# How to Manually Set Authentication Tokens for Twitter in Agent Reach

> Learn to manually set Twitter authentication tokens in Agent Reach using agent-reach configure twitter-cookies. Securely store credentials for smoother platform integration.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-06-25

---

**You can manually configure Twitter authentication tokens in Agent Reach by running `agent-reach configure twitter-cookies` with either plain `auth_token` and `ct0` values or a full browser cookie header, which stores the credentials in `~/.agent-reach/config.yaml` with 600 permissions and exposes them via the `Config` class.**

Agent Reach stores platform-specific credentials in a user-specific YAML configuration file. This guide explains how to manually set authentication tokens for platforms like Twitter using the CLI and underlying Python classes in the Panniantong/Agent-Reach repository. We will examine the specific implementations in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) and [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) to show exactly how tokens are parsed, secured, and retrieved.

## Where Agent Reach Stores Platform Credentials

Agent Reach maintains a local configuration directory at `~/.agent-reach/`. The file [`config.yaml`](https://github.com/Panniantong/Agent-Reach/blob/main/config.yaml) within this directory holds all user-specific settings, including authentication tokens. According to the source code in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py), the `Config` class handles loading and saving this file with strict permissions (600), ensuring only the owner can read or write sensitive credentials (lines 21-28).

When you set Twitter tokens, the system stores them under the keys `twitter_auth_token` and `twitter_ct0`. These values persist across sessions and are accessible via the `Config.get` method throughout the application. The [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) file provides additional utilities for automated browser extraction, though manual configuration bypasses this helper.

## Using the Configure Command to Set Twitter Tokens

The [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) file implements the `configure` sub-command, which provides the primary interface for manual token entry. The command supports two input formats through the internal `_parse_twitter_cookie_input` helper function.

### Option 1: Plain Token Values

The most common approach is passing the two tokens as separate arguments:

```bash
agent-reach configure twitter-cookies myAuthToken123 myCt0Token456

```

In this format, the CLI treats the first argument as the `auth_token` and the second as the `ct0` value. The `_parse_twitter_cookie_input` function identifies this pattern when the input contains exactly two space-separated strings without cookie delimiters.

### Option 2: Full Cookie Header

Alternatively, you can paste the entire Cookie header copied from your browser:

```bash
agent-reach configure twitter-cookies "auth_token=myAuthToken123; ct0=myCt0Token456; other=ignore"

```

The parser extracts the `auth_token` and `ct0` values from the semicolon-delimited string, ignoring unrelated cookies. Both input methods result in identical storage in the configuration file.

## Underlying Implementation and Storage Flow

When you execute the configure command, the following flow occurs in the source code:

1. **Parsing**: In [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 50-66), the `_parse_twitter_cookie_input` function determines whether the input is a plain pair or a full header string.
2. **Storage**: The parsed values are passed to `Config.set`, which updates the internal mapping. In [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) (lines 80-84), the `Config` class writes the updated mapping to `~/.agent-reach/config.yaml`.
3. **Permissions**: The `Config` class explicitly sets file permissions to 600 during the save operation (lines 21-28 in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py)), preventing other users from accessing the credentials.
4. **Environment**: Before invoking external tools like `twitter-cli` for validation (lines 63-82 in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py)), the CLI exports `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables containing the stored values.

You can verify the stored values programmatically:

```python
from agent_reach.config import Config

cfg = Config()
print(cfg.get("twitter_auth_token"))  # Outputs: myAuthToken123

print(cfg.get("twitter_ct0"))         # Outputs: myCt0Token456

```

## Direct YAML File Editing

If you prefer manual configuration without the CLI, edit `~/.agent-reach/config.yaml` directly:

```yaml
twitter_auth_token: myAuthToken123
twitter_ct0: myCt0Token456

```

Ensure the file maintains 600 permissions (`chmod 600 ~/.agent-reach/config.yaml`) to match the security standards enforced by the `Config` class implementation in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py).

## Verifying Your Configuration

After setting tokens via either method, run the verification command:

```bash
agent-reach doctor

```

This command retrieves the credentials using `Config.get`, loads them into the `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables, and performs a health check against `twitter-cli` to confirm the tokens are valid and recognized by the platform.

## Summary

- Agent Reach stores Twitter credentials in `~/.agent-reach/config.yaml` under the keys `twitter_auth_token` and `twitter_ct0`.
- Use **`agent-reach configure twitter-cookies`** with either plain values or a full cookie header to set tokens via the CLI.
- The **`_parse_twitter_cookie_input`** function in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) handles both input formats, while the **`Config`** class in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) manages secure persistence with 600 file permissions.
- Environment variables **`TWITTER_AUTH_TOKEN`** and **`TWITTER_CT0`** expose the credentials to external tools like `twitter-cli` during validation.
- Run **`agent-reach doctor`** to verify that stored tokens are correctly recognized by the system.

## Frequently Asked Questions

### What file permissions does Agent Reach use for the configuration file?

Agent Reach explicitly sets 600 permissions (read/write for owner only) on `~/.agent-reach/config.yaml` when writing credentials. This is implemented in the `Config` class within [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) (lines 21-28) to prevent unauthorized access to authentication tokens.

### Can I use the configure command for platforms other than Twitter?

While the current analysis focuses on Twitter's `auth_token` and `ct0` cookies, the [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) infrastructure supports arbitrary key-value storage via `Config.set` and `Config.get`. Platforms using similar cookie-based authentication would follow an analogous pattern, though the specific CLI sub-commands and parsing logic in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) would need to handle platform-specific cookie names.

### How does Agent Reach validate the tokens I provide?

When you run `agent-reach configure twitter-cookies`, the CLI optionally validates tokens by exporting them as `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables and invoking `twitter-cli` for a health check. This verification logic appears in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 63-82), ensuring the credentials are functional before completing the configuration process.

### Where is the cookie parsing logic implemented?

The **`_parse_twitter_cookie_input`** function in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 50-66) implements the parsing logic. It determines whether input is a pair of plain tokens or a full browser cookie header, extracts the `auth_token` and `ct0` values, and returns them for storage via the `Config` class.