
X Api
- 5.1k installs
- 238k repo stars
- Updated August 5, 2026
- affaan-m/everything-claude-code
x-api is an agent skill for X API v2 posting, threads, search, timelines, media upload, and rate-limit aware OAuth setup.
About
The x-api skill documents programmatic X integration for posting, reading, searching, and analytics. OAuth 2.0 bearer tokens suit read-heavy search and public data via X_BEARER_TOKEN headers against api.x.com v2 endpoints. OAuth 1.0a user context with X_CONSUMER_KEY, X_CONSUMER_SECRET, X_ACCESS_TOKEN, and X_ACCESS_TOKEN_SECRET is required for posting tweets, threads, account management, and DMs using requests_oauthlib OAuth1Session. Core operations include single tweet POST, thread helper chaining reply in_reply_to_tweet_id, user timeline fetch with tweet.fields metrics, recent search with query operators, voice sampling search excluding retweets and replies, user lookup by username, and v1.1 media upload followed by v2 tweet with media_ids. Rate limits vary by endpoint and tier; read x-rate-limit-remaining and x-rate-limit-reset headers at runtime with backoff instead of hardcoded tables. Security rules forbid hardcoding tokens, committing .env files, and require rotation on exposure. Content integration flows through brand-voice and content-engine with draft approval before posting unless explicitly requested.
- Bearer token for read search; OAuth 1.0a user context required for writes and DMs.
- Documents post tweet, thread reply chain, timeline, search, and media upload v1.1 flow.
- Rate limit handling reads x-rate-limit-remaining and reset headers dynamically.
- Security: env vars only, never commit .env, rotate exposed tokens at developer.x.com.
- Integrates with brand-voice and content-engine for draft approval before posting.
X Api by the numbers
- 5,102 all-time installs (skills.sh)
- +247 installs in the week ending Aug 4, 2026 (Skillselion tracking)
- Ranked #73 of 2,715 Automation & Workflows skills by installs in the Skillselion catalog
- Security screen: MEDIUM risk (skills.sh audit)
- Data as of Aug 5, 2026 (Skillselion catalog sync)
x-api capabilities & compatibility
- Capabilities
- oauth 2.0 bearer read operations · oauth 1.0a write and dm flows · thread posting helper pattern · media upload v1.1 plus v2 tweet · dynamic rate limit header backoff
- Works with
- openai
- Use cases
- marketing · orchestration · research
What x-api says it does
OAuth 1.0a (User Context) Required for: posting tweets, managing account, DMs
Return the draft for approval unless the user explicitly asked to post now
npx skills add https://github.com/affaan-m/everything-claude-code --skill x-apiAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 5.1k |
|---|---|
| repo stars | ★ 238k |
| Security audit | 2 / 3 scanners passed |
| Last updated | August 5, 2026 |
| Repository | affaan-m/everything-claude-code ↗ |
How do I post tweets or search X programmatically with correct OAuth and rate limit handling?
Integrate X Twitter API v2 for posting tweets and threads, timelines, search, media upload, and rate-limit aware error handling.
Who is it for?
Developers automating X posting, search, or analytics with documented OAuth patterns.
Skip if: Skip when only multi-platform copy adaptation is needed; use crosspost without API calls.
When should I use this skill?
User says post to X, tweet, X API, Twitter API, or wants timeline search automation.
What you get
Working X API calls for read or write flows with env-based credentials and approval gates.
- Posted tweets or threads
- Search and timeline results
By the numbers
- Media upload uses v1.1 endpoint before v2 tweet post
- Voice sampling query uses max_results 25 in example
Files
X API
Programmatic interaction with X (Twitter) for posting, reading, searching, and analytics.
When to Activate
- User wants to post tweets or threads programmatically
- Reading timeline, mentions, or user data from X
- Searching X for content, trends, or conversations
- Building X integrations or bots
- Analytics and engagement tracking
- User says "post to X", "tweet", "X API", or "Twitter API"
Authentication
OAuth 2.0 Bearer Token (App-Only)
Best for: read-heavy operations, search, public data.
# Environment setup
export X_BEARER_TOKEN="your-bearer-token"import os
import requests
bearer = os.environ["X_BEARER_TOKEN"]
headers = {"Authorization": f"Bearer {bearer}"}
# Search recent tweets
resp = requests.get(
"https://api.x.com/2/tweets/search/recent",
headers=headers,
params={"query": "claude code", "max_results": 10}
)
tweets = resp.json()OAuth 1.0a (User Context)
Required for: posting tweets, managing account, DMs, and any write flow.
