Patch release 1.0.45: HTTP/SSE MCP servers can take a rotating bearer token from a file, custom models can show a persistent notice above the prompt, and spawn/compact behavior is tightened.
Changelog
[new] HTTP and SSE MCP servers accept bearer_token_file — an absolute or ~/ path (with optional ${VAR}) that Grok re-reads on every request and sends as Authorization: Bearer. Rotated tokens apply on the next call without restarting or reconnecting; the setting replaces an Authorization header or bearer_token_env_var and skips OAuth discovery. Missing, empty, oversized (>16 KiB), non-UTF-8, or header-illegal files fail the request with the path named. Write the file atomically (temp file, then rename) so a rewrite-in-place cannot race a request.
[new] Custom models can set notice (severity = info / warning / critical, required text, optional label) to pin a non-dismissible banner above the prompt while that model is selected. Remote catalogs may send the same object as notice or _meta.notice. Clear a built-in or remote notice with notice = { text = "" }.
[new] Custom models can advertise several sizes with context_windows (for example context_windows = [256000, 500000]). context_window remains the default — the first listed size when unset — and older clients ignore the list.
[changed] Built-in subagent types still exist as host types, but the model cannot pick them by name; an omitted subagent_type is general-purpose. When plugin, project, or user agents exist, spawn_subagent exposes those types as an optional enum (for example my-plugin:reviewer), restricted further if the parent’s tools list uses Agent(...). Unknown types fail with the list of valid names. Built-in and xAI-bundled agents are not listed.
[changed] /compact is documented without an optional [context] argument.
Upgrade notes
If you compact with extra arguments, switch to /compact with no context parameter.
To hide a notice that a built-in or remote model ships with, set notice = { text = "" } on that model.
If you adopt bearer_token_file, use an absolute or ~/ path and replace the file with a same-directory write-then-rename so readers never see a truncated token.