The Blog

xAI offers Grok models via its API for text generation, reasoning, coding, tool use, document-centric workflows, and agentic research. The current docs focus primarily on Grok 4.20 as the new flagship, as well as on server-side tools such as Web Search, X Search, Code Execution, and Collections Search.

Additionally, xAI documents classic model-listing endpoints such as /v1/models and /v1/language-models.
xAI API – Grok

LLM “Build with Grok, the AI model designed to deliver truthful, insightful answers.”

(0)

Your review

Click the stars to start your review.

7.1/10 KIFOX Score – Good

Location: USA X.AI LLC, 1450 Page Mill Road, Palo Alto, CA 94304, USA

Image Generation Function Calling AI Agents LLM API Multimodal AI Programming Reasoning Model Language Model
Other Token-based API usage Billing based on input, reasoning, completion, image, and cached prompt tokens per model.

Server-side Tools Additional billing for tool invocations; costs may increase with the complexity of agentic requests.

Credits / API Key API usage takes place via an xAI account, API key, and purchased credits.

Enterprise / ZDR Enterprise customers can use Zero Data Retention so that API requests and responses are not stored.

Voice / Imagine / Batch / Tools Additional product areas for real-time conversations, TTS/STT, image/video generation, batch processing, web search, and structured outputs.

Target audience
The xAI Grok API is aimed primarily at developers, technical teams, start-ups, agencies, and companies that want to build their own LLM-powered applications. It is especially interesting for teams that want to combine research, coding, agent workflows, and tool orchestration, because xAI strongly emphasizes exactly these patterns in the docs. For pure end users without a build context, the API is far less obvious than Grok Web/App.

Outstanding features
The most striking differentiators are the server-side research and agent tools. xAI documents Web Search, X Search, Code Execution, and Collections Search as integrated tools for Grok. In addition, there is Grok 4.20 with a large context window, automatic reasoning, and strict prompt adherence, as well as Grok 4.20 Multi-agent for multi-agent research. For Enterprise, DPA, subprocessor transparency, retention rules, billing/usage controls, and Provisioned Throughput are also relevant.

Target audienceAssessment
Developers / product teamsVery suitable – for Grok-based chat, reasoning, tool, web/X search, voice, image, and video applications.
SaaS providers / startupsSuitable – if current information, Grok models, and multimodal API functions are relevant.
Creator and social-adjacent productsSuitable to very suitable – especially for applications with real-time/X relevance, content, research, and conversation.
SMEs with technical implementationSuitable – for assistants, search, support, research, automation, and multimodal AI functions.
Enterprise / compliance teamsConditionally to well suited – xAI offers a DPA, a no-training statement for API data, and ZDR for Enterprise, but EU data residency is not publicly documented as a standard.

Calculate tokens and costs with the KIFOX Tokenizer

Hosting & Data

✅ = well covered ⚠️ = partial / indirect ❓ = not available / unclear
?

1) On-prem / local hosting
Meaning: The company operates the solution on its own hardware or within its own infrastructure. In the strictest sense, not only the application runs locally, but ideally the model as well.

2) Private cloud / data center
Meaning: The solution runs in a dedicated or more clearly separated cloud environment, often with a hosting provider or hyperscaler, but in a German data center or in a particularly controlled environment.

3) EU SaaS / managed
Meaning: The provider operates the solution itself as a service. The company uses the tool as a ready-made cloud service, ideally with EU data residency.

4) Hybrid
Meaning: One part of the processing remains internal / local / in a private cloud, while another part runs in an external cloud or EU SaaS.

5) AVV / DPA
Meaning: This is the data processing agreement or Data Processing Addendum. It governs that the provider processes personal data on behalf of the customer and is bound by the customer's instructions.

6) No training
Meaning: The provider does not use your prompts, uploads, attachments, chat histories, or outputs for training or improving the general model — ideally excluded by contract.

7) Open-source / transparency path
Meaning: There is a path toward greater technical transparency and sovereignty, for example through:
- open models
- documented components
- self-hostable parts
- traceable architecture
- export / switching options

✅ = well covered ⚠️ = partial / indirect ❓ = not available / unclear
On-prem / local hosting
Private cloud / data center ⚠️
EU SaaS / Managed ⚠️
Hybrid ⚠️
DPA / AVV ⚠️
No training on customer data
Open source / transparency path ⚠️

On-Prem / local hosting: indirect / not available

No true on-premise or local model deployment on the customer's own infrastructure was found on the website. What is documented is primarily the use of xAI inference services; with Grok Build, tool execution and parts of the data processing take place locally, but inference still runs via the provider.

Private Cloud / data center: partial

The website mentions for Enterprise 'EU data residency options', 'Regional processing for compliance requirements', 'Multi-region infrastructure with custom SLAs' as well as dedicated Enterprise features such as ZDR. However, an explicitly dedicated private cloud or isolated EU data center deployment is not specifically described on the website.

EU SaaS / managed: partial

There are references on the website to 'EU data residency options' and 'Regional processing for compliance requirements'. However, specific EU/EEA data centers, countries, or EU data residency available by default for all API customers are not mentioned.

Hybrid: partial

For Grok Build, the website describes a mixed approach: user inputs and file contents are assembled locally, tool execution takes place locally in a sandbox, but inference is sent to the xAI service. This is a hybrid pattern, but it is not described as a formal hybrid hosting offering for the entire platform.

DPA / DPA: partial

The website refers to 'Legal Resources' with 'Data Processing Addendum' and mentions 'Data processing agreements' for the Voice APIs. However, a specifically accessible DPA text or detailed terms were not found on the reviewed domain itself.

