Hey @stacker21, thanks for raising this, and good instinct to check.
The prompt you’re seeing is 1Password’s standard authorization for a one-time CLI session. Grok Bot uses that short session (it expires after about 10 minutes of inactivity or when 1Password locks) only to create a vault called “Shared with Grok Bot” and to mint a service account that can read just that vault. That service account is the only thing Grok Bot keeps. It has read-only access to that single vault, and you still approve each fill from your device.
So today the way to share only what you want is to move the specific logins into the “Shared with Grok Bot” vault. Anything you leave in your other vaults is never visible to Grok Bot.
Got it, thanks for clearing that up! I was able to get it working. I’d suggest making this clearer in the app, as the current prompt is a bit misleading about what it’s actually accessing. Thanks again!