doomed refresh attempt instead of replaying the same 401 over and over. The agent surfaces a single "re-authentication required" message and stays out of the way until you log in again.

Fix: run hermes auth add xai-oauth again to start a fresh login. The quarantine clears on the next successful exchange.

Authorization timed out

Device-code approval has a finite expiry window (xAI sets expires_in on the device-code response, typically on the order of tens of minutes). If you do not approve the login in time, Hermes raises a timeout error.

Fix: re-run hermes auth add xai-oauth (or hermes model). The flow starts fresh.

Logging in from a remote server

On SSH or container sessions Hermes prints the verification URL and user code instead of opening a browser. Open that URL in a browser on your laptop or in a cloud console — no SSH port forward is needed for xAI Grok OAuth.

Shellسطر واحد
hermes auth add xai-oauth --no-browser

For loopback-redirect providers (Spotify, MCP servers), see OAuth over SSH / Remote Hosts.

HTTP 403 after a successful login (tier / entitlement)

OAuth completed in the browser, tokens are saved, but inference or token refresh returns HTTP 403 with a message similar to "The caller does not have permission to execute the specified operation".

This is not a stale-token problem — re-running hermes model won't change it. xAI's backend has been seen to restrict OAuth API access to specific SuperGrok tiers despite the in-app subscription being active (issue #26847 ↗).

Fix: set XAI_API_KEY and switch to the API-key path:

Shellسطران
export XAI_API_KEY=xai-...
hermes config set model.provider xai

Or upgrade your subscription at x.ai/grok ↗ if the OAuth route is required.

"No xAI credentials found" error at runtime

The auth store has no xai-oauth entry and no XAI_API_KEY is set. You haven't logged in yet, or the credential file was deleted.

Fix: run hermes model and pick the xAI Grok OAuth provider, or run hermes auth add xai-oauth.

Logging Out

أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes auth list xai-oauth، hermes auth logout xai-oauth.

To remove all stored xAI Grok OAuth credentials:

Shellسطر واحد
hermes auth logout xai-oauth

This clears both the singleton OAuth entry in auth.json and any credential-pool rows for xai-oauth. Use hermes auth remove xai-oauth <index|id|label> if you only want to drop a single pool entry (run hermes auth list xai-oauth to see them).

See Also

شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: كلمات السر ومفاتيح الخدمات التي يحتاجها Hermes ليدخل إلى حساباتك.

اختبار الفهم

5 أسئلة إجاباتها كلها في هذه الصفحة.

كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.

1. في جدول هذا الدرس، ما «Value» المقابل لـ«Requires env var»؟
2. أي متغير بيئة من التالي يظهر فعليًا في هذا الدرس؟
3. ما التحذير الذي يذكره المصدر في هذا الدرس؟
4. أي عنوان من التالي لا يظهر في هذا الدرس؟
5. أي مفتاح إعداد يظهر في أمثلة هذا الدرس؟