How to Configure Twitter Cookies for Agent-Reach Using Cookie-Editor
Configure Twitter cookies for Agent-Reach by extracting auth_token and ct0 from Twitter/X using the Cookie-Editor extension, then run agent-reach configure twitter-cookies AUTH_TOKEN CT0 to store them in ~/.agent-reach/config.yaml.
Agent-Reach requires active Twitter/X authentication to enable agent-based interactions with the platform. According to the Panniantong/Agent-Reach source code, the CLI persists two specific session cookies—auth_token and ct0—in your local configuration to authenticate API requests. This guide demonstrates how to extract these credentials using Cookie-Editor and configure them using the official CLI commands.
Required Cookies and Storage Locations
Agent-Reach uses two specific X (Twitter) authentication tokens that must be present in your configuration file:
auth_token: The primary session authentication tokenct0: The CSRF token required for API validation
These values are stored in ~/.agent-reach/config.yaml under the keys twitter_auth_token and twitter_ct0, as defined in agent_reach/config.py lines 22-25. The configuration system also synchronizes these credentials to legacy helper tools including xfetch (~/.config/xfetch/session.json) and bird-cli (~/.config/bird/credentials.env) for backward compatibility.
Method 1: Manual Configuration Using Cookie-Editor
This method uses the Cookie-Editor browser extension to extract values directly from your logged-in Twitter/X session.
Step 1: Extract Cookies from Twitter/X
- Install the Cookie-Editor extension for Chrome, Firefox, or Edge.
- Navigate to
x.com(ortwitter.com) and ensure you are logged in. - Click the Cookie-Editor extension icon to open the cookie inspector.
- Locate and copy the value for the
auth_tokencookie. - Locate and copy the value for the
ct0cookie.
Alternatively, export the raw cookie header string from Cookie-Editor using the "Copy > Copy Cookies" option, which produces a format like auth_token=AAA; ct0=BBB; other=value.
Step 2: Configure Agent-Reach via CLI
Pass the extracted values to the configuration command. The CLI accepts either separate arguments or a raw cookie string:
# Option A: Two separate values
agent-reach configure twitter-cookies YOUR_AUTH_TOKEN_VALUE YOUR_CT0_VALUE
# Option B: Raw cookie header string (from Cookie-Editor's "Copy Cookies")
agent-reach configure twitter-cookies "auth_token=AAA; ct0=BBB; other=ignore"
The parsing logic in agent_reach/cli.py (lines 24-42) handles both formats via the _parse_twitter_cookie_input function, extracting only the required auth_token and ct0 keys while ignoring extraneous values.
Step 3: Validation
The CLI validates credentials by spawning twitter status as a subprocess. In agent_reach/cli.py lines 65-78, the _cmd_configure function temporarily exports the cookies as TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables for the validation check. Upon success, you will see:
✅ Twitter cookies configured!
Testing Twitter access... ✅ Twitter access works!
Method 2: Automatic Extraction from Browser
If you prefer not to use Cookie-Editor manually, Agent-Reach can automatically extract cookies from supported browsers (Chrome, Firefox, Edge, Brave, or Opera):
agent-reach configure --from-browser chrome
This command invokes configure_from_browser in agent_reach/cookie_extract.py (lines 18-35), which uses either rookiepy or browser-cookie3 to read the browser's cookie store. When successful, it automatically sets:
config.set("twitter_auth_token", tc["auth_token"])
config.set("twitter_ct0", tc["ct0"])
The function also calls _sync_xfetch_session and _sync_bird_env to update legacy tool configurations.
Verification and Troubleshooting
Confirm your configuration is properly stored:
cat ~/.agent-reach/config.yaml
Expected output:
twitter_auth_token: "your_auth_token_here..."
twitter_ct0: "your_ct0_here..."
If the automatic validation fails during configuration, verify that:
- You are currently logged into Twitter/X in your browser
- The
ct0token has not expired (refresh the Twitter page and re-copy from Cookie-Editor) - You have write permissions for
~/.agent-reach/
Run agent-reach doctor to check the status of all configured channels including Twitter/X.
Summary
- Agent-Reach requires two cookies:
auth_tokenandct0from Twitter/X to authenticate agent operations. - Storage location: These are persisted in
~/.agent-reach/config.yamlunder keystwitter_auth_tokenandtwitter_ct0via theConfigclass inagent_reach/config.py. - Cookie-Editor method: Extract the two values manually and pass them to
agent-reach configure twitter-cookies. - Automatic method: Use
agent-reach configure --from-browser chrometo extract cookies directly from browser storage usingagent_reach/cookie_extract.py. - Validation: The CLI automatically tests credentials by running
twitter statusvia subprocess injection ofTWITTER_AUTH_TOKENandTWITTER_CT0environment variables. - Legacy sync: Credentials automatically sync to
xfetchandbird-cliconfigurations for backward compatibility.
Frequently Asked Questions
What specific cookies does Agent-Reach need from Twitter/X?
Agent-Reach specifically requires the auth_token and ct0 cookies. The auth_token serves as the primary session identifier, while ct0 functions as the CSRF token required for validating API requests to X (Twitter). These are stored in your configuration file under the keys twitter_auth_token and twitter_ct0 respectively.
Can I use a raw cookie string from Cookie-Editor instead of separate values?
Yes. The CLI's _parse_twitter_cookie_input function in agent_reach/cli.py (lines 24-42) accepts a raw cookie header string (e.g., "auth_token=AAA; ct0=BBB; other=ignore") and extracts only the required values. You can paste the entire string copied from Cookie-Editor's "Copy Cookies" function directly into the agent-reach configure twitter-cookies command.
Where does Agent-Reach store the Twitter cookies after configuration?
The cookies are persisted in ~/.agent-reach/config.yaml. The Config class in agent_reach/config.py handles the reading and writing of these values. Additionally, the system synchronizes these credentials to ~/.config/xfetch/session.json for the legacy xfetch tool and ~/.config/bird/credentials.env for the bird-cli tool.
How does Agent-Reach verify that the Twitter cookies are valid?
During configuration, the CLI spawns a subprocess running twitter status and checks the output for "ok: true" to confirm the credentials work. As implemented in agent_reach/cli.py lines 65-78, the _cmd_configure function temporarily injects the cookies as TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables for the validation check. If validation fails, you can re-run the configuration step after refreshing your browser session and extracting fresh cookies using Cookie-Editor.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →