Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
affaan-m avatar

X Api

  • 5.1k installs
  • 238k repo stars
  • Updated August 5, 2026
  • affaan-m/everything-claude-code

x-api is an agent skill for X API v2 posting, threads, search, timelines, media upload, and rate-limit aware OAuth setup.

About

The x-api skill documents programmatic X integration for posting, reading, searching, and analytics. OAuth 2.0 bearer tokens suit read-heavy search and public data via X_BEARER_TOKEN headers against api.x.com v2 endpoints. OAuth 1.0a user context with X_CONSUMER_KEY, X_CONSUMER_SECRET, X_ACCESS_TOKEN, and X_ACCESS_TOKEN_SECRET is required for posting tweets, threads, account management, and DMs using requests_oauthlib OAuth1Session. Core operations include single tweet POST, thread helper chaining reply in_reply_to_tweet_id, user timeline fetch with tweet.fields metrics, recent search with query operators, voice sampling search excluding retweets and replies, user lookup by username, and v1.1 media upload followed by v2 tweet with media_ids. Rate limits vary by endpoint and tier; read x-rate-limit-remaining and x-rate-limit-reset headers at runtime with backoff instead of hardcoded tables. Security rules forbid hardcoding tokens, committing .env files, and require rotation on exposure. Content integration flows through brand-voice and content-engine with draft approval before posting unless explicitly requested.

  • Bearer token for read search; OAuth 1.0a user context required for writes and DMs.
  • Documents post tweet, thread reply chain, timeline, search, and media upload v1.1 flow.
  • Rate limit handling reads x-rate-limit-remaining and reset headers dynamically.
  • Security: env vars only, never commit .env, rotate exposed tokens at developer.x.com.
  • Integrates with brand-voice and content-engine for draft approval before posting.

X Api by the numbers

  • 5,102 all-time installs (skills.sh)
  • +247 installs in the week ending Aug 4, 2026 (Skillselion tracking)
  • Ranked #73 of 2,715 Automation & Workflows skills by installs in the Skillselion catalog
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

x-api capabilities & compatibility

Capabilities
oauth 2.0 bearer read operations · oauth 1.0a write and dm flows · thread posting helper pattern · media upload v1.1 plus v2 tweet · dynamic rate limit header backoff
Works with
openai
Use cases
marketing · orchestration · research
From the docs

What x-api says it does

OAuth 1.0a (User Context) Required for: posting tweets, managing account, DMs
SKILL.md
Return the draft for approval unless the user explicitly asked to post now
SKILL.md
npx skills add https://github.com/affaan-m/everything-claude-code --skill x-api

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs5.1k
repo stars238k
Security audit2 / 3 scanners passed
Last updatedAugust 5, 2026
Repositoryaffaan-m/everything-claude-code

How do I post tweets or search X programmatically with correct OAuth and rate limit handling?

Integrate X Twitter API v2 for posting tweets and threads, timelines, search, media upload, and rate-limit aware error handling.

Who is it for?

Developers automating X posting, search, or analytics with documented OAuth patterns.

Skip if: Skip when only multi-platform copy adaptation is needed; use crosspost without API calls.

When should I use this skill?

User says post to X, tweet, X API, Twitter API, or wants timeline search automation.

What you get

Working X API calls for read or write flows with env-based credentials and approval gates.

  • Posted tweets or threads
  • Search and timeline results

By the numbers

  • Media upload uses v1.1 endpoint before v2 tweet post
  • Voice sampling query uses max_results 25 in example

Files

SKILL.mdMarkdownGitHub ↗

X API

Programmatic interaction with X (Twitter) for posting, reading, searching, and analytics.

When to Activate

  • User wants to post tweets or threads programmatically
  • Reading timeline, mentions, or user data from X
  • Searching X for content, trends, or conversations
  • Building X integrations or bots
  • Analytics and engagement tracking
  • User says "post to X", "tweet", "X API", or "Twitter API"

Authentication

OAuth 2.0 Bearer Token (App-Only)

Best for: read-heavy operations, search, public data.

# Environment setup
export X_BEARER_TOKEN="your-bearer-token"
import os
import requests

bearer = os.environ["X_BEARER_TOKEN"]
headers = {"Authorization": f"Bearer {bearer}"}

# Search recent tweets
resp = requests.get(
    "https://api.x.com/2/tweets/search/recent",
    headers=headers,
    params={"query": "claude code", "max_results": 10}
)
tweets = resp.json()

OAuth 1.0a (User Context)

Required for: posting tweets, managing account, DMs, and any write flow.

