Since about 10 Oct 2026, after a Grok Bot desktop update on macOS, every gateway command in grok-bot-cli 0.12.4 (the latest on npm) fails:
$ gbot doctor
gateway auth: present
Grok Bot app session: present but unusable: Unsupported Grok Bot gateway descriptor version 3.
What changed in v3
I only looked at structure and field names. The wrapper is the v2 layout, with a savedAtMs added to each entry:
{ "version": 3, "entries": { "<hash>": { "savedAtMs": <number>, "encrypted": "v10…" } } }
The decrypted payload still has baseUrl, token and headers (x-anyrun-network-token). It also adds a vncProxy object (primaryUrl, forkBaseUrl, networkToken), which gbot doesn't use. baseUrl is still https on a Cursor host, so the URL policy passes it unchanged.
Fix
encryptedPayload() in src/core/app-session.js needs to accept version === 3 and read it the same way as v2. The single-entry / AMBIGUOUS_ENTRIES check stays as it is. #143 does exactly this. I applied the same two-line change to the 0.12.4 dist bundles (bin/gbot*.mjs, mcp/mcp-grok-bot-*.mjs). After that, gbot doctor reports Grok Bot app session: usable, and gbot send / gbot thread round trips work again on macOS.
One thing to watch if anyone else patches the published package by hand: scripts/gbot-relay.mjs is checked against the sha256 in agent-bundle.manifest.json at run time. Patching that file without updating the manifest breaks the relay with "Packaged relay worker checksum mismatch". #143 rebuilds the artifact, so it doesn't hit this.
Could #143 be merged and released? #145 includes the same v3 change plus the missing-descriptor fallback (#147), if you'd rather take that one.
Since about 10 Oct 2026, after a Grok Bot desktop update on macOS, every gateway command in grok-bot-cli 0.12.4 (the latest on npm) fails:
What changed in v3
I only looked at structure and field names. The wrapper is the v2 layout, with a
savedAtMsadded to each entry:{ "version": 3, "entries": { "<hash>": { "savedAtMs": <number>, "encrypted": "v10…" } } }The decrypted payload still has
baseUrl,tokenandheaders(x-anyrun-network-token). It also adds avncProxyobject (primaryUrl,forkBaseUrl,networkToken), which gbot doesn't use.baseUrlis still https on a Cursor host, so the URL policy passes it unchanged.Fix
encryptedPayload()insrc/core/app-session.jsneeds to acceptversion === 3and read it the same way as v2. The single-entry /AMBIGUOUS_ENTRIEScheck stays as it is. #143 does exactly this. I applied the same two-line change to the 0.12.4 dist bundles (bin/gbot*.mjs,mcp/mcp-grok-bot-*.mjs). After that,gbot doctorreportsGrok Bot app session: usable, andgbot send/gbot threadround trips work again on macOS.One thing to watch if anyone else patches the published package by hand:
scripts/gbot-relay.mjsis checked against the sha256 inagent-bundle.manifest.jsonat run time. Patching that file without updating the manifest breaks the relay with "Packaged relay worker checksum mismatch". #143 rebuilds the artifact, so it doesn't hit this.Could #143 be merged and released? #145 includes the same v3 change plus the missing-descriptor fallback (#147), if you'd rather take that one.