# Agent Reach Platform Authentication Methods: Complete Guide for All Supported Channels

> Master Agent Reach platform authentication methods for Twitter, Reddit, GitHub, and more. Explore environment variables, CLI logins, and browser cookies for secure access.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-07-02

---

**Agent Reach requires authentication for Twitter, Reddit, GitHub, XiaoHongShu, and LinkedIn via environment variables, CLI logins, or browser cookies, while YouTube, V2EX, and Bilibili support unauthenticated access.**

The Panniantong/Agent-Reach repository provides a unified "glue" layer that routes AI agent calls to native platform CLIs and APIs. Understanding the specific Agent Reach platform authentication methods for each supported channel is essential for seamless integration, as the system detects required credentials through the `check()` method and reports status as `ok`, `warn`, `error`, or `off`.

## Authentication Requirements by Platform

Agent Reach supports multiple backends per platform, each with distinct authentication mechanisms. The `doctor` command aggregates these checks and provides remediation steps when credentials are missing.

### Platforms Requiring Authentication

The following platforms mandate a logged-in session for all backend implementations:

- **Twitter / X**: Requires active session via `twitter-cli`, `bird CLI`, or `OpenCLI`
- **Reddit**: Requires logged-in state for `rdt-cli` or browser cookies for `OpenCLI`
- **XiaoHongShu (XHS)**: Requires authentication for `xhs-cli`, `xiaohongshu-mcp`, and `OpenCLI`
- **GitHub**: Requires authenticated `gh` CLI
- **LinkedIn**: Requires configured MCP server with browser-derived cookies

### Platforms Without Authentication

The following platforms operate without login credentials:

- **YouTube**: Uses `yt-dlp` to access public video information and subtitles
- **V2EX**: Connects to public API endpoints
- **Bilibili**: Supports unauthenticated access via `bili-cli` (optional login for OpenCLI subtitle extraction)

## How Authentication Works in Agent Reach

Each channel implements a `check()` method that verifies backend availability and authentication status. As implemented in Panniantong/Agent-Reach, these methods inspect environment variables, configuration files, and CLI session states to determine whether the platform is ready for use.

The system checks for:
- Environment variables containing tokens (e.g., `TWITTER_AUTH_TOKEN`)
- Credential files in standard locations (e.g., `~/.config/gh/hosts.yml`)
- Browser session cookies (for OpenCLI-based backends)
- Running MCP server configurations

## Setting Up Authentication for Each Platform

### Twitter / X Configuration

In [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py) (lines 84-88), the `_check_twitter_cli` method validates three potential backends:

**twitter-cli** requires environment variables:

```bash
export TWITTER_AUTH_TOKEN="YOUR_TWITTER_BEARER_TOKEN"
export TWITTER_CT0="YOUR_TWITTER_CT0_COOKIE"

```

**bird CLI** expects similar variables:

```bash
export AUTH_TOKEN="YOUR_TWITTER_BEARER_TOKEN"
export CT0="YOUR_TWITTER_CT0_COOKIE"

```

**OpenCLI** automatically re-uses Chrome or Edge login sessions without additional configuration.

### Reddit Authentication

According to [`agent_reach/channels/reddit.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/reddit.py) (lines 141-155), the `_check_rdt` method handles two backends:

**rdt-cli** stores credentials in `~/.config/rdt-cli/credential.json`. Initialize with:

```bash
rdt login

# Opens browser for OAuth; cookies saved automatically

```

**OpenCLI** uses the browser's existing Reddit cookies without separate CLI authentication.

### GitHub CLI Setup

The `GitHubChannel.check` method in [`agent_reach/channels/github.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/github.py) (lines 40-42) verifies `gh` CLI authentication:

```bash
gh auth login

# Follow interactive OAuth/device flow

# Token stored in ~/.config/gh/hosts.yml

```

### XiaoHongShu (XHS) Login Methods

As defined in [`agent_reach/channels/xiaohongshu.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/xiaohongshu.py) (lines 49-53), three backends support XHS:

**xhs-cli** provides native login:

```bash
xhs login

# Launches browser tab or QR-code flow

```

**xiaohongshu-mcp** runs a local MCP server supporting QR-code authentication.

**OpenCLI** re-uses Chrome login state for immediate access.

### LinkedIn MCP Configuration

The `LinkedInChannel.check` method in [`agent_reach/channels/linkedin.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/linkedin.py) (lines 36-38) requires MCP server setup:

```bash
npm install -g mcporter
mcporter config add linkedin http://localhost:3000/mcp

# Extracts logged-in cookies from browser session

```

## Summary

- **Authentication required**: Twitter/X, Reddit, GitHub, XiaoHongShu, and LinkedIn require active sessions via environment variables, CLI logins, or browser cookies
- **No authentication**: YouTube, V2EX, and Bilibili (`bili-cli`) work without credentials
- **Detection method**: The `check()` method in each channel file verifies backend-specific requirements
- **Remediation**: The `doctor` command provides platform-specific setup instructions when authentication is missing
- **Storage locations**: Credentials reside in environment variables, `~/.config/` directories, or browser cookie stores depending on the backend

## Frequently Asked Questions

### Does Agent Reach store my social media passwords?

No. Agent Reach does not store passwords directly. According to the source code, the platform relies on external CLI tools (`gh`, `rdt`, `xhs`) or browser cookies to maintain sessions. Credentials remain in the native tool's configuration files (e.g., `~/.config/gh/hosts.yml`) or environment variables, not within Agent Reach itself.

### Can I use Agent Reach without installing platform-specific CLIs?

Partially. Platforms like YouTube and V2EX require no authentication and minimal setup. However, Twitter, Reddit, GitHub, and LinkedIn require their respective CLI tools or MCP servers to be installed and authenticated before Agent Reach can route requests to them.

### What happens if authentication expires during operation?

The `check()` method reports the current status as `ok`, `warn`, `error`, or `off`. If a session expires, the channel will return `error` or `warn` status, and the `doctor` command will suggest re-authentication steps specific to that platform (e.g., running `gh auth login` or exporting fresh `TWITTER_AUTH_TOKEN` values).

### Is OpenCLI authentication secure for production use?

OpenCLI re-uses existing browser sessions from Chrome or Edge, which is convenient for development but depends on browser security. For production deployments, CLI-based authentication with explicit tokens (using `twitter-cli`, `rdt-cli`, or `gh auth login`) provides more controlled and auditable credential management.