# How to Configure Twitter/X Cookies for Agent-Reach: Manual and Automatic Methods

> Learn how to configure Twitter X cookies for Agent-Reach. Easily set up auth_token and ct0 cookies manually via CLI or automatically from your browser for enhanced search.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-06-23

---

**Agent-Reach requires the `auth_token` and `ct0` cookies from your X (Twitter) session to enable search functionality, which you can configure either manually via the CLI or extract automatically from your browser.**

The open-source [Panniantong/Agent-Reach](https://github.com/Panniantong/Agent-Reach) repository provides automation tools for social media platforms, but accessing Twitter/X data requires valid authentication cookies stored in your local configuration. This guide explains exactly how to configure Twitter cookies for Agent-Reach using the two supported methods: manual CLI input and automatic browser extraction.

## Required Cookies for X Authentication

Agent-Reach specifically needs two authentication tokens that X uses to maintain your session: **`auth_token`** and **`ct0`**. These values are persisted in your user configuration file at `~/.agent-reach/config.yaml` under the keys `twitter_auth_token` and `twitter_ct0`.

According to the source code in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py), the `Config` class manages these values using the `set()` method to store sensitive credentials securely. When properly configured, these cookies enable the `TwitterChannel` class (defined in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py)) to authenticate requests and perform search operations on your behalf.

## Method 1: Manual Configuration via CLI

The most direct way to configure Twitter cookies for Agent-Reach is using the `configure twitter-cookies` command, which accepts either separate arguments or a raw cookie header string.

Pass the values as separate arguments:

```bash
agent-reach configure twitter-cookies AUTH_TOKEN_VALUE CT0_VALUE

```

Or paste a raw cookie header (copied directly from Chrome’s “Copy > Copy Cookies”):

```bash
agent-reach configure twitter-cookies "auth_token=AAA; ct0=BBB; other=ignore"

```

The CLI parses your input using the `_parse_twitter_cookie_input` function in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 24-42) to extract the relevant tokens regardless of extra cookie data. After storage, the tool validates the credentials by invoking `twitter status` via subprocess and checking for `"ok: true"` in the output. Success appears as:

```

✅ Twitter cookies configured!
Testing Twitter access... ✅ Twitter access works!

```

## Method 2: Automatic Extraction from Browser

Agent-Reach can automatically extract `auth_token` and `ct0` from your existing browser sessions without manual copy-pasting. This method supports Chrome, Firefox, Edge, Brave, and Opera.

Run the configuration command with the browser flag:

```bash
agent-reach configure --from-browser chrome

```

Under the hood, the `configure_from_browser` function in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) iterates through supported platforms and extracts cookies using either **rookiepy** or **browser-cookie3**. When it finds the Twitter cookies, it stores them via:

```python
config.set("twitter_auth_token", tc["auth_token"])
config.set("twitter_ct0", tc["ct0"])

```

The function also synchronizes these credentials to legacy helper tools through `_sync_xfetch_session` (writing to `~/.config/xfetch/session.json`) and `_sync_bird_env` (writing to `~/.config/bird/credentials.env`). Successful extraction produces output similar to:

```

Extracting cookies from chrome...

✅ Twitter/X: auth_token + ct0
...
✅ Cookies configured! Run `agent-reach doctor` to see updated status.

```

## Where Credentials Are Stored and Synced

Your Twitter cookies are stored in multiple locations to ensure compatibility with different Agent-Reach components:

- **Primary storage**: `~/.agent-reach/config.yaml` contains `twitter_auth_token` and `twitter_ct0` as defined in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py)
- **xfetch legacy**: `~/.config/xfetch/session.json` receives synced values via `_sync_xfetch_session` for backward compatibility
- **bird-cli**: `~/.config/bird/credentials.env` receives a source-able file via `_sync_bird_env` containing `AUTH_TOKEN` and `CT0` environment variables

You can verify the stored configuration (with redacted values) by viewing the YAML file directly:

```bash
cat ~/.agent-reach/config.yaml

```

## Troubleshooting Validation Failures

If you see an error during the "Testing Twitter access" phase, the cookies may be expired or invalid. The validation logic in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (within `_cmd_configure`, lines 65-78) checks the subprocess output of `twitter status` and reports specific errors if `"ok: true"` is missing.

To resolve validation failures:
1. Re-run the configuration with fresh cookies from your browser
2. Ensure you are using the `--from-browser` flag if manually copied values fail
3. Check that `twitter-cli` is installed and accessible in your PATH, as Agent-Reach relies on this external tool to verify credentials

## Summary

- **Agent-Reach requires two specific cookies**: `auth_token` and `ct0` from X (Twitter) to enable search capabilities.
- **Configuration file**: Values are stored in `~/.agent-reach/config.yaml` under `twitter_auth_token` and `twitter_ct0`.
- **Two configuration methods**: Manual CLI input using `agent-reach configure twitter-cookies` or automatic extraction via `agent-reach configure --from-browser chrome`.
- **Legacy synchronization**: The tool automatically syncs credentials to `~/.config/xfetch/session.json` and `~/.config/bird/credentials.env` for helper tool compatibility.
- **Validation**: The CLI runs `twitter status` after configuration to verify connectivity and reports immediate success or failure.

## Frequently Asked Questions

### What are the auth_token and ct0 cookies?

The `auth_token` is your primary session identifier for X (formerly Twitter), while `ct0` is a cross-site request forgery (CSRF) token required for API calls. According to the Agent-Reach source code, both must be present in `~/.agent-reach/config.yaml` for the `TwitterChannel` to authenticate requests successfully.

### Which browsers support automatic cookie extraction?

Agent-Reach supports automatic extraction from Chrome, Firefox, Edge, Brave, and Opera. The `configure_from_browser` function in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) uses platform-specific libraries (rookiepy or browser-cookie3) to read the SQLite cookie databases from these browsers without requiring manual export.

### Where does Agent-Reach store my Twitter credentials?

Credentials are primarily stored in `~/.agent-reach/config.yaml` using the `Config` class from [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py). Additionally, the tool synchronizes these values to legacy locations: `~/.config/xfetch/session.json` for the xfetch tool and `~/.config/bird/credentials.env` for bird-cli compatibility.

### Why does the configuration fail validation even with correct cookies?

Validation failures usually occur when the external `twitter-cli` tool is not installed in your PATH, or when the cookies have expired. The `_cmd_configure` function in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) runs `twitter status` via subprocess and checks for `"ok: true"` in the output. Ensure your shell can execute `twitter status` independently, or re-extract fresh cookies if your session expired.