Grok custom connectors often never open an OAuth page and have no API-key field. Use a personal MCP URL instead — one paste into Grok, no browser OAuth.
Create a key at Dashboard → API Keys. We validate it against TurboPentest, then sign a path token. The key is not stored on this server.