# Environment setup — source before use
export X_CONSUMER_KEY="your-consumer-key"
export X_CONSUMER_SECRET="your-consumer-secret"
export X_ACCESS_TOKEN="your-access-token"
export X_ACCESS_TOKEN_SECRET="your-access-token-secret"

Legacy aliases such as X_API_KEY, X_API_SECRET, and X_ACCESS_SECRET may exist in older setups. Prefer the X_CONSUMER_* and X_ACCESS_TOKEN_SECRET names when documenting or wiring new flows.

import os
from requests_oauthlib import OAuth1Session

oauth = OAuth1Session(
    os.environ["X_CONSUMER_KEY"],
    client_secret=os.environ["X_CONSUMER_SECRET"],
    resource_owner_key=os.environ["X_ACCESS_TOKEN"],
    resource_owner_secret=os.environ["X_ACCESS_TOKEN_SECRET"],
)

Core Operations

Post a Tweet

resp = oauth.post(
    "https://api.x.com/2/tweets",
    json={"text": "Hello from Claude Code"}
)
resp.raise_for_status()
tweet_id = resp.json()["data"]["id"]

Post a Thread

def post_thread(oauth, tweets: list[str]) -> list[str]:
    ids = []
    reply_to = None
    for text in tweets:
        payload = {"text": text}
        if reply_to:
            payload["reply"] = {"in_reply_to_tweet_id": reply_to}
        resp = oauth.post("https://api.x.com/2/tweets", json=payload)
        tweet_id = resp.json()["data"]["id"]
        ids.append(tweet_id)
        reply_to = tweet_id
    return ids

Read User Timeline

resp = requests.get(
    f"https://api.x.com/2/users/{user_id}/tweets",
    headers=headers,
    params={
        "max_results": 10,
        "tweet.fields": "created_at,public_metrics",
    }
)

Search Tweets

resp = requests.get(
    "https://api.x.com/2/tweets/search/recent",
    headers=headers,
    params={
        "query": "from:affaanmustafa -is:retweet",
        "max_results": 10,
        "tweet.fields": "public_metrics,created_at",
    }
)

Pull Recent Original Posts for Voice Modeling

resp = requests.get(
    "https://api.x.com/2/tweets/search/recent",
    headers=headers,
    params={
        "query": "from:affaanmustafa -is:retweet -is:reply",
        "max_results": 25,
        "tweet.fields": "created_at,public_metrics",
    }
)
voice_samples = resp.json()

Get User by Username

resp = requests.get(
    "https://api.x.com/2/users/by/username/affaanmustafa",
    headers=headers,
    params={"user.fields": "public_metrics,description,created_at"}
)

Upload Media and Post

# Media upload uses v1.1 endpoint

# Step 1: Upload media
media_resp = oauth.post(
    "https://upload.twitter.com/1.1/media/upload.json",
    files={"media": open("image.png", "rb")}
)
media_id = media_resp.json()["media_id_string"]

# Step 2: Post with media
resp = oauth.post(
    "https://api.x.com/2/tweets",
    json={"text": "Check this out", "media": {"media_ids": [media_id]}}
)

Rate Limits

X API rate limits vary by endpoint, auth method, and account tier, and they change over time. Always:

  • Check the current X developer docs before hardcoding assumptions
  • Read x-rate-limit-remaining and x-rate-limit-reset headers at runtime
  • Back off automatically instead of relying on static tables in code
import time

remaining = int(resp.headers.get("x-rate-limit-remaining", 0))
if remaining < 5:
    reset = int(resp.headers.get("x-rate-limit-reset", 0))
    wait = max(0, reset - int(time.time()))
    print(f"Rate limit approaching. Resets in {wait}s")

Error Handling

resp = oauth.post("https://api.x.com/2/tweets", json={"text": content})
if resp.status_code == 201:
    return resp.json()["data"]["id"]
elif resp.status_code == 429:
    reset = int(resp.headers["x-rate-limit-reset"])
    raise Exception(f"Rate limited. Resets at {reset}")
elif resp.status_code == 403:
    raise Exception(f"Forbidden: {resp.json().get('detail', 'check permissions')}")
else:
    raise Exception(f"X API error {resp.status_code}: {resp.text}")

Security

  • Never hardcode tokens. Use environment variables or .env files.
  • Never commit `.env` files. Add to .gitignore.
  • Rotate tokens if exposed. Regenerate at developer.x.com.
  • Use read-only tokens when write access is not needed.
  • Store OAuth secrets securely — not in source code or logs.

Integration with Content Engine

Use brand-voice plus content-engine to generate platform-native content, then post via X API: 1. Pull recent original posts when voice matching matters 2. Build or reuse a VOICE PROFILE 3. Generate content with content-engine in X-native format 4. Validate length and thread structure 5. Return the draft for approval unless the user explicitly asked to post now 6. Post via X API only after approval 7. Track engagement via public_metrics

Related Skills

  • brand-voice — Build a reusable voice profile from real X and site/source material
  • content-engine — Generate platform-native content for X
  • crosspost — Distribute content across X, LinkedIn, and other platforms
  • connections-optimizer — Reorganize the X graph before drafting network-driven outreach

Related skills

Forks & variants (1)

X Api has 1 known copy in the catalog totaling 1.4k installs. They canonicalize to this original listing.

How it compares

Use x-api for X/Twitter backend integration; use magicpath for MagicPath SaaS CLI auth when the target platform is MagicPath instead of social APIs.

FAQ

Who is x-api for?

Developers integrating X API v2 for posting, threads, search, and timeline reads.

When should I use x-api?

When writing OAuth-authenticated X scripts with rate limit checks and media uploads.

Is x-api safe to install?

Review Security Audits panel; OAuth secrets must stay in env vars never in source or logs.

Automation & Workflowsdistributioncontent

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.