How to Configure Twitter Cookies for Agent-Reach Using Cookie-Editor

Configure Twitter cookies for Agent-Reach by extracting auth_token and ct0 from Twitter/X using the Cookie-Editor extension, then run agent-reach configure twitter-cookies AUTH_TOKEN CT0 to store them in ~/.agent-reach/config.yaml.

Agent-Reach requires active Twitter/X authentication to enable agent-based interactions with the platform. According to the Panniantong/Agent-Reach source code, the CLI persists two specific session cookies—auth_token and ct0—in your local configuration to authenticate API requests. This guide demonstrates how to extract these credentials using Cookie-Editor and configure them using the official CLI commands.

Required Cookies and Storage Locations

Agent-Reach uses two specific X (Twitter) authentication tokens that must be present in your configuration file:

  • auth_token: The primary session authentication token
  • ct0: The CSRF token required for API validation

These values are stored in ~/.agent-reach/config.yaml under the keys twitter_auth_token and twitter_ct0, as defined in agent_reach/config.py lines 22-25. The configuration system also synchronizes these credentials to legacy helper tools including xfetch (~/.config/xfetch/session.json) and bird-cli (~/.config/bird/credentials.env) for backward compatibility.

This method uses the Cookie-Editor browser extension to extract values directly from your logged-in Twitter/X session.

Step 1: Extract Cookies from Twitter/X

  1. Install the Cookie-Editor extension for Chrome, Firefox, or Edge.
  2. Navigate to x.com (or twitter.com) and ensure you are logged in.
  3. Click the Cookie-Editor extension icon to open the cookie inspector.
  4. Locate and copy the value for the auth_token cookie.
  5. Locate and copy the value for the ct0 cookie.

Alternatively, export the raw cookie header string from Cookie-Editor using the "Copy > Copy Cookies" option, which produces a format like auth_token=AAA; ct0=BBB; other=value.

Step 2: Configure Agent-Reach via CLI

Pass the extracted values to the configuration command. The CLI accepts either separate arguments or a raw cookie string:


# Option A: Two separate values

agent-reach configure twitter-cookies YOUR_AUTH_TOKEN_VALUE YOUR_CT0_VALUE

# Option B: Raw cookie header string (from Cookie-Editor's "Copy Cookies")

agent-reach configure twitter-cookies "auth_token=AAA; ct0=BBB; other=ignore"

The parsing logic in agent_reach/cli.py (lines 24-42) handles both formats via the _parse_twitter_cookie_input function, extracting only the required auth_token and ct0 keys while ignoring extraneous values.

Step 3: Validation

The CLI validates credentials by spawning twitter status as a subprocess. In agent_reach/cli.py lines 65-78, the _cmd_configure function temporarily exports the cookies as TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables for the validation check. Upon success, you will see:


✅ Twitter cookies configured!
Testing Twitter access... ✅ Twitter access works!

Method 2: Automatic Extraction from Browser

If you prefer not to use Cookie-Editor manually, Agent-Reach can automatically extract cookies from supported browsers (Chrome, Firefox, Edge, Brave, or Opera):

agent-reach configure --from-browser chrome

This command invokes configure_from_browser in agent_reach/cookie_extract.py (lines 18-35), which uses either rookiepy or browser-cookie3 to read the browser's cookie store. When successful, it automatically sets:

config.set("twitter_auth_token", tc["auth_token"])
config.set("twitter_ct0", tc["ct0"])

The function also calls _sync_xfetch_session and _sync_bird_env to update legacy tool configurations.

Verification and Troubleshooting

Confirm your configuration is properly stored:

cat ~/.agent-reach/config.yaml

Expected output:

twitter_auth_token: "your_auth_token_here..."
twitter_ct0: "your_ct0_here..."

If the automatic validation fails during configuration, verify that:

  • You are currently logged into Twitter/X in your browser
  • The ct0 token has not expired (refresh the Twitter page and re-copy from Cookie-Editor)
  • You have write permissions for ~/.agent-reach/

Run agent-reach doctor to check the status of all configured channels including Twitter/X.

Summary

  • Agent-Reach requires two cookies: auth_token and ct0 from Twitter/X to authenticate agent operations.
  • Storage location: These are persisted in ~/.agent-reach/config.yaml under keys twitter_auth_token and twitter_ct0 via the Config class in agent_reach/config.py.
  • Cookie-Editor method: Extract the two values manually and pass them to agent-reach configure twitter-cookies.
  • Automatic method: Use agent-reach configure --from-browser chrome to extract cookies directly from browser storage using agent_reach/cookie_extract.py.
  • Validation: The CLI automatically tests credentials by running twitter status via subprocess injection of TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables.
  • Legacy sync: Credentials automatically sync to xfetch and bird-cli configurations for backward compatibility.

Frequently Asked Questions

What specific cookies does Agent-Reach need from Twitter/X?

Agent-Reach specifically requires the auth_token and ct0 cookies. The auth_token serves as the primary session identifier, while ct0 functions as the CSRF token required for validating API requests to X (Twitter). These are stored in your configuration file under the keys twitter_auth_token and twitter_ct0 respectively.

Yes. The CLI's _parse_twitter_cookie_input function in agent_reach/cli.py (lines 24-42) accepts a raw cookie header string (e.g., "auth_token=AAA; ct0=BBB; other=ignore") and extracts only the required values. You can paste the entire string copied from Cookie-Editor's "Copy Cookies" function directly into the agent-reach configure twitter-cookies command.

Where does Agent-Reach store the Twitter cookies after configuration?

The cookies are persisted in ~/.agent-reach/config.yaml. The Config class in agent_reach/config.py handles the reading and writing of these values. Additionally, the system synchronizes these credentials to ~/.config/xfetch/session.json for the legacy xfetch tool and ~/.config/bird/credentials.env for the bird-cli tool.

How does Agent-Reach verify that the Twitter cookies are valid?

During configuration, the CLI spawns a subprocess running twitter status and checks the output for "ok: true" to confirm the credentials work. As implemented in agent_reach/cli.py lines 65-78, the _cmd_configure function temporarily injects the cookies as TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables for the validation check. If validation fails, you can re-run the configuration step after refreshing your browser session and extracting fresh cookies using Cookie-Editor.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →