# How to Configure Twitter Cookies for Agent-Reach Using Cookie-Editor

> Learn how to configure Twitter cookies for Agent-Reach using Cookie-Editor. Extract auth_token and ct0 from Twitter/X easily and store them for seamless integration with Agent-Reach.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-07-01

---

**Configure Twitter cookies for Agent-Reach by extracting `auth_token` and `ct0` from Twitter/X using the Cookie-Editor extension, then run `agent-reach configure twitter-cookies AUTH_TOKEN CT0` to store them in `~/.agent-reach/config.yaml`.**

Agent-Reach requires active Twitter/X authentication to enable agent-based interactions with the platform. According to the [Panniantong/Agent-Reach](https://github.com/Panniantong/Agent-Reach) source code, the CLI persists two specific session cookies—`auth_token` and `ct0`—in your local configuration to authenticate API requests. This guide demonstrates how to extract these credentials using Cookie-Editor and configure them using the official CLI commands.

## Required Cookies and Storage Locations

Agent-Reach uses two specific X (Twitter) authentication tokens that must be present in your configuration file:

- **`auth_token`**: The primary session authentication token
- **`ct0`**: The CSRF token required for API validation

These values are stored in `~/.agent-reach/config.yaml` under the keys `twitter_auth_token` and `twitter_ct0`, as defined in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) lines 22-25. The configuration system also synchronizes these credentials to legacy helper tools including `xfetch` (`~/.config/xfetch/session.json`) and `bird-cli` (`~/.config/bird/credentials.env`) for backward compatibility.

## Method 1: Manual Configuration Using Cookie-Editor

This method uses the Cookie-Editor browser extension to extract values directly from your logged-in Twitter/X session.

### Step 1: Extract Cookies from Twitter/X

1. Install the [Cookie-Editor](https://cookie-editor.com/) extension for Chrome, Firefox, or Edge.
2. Navigate to `x.com` (or `twitter.com`) and ensure you are logged in.
3. Click the Cookie-Editor extension icon to open the cookie inspector.
4. Locate and copy the value for the `auth_token` cookie.
5. Locate and copy the value for the `ct0` cookie.

Alternatively, export the raw cookie header string from Cookie-Editor using the "Copy > Copy Cookies" option, which produces a format like `auth_token=AAA; ct0=BBB; other=value`.

### Step 2: Configure Agent-Reach via CLI

Pass the extracted values to the configuration command. The CLI accepts either separate arguments or a raw cookie string:

```bash

# Option A: Two separate values

agent-reach configure twitter-cookies YOUR_AUTH_TOKEN_VALUE YOUR_CT0_VALUE

# Option B: Raw cookie header string (from Cookie-Editor's "Copy Cookies")

agent-reach configure twitter-cookies "auth_token=AAA; ct0=BBB; other=ignore"

```

The parsing logic in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 24-42) handles both formats via the `_parse_twitter_cookie_input` function, extracting only the required `auth_token` and `ct0` keys while ignoring extraneous values.

### Step 3: Validation

The CLI validates credentials by spawning `twitter status` as a subprocess. In [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) lines 65-78, the `_cmd_configure` function temporarily exports the cookies as `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables for the validation check. Upon success, you will see:

```

✅ Twitter cookies configured!
Testing Twitter access... ✅ Twitter access works!

```

## Method 2: Automatic Extraction from Browser

If you prefer not to use Cookie-Editor manually, Agent-Reach can automatically extract cookies from supported browsers (Chrome, Firefox, Edge, Brave, or Opera):

```bash
agent-reach configure --from-browser chrome

```

This command invokes `configure_from_browser` in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) (lines 18-35), which uses either **rookiepy** or **browser-cookie3** to read the browser's cookie store. When successful, it automatically sets:

```python
config.set("twitter_auth_token", tc["auth_token"])
config.set("twitter_ct0", tc["ct0"])

```

The function also calls `_sync_xfetch_session` and `_sync_bird_env` to update legacy tool configurations.

## Verification and Troubleshooting

Confirm your configuration is properly stored:

```bash
cat ~/.agent-reach/config.yaml

```

Expected output:

```yaml
twitter_auth_token: "your_auth_token_here..."
twitter_ct0: "your_ct0_here..."

```

If the automatic validation fails during configuration, verify that:
- You are currently logged into Twitter/X in your browser
- The `ct0` token has not expired (refresh the Twitter page and re-copy from Cookie-Editor)
- You have write permissions for `~/.agent-reach/`

Run `agent-reach doctor` to check the status of all configured channels including Twitter/X.

## Summary

- **Agent-Reach requires two cookies**: `auth_token` and `ct0` from Twitter/X to authenticate agent operations.
- **Storage location**: These are persisted in `~/.agent-reach/config.yaml` under keys `twitter_auth_token` and `twitter_ct0` via the `Config` class in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py).
- **Cookie-Editor method**: Extract the two values manually and pass them to `agent-reach configure twitter-cookies`.
- **Automatic method**: Use `agent-reach configure --from-browser chrome` to extract cookies directly from browser storage using [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py).
- **Validation**: The CLI automatically tests credentials by running `twitter status` via subprocess injection of `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables.
- **Legacy sync**: Credentials automatically sync to `xfetch` and `bird-cli` configurations for backward compatibility.

## Frequently Asked Questions

### What specific cookies does Agent-Reach need from Twitter/X?

Agent-Reach specifically requires the **`auth_token`** and **`ct0`** cookies. The `auth_token` serves as the primary session identifier, while `ct0` functions as the CSRF token required for validating API requests to X (Twitter). These are stored in your configuration file under the keys `twitter_auth_token` and `twitter_ct0` respectively.

### Can I use a raw cookie string from Cookie-Editor instead of separate values?

Yes. The CLI's `_parse_twitter_cookie_input` function in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 24-42) accepts a raw cookie header string (e.g., `"auth_token=AAA; ct0=BBB; other=ignore"`) and extracts only the required values. You can paste the entire string copied from Cookie-Editor's "Copy Cookies" function directly into the `agent-reach configure twitter-cookies` command.

### Where does Agent-Reach store the Twitter cookies after configuration?

The cookies are persisted in **`~/.agent-reach/config.yaml`**. The `Config` class in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) handles the reading and writing of these values. Additionally, the system synchronizes these credentials to `~/.config/xfetch/session.json` for the legacy xfetch tool and `~/.config/bird/credentials.env` for the bird-cli tool.

### How does Agent-Reach verify that the Twitter cookies are valid?

During configuration, the CLI spawns a subprocess running `twitter status` and checks the output for `"ok: true"` to confirm the credentials work. As implemented in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) lines 65-78, the `_cmd_configure` function temporarily injects the cookies as `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables for the validation check. If validation fails, you can re-run the configuration step after refreshing your browser session and extracting fresh cookies using Cookie-Editor.