No training: covered

The website explicitly states that xAI does not use API inputs and outputs for training without explicit permission. In addition, for Collections it is explained that user data stored there is not used for model training. For Voice APIs, it also states that audio data is processed in real time and is neither stored nor used for training.

Open source / transparency path: partial

There is some transparency path on the website: protobuf definitions can be downloaded and a repository called 'xai-proto' is mentioned; in addition, local policies, sandboxing, and client-side control for Grok Build can be configured. However, no clear open-source or self-hostable model path for the core models was found.

Data processing

According to the Security FAQ, the standard API temporarily stores requests and responses for 30 days for abuse review and deletes them afterward. For Enterprise, there is Zero Data Retention, in which prompts, responses, and metadata are processed in real time but not persisted. For Grok Build, the website describes a process in which inputs and file contents are assembled locally, inference runs via the provider, and tool execution takes place locally in a sandbox. For Voice APIs, the website additionally mentions EU data residency options and regional processing without naming specific EU/EEA locations.

Conclusion

For an EU/EEA tool directory, from the website perspective xAI API – Grok is not clearly fully GDPR-ready in the standard configuration, but can potentially be used in a more privacy-friendly way under certain conditions: in particular with an Enterprise agreement, DPA, enabled Zero Data Retention, and explicitly agreed EU data residency. Without these additional prerequisites, too many points remain open or are only stated in general terms from a European perspective, especially regarding specific server locations, subprocessors, and standard data processing.

Sources

On-prem / local hosting
Private cloud / data center ⚠️
EU SaaS / Managed ⚠️
Hybrid ⚠️
DPA / AVV ⚠️
No training on customer data
Open source / transparency path ⚠️

On-Prem / local hosting: indirect / not available

No true on-premise or local model deployment on the customer's own infrastructure was found on the website. What is documented is primarily the use of xAI inference services; with Grok Build, tool execution and parts of the data processing take place locally, but inference still runs via the provider.

Private Cloud / data center: partial

The website mentions for Enterprise 'EU data residency options', 'Regional processing for compliance requirements', 'Multi-region infrastructure with custom SLAs' as well as dedicated Enterprise features such as ZDR. However, an explicitly dedicated private cloud or isolated EU data center deployment is not specifically described on the website.

EU SaaS / managed: partial

There are references on the website to 'EU data residency options' and 'Regional processing for compliance requirements'. However, specific EU/EEA data centers, countries, or EU data residency available by default for all API customers are not mentioned.

Hybrid: partial

For Grok Build, the website describes a mixed approach: user inputs and file contents are assembled locally, tool execution takes place locally in a sandbox, but inference is sent to the xAI service. This is a hybrid pattern, but it is not described as a formal hybrid hosting offering for the entire platform.

DPA / DPA: partial

The website refers to 'Legal Resources' with 'Data Processing Addendum' and mentions 'Data processing agreements' for the Voice APIs. However, a specifically accessible DPA text or detailed terms were not found on the reviewed domain itself.

No training: covered

The website explicitly states that xAI does not use API inputs and outputs for training without explicit permission. In addition, for Collections it is explained that user data stored there is not used for model training. For Voice APIs, it also states that audio data is processed in real time and is neither stored nor used for training.

Open source / transparency path: partial

There is some transparency path on the website: protobuf definitions can be downloaded and a repository called 'xai-proto' is mentioned; in addition, local policies, sandboxing, and client-side control for Grok Build can be configured. However, no clear open-source or self-hostable model path for the core models was found.

Data processing

According to the Security FAQ, the standard API temporarily stores requests and responses for 30 days for abuse review and deletes them afterward. For Enterprise, there is Zero Data Retention, in which prompts, responses, and metadata are processed in real time but not persisted. For Grok Build, the website describes a process in which inputs and file contents are assembled locally, inference runs via the provider, and tool execution takes place locally in a sandbox. For Voice APIs, the website additionally mentions EU data residency options and regional processing without naming specific EU/EEA locations.

Conclusion

For an EU/EEA tool directory, from the website perspective xAI API – Grok is not clearly fully GDPR-ready in the standard configuration, but can potentially be used in a more privacy-friendly way under certain conditions: in particular with an Enterprise agreement, DPA, enabled Zero Data Retention, and explicitly agreed EU data residency. Without these additional prerequisites, too many points remain open or are only stated in general terms from a European perspective, especially regarding specific server locations, subprocessors, and standard data processing.

Sources

Strengths & weaknesses at a glance

Strengths Weaknesses
- Very strong in real-time research because Grok integrates web search and X search as official tools. - The documentation is currently inconsistent between new model names like grok-4.20-reasoning and older/dated IDs like grok-4-0709; as a result, the model landscape is less clear than with some competitors.
- Well positioned for coding, agentic tool workflows, and document-based analysis. - Exact token prices for some new models are referenced on the official pricing page, but in the officially parseable sources here they are not cleanly extractable for every model.
- xAI explicitly positions Grok 4.20 as a fast, precise model with strict prompt adherence. - xAI itself points out that outputs may hallucinate or be inaccurate and must be reviewed by the customer.
- For enterprise/API data, there is a DPA, a subprocessor list, and according to the Enterprise Terms, a 30-day deletion of User Content unless an exception applies. - For enterprise customers, operating competing services with the xAI API is prohibited according to the Terms.

Data last updated: 17. April 2026

Reviews

0 reviews in total

(0)
5★ 0.0%
4★ 0.0%
3★ 0.0%
2★ 0.0%
1★ 0.0%

There are no confirmed reviews for this tool yet.