# Environment setup — source before use
export X_CONSUMER_KEY="your-consumer-key"
export X_CONSUMER_SECRET="your-consumer-secret"
export X_ACCESS_TOKEN="your-access-token"
export X_ACCESS_TOKEN_SECRET="your-access-token-secret"Legacy aliases such as X_API_KEY, X_API_SECRET, and X_ACCESS_SECRET may exist in older setups. Prefer the X_CONSUMER_* and X_ACCESS_TOKEN_SECRET names when documenting or wiring new flows.
import os
from requests_oauthlib import OAuth1Session
oauth = OAuth1Session(
os.environ["X_CONSUMER_KEY"],
client_secret=os.environ["X_CONSUMER_SECRET"],
resource_owner_key=os.environ["X_ACCESS_TOKEN"],
resource_owner_secret=os.environ["X_ACCESS_TOKEN_SECRET"],
)Core Operations
Post a Tweet
resp = oauth.post(
"https://api.x.com/2/tweets",
json={"text": "Hello from Claude Code"}
)
resp.raise_for_status()
tweet_id = resp.json()["data"]["id"]Post a Thread
def post_thread(oauth, tweets: list[str]) -> list[str]:
ids = []
reply_to = None
for text in tweets:
payload = {"text": text}
if reply_to:
payload["reply"] = {"in_reply_to_tweet_id": reply_to}
resp = oauth.post("https://api.x.com/2/tweets", json=payload)
tweet_id = resp.json()["data"]["id"]
ids.append(tweet_id)
reply_to = tweet_id
return idsRead User Timeline
resp = requests.get(
f"https://api.x.com/2/users/{user_id}/tweets",
headers=headers,
params={
"max_results": 10,
"tweet.fields": "created_at,public_metrics",
}
)Search Tweets
resp = requests.get(
"https://api.x.com/2/tweets/search/recent",
headers=headers,
params={
"query": "from:affaanmustafa -is:retweet",
"max_results": 10,
"tweet.fields": "public_metrics,created_at",
}
)Pull Recent Original Posts for Voice Modeling
resp = requests.get(
"https://api.x.com/2/tweets/search/recent",
headers=headers,
params={
"query": "from:affaanmustafa -is:retweet -is:reply",
"max_results": 25,
"tweet.fields": "created_at,public_metrics",
}
)
voice_samples = resp.json()Get User by Username
resp = requests.get(
"https://api.x.com/2/users/by/username/affaanmustafa",
headers=headers,
params={"user.fields": "public_metrics,description,created_at"}
)Upload Media and Post
# Media upload uses v1.1 endpoint
# Step 1: Upload media
media_resp = oauth.post(
"https://upload.twitter.com/1.1/media/upload.json",
files={"media": open("image.png", "rb")}
)
media_id = media_resp.json()["media_id_string"]
# Step 2: Post with media
resp = oauth.post(
"https://api.x.com/2/tweets",
json={"text": "Check this out", "media": {"media_ids": [media_id]}}
)Rate Limits
X API rate limits vary by endpoint, auth method, and account tier, and they change over time. Always:
- Check the current X developer docs before hardcoding assumptions
- Read
x-rate-limit-remainingandx-rate-limit-resetheaders at runtime - Back off automatically instead of relying on static tables in code
import time
remaining = int(resp.headers.get("x-rate-limit-remaining", 0))
if remaining < 5:
reset = int(resp.headers.get("x-rate-limit-reset", 0))
wait = max(0, reset - int(time.time()))
print(f"Rate limit approaching. Resets in {wait}s")Error Handling
resp = oauth.post("https://api.x.com/2/tweets", json={"text": content})
if resp.status_code == 201:
return resp.json()["data"]["id"]
elif resp.status_code == 429:
reset = int(resp.headers["x-rate-limit-reset"])
raise Exception(f"Rate limited. Resets at {reset}")
elif resp.status_code == 403:
raise Exception(f"Forbidden: {resp.json().get('detail', 'check permissions')}")
else:
raise Exception(f"X API error {resp.status_code}: {resp.text}")Security
- Never hardcode tokens. Use environment variables or
.envfiles. - Never commit `.env` files. Add to
.gitignore. - Rotate tokens if exposed. Regenerate at developer.x.com.
- Use read-only tokens when write access is not needed.
- Store OAuth secrets securely — not in source code or logs.
Integration with Content Engine
Use brand-voice plus content-engine to generate platform-native content, then post via X API: 1. Pull recent original posts when voice matching matters 2. Build or reuse a VOICE PROFILE 3. Generate content with content-engine in X-native format 4. Validate length and thread structure 5. Return the draft for approval unless the user explicitly asked to post now 6. Post via X API only after approval 7. Track engagement via public_metrics
Related Skills
brand-voice— Build a reusable voice profile from real X and site/source materialcontent-engine— Generate platform-native content for Xcrosspost— Distribute content across X, LinkedIn, and other platformsconnections-optimizer— Reorganize the X graph before drafting network-driven outreach
interface:
display_name: "X API"
short_description: "X API posting, timelines, and analytics"
brand_color: "#000000"
default_prompt: "Use $x-api to build X API posting, timeline, or analytics workflows."
policy:
allow_implicit_invocation: true
Related skills
Forks & variants (1)
X Api has 1 known copy in the catalog totaling 1.4k installs. They canonicalize to this original listing.
- affaan-m - 1.4k installs
How it compares
Use x-api for X/Twitter backend integration; use magicpath for MagicPath SaaS CLI auth when the target platform is MagicPath instead of social APIs.
FAQ
Who is x-api for?
Developers integrating X API v2 for posting, threads, search, and timeline reads.
When should I use x-api?
When writing OAuth-authenticated X scripts with rate limit checks and media uploads.
Is x-api safe to install?
Review Security Audits panel; OAuth secrets must stay in env vars never in source or logs.