Grok

Use Thirdfy MCP from xAI Grok with remote MCP tools in the xAI Responses API and the xai-sdk.

xAI's API connects Grok to remote MCP servers. You add Thirdfy to the tools of a request, and xAI handles the connection. See xAI's Remote MCP tools docs.

You need a Thirdfy agent API key (agent-...) for any tool that acts for your agent. Get one with email onboarding: run it once through any MCP client or with the Agent CLI.

Request

authorization is sent to Thirdfy in the Authorization header.

xai-sdk
curl
import os

from xai_sdk import Client
from xai_sdk.chat import user
from xai_sdk.tools import mcp

client = Client(api_key=os.environ["XAI_API_KEY"])

chat = client.chat.create(
    model="grok-4.7",
    tools=[
        mcp(
            server_url="https://mcp.thirdfy.com/mcp",
            server_label="thirdfy",
            authorization=os.environ["AGENT_API_KEY"],
            allowed_tool_names=["getProviderActions", "getVenueReadiness", "agentRun"],
        ),
    ],
)

chat.append(user("Using Thirdfy, read the latest BTC funding on Hyperliquid."))
print(chat.sample().content)

Keep writes under control

xAI runs MCP tool calls without an approval step: it does not support require_approval. Limit what Grok can do in two places:

  • allowed_tools (allowed_tool_names in the xai-sdk). List only the tools the task needs. Without it, every Thirdfy tool is loaded, which also adds context.
  • Your agent's policy in Thirdfy. The key's action allowlist and daily limit bind every call, whatever the model asks for. See Delegation & protection.

For a research agent, allow only getActionsCatalog, getProviderActions and agentRun, and ask it to run read actions such as the get_openmarket_* and get_cmc_* reads.

Troubleshooting

IssueFix
401 Authentication requiredPass the agent key in authorization
Grok calls a tool you didn't expectNarrow allowed_tools, and the key's action allowlist
AGENT_IDENTITY_MISMATCHThe model passed a different key in arguments. The bearer key is used