Patch release: PostToolUse / PostToolUseFailure hooks can rewrite the text the model sees (including large and failed tool results), and the updater understands named channels plus an optional private artifact prefix.
Changelog
[new]PostToolUseFailure hooks can replace the error text the model sees, not only attach additionalContext. They still cannot block. The event’s error field is what a replacement stands in for; updatedToolOutput or updatedMCPToolOutput wins last-writer, and a dispatch failure still reaches the model as Tool \` failed: `.
[changed]PostToolUseupdatedToolOutput accepts a JSON string on any tool and uses it as the model-facing text verbatim, so a redaction hook can mask secrets and send the text back. Structured replacements on built-in tools still have to match grok’s own tagged output shape; a mismatched object is ignored and the original stands.
[fix] Oversized tool results can be redacted. Typed toolResult is sent while its JSON fits in 128 KB; larger results arrive as the full model-facing text with toolResultTruncated set, and a hook can echo that string back. Previously an oversized payload could not be returned as a replacement.
[changed] A replacement may be up to 64 K characters longer than the text it replaces. A redacted copy of a large output is never clipped. Block reasons and additionalContext are still capped at 10,000 characters.
[new]cli.update_base sets an optional private artifact prefix for the internal installer. Only an allowlisted prefix is accepted; the updater attaches a gcloud auth print-access-token bearer only to URLs under that prefix.
[changed]cli.channel is trimmed and lowercased and accepts stable, alpha, enterprise, and other named channels. Blank means stable; unknown names follow stable version rules. A user’s config.toml still wins over a fleet default on this key.
Upgrade notes
Hook authors: send a JSON string when you want to rewrite model-facing text; use PostToolUseFailure when you need to replace error text. Record, transcript, and telemetry still keep the original output.
Private or enterprise installs: set cli.update_base to an allowlisted prefix and run gcloud auth login first. To return to the public channel, set update_base = "" and run grok update --stable.