How to Configure Twitter Cookies for Agent-Reach: Manual and Automatic Methods
Agent-Reach requires the auth_token and ct0 cookies from X (formerly Twitter) to authenticate API requests, which you can configure either manually via the CLI or automatically by extracting them from Chrome, Firefox, Edge, Brave, or Opera.
Agent-Reach is an open-source automation framework maintained in the Panniantong/Agent-Reach repository that enables AI agents to interact with social platforms. To enable Twitter functionality, you must configure Twitter cookies for Agent-Reach by providing the two authentication tokens that X uses to validate browser sessions. This process stores credentials in ~/.agent-reach/config.yaml and synchronizes them to helper tools that interface with the platform.
Understanding the Required Twitter Credentials
Agent-Reach specifically looks for two authentication cookies that X uses to maintain logged-in sessions:
auth_token– The session authentication token that identifies your X accountct0– The cross-site request forgery (CSRF) token required for API validation
These values map to configuration keys twitter_auth_token and twitter_ct0 in the Agent-Reach configuration system. When the CLI runs, it reads these keys from ~/.agent-reach/config.yaml (handled by the Config class in agent_reach/config.py lines 22-25) and injects them into subprocess environments as TWITTER_AUTH_TOKEN and TWITTER_CT0 for compatibility with external tools like twitter-cli.
Method 1: Configure Twitter Cookies Manually via CLI
The agent-reach configure twitter-cookies command accepts credentials in two formats, both parsed by the _parse_twitter_cookie_input function in agent_reach/cli.py (lines 24-42).
Using Separate Arguments
Provide the two cookie values as distinct positional arguments:
agent-reach configure twitter-cookies AUTH_TOKEN_VALUE CT0_VALUE
The CLI validates these values immediately by executing twitter status via subprocess.run (as implemented in _cmd_configure in agent_reach/cli.py lines 65-78) and checking for "ok: true" in the output.
Using Raw Cookie Header Format
If you have copied a raw cookie string from browser developer tools (Chrome’s "Copy > Copy Cookies"), pass it as a single quoted string:
agent-reach configure twitter-cookies "auth_token=AAA; ct0=BBB; other=ignore"
The parser extracts only the auth_token and ct0 values, ignoring other cookies in the string.
Validation Process
After successful storage, the CLI tests connectivity by running twitter status. You will see output similar to:
✅ Twitter cookies configured!
Testing Twitter access... ✅ Twitter access works!
If validation fails, the configuration step returns an error and you must re-run the command with corrected values.
Method 2: Automatic Browser Cookie Extraction
For convenience, Agent-Reach can extract cookies directly from your locally installed browsers using the configure --from-browser command.
Supported Browsers
The automatic extraction supports Chrome, Firefox, Edge, Brave, and Opera. Specify the browser name as an argument:
agent-reach configure --from-browser chrome
You can also use firefox, edge, brave, or opera as the browser value.
How Automatic Extraction Works
Under the hood, the configure_from_browser function in agent_reach/cookie_extract.py (lines 20-35) iterates through supported platforms using either rookiepy or browser-cookie3 libraries to extract cookies. When it finds X (Twitter) cookies, it executes the following logic:
if "twitter" in extracted:
tc = extracted["twitter"]
if "auth_token" in tc and "ct0" in tc:
config.set("twitter_auth_token", tc["auth_token"])
config.set("twitter_ct0", tc["ct0"])
_sync_xfetch_session(tc["auth_token"], tc["ct0"])
This writes the values to your configuration file and synchronizes them to legacy tools. Successful extraction produces output showing:
Extracting cookies from chrome...
✅ Twitter/X: auth_token + ct0
...
✅ Cookies configured! Run `agent-reach doctor` to see updated status.
Where Credentials Are Stored and Synced
Understanding the storage architecture helps when troubleshooting or manually verifying your setup.
Primary Configuration File
All methods ultimately write to ~/.agent-reach/config.yaml. Verify your stored credentials with:
cat ~/.agent-reach/config.yaml
You will see entries like:
twitter_auth_token: "AAA..."
twitter_ct0: "BBB..."
The Config.to_dict() method masks sensitive fields when displaying summaries in the CLI, but the raw file contains the full values.
Legacy Tool Synchronization
According to the source code in agent_reach/cookie_extract.py, Agent-Reach synchronizes your Twitter credentials to multiple destinations for backward compatibility:
twitter-clienvironment: InjectsTWITTER_AUTH_TOKENandTWITTER_CT0environment variables when spawning subprocesses- xfetch legacy: Writes to
~/.config/xfetch/session.jsonvia_sync_xfetch_session(lines 21-28) - bird-cli: Creates
~/.config/bird/credentials.envwithAUTH_TOKEN=...andCT0=...entries via_sync_bird_env
This ensures that external tools reading these locations can authenticate without separate configuration.
Verifying Your Configuration
After configuration, confirm everything is working by checking the TwitterChannel implementation in agent_reach/channels/twitter.py, which verifies that twitter-cli or bird binaries are present and that credentials are accessible. Run the built-in diagnostic:
agent-reach doctor
This command reports whether the Twitter channel detects valid authentication tokens in your configuration and whether the helper tools can successfully communicate with the X API.
Summary
- Agent-Reach requires two specific cookies:
auth_tokenandct0from X (Twitter), stored astwitter_auth_tokenandtwitter_ct0in~/.agent-reach/config.yaml. - Manual configuration uses
agent-reach configure twitter-cookieswith either separate values or a raw cookie header, parsed by_parse_twitter_cookie_inputinagent_reach/cli.py. - Automatic extraction uses
agent-reach configure --from-browser [chrome|firefox|edge|brave|opera]to read cookies directly from browser storage viaagent_reach/cookie_extract.py. - Validation occurs immediately via
twitter statussubprocess calls that check for"ok: true"in the output. - Credentials sync to multiple locations including legacy
xfetchandbird-cliconfiguration files for cross-tool compatibility.
Frequently Asked Questions
What are the specific cookie names required for Agent-Reach Twitter authentication?
Agent-Reach specifically requires two cookies from X (formerly Twitter): auth_token and ct0. These map to configuration keys twitter_auth_token and twitter_ct0 in the YAML configuration file. The auth_token authenticates your user session, while ct0 provides the CSRF token required for POST requests to the X API.
Can I configure Twitter cookies for Agent-Reach without using a browser?
Yes, manual configuration does not require browser access. Use the agent-reach configure twitter-cookies command with either separate token arguments or a copied cookie header string. The CLI parses your input using the _parse_twitter_cookie_input helper in agent_reach/cli.py (lines 24-42) and writes the extracted values directly to your configuration file without reading browser data.
Where does Agent-Reach store the Twitter authentication tokens?
The tokens are persisted in ~/.agent-reach/config.yaml under the keys twitter_auth_token and twitter_ct0, as handled by the Config class in agent_reach/config.py. Additionally, the _sync_xfetch_session and _sync_bird_env functions in agent_reach/cookie_extract.py copy these credentials to ~/.config/xfetch/session.json and ~/.config/bird/credentials.env respectively for compatibility with legacy tooling.
How does Agent-Reach validate that the configured Twitter cookies are working?
After you run the configure command, Agent-Reach validates the cookies by executing twitter status via subprocess.run (as seen in _cmd_configure in agent_reach/cli.py lines 65-78) and checking the output for "ok: true". If the check fails, the CLI returns an error message indicating that the tokens are invalid or expired, allowing you to re-run the configuration step immediately.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →