xAI offers a consolidated account for both Grok and the xAI API, accessible through console.x.ai. Users can sign up with an X account to link it automatically or create multiple accounts with different sign-in methods using the same email. While accounts are shared, billing for Grok and the xAI API is managed separately.
For enterprise users, xAI provides a Management API to programmatically handle team API keys and other team details. This API allows for the creation, listing, updating, and deletion of API keys, as well as the management of associated access control lists (ACLs).
xAI states it does not train on customer API inputs or outputs without explicit permission. API requests and responses are temporarily stored for 30 days for audit purposes and then automatically deleted.
Key Points
- Accounts for Grok and the xAI API are shared and can be managed at accounts.x.ai.
- Billing for Grok is separate from xAI API billing, managed via grok.com settings or app stores for Grok, and the xAI Console for the API.
- Users can create multiple xAI accounts with the same email but different sign-in methods; content and subscriptions are not merged between these accounts.
- A Management API is available for enterprise users to programmatically manage API keys and access control lists (ACLs).
- xAI does not train on customer API inputs or outputs without explicit permission.
- API requests and responses are temporarily stored for 30 days for abuse auditing before automatic deletion.
- xAI is SOC 2 Type 2 compliant, with audit logs available for team admins to view user interactions with the API server.
Context
According to xAI, the account system is designed to integrate access to both Grok and the xAI API, while maintaining distinct billing processes. The company also emphasizes security measures, including multi-factor authentication (MFA) recommendations and a policy against training on customer API data without explicit consent. For enterprise clients, the Management API offers granular control over API keys and their permissions, as detailed in the xAI documentation.
Why It Matters
Builders can manage their xAI API access and Grok usage through a unified account, streamlining administrative tasks. The availability of a Management API provides enterprise users with automation capabilities for API key lifecycle management and access control, which is crucial for integrating xAI's services into larger systems. xAI's data privacy stance and security certifications offer clarity regarding data handling practices.
What To Do
- Review the xAI Console for API key management and billing details.
- Explore the Management API documentation if programmatic control over API keys and ACLs is required.
- Implement multi-factor authentication (MFA) for xAI accounts to enhance security.
- Note the 30-day data retention policy for API requests and responses for compliance planning.
- Check the xAI Trust Center for details on certifications and data governance, especially if an NDA is in place.
