# Required Cookie Values for Twitter/X Authentication in Agent-Reach

> Learn the two essential cookie values auth_token and ct0 required for Twitter X authentication in Agent-Reach. Get them from browser profiles or CLI input.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-07-04

---

**Agent-Reach requires exactly two cookie values—`auth_token` and `ct0`—to authenticate with Twitter/X, accepting them either from browser profiles or manual CLI input.**

Agent-Reach is an open-source automation framework that interfaces with Twitter/X through authenticated API calls. To access the platform, the system must validate the user session using specific authentication tokens extracted from browser storage or provided directly by the user.

## The Two Required Twitter/X Authentication Cookies

The platform expects **two specific cookie fields** for every authenticated request:

- **`auth_token`** – The primary OAuth token that authorizes API calls on behalf of the user.
- **`ct0`** – A secondary CSRF token required alongside `auth_token` for signed requests.

If either cookie is missing, Agent-Reach reports an error and cannot access the platform. Both values are mandatory for successful authentication.

## Source Code Implementation

Cookie handling is split between browser extraction logic and CLI input parsing.

### Browser Profile Extraction

When scanning a browser profile, Agent-Reach looks for both keys under the `twitter` entry and stores them in the configuration. In [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) at lines 52‑56, the code checks for the presence of both `auth_token` and `ct0` before updating the internal config.

### CLI String Parsing

For manual configuration, the CLI helper `_parse_twitter_cookie_input` in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) (lines 54‑71) extracts the two tokens from user-supplied strings. This function accepts input either as a full cookie header string or as space-separated values, then writes them to the configuration keys `twitter_auth_token` and `twitter_ct0`.

## Configuring Cookies via the Command Line

You can provide the required cookie values using the `configure twitter-cookies` command. The parser accepts two formats:

```bash

# Format 1: Full cookie header string

agent-reach configure twitter-cookies "auth_token=YOUR_TOKEN; ct0=YOUR_CSRF"

# Format 2: Space-separated tokens

agent-reach configure twitter-cookies "YOUR_TOKEN YOUR_CSRF"

```

These commands trigger the parsing logic in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py), update the configuration via `config.set("twitter_auth_token", ...)` and `config.set("twitter_ct0", ...)`, and synchronize the credentials with downstream tools.

## Downstream Session Synchronization

After extraction, the cookies are persisted to [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) under the keys `twitter_auth_token` and `twitter_ct0`. Additionally, the system synchronizes these credentials with legacy tooling through two internal functions in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py):

- **`_sync_xfetch_session`** – Writes the tokens to the legacy `xfetch` session file.
- **`_sync_bird_env`** – Updates the Bird CLI environment variables.

This ensures compatibility with external tools that depend on the same authentication context.

## Summary

- **Two cookies required**: `auth_token` (OAuth) and `ct0` (CSRF).
- **Extraction locations**: [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) for browser profiles, [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) for manual input.
- **Configuration keys**: Stored as `twitter_auth_token` and `twitter_ct0` in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py).
- **Input formats**: Accepts either header-style strings (`auth_token=X; ct0=Y`) or space-separated tokens.
- **Legacy support**: Automatically syncs to `xfetch` sessions and Bird CLI environment via internal sync functions.

## Frequently Asked Questions

### What happens if one of the required cookies is missing?

Agent-Reach will report an error and refuse to access the Twitter/X platform. Both `auth_token` and `ct0` are mandatory; the extraction logic in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py) explicitly checks for both keys before allowing the session to proceed.

### Can I provide the cookies as separate arguments instead of a header string?

Yes. The `_parse_twitter_cookie_input` function in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) accepts both formats: a full cookie header (`auth_token=X; ct0=Y`) or two space-separated values (`X Y`). Both methods extract and store the tokens correctly.

### Where are the cookies stored after configuration?

The values are written to [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) under the keys `twitter_auth_token` and `twitter_ct0`. They are also synchronized to legacy session files and environment variables through `_sync_xfetch_session` and `_sync_bird_env` in [`agent_reach/cookie_extract.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cookie_extract.py).

### What is the purpose of the `ct0` cookie?

The `ct0` value serves as a CSRF (Cross-Site Request Forgery) token. According to the source code, it is required alongside `auth_token` for signed requests to Twitter/X's API endpoints, preventing unauthorized cross-site commands.