How to Manually Set Authentication Tokens for Twitter in Agent Reach
You can manually configure Twitter authentication tokens in Agent Reach by running agent-reach configure twitter-cookies with either plain auth_token and ct0 values or a full browser cookie header, which stores the credentials in ~/.agent-reach/config.yaml with 600 permissions and exposes them via the Config class.
Agent Reach stores platform-specific credentials in a user-specific YAML configuration file. This guide explains how to manually set authentication tokens for platforms like Twitter using the CLI and underlying Python classes in the Panniantong/Agent-Reach repository. We will examine the specific implementations in agent_reach/config.py and agent_reach/cli.py to show exactly how tokens are parsed, secured, and retrieved.
Where Agent Reach Stores Platform Credentials
Agent Reach maintains a local configuration directory at ~/.agent-reach/. The file config.yaml within this directory holds all user-specific settings, including authentication tokens. According to the source code in agent_reach/config.py, the Config class handles loading and saving this file with strict permissions (600), ensuring only the owner can read or write sensitive credentials (lines 21-28).
When you set Twitter tokens, the system stores them under the keys twitter_auth_token and twitter_ct0. These values persist across sessions and are accessible via the Config.get method throughout the application. The agent_reach/cookie_extract.py file provides additional utilities for automated browser extraction, though manual configuration bypasses this helper.
Using the Configure Command to Set Twitter Tokens
The agent_reach/cli.py file implements the configure sub-command, which provides the primary interface for manual token entry. The command supports two input formats through the internal _parse_twitter_cookie_input helper function.
Option 1: Plain Token Values
The most common approach is passing the two tokens as separate arguments:
agent-reach configure twitter-cookies myAuthToken123 myCt0Token456
In this format, the CLI treats the first argument as the auth_token and the second as the ct0 value. The _parse_twitter_cookie_input function identifies this pattern when the input contains exactly two space-separated strings without cookie delimiters.
Option 2: Full Cookie Header
Alternatively, you can paste the entire Cookie header copied from your browser:
agent-reach configure twitter-cookies "auth_token=myAuthToken123; ct0=myCt0Token456; other=ignore"
The parser extracts the auth_token and ct0 values from the semicolon-delimited string, ignoring unrelated cookies. Both input methods result in identical storage in the configuration file.
Underlying Implementation and Storage Flow
When you execute the configure command, the following flow occurs in the source code:
- Parsing: In
agent_reach/cli.py(lines 50-66), the_parse_twitter_cookie_inputfunction determines whether the input is a plain pair or a full header string. - Storage: The parsed values are passed to
Config.set, which updates the internal mapping. Inagent_reach/config.py(lines 80-84), theConfigclass writes the updated mapping to~/.agent-reach/config.yaml. - Permissions: The
Configclass explicitly sets file permissions to 600 during the save operation (lines 21-28 inagent_reach/config.py), preventing other users from accessing the credentials. - Environment: Before invoking external tools like
twitter-clifor validation (lines 63-82 inagent_reach/cli.py), the CLI exportsTWITTER_AUTH_TOKENandTWITTER_CT0environment variables containing the stored values.
You can verify the stored values programmatically:
from agent_reach.config import Config
cfg = Config()
print(cfg.get("twitter_auth_token")) # Outputs: myAuthToken123
print(cfg.get("twitter_ct0")) # Outputs: myCt0Token456
Direct YAML File Editing
If you prefer manual configuration without the CLI, edit ~/.agent-reach/config.yaml directly:
twitter_auth_token: myAuthToken123
twitter_ct0: myCt0Token456
Ensure the file maintains 600 permissions (chmod 600 ~/.agent-reach/config.yaml) to match the security standards enforced by the Config class implementation in agent_reach/config.py.
Verifying Your Configuration
After setting tokens via either method, run the verification command:
agent-reach doctor
This command retrieves the credentials using Config.get, loads them into the TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables, and performs a health check against twitter-cli to confirm the tokens are valid and recognized by the platform.
Summary
- Agent Reach stores Twitter credentials in
~/.agent-reach/config.yamlunder the keystwitter_auth_tokenandtwitter_ct0. - Use
agent-reach configure twitter-cookieswith either plain values or a full cookie header to set tokens via the CLI. - The
_parse_twitter_cookie_inputfunction inagent_reach/cli.pyhandles both input formats, while theConfigclass inagent_reach/config.pymanages secure persistence with 600 file permissions. - Environment variables
TWITTER_AUTH_TOKENandTWITTER_CT0expose the credentials to external tools liketwitter-cliduring validation. - Run
agent-reach doctorto verify that stored tokens are correctly recognized by the system.
Frequently Asked Questions
What file permissions does Agent Reach use for the configuration file?
Agent Reach explicitly sets 600 permissions (read/write for owner only) on ~/.agent-reach/config.yaml when writing credentials. This is implemented in the Config class within agent_reach/config.py (lines 21-28) to prevent unauthorized access to authentication tokens.
Can I use the configure command for platforms other than Twitter?
While the current analysis focuses on Twitter's auth_token and ct0 cookies, the agent_reach/config.py infrastructure supports arbitrary key-value storage via Config.set and Config.get. Platforms using similar cookie-based authentication would follow an analogous pattern, though the specific CLI sub-commands and parsing logic in agent_reach/cli.py would need to handle platform-specific cookie names.
How does Agent Reach validate the tokens I provide?
When you run agent-reach configure twitter-cookies, the CLI optionally validates tokens by exporting them as TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables and invoking twitter-cli for a health check. This verification logic appears in agent_reach/cli.py (lines 63-82), ensuring the credentials are functional before completing the configuration process.
Where is the cookie parsing logic implemented?
The _parse_twitter_cookie_input function in agent_reach/cli.py (lines 50-66) implements the parsing logic. It determines whether input is a pair of plain tokens or a full browser cookie header, extracts the auth_token and ct0 values, and returns them for storage via the Config class.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →