How to Configure Twitter/X Authentication Using Cookie-Editor Export in Agent Reach
Agent Reach stores Twitter/X authentication tokens from Cookie-Editor exports in ~/.agent-reach/config.yaml and exposes them to downstream tools via the twitter-cookies CLI command.
The Panniantong/Agent-Reach repository provides a CLI-driven workflow to configure Twitter/X authentication without manual file editing. By extracting the auth_token and ct0 cookies from your browser and passing them to the agent-reach configure command, you create a persistent, secure credential store that the TwitterChannel class consumes to probe the twitter-cli backend.
What You Need to Extract
Agent Reach requires two specific cookies from the X (formerly Twitter) domain:
auth_token– The session authentication tokenct0– The CSRF token required for API calls
You can export these using the Cookie-Editor browser extension or any compatible tool that supports either header string format (auth_token=...; ct0=...) or JSON array format.
Step-by-Step Configuration
Export Cookies from Your Browser
Install the Cookie-Editor extension for Chrome, Edge, or Firefox. Navigate to x.com or twitter.com, ensure you are logged in, then:
- Open Cookie-Editor → Select the domain
x.comortwitter.com - Click Export → Choose Export as Header or Export as JSON
- Copy the resulting string
For header format, you will see:
auth_token=AAAAAAAAAAAAAAAAAAAA; ct0=BBBBBBBBBBBBBBBBBBBB; other_cookie=xyz
Configure Agent Reach via CLI
Pass the exported string directly to the CLI. The handler in agent_reach/cli.py (lines 50-61) recognizes the twitter-cookies key and delegates to _parse_twitter_cookie_input (lines 32-49).
Using the header string format:
agent-reach configure twitter-cookies "auth_token=AAAAAAAAAAAAAAAAAAAA; ct0=BBBBBBBBBBBBBBBBBBBB"
Using the JSON array format:
agent-reach configure twitter-cookies '[{"name":"auth_token","value":"AAAAAAAAAAAAAAAAAAAA","domain":".x.com"},{"name":"ct0","value":"BBBBBBBBBBBBBBBBBBBB","domain":".x.com"}]'
The parser automatically detects the format. If the input contains auth_token= and ct0=, it parses the header string; if it contains two space-separated tokens, it treats them as raw values.
Verify the Setup
Run the health-check to confirm the credentials work:
agent-reach doctor
The TwitterChannel.check method in agent_reach/channels/twitter.py (lines 20-52) executes twitter-cli status using the stored credentials. You should see:
Twitter/X ✔ twitter-cli (ok: true)
How the Configuration Works Under the Hood
When you run the configure command, three components handle the data flow:
-
Input Parsing – The
_parse_twitter_cookie_inputfunction inagent_reach/cli.py(lines 32-49) sanitizes the input and extracts the two token values. -
Secure Storage – The
Configclass inagent_reach/config.py(lines 49-66) writes the tokens to~/.agent-reach/config.yamlunder the keystwitter_auth_tokenandtwitter_ct0with0600file permissions, ensuring only the owner can read the file. -
Environment Exposure – The
TwitterChannelimplementation inagent_reach/channels/twitter.py(lines 84-88) exposes these values asTWITTER_AUTH_TOKENandTWITTER_CT0environment variables when spawningtwitter-cliprocesses. TheConfigclass (lines 70-78) also falls back to environment variables if the config file is absent.
Additionally, agent_reach/cookie_extract.py (lines 18-22, 44-53) defines the Twitter cookie specification and can auto-extract these values from browser sessions if you prefer automated extraction over manual Cookie-Editor exports.
Summary
- Agent Reach requires
auth_tokenandct0fromx.comortwitter.comto authenticate with the Twitter/X API. - Use
agent-reach configure twitter-cookiesfollowed by your Cookie-Editor export string (header or JSON format). - Credentials are stored securely in
~/.agent-reach/config.yamlwith restricted permissions. - Verify functionality with
agent-reach doctor, which callsTwitterChannel.checkto test thetwitter-clibackend. - The configuration is available to downstream tools via environment variables or the
Configclass singleton.
Frequently Asked Questions
What format does the Cookie-Editor export need to be in?
Agent Reach accepts two formats: a header string like auth_token=AAA; ct0=BBB or a JSON array of cookie objects. The parser in agent_reach/cli.py detects which format you provide and extracts the values accordingly.
Where are the credentials stored on disk?
The tokens are written to ~/.agent-reach/config.yaml by the Config class in agent_reach/config.py. The file is created with 0600 permissions, meaning only the current user can read or write it, preventing credential leakage to other system users.
Can I use environment variables instead of the config file?
Yes. According to the Config class implementation (lines 70-78), Agent Reach falls back to TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables if the config file keys are missing. This is useful for CI/CD pipelines where writing files is undesirable.
Why does the doctor command fail even with correct cookies?
The TwitterChannel.check method (lines 20-52) in agent_reach/channels/twitter.py spawns twitter-cli status and expects a specific JSON response containing "ok": true. If twitter-cli is not installed, not in your PATH, or the cookies have expired (causing a 401/403 response), the check will fail even if the configuration syntax is correct.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →