How to Manually Set Authentication Tokens for Twitter in Agent Reach

You can manually configure Twitter authentication tokens in Agent Reach by running agent-reach configure twitter-cookies with either plain auth_token and ct0 values or a full browser cookie header, which stores the credentials in ~/.agent-reach/config.yaml with 600 permissions and exposes them via the Config class.

Agent Reach stores platform-specific credentials in a user-specific YAML configuration file. This guide explains how to manually set authentication tokens for platforms like Twitter using the CLI and underlying Python classes in the Panniantong/Agent-Reach repository. We will examine the specific implementations in agent_reach/config.py and agent_reach/cli.py to show exactly how tokens are parsed, secured, and retrieved.

Where Agent Reach Stores Platform Credentials

Agent Reach maintains a local configuration directory at ~/.agent-reach/. The file config.yaml within this directory holds all user-specific settings, including authentication tokens. According to the source code in agent_reach/config.py, the Config class handles loading and saving this file with strict permissions (600), ensuring only the owner can read or write sensitive credentials (lines 21-28).

When you set Twitter tokens, the system stores them under the keys twitter_auth_token and twitter_ct0. These values persist across sessions and are accessible via the Config.get method throughout the application. The agent_reach/cookie_extract.py file provides additional utilities for automated browser extraction, though manual configuration bypasses this helper.

Using the Configure Command to Set Twitter Tokens

The agent_reach/cli.py file implements the configure sub-command, which provides the primary interface for manual token entry. The command supports two input formats through the internal _parse_twitter_cookie_input helper function.

Option 1: Plain Token Values

The most common approach is passing the two tokens as separate arguments:

agent-reach configure twitter-cookies myAuthToken123 myCt0Token456

In this format, the CLI treats the first argument as the auth_token and the second as the ct0 value. The _parse_twitter_cookie_input function identifies this pattern when the input contains exactly two space-separated strings without cookie delimiters.

Alternatively, you can paste the entire Cookie header copied from your browser:

agent-reach configure twitter-cookies "auth_token=myAuthToken123; ct0=myCt0Token456; other=ignore"

The parser extracts the auth_token and ct0 values from the semicolon-delimited string, ignoring unrelated cookies. Both input methods result in identical storage in the configuration file.

Underlying Implementation and Storage Flow

When you execute the configure command, the following flow occurs in the source code:

  1. Parsing: In agent_reach/cli.py (lines 50-66), the _parse_twitter_cookie_input function determines whether the input is a plain pair or a full header string.
  2. Storage: The parsed values are passed to Config.set, which updates the internal mapping. In agent_reach/config.py (lines 80-84), the Config class writes the updated mapping to ~/.agent-reach/config.yaml.
  3. Permissions: The Config class explicitly sets file permissions to 600 during the save operation (lines 21-28 in agent_reach/config.py), preventing other users from accessing the credentials.
  4. Environment: Before invoking external tools like twitter-cli for validation (lines 63-82 in agent_reach/cli.py), the CLI exports TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables containing the stored values.

You can verify the stored values programmatically:

from agent_reach.config import Config

cfg = Config()
print(cfg.get("twitter_auth_token"))  # Outputs: myAuthToken123

print(cfg.get("twitter_ct0"))         # Outputs: myCt0Token456

Direct YAML File Editing

If you prefer manual configuration without the CLI, edit ~/.agent-reach/config.yaml directly:

twitter_auth_token: myAuthToken123
twitter_ct0: myCt0Token456

Ensure the file maintains 600 permissions (chmod 600 ~/.agent-reach/config.yaml) to match the security standards enforced by the Config class implementation in agent_reach/config.py.

Verifying Your Configuration

After setting tokens via either method, run the verification command:

agent-reach doctor

This command retrieves the credentials using Config.get, loads them into the TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables, and performs a health check against twitter-cli to confirm the tokens are valid and recognized by the platform.

Summary

  • Agent Reach stores Twitter credentials in ~/.agent-reach/config.yaml under the keys twitter_auth_token and twitter_ct0.
  • Use agent-reach configure twitter-cookies with either plain values or a full cookie header to set tokens via the CLI.
  • The _parse_twitter_cookie_input function in agent_reach/cli.py handles both input formats, while the Config class in agent_reach/config.py manages secure persistence with 600 file permissions.
  • Environment variables TWITTER_AUTH_TOKEN and TWITTER_CT0 expose the credentials to external tools like twitter-cli during validation.
  • Run agent-reach doctor to verify that stored tokens are correctly recognized by the system.

Frequently Asked Questions

What file permissions does Agent Reach use for the configuration file?

Agent Reach explicitly sets 600 permissions (read/write for owner only) on ~/.agent-reach/config.yaml when writing credentials. This is implemented in the Config class within agent_reach/config.py (lines 21-28) to prevent unauthorized access to authentication tokens.

Can I use the configure command for platforms other than Twitter?

While the current analysis focuses on Twitter's auth_token and ct0 cookies, the agent_reach/config.py infrastructure supports arbitrary key-value storage via Config.set and Config.get. Platforms using similar cookie-based authentication would follow an analogous pattern, though the specific CLI sub-commands and parsing logic in agent_reach/cli.py would need to handle platform-specific cookie names.

How does Agent Reach validate the tokens I provide?

When you run agent-reach configure twitter-cookies, the CLI optionally validates tokens by exporting them as TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables and invoking twitter-cli for a health check. This verification logic appears in agent_reach/cli.py (lines 63-82), ensuring the credentials are functional before completing the configuration process.

The _parse_twitter_cookie_input function in agent_reach/cli.py (lines 50-66) implements the parsing logic. It determines whether input is a pair of plain tokens or a full browser cookie header, extracts the auth_token and ct0 values, and returns them for storage via the Config class.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →