BreadDocs
Browse documentation

Integration guide

Grok Build

Supported hooks and disposable validation for Grok Build.

Open source

Bread implements Grok's documented command-hook contract, but Grok Build has not yet completed Bread's live CLI release gate. Treat every Grok capability below as implementation coverage that requires a disposable sandbox check before relying on it for enforcement.

CapabilityStatusBehavior
Project hooksImplemented; live validation pending.grok/hooks/bread.json; requires /hooks-trust or --trust
User hooksImplemented; live validation pending~/.grok/hooks/bread.json via explicit bread install grok-user
SessionStartImplemented; live validation pendingStarts the shared daemon through the normal hook path
PreToolUseImplemented; live validation pendingRestricted Edit/Write/apply_patch paths return decision=deny; exit 2
PostToolUseImplemented, observe-onlyNo stdout mutation; native result remains untouched
updatedInputUnsupportedPass-through
Result replacementUnsupportedPass-through
Prompt injectionUnsupportedPass-through
ACPNot a hook surfaceTest separately; Bread does not speak ACP

Grok treats only explicit decision: deny as blocking. Hook crashes, timeouts, malformed output, and other non-zero failures are fail-open in the documented contract. Bread therefore emits no synthetic success payload and does not claim rewrite or result-substitution support.

User-hook lifecycle and compatibility

bread install grok-user writes Bread's hook configuration to ~/.grok/hooks/bread.json and keeps any prior file at ~/.bread/grok-hooks.backup. bread uninstall grok-user restores that backup when it exists; otherwise it removes the Bread-owned file. Project hooks use the same layout under the target repository and keep their backup in that repository's .bread/ directory. Workspace indexes and daemon state remain workspace-local; a user hook does not move source content into HOME.

The generated manifest binds SessionStart, PreToolUse for Edit|Write|apply_patch, and observe-only PostToolUse for Read|Edit|Write|apply_patch. Review that manifest through Grok's trust flow before enabling it.

No Grok Build CLI version is live-validated yet. Record the exact CLI version and output format in the disposable sandbox, and treat an unsuccessful or unrun check as unsupported for enforcement-sensitive workflows.

Disposable validation

Use scripts/cli-sandbox for live tests. Run them in this order: Codex CLI, Claude Code CLI, Grok Build CLI. Use the cheapest capable model and record the CLI version, model, output format, trust state, and exit status. Authentication must happen only inside the named sandbox.

The deterministic fixture uses grok -p with --output-format json or streaming-json, --no-auto-update, and a pinned --model. ACP smoke is a separate stdout-integrity check and must not be mixed with hook JSON.

Sources checked 2026-07-14: