How to Configure Twitter Authentication Using Cookies in Agent Reach
You can configure Twitter authentication in Agent Reach by extracting cookies from your browser using the CLI command python -m agent_reach.cli configure --from-browser chrome (or firefox, edge, etc.), which stores the auth_token and ct0 values in ~/.agent-reach/config.yaml.
Agent Reach is a Python glue layer that provides AI agents with read and search access to web platforms including Twitter (now X). According to the Panniantong/Agent-Reach source code, the library supports multiple authentication methods for Twitter, with browser cookie extraction being the most convenient for users already logged into the platform. This guide explains how to configure Twitter authentication using cookies, where credentials are stored, and how the authentication flow works across different backends.
Authentication Backends Overview
Agent Reach supports three different backends for Twitter operations, each discovered automatically by TwitterChannel.check() in agent_reach/channels/twitter.py:
- twitter-cli: Discovered by running
twitter statusand inspecting the output - OpenCLI: Detected via
self._check_opencli()which checks if the OpenCLI server is installed and ready - bird (legacy): Located by calling
bird check(orbirdx) and examining the result
When a backend reports ok status, TwitterChannel marks it as active and routes all read and search calls through it. The authentication credentials work across all backends once configured.
Where Twitter Credentials Are Stored
Credentials extracted from browser cookies are stored in multiple locations to ensure compatibility:
Configuration File
The primary storage is ~/.agent-reach/config.yaml, managed by agent_reach/config.py. The relevant keys are:
twitter_auth_tokentwitter_ct0
Environment Variables
The Config.get() method falls back to uppercase environment variables. You can export:
TWITTER_AUTH_TOKENTWITTER_CT0
Legacy Sync Locations
For compatibility with existing tools, agent_reach/cookie_extract.py also synchronizes credentials to:
~/.config/xfetch/session.json(for twitter-cli)~/.config/bird/credentials.env(for bird CLI)
Configuration Methods
Using the CLI with Browser Extraction
The simplest method uses the configure command in agent_reach/cli.py (lines 1070-1085):
# Extract from Chrome (also supports firefox, edge, brave, opera)
python -m agent_reach.cli configure --from-browser chrome
This executes cookie_extract.configure_from_browser(), which:
- Reads the browser's cookie store using
rookiepyorbrowser-cookie3 - Extracts
auth_tokenandct0cookies - Writes them to
~/.agent-reach/config.yaml - Syncs to legacy locations if applicable
Using Environment Variables
For CI/CD or temporary configuration:
export TWITTER_AUTH_TOKEN="your-auth-token-here"
export TWITTER_CT0="your-ct0-value-here"
# Verify configuration
python -m agent_reach.cli doctor
The doctor command invokes TwitterChannel.check(), which reads these values via config.get("twitter_auth_token") and reports ok if valid.
Using the Python API
For programmatic configuration:
from agent_reach.core import AgentReach
from agent_reach.config import Config
# Load configuration from ~/.agent-reach/config.yaml
cfg = Config()
ar = AgentReach(config=cfg)
# Search Twitter
results = ar.search("site:x.com \"machine learning\"")
print(results)
# Read specific tweet
tweet = ar.read("https://x.com/username/status/123456789")
print(tweet)
AgentReach routes requests to TwitterChannel.read() or search(), which delegate to the active backend.
How the Authentication Flow Works
-
Extraction:
configure_from_browser()inagent_reach/cookie_extract.pyreturns a dictionary mapping{"twitter": {"auth_token": "AAA", "ct0": "BBB"}} -
Storage: The configuration step writes these to the YAML config under the standard keys
-
Validation: When Twitter operations run,
TwitterChannel.check()verifies credentials exist viaconfig.get("twitter_auth_token") -
Routing: If credentials are missing, the channel reports warn status and displays a hint to export the environment variables
Inspecting Stored Configuration
To verify credentials without exposing secrets:
from agent_reach.config import Config
cfg = Config()
print(cfg.to_dict()) # Shows only first 8 characters of tokens
The to_dict() method (lines 108-130 in config.py) masks any key containing "auth", "token", or "ct0" to prevent accidental credential leaks.
Summary
- Primary method: Use
python -m agent_reach.cli configure --from-browser <browser>to extract Twitter cookies automatically - Storage locations:
~/.agent-reach/config.yaml(primary), environment variables (fallback), and legacy paths for tool compatibility - Key parameters:
twitter_auth_tokenandtwitter_ct0(orTWITTER_AUTH_TOKENandTWITTER_CT0for env vars) - Backend support: Credentials work across
twitter-cli, OpenCLI, andbirdbackends once configured - Security: The
Config.to_dict()method masks secrets when displaying configuration
Frequently Asked Questions
How do I configure Twitter authentication if I don't use Chrome?
Agent Reach supports extracting cookies from Firefox, Edge, Brave, and Opera in addition to Chrome. Simply replace chrome with your browser name in the command: python -m agent_reach.cli configure --from-browser firefox. The cookie_extract.py module uses rookiepy or browser-cookie3 to read the specific cookie store format for each browser.
What happens if both config file and environment variables are set?
The Config.get() method in agent_reach/config.py checks environment variables as a fallback. If both are present, the configuration file values take precedence during normal operation, but environment variables provide a convenient override for temporary sessions or CI/CD pipelines without modifying files.
Can I use Agent Reach with Twitter without installing a separate CLI tool?
Yes, but you need at least one backend installed. The TwitterChannel class probes for twitter-cli, OpenCLI, or bird automatically. If none are found, the channel reports a warning. The authentication credentials (auth_token and ct0) are required regardless of which backend you choose, as they authenticate your requests to Twitter's API.
Why does Agent Reach sync credentials to legacy locations like ~/.config/xfetch/?
The configure_from_browser() function in agent_reach/cookie_extract.py writes to ~/.config/xfetch/session.json and ~/.config/bird/credentials.env to maintain compatibility with existing standalone tools (twitter-cli and bird). This allows you to use the same credentials both within Agent Reach and when using these CLIs directly outside the Agent Reach ecosystem.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →