# Manually Configuring Twitter Cookies Without Browser Auto-Extraction

> Learn to manually configure Twitter cookies for Agent-Reach bypassing browser extraction. Use auth_token and ct0 cookies via CLI or environment variables for seamless authentication.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-06-30

---

**Agent-Reach allows you to manually configure Twitter authentication by supplying the `auth_token` and `ct0` cookies directly via CLI commands or environment variables, completely bypassing the need for browser-based cookie extraction tools.**

Agent-Reach interfaces with Twitter/X through the underlying `twitter-cli` executable, which requires two specific authentication tokens to issue API requests. Instead of relying on browser extensions or automated extraction scripts to harvest these values, the library provides built-in utilities to manually configure credentials through the command line. This manual configuration approach gives you full control over the authentication flow while maintaining compatibility with the `twitter-cli` dependency.

## Understanding the Manual Configuration Flow

Agent-Reach authenticates with Twitter by injecting the `auth_token` and `ct0` values into the subprocess environment before spawning `twitter-cli`. The implementation relies on two core mechanisms in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py): the input parser and the runtime environment injector.

When you run the configuration command, the `_parse_twitter_cookie_input` function (lines 32-49) validates and normalizes your input. This parser accepts both space-separated token pairs and raw cookie header strings, extracting the two required values regardless of format.

During execution, the `_configure_twitter_cookies` block (lines 1070-1078) automatically exports `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables before any `twitter-cli` subprocess is created. This ensures the authentication context is always present when the underlying Twitter client initializes, as verified by the health-check logic in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py).

## Configuring Cookies via the Agent-Reach CLI

The `agent-reach configure twitter-cookies` command provides the primary interface for manual credential setup. This method persists the values internally and handles environment preparation automatically for all subsequent Twitter operations.

You can provide the cookies using one of two supported formats:

**Option A: Separate token arguments**

```bash
agent-reach configure twitter-cookies AUTH_TOKEN_VALUE CT0_VALUE

```

**Option B: Full cookie header string**

```bash
agent-reach configure twitter-cookies "auth_token=AUTH_TOKEN_VALUE; ct0=CT0_VALUE"

```

Both formats trigger the `_parse_twitter_cookie_input` logic, which strips whitespace, handles delimiters, and stores the normalized credentials in the user configuration file.

## Alternative: Direct Environment Variable Configuration

For CI/CD pipelines, containerized deployments, or secrets management integrations, you can bypass the configuration command and export the variables directly. Agent-Reach respects existing `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` variables during the subprocess initialization phase.

Set the variables before invoking Agent-Reach commands:

```bash
export TWITTER_AUTH_TOKEN="YOUR_AUTH_TOKEN"
export TWITTER_CT0="YOUR_CT0"

```

When `_configure_twitter_cookies` executes (cli.py lines 1070-1078), it detects these pre-existing environment variables and preserves them for the child `twitter-cli` process. This approach allows you to manage credentials through external secret stores or shell profiles without modifying Agent-Reach's internal configuration state.

## Verifying Your Twitter Authentication

After configuration, validate the setup using the built-in health-check mechanism. The `TwitterChannel` class in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py) implements `_check_twitter_cli` (lines 84-89) to verify that both required cookies are present and that `twitter-cli` reports a healthy connection status.

Run the diagnostic command:

```bash
agent-reach doctor

```

A successful configuration displays **✅ Twitter-CLI 完整可用**, confirming that the authentication tokens are valid and the CLI can successfully communicate with Twitter's API. If the check fails, the output references the specific missing variables defined in the warning strings of the `TwitterChannel` implementation, allowing you to identify whether `auth_token` or `ct0` requires regeneration.

## Summary

- **Manual configuration requires two cookies**: `auth_token` and `ct0`, which map to the `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables expected by `twitter-cli`.
- **Flexible CLI input** via `agent-reach configure twitter-cookies` accepts either separate arguments or full header strings through the `_parse_twitter_cookie_input` function (cli.py lines 32-49).
- **Automatic environment injection** occurs in `_configure_twitter_cookies` (cli.py lines 1070-1078), ensuring credentials are available to subprocesses without manual export.
- **Health verification** is available through `agent-reach doctor`, which executes validation logic in [`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py) to confirm authentication status.
- **No browser dependencies**: The entire workflow operates through command-line configuration and environment variables, eliminating the need for browser-based extraction tools.

## Frequently Asked Questions

### Where does Agent-Reach store the Twitter cookies after configuration?

Agent-Reach persists the parsed values in the user's local configuration file after processing through `_parse_twitter_cookie_input`. These values are subsequently loaded and injected into `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` environment variables at runtime by the `_configure_twitter_cookies` function before spawning any `twitter-cli` subprocess.

### Can I use cookies copied directly from my browser?

Yes. You can manually extract the `auth_token` and `ct0` values from your browser's developer tools (Application/Storage > Cookies for twitter.com) and provide them to the `agent-reach configure twitter-cookies` command. The parser accepts raw cookie header formats, allowing you to paste values directly from browser consoles without manual reformatting.

### What happens if I set both configuration file values and environment variables?

Agent-Reach checks for existing environment variables during the subprocess initialization phase. If `TWITTER_AUTH_TOKEN` and `TWITTER_CT0` are already present in the shell environment, the system preserves those values. However, subsequent runs of `agent-reach configure twitter-cookies` will update the persistent configuration file, which may take precedence in future sessions depending on the execution context.

### How do I know if my cookies have expired or are invalid?

Run `agent-reach doctor` to execute the health-check implemented in `TwitterChannel._check_twitter_cli` ([`agent_reach/channels/twitter.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/channels/twitter.py) lines 84-89). If the authentication fails, the check will display a warning indicating that the required variables are missing or rejected, prompting you to obtain fresh `auth_token` and `ct0` values from your browser and re-run the configuration command.