Agent-Reach Authentication Methods: Platform-by-Platform Requirements

Agent-Reach requires environment variables or CLI-based logins for Twitter, Reddit, GitHub, XiaoHongShu, and LinkedIn, while YouTube, V2EX, and Bilibili (via bili-cli) operate without credentials.

Agent-Reach serves as a thin glue layer that routes AI-agent calls to the native CLI or API of each supported internet platform. For every channel, the check() method detects whether required authentication material is present and reports the status (ok, warn, error, or off). This guide details the specific Agent-Reach authentication methods for each backend, referencing the exact source files where these checks are implemented.

Platforms Requiring Authentication

Twitter / X

Twitter integration relies on three potential backends—twitter-cli, bird CLI, and OpenCLI—all of which require an authenticated session.

  • twitter-cli reads the TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables. Alternatively, it can reuse an already-logged-in browser session.
  • bird CLI expects the AUTH_TOKEN and CT0 environment variables.
  • OpenCLI extracts the login state directly from Chrome or Edge cookies.

In agent_reach/channels/twitter.py, the TwitterChannel._check_twitter_cli method (lines 84‑88) validates the presence of these tokens before marking the channel as operational.

Reddit

Reddit supports two authenticated backends: OpenCLI and rdt-cli.

  • OpenCLI leverages the browser’s existing Reddit cookies.
  • rdt-cli stores session data in ~/.config/rdt-cli/credential.json. Users must run rdt login to generate this file, or manually populate it with cookie values.

The validation logic resides in agent_reach/channels/reddit.py within RedditChannel._check_rdt (lines 141‑155), which surfaces detailed remediation steps if the credential file is missing.

GitHub

GitHub access is mediated entirely through the official gh CLI. Users must execute gh auth login, which initiates an OAuth/device flow and persists the token to ~/.config/gh/hosts.yml. The GitHubChannel.check method in agent_reach/channels/github.py (lines 40‑42) verifies this file’s existence before allowing operations.

XiaoHongShu (XHS)

XiaoHongShu offers three backends, each requiring a logged-in state:

  • OpenCLI reuses the Chrome login session.
  • xiaohongshu-mcp spawns a local MCP server that can fetch a QR-code login.
  • xhs-cli provides a native xhs login command for browser-based cookie extraction or QR-code authentication.

The check is performed in agent_reach/channels/xiaohongshu.py by XiaoHongShuChannel._check_xhs_cli (lines 49‑53).

LinkedIn

LinkedIn access requires the linkedin-scraper-mcp backend. Users must first configure the MCP server using mcporter config add linkedin http://localhost:3000/mcp, which then extracts logged-in LinkedIn cookies from the browser session. The prerequisite check is defined in agent_reach/channels/linkedin.py inside LinkedInChannel.check (lines 36‑38).

Platforms with Optional or No Authentication

Bilibili

Bilibili offers mixed authentication requirements. The bili-cli backend functions fully without a login, enabling immediate access to public video data. Only when using OpenCLI to fetch subtitles does Agent-Reach require the browser’s logged-in cookies. This logic is handled in agent_reach/channels/bilibili.py by BilibiliChannel._check_bili_cli (lines 92‑94).

YouTube

YouTube requires no authentication credentials. The YouTubeChannel.check method in agent_reach/channels/youtube.py (lines 51‑57) only verifies that yt-dlp is installed and that a JavaScript runtime (node or deno) is available for signature deciphering. Public video metadata and subtitles remain accessible without logging in.

V2EX

V2EX utilizes a public API that requires no authentication whatsoever. The V2EXChannel.check implementation in agent_reach/channels/v2ex.py (lines 45‑46) returns immediately without checking for tokens or session files.

How to Authenticate Each Platform

Configure each backend using the following commands before running agent-reach install:

Authenticate Twitter via environment variables:

export TWITTER_AUTH_TOKEN="YOUR_TWITTER_BEARER_TOKEN"
export TWITTER_CT0="YOUR_TWITTER_CT0_COOKIE"
agent-reach install --channels twitter

Log in to Reddit using rdt-cli:

rdt login
agent-reach install --channels reddit

Authenticate GitHub via the official CLI:

gh auth login
agent-reach install --channels github

Use OpenCLI for platforms supporting browser-derived sessions:


# Ensure you are logged into the target site in Chrome/Edge

agent-reach install --channels opencli

Log in to XiaoHongShu via xhs-cli:

xhs login
agent-reach install --channels xiaohongshu

Configure LinkedIn MCP access:

npm install -g mcporter
mcporter config add linkedin http://localhost:3000/mcp
agent-reach install --channels linkedin

Summary

  • Twitter: Requires TWITTER_AUTH_TOKEN and TWITTER_CT0 environment variables, or a logged-in browser session for OpenCLI.
  • Reddit: Uses rdt-cli (storing cookies in ~/.config/rdt-cli/credential.json) or OpenCLI browser cookies.
  • GitHub: Requires gh auth login to populate ~/.config/gh/hosts.yml.
  • XiaoHongShu: Supports xhs login, MCP QR codes, or OpenCLI browser sessions.
  • LinkedIn: Requires MCP configuration with browser-derived cookies via mcporter.
  • YouTube: No authentication required; only needs a JavaScript runtime for yt-dlp.
  • Bilibili: No authentication required for bili-cli; optional browser login for OpenCLI subtitle access.
  • V2EX:Public API with no authentication requirements.

Frequently Asked Questions

How does Agent-Reach verify that I am logged in?

Agent-Reach delegates credential storage to the underlying platform CLIs. Each channel’s check() method—such as GitHubChannel.check or TwitterChannel._check_twitter_cli—inspects specific paths (e.g., ~/.config/gh/hosts.yml) or environment variables (e.g., TWITTER_AUTH_TOKEN) to confirm a valid session exists before marking the channel status as ok.

Can I use Twitter with Agent-Reach without providing credentials?

No. According to the source in agent_reach/channels/twitter.py, the TwitterChannel._check_twitter_cli method returns an error status unless the TWITTER_AUTH_TOKEN and TWITTER_CT0 variables are set, or OpenCLI detects an active browser login. Anonymous access is not supported.

Why does YouTube require Node.js if it does not need a login?

The YouTubeChannel.check method in agent_reach/channels/youtube.py requires a JavaScript runtime (node or deno) because yt-dlp needs to execute player JavaScript to decipher video signatures. This is a technical prerequisite for metadata extraction, not an authentication barrier.

Is Bilibili completely free of authentication requirements?

Only when using the bili-cli backend. As implemented in agent_reach/channels/bilibili.py, BilibiliChannel._check_bili_cli confirms that bili-cli operates without credentials. If you instead configure the OpenCLI backend to fetch restricted subtitles, you must be logged into Bilibili in your browser.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →