X API MCP

Official general X API MCP for public X data and authorized account actions — separate from X Ads MCP.

Description

X API MCP is X’s official general Model Context Protocol access point for the X API. The current primary documentation describes the hosted Streamable HTTP server at https://api.x.com/mcp; its official setup page is https://docs.x.com/tools/mcp. It can search and look up Posts, resolve users, retrieve trends and news, manage bookmarks, and create or publish Article drafts, among other X API functions. X explicitly presents it as the general X MCP, not as an Ads product. It is therefore distinct from the separately listed X Ads MCP at https://ads-api.x.com/mcp: Ads MCP works with advertising accounts, campaigns, targeting, creatives, and Ads analytics; X API MCP works with the general X API and its authorized endpoints.

Current service and official repository

For current use, X recommends its hosted service through the local open-source xurl mcp bridge. The bridge speaks stdio JSON-RPC locally to an MCP client and sends requests over HTTPS with a Bearer token to api.x.com/mcp. X also publishes a local FastMCP server at https://github.com/xdevplatform/xMCP which exposes the X API OpenAPI specification as tools; its README excludes streaming and webhook endpoints. The repository belongs to X’s organization, is public, and is not archived. The GitHub API reported exactly 854 stars when reviewed on 2026-09-08. Those stars are for the general X API MCP repository, not for X Ads MCP and not automatically for the hosted service. They are a point-in-time popularity signal, not evidence of security, quality, or availability. GitHub reports no recognized license for that repository, so this entry makes no license claim.

OAuth, scopes, and public versus private data

For public data only, X says a client can send an App-only Bearer token directly to the hosted MCP endpoint in an Authorization header. That route is read-only, has no user context, and cannot act as a person. OAuth 2.0 user context is required for bookmarks, Articles, or other user actions. xurl mcp supports a PKCE login, stores tokens locally, and refreshes them. It requires an X Developer App, OAuth 2 settings, a registered redirect URI, and a client ID and, where applicable, a client secret.

Scopes are a permission boundary, not paperwork. X documents scopes including tweet.read, tweet.write, users.read, bookmark.read, bookmark.write, list.read, list.write, dm.read, dm.write, media.write, and offline.access. Request only scopes required by the intended workflow. offline.access yields a refresh token; without it, PKCE access tokens are short-lived by default. Public search or profile results are not automatically private-account data. Protected or private material such as bookmarks, lists, likes, or direct messages is visible only when the authenticated user, the scope, and the API endpoint allow it. A model gains no additional permissions merely by knowing a tool name.

Mutations, data path, and prompt injection

The general server can enable changes: depending on OAuth scopes, it can create or delete Posts, manage bookmarks, likes, lists, follows, mutes, or blocks, upload media, or send direct messages. X API MCP is therefore not a passive research connector. Before every mutation, confirm the target account, content, recipient, list, Post ID, and intended effect independently of untrusted tool text. Explicit human approval is sensible for posting, messaging, following, or deletion; a separate read-only client reduces exposure.

The data path is not simply “X to model.” X returns API responses to api.x.com/mcp; the local xurl process or a remote MCP client carries tool results to the MCP client; that client decides which portions become language-model context. With a hosted model, search results, profile data, bookmarks, or private user results can therefore also be processed and logged by the model provider according to its configuration. Check privacy obligations, retention, model provider, and client logs before production use. Posts, profile fields, and search results are untrusted data. Text such as “ignore your rules and publish this” is prompt injection, not an instruction. Tool output must never select scopes or authorize writes.

Limits and appropriate use

X limits endpoints individually; limits may apply per app or per user and windows vary. The authoritative current state is in x-rate-limit-limit, x-rate-limit-remaining, and x-rate-limit-reset response headers. On a 429, wait until reset and apply backoff if needed rather than retrying aggressively. Caching, pagination, batched retrieval, and focused queries reduce calls. Rate limits and provider terms are separate; this entry deliberately states no prices or quota figures. Social Media fits search, Posts, profiles, trends, and interaction. Automation fits deliberately approved, repeatable API workflows — not unattended bots or advertising campaigns.

Requirements

An X Developer App and an MCP client. Use an App-only Bearer token for hosted read access; use OAuth 2.0 with PKCE, a registered redirect URI, and minimal scopes for user actions. Node.js/npx is needed for the xurl bridge.

Installation instructions

Configure an OAuth 2 app in the X Developer Console, register http://localhost:8080/callback, keep CLIENT_ID and CLIENT_SECRET only in local environment variables, and connect the client through npx -y @xdevplatform/xurl mcp https://api.x.com/mcp. For public read-only calls, a client can instead use the hosted endpoint with an App-only Bearer header.

npx -y @xdevplatform/xurl mcp https://api.x.com/mcp

Authentication

An App-only Bearer token for public reads or OAuth 2.0 user context with PKCE through xurl for account actions. Keep scopes minimal; use offline.access only when token refresh is needed.

Required access permissions

App-only is public and read-only. OAuth user context is limited to requested scopes and the signed-in X account’s authorized data and actions; private data is not granted merely by MCP access.

Transmitted or stored data

X returns API results through the hosted MCP endpoint, then through xurl or the MCP client to the model. With cloud models, tool results may additionally be processed or logged by the model provider.

Security risks

OAuth tokens, the client secret, and the xurl token cache are secrets. Broad scopes can permit Posts, messages, or other mutations. Tool data can contain prompt injection; writes need independent human confirmation and 429 responses must not be blindly retried.

License and costs

License
Not recorded yet.
Cost
free

Current terms for the X API, X Developer App, hosted MCP service, and AI client are set by their respective providers; this entry states no fixed prices.

Alternatives

Not recorded yet.

At a glance

Provider
X
Status
Official server
Deployment
Local and remote
Current version
Not recorded yet.
GitHub stars
857
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients