IntegrationsIntegration setup guides

X (Twitter)

Connect X (Twitter) to your Appstrate agents.

Overview

X is a social network. The integration uses the X API v2 with OAuth 2.0 and PKCE, and requests offline.access by default so tokens can refresh.

Integration: @appstrate/x (version 1.0.5), reached through the api_call tool. For how this works, see How integrations work.

Authentication

PropertyValue
Typeoauth2
Credential sent asAuthorization: Bearer <credential>
Default scopestweet.read, users.read, offline.access
Token endpoint authclient_secret_basic
PKCES256

Scopes

The scopes below are the catalogue the integration declares. An agent gets the default scopes plus any it lists under scopes in its integrations_configuration.

ScopeDescriptionDefault
tweet.readRead tweetsyes
tweet.writePost & delete tweets
tweet.moderate.writeModerate tweet replies
users.readRead user profilesyes
follows.readRead followers & following
follows.writeFollow & unfollow users
like.readRead likes
like.writeLike & unlike tweets
list.readRead lists
list.writeCreate & manage lists
bookmark.readRead bookmarks
bookmark.writeManage bookmarks
space.readRead Spaces
dm.readRead direct messages
dm.writeSend direct messages
offline.accessRefresh token (long-lived access)yes

Authorized URIs

The sidecar sends the credential only to URLs that match one of these patterns:

  • https://api.x.com/**

Connect X (Twitter)

An administrator registers an OAuth client once, then members connect their own accounts.

Create a project and an app in the X developer portal, then enable OAuth 2.0 (open).

Register the redirect URI as the app's callback URI: it is APP_URL followed by /api/integrations/callback, also shown in the integration's setup panel.

In Appstrate, open the integration and register the OAuth client (client ID and client secret). See How integrations work.

Use it in an agent

Excerpt of the agent manifest:

{
  "dependencies": {
    "integrations": { "@appstrate/x": "^1.0.0" }
  },
  "integrations_configuration": {
    "@appstrate/x": {
      "tools": ["api_call"],
      "scopes": ["tweet.write"]
    }
  }
}

api_call has no per-tool scopes, so scopes beyond the defaults are listed explicitly (here tweet.write).

Example prompt:

Summarize the replies to my last three posts and draft an answer to each one for my review.

On this page