# How to Configure Twitter Authentication Using Cookies in Agent Reach

> Easily configure Twitter authentication in Agent Reach using browser cookies. Learn how to extract auth tokens via the CLI and store them for secure access. Get started now.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-07-04

---

**You can configure Twitter authentication in Agent Reach by extracting cookies from your browser using the CLI command `python -m agent_reach.cli configure --from-browser chrome` (or firefox, edge, etc.), which stores the `auth_token` and `ct0` values in `~/.agent-reach/config.yaml`.**

Agent Reach is a Python glue layer that provides AI agents with read and search access to web platforms including Twitter (now X). According to the Panniantong/Agent-Reach source code, the library supports multiple authentication methods for Twitter, with browser cookie extraction being the most convenient for users already logged into the platform. This guide explains how to configure Twitter authentication using cookies, where credentials are stored, and how the authentication flow works across different backends.

## Authentication Backends Overview

Agent Reach supports three different backends for Twitter operations, each discovered automatically by `TwitterChannel.check()` in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py):

- **twitter-cli**: Discovered by running `twitter status` and inspecting the output
- **OpenCLI**: Detected via `self._check_opencli()` which checks if the OpenCLI server is installed and ready
- **bird** (legacy): Located by calling `bird check` (or `birdx`) and examining the result

When a backend reports **ok** status, `TwitterChannel` marks it as active and routes all `read` and `search` calls through it. The authentication credentials work across all backends once configured.

## Where Twitter Credentials Are Stored

Credentials extracted from browser cookies are stored in multiple locations to ensure compatibility:

### Configuration File

The primary storage is `~/.agent-reach/config.yaml`, managed by [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py). The relevant keys are:
- `twitter_auth_token`
- `twitter_ct0`

### Environment Variables

The `Config.get()` method falls back to uppercase environment variables. You can export:
- `TWITTER_AUTH_TOKEN`
- `TWITTER_CT0`

### Legacy Sync Locations

For compatibility with existing tools, [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) also synchronizes credentials to:
- `~/.config/xfetch/session.json` (for twitter-cli)
- `~/.config/bird/credentials.env` (for bird CLI)

## Configuration Methods

### Using the CLI with Browser Extraction

The simplest method uses the `configure` command in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 1070-1085):

```bash

# Extract from Chrome (also supports firefox, edge, brave, opera)

python -m agent_reach.cli configure --from-browser chrome

```

This executes `cookie_extract.configure_from_browser()`, which:
1. Reads the browser's cookie store using `rookiepy` or `browser-cookie3`
2. Extracts `auth_token` and `ct0` cookies
3. Writes them to `~/.agent-reach/config.yaml`
4. Syncs to legacy locations if applicable

### Using Environment Variables

For CI/CD or temporary configuration:

```bash
export TWITTER_AUTH_TOKEN="your-auth-token-here"
export TWITTER_CT0="your-ct0-value-here"

# Verify configuration

python -m agent_reach.cli doctor

```

The `doctor` command invokes `TwitterChannel.check()`, which reads these values via `config.get("twitter_auth_token")` and reports **ok** if valid.

### Using the Python API

For programmatic configuration:

```python
from agent_reach.core import AgentReach
from agent_reach.config import Config

# Load configuration from ~/.agent-reach/config.yaml

cfg = Config()
ar = AgentReach(config=cfg)

# Search Twitter

results = ar.search("site:x.com \"machine learning\"")
print(results)

# Read specific tweet

tweet = ar.read("https://x.com/username/status/123456789")
print(tweet)

```

`AgentReach` routes requests to `TwitterChannel.read()` or `search()`, which delegate to the active backend.

## How the Authentication Flow Works

1. **Extraction**: `configure_from_browser()` in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) returns a dictionary mapping `{"twitter": {"auth_token": "AAA", "ct0": "BBB"}}`

2. **Storage**: The configuration step writes these to the YAML config under the standard keys

3. **Validation**: When Twitter operations run, `TwitterChannel.check()` verifies credentials exist via `config.get("twitter_auth_token")`

4. **Routing**: If credentials are missing, the channel reports **warn** status and displays a hint to export the environment variables

### Inspecting Stored Configuration

To verify credentials without exposing secrets:

```python
from agent_reach.config import Config

cfg = Config()
print(cfg.to_dict())  # Shows only first 8 characters of tokens

```

The `to_dict()` method (lines 108-130 in [`config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/config.py)) masks any key containing "auth", "token", or "ct0" to prevent accidental credential leaks.

## Summary

- **Primary method**: Use `python -m agent_reach.cli configure --from-browser <browser>` to extract Twitter cookies automatically
- **Storage locations**: `~/.agent-reach/config.yaml` (primary), environment variables (fallback), and legacy paths for tool compatibility
- **Key parameters**: `twitter_auth_token` and `twitter_ct0` (or `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` for env vars)
- **Backend support**: Credentials work across `twitter-cli`, OpenCLI, and `bird` backends once configured
- **Security**: The `Config.to_dict()` method masks secrets when displaying configuration

## Frequently Asked Questions

### How do I configure Twitter authentication if I don't use Chrome?

Agent Reach supports extracting cookies from Firefox, Edge, Brave, and Opera in addition to Chrome. Simply replace `chrome` with your browser name in the command: `python -m agent_reach.cli configure --from-browser firefox`. The [`cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/cookie_extract.py) module uses `rookiepy` or `browser-cookie3` to read the specific cookie store format for each browser.

### What happens if both config file and environment variables are set?

The `Config.get()` method in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) checks environment variables as a fallback. If both are present, the configuration file values take precedence during normal operation, but environment variables provide a convenient override for temporary sessions or CI/CD pipelines without modifying files.

### Can I use Agent Reach with Twitter without installing a separate CLI tool?

Yes, but you need at least one backend installed. The `TwitterChannel` class probes for `twitter-cli`, OpenCLI, or `bird` automatically. If none are found, the channel reports a warning. The authentication credentials (auth_token and ct0) are required regardless of which backend you choose, as they authenticate your requests to Twitter's API.

### Why does Agent Reach sync credentials to legacy locations like `~/.config/xfetch/`?

The `configure_from_browser()` function in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) writes to `~/.config/xfetch/session.json` and `~/.config/bird/credentials.env` to maintain compatibility with existing standalone tools (`twitter-cli` and `bird`). This allows you to use the same credentials both within Agent Reach and when using these CLIs directly outside the Agent Reach ecosystem.