From creating the canal to registering a custom connector on grok.com, granting approval, and verifying it works. A careful step-by-step walkthrough with screenshots of the actual screens.
We will make the MCP server running on your local (in-house) machine usable from Grok — without opening any inbound ports. The flow has 4 parts: create a canal in WireCanal → start the Agent → register the connector in Grok → approve the connection.
http://localhost:9310/mcp)On the dashboard, click "Create a new canal", choose MCP as the type, and click "Next".

Just pick the AI you will use, and the connection settings for that AI are prepared automatically. Here, check Grok.

For the public address (hostname), the "auto-assigned subdomain" is fine. You can also reserve a name of your choice or use a custom domain.

For the forwarding target, enter the address of the MCP server running on your machine (e.g. localhost:9310).


Right after creation, the "MCP connection" tab shows the client ID and client secret for the Grok connection (the secret is shown only this once). For the normal flow below you will not need them — Grok registers itself with WireCanal automatically. Note them down only if you plan to configure the OAuth settings manually.

Download the configuration file wirecanal.json from the "Setup" tab, and list only the tool names you are willing to show to the outside AI in tools.allow (the default is deny-all). For the syntax and all options, see the wirecanal.json configuration reference.

{
"access_key": "ck_...",
"forward_target": "localhost:9310",
"mode": "mcp",
"tools": { "default": "deny", "allow": ["get_time", "echo"] }
}Start the Agent on the same machine. No inbound ports need to be opened. If you have not installed the Agent yet, or want to keep it running as a service (auto-start), see the OS-specific setup guides.
wirecanal.exe -config wirecanal.jsonWhen the startup log shows a line saying that canal <ID> will deliver access to https://<hostname> to your local forwarding target, the connection is established.
On grok.com, open "Skills and Connectors" in the left menu → "New Connector", and choose "Custom (add your own custom connector)".

Enter a name (anything you like) and the Server URL (the canal's public URL + /mcp, e.g. https://<hostname>/mcp), then click "Add Connector". Grok registers itself with WireCanal automatically (no client ID or secret to paste), and WireCanal's connection-consent screen opens in a popup window.

If Grok asks for OAuth credentials instead, paste the client ID / secret from step 6 and set the token authentication method to client_secret_post — everything else can stay at the auto-detected values.
In the popup, review the details and simply click "Approve". Only the canal owner can grant approval.
Log in to both Grok and WireCanal in the same browser (same profile). If they are split across profiles, a login screen will open instead of the consent screen.

When your connector shows Connected under the "Installed" section of "Skills and Connectors", the connection is complete.

Just mention the connector by name in a chat and call the tool. For example, ask "Use get_time to tell me the current time in Japan" — and the real data returned by your local MCP server is used in Grok's answer.

If a tool is not in tools.allow, the local Agent refuses it on the spot even when the AI tries to call it, and the call never reaches your in-house MCP server. We have verified this behavior in real connections with Grok as well (two-key).
Sign-up is free. No credit card required — create your first canal right now.
Sign up free and get started