# How to Configure Twitter/X Authentication Using Cookie-Editor Export in Agent Reach

> Configure TwitterX authentication in Agent Reach easily. Learn how to export cookies using Cookie-Editor and store them for downstream tools. Get started now!

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-06-27

---

**Agent Reach stores Twitter/X authentication tokens from Cookie-Editor exports in `~/.agent-reach/config.yaml` and exposes them to downstream tools via the `twitter-cookies` CLI command.**

The Panniantong/Agent-Reach repository provides a CLI-driven workflow to configure Twitter/X authentication without manual file editing. By extracting the `auth_token` and `ct0` cookies from your browser and passing them to the `agent-reach configure` command, you create a persistent, secure credential store that the `TwitterChannel` class consumes to probe the `twitter-cli` backend.

## What You Need to Extract

Agent Reach requires two specific cookies from the X (formerly Twitter) domain:

- **`auth_token`** – The session authentication token
- **`ct0`** – The CSRF token required for API calls

You can export these using the Cookie-Editor browser extension or any compatible tool that supports either **header string** format (`auth_token=...; ct0=...`) or **JSON array** format.

## Step-by-Step Configuration

### Export Cookies from Your Browser

Install the Cookie-Editor extension for Chrome, Edge, or Firefox. Navigate to `x.com` or `twitter.com`, ensure you are logged in, then:

1. Open Cookie-Editor → Select the domain `x.com` or `twitter.com`
2. Click **Export** → Choose **Export as Header** or **Export as JSON**
3. Copy the resulting string

For header format, you will see:

```

auth_token=AAAAAAAAAAAAAAAAAAAA; ct0=BBBBBBBBBBBBBBBBBBBB; other_cookie=xyz

```

### Configure Agent Reach via CLI

Pass the exported string directly to the CLI. The handler in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 50-61) recognizes the `twitter-cookies` key and delegates to `_parse_twitter_cookie_input` (lines 32-49).

**Using the header string format:**

```bash
agent-reach configure twitter-cookies "auth_token=AAAAAAAAAAAAAAAAAAAA; ct0=BBBBBBBBBBBBBBBBBBBB"

```

**Using the JSON array format:**

```bash
agent-reach configure twitter-cookies '[{"name":"auth_token","value":"AAAAAAAAAAAAAAAAAAAA","domain":".x.com"},{"name":"ct0","value":"BBBBBBBBBBBBBBBBBBBB","domain":".x.com"}]'

```

The parser automatically detects the format. If the input contains `auth_token=` and `ct0=`, it parses the header string; if it contains two space-separated tokens, it treats them as raw values.

### Verify the Setup

Run the health-check to confirm the credentials work:

```bash
agent-reach doctor

```

The `TwitterChannel.check` method in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py) (lines 20-52) executes `twitter-cli status` using the stored credentials. You should see:

```

Twitter/X  ✔  twitter-cli (ok: true)

```

## How the Configuration Works Under the Hood

When you run the configure command, three components handle the data flow:

- **Input Parsing** – The `_parse_twitter_cookie_input` function in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 32-49) sanitizes the input and extracts the two token values.

- **Secure Storage** – The `Config` class in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) (lines 49-66) writes the tokens to `~/.agent-reach/config.yaml` under the keys `twitter_auth_token` and `twitter_ct0` with `0600` file permissions, ensuring only the owner can read the file.

- **Environment Exposure** – The `TwitterChannel` implementation in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py) (lines 84-88) exposes these values as `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables when spawning `twitter-cli` processes. The `Config` class (lines 70-78) also falls back to environment variables if the config file is absent.

Additionally, [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) (lines 18-22, 44-53) defines the Twitter cookie specification and can auto-extract these values from browser sessions if you prefer automated extraction over manual Cookie-Editor exports.

## Summary

- **Agent Reach** requires `auth_token` and `ct0` from `x.com` or `twitter.com` to authenticate with the Twitter/X API.
- Use `agent-reach configure twitter-cookies` followed by your Cookie-Editor export string (header or JSON format).
- Credentials are stored securely in `~/.agent-reach/config.yaml` with restricted permissions.
- Verify functionality with `agent-reach doctor`, which calls `TwitterChannel.check` to test the `twitter-cli` backend.
- The configuration is available to downstream tools via environment variables or the `Config` class singleton.

## Frequently Asked Questions

### What format does the Cookie-Editor export need to be in?

Agent Reach accepts two formats: a **header string** like `auth_token=AAA; ct0=BBB` or a **JSON array** of cookie objects. The parser in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) detects which format you provide and extracts the values accordingly.

### Where are the credentials stored on disk?

The tokens are written to `~/.agent-reach/config.yaml` by the `Config` class in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py). The file is created with `0600` permissions, meaning only the current user can read or write it, preventing credential leakage to other system users.

### Can I use environment variables instead of the config file?

Yes. According to the `Config` class implementation (lines 70-78), Agent Reach falls back to `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables if the config file keys are missing. This is useful for CI/CD pipelines where writing files is undesirable.

### Why does the doctor command fail even with correct cookies?

The `TwitterChannel.check` method (lines 20-52) in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py) spawns `twitter-cli status` and expects a specific JSON response containing `"ok": true`. If `twitter-cli` is not installed, not in your PATH, or the cookies have expired (causing a 401/403 response), the check will fail even if the configuration syntax is correct.