Model or dataset
nirholas/XActions avatar
nirholas/XActions

XActions: X/Twitter Automation Toolkit with MCP, CLI, and Browser Scripts

⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/GPT), CLI, browser scripts. No API fees. Open source. Unfollow people who don't follow back. Monitor real-time analytics. Auto follow, like, comment, scrape, without API. Follow Bot. Like bot. Grow your account automatically.

548 stars104 forksHTMLApache-2.0

At a glance

What is it?
XActions is an open-source JavaScript toolkit for automating X (formerly Twitter) without official API keys, using browser session cookies instead. It provides 154 MCP server tools for AI agents, a 56-command CLI, 95 browser console scripts, a browser extension, and a Docker-deployable backend with PostgreSQL and Redis. It is aimed at developers, AI agents, and automation engineers who need Twitter data or workflow automation outside the constraints of the paid X API.
Who is it for?
XActions is a practical option for developers who need X/Twitter data or automation and have been blocked by the cost or restrictions of the official X API. The absence of an API key requirement is the core trade-off: it gives broad access but relies on browser session cookies and unofficial request patterns, which means X can change behavior without notice and sessions may be invalidated.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly HTML, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What XActions Addresses and Who It Is For

Twitter's official API access tiers moved most developer use cases behind paid plans. That change cut off a significant group: developers who need profile data, tweet archives, search results, or follower lists for automation, research, or AI agent tooling, but whose use case does not justify an enterprise API contract.

XActions addresses this by authenticating through browser session cookies rather than official API credentials. A profile lookup, a tweet timeline download, or a keyword search all work without registering a developer account or paying an API fee. The zero-install quick start illustrates this: one npx command retrieves a public profile.

The toolkit targets three distinct users. Developers who want a CLI or JavaScript library for data access and automation scripts are one group. Teams building AI agents on Claude or other LLM systems that need Twitter context or actions are another, through the 154-tool MCP server. The browser extension and console scripts serve a third group: users who want to run automations directly on x.com without writing code.

How XActions Authenticates Without API Keys

XActions uses x.com browser session cookies in place of API credentials. The README documents several ways to supply these cookies: the --from-browser flag reads cookies directly from an installed Chrome, Chromium, Brave, Edge, Arc, or Firefox profile; --cookies-file imports a Netscape cookies.txt, a Cookie-Editor or EditThisCookie JSON export, or a Playwright/Puppeteer storageState file.

For read-only public data (public profiles, tweet counts), the README shows that no login at all is needed. The profile lookup example works with no account and no browser:

bash
npx xactions profile nasa

For operations that require authentication (search, followers, direct messages), xactions login sets up session cookies. The README notes that a full cookie jar beats a bare auth_token because it carries the ct0 token that every write operation requires.

XActions also manages the GraphQL query IDs that X rotates periodically. When X rotates these IDs, tools that embed them statically break. XActions discovers the current IDs from x.com's own JavaScript bundles and caches them. The xactions doctor command reports the cache age. Every GraphQL call also carries the x-client-transaction-id header computed the same way the x.com web client computes it, which helps requests receive the same responses a browser would.

CLI Commands, Browser Scripts, and First Use

The CLI covers 56 commands grouped by task. A guided first-run walkthrough is available:

bash
npx xactions quickstart

Shell tab completion can be added with:

bash
xactions completion bash

Or zsh, or fish. The completion script is generated from the live command tree, so it stays current as new commands are added.

Common data export commands:

bash
npx xactions tweets nasa --limit 100 --output nasa.csv
npx xactions login
npx xactions search "your brand" --limit 50

The first command exports the NASA account's last 100 tweets to a CSV file. The second sets up authentication for operations that require it. The third runs a keyword search limited to 50 results.

For a full deployment with the API server, background worker, PostgreSQL, and Redis:

bash
docker compose up -d

The docker-compose.yml in the repository defines four services: postgres (version 16, for persistent session and data storage), redis (version 7, for job queues and caching), the API server on port 3001, and a background worker. The .env.example file documents the required environment variables including the X402 payment configuration for AI agent monetization.

The Approval Gate and Daily Action Caps

Write operations in XActions are held as drafts pending human approval before execution. The README identifies this as a deliberate design choice borrowed from the x-use project. Drafts cover actions like posting, liking, replying, and unfollowing. This prevents an AI agent or automated script from executing writes without a human seeing what is about to happen.

Daily action caps are stored on disk and persist across restarts. The caps are configured per account and apply a ceiling to how many times a given action type can run in a day. This is a practical guard against account suspension from rate-limit violations; X's own headers inform the per-operation rate-limit windows that the account pool respects.

The account pool itself stores sessions in SQLite, with each session holding its own proxy configuration and per-operation rate-limit state. When a session receives a 429 response, the pool rotates to the next available session and locks the throttled one for the duration of the window read from X's response headers.

Scrapes that span many pages checkpoint their position using cursor values. If a long scrape is interrupted, resuming from the last cursor avoids refetching data already retrieved.

Comparison with twikit and Scope of Write Actions

twikit (github.com/d60/twikit) is a Python library that also authenticates through browser cookies rather than the official X API. It offers account interaction (posting, liking, following) and timeline access without API keys.

The functional scope difference is significant. twikit is a Python library without an MCP server, a browser extension, or browser console scripts. XActions bundles all of these into one JavaScript package, which matters for teams building AI agent pipelines that need an MCP-compatible Twitter interface. The README's comparison table also notes that twikit lacks the approval gate on write operations and the daily action caps, which XActions inherited from x-use. For teams where oversight of automated writes is required, that distinction is concrete.

Both projects carry the same fundamental legal risk: authenticating through session cookies and bypassing the official API goes against X's terms of service. X's enforcement posture can change at any time, and accounts using such tools may be suspended. XActions mitigates some operational risk through the approval gate and caps, but the terms of service exposure remains.

Licence, Maintenance, and the AI Voice Agent Feature

XActions is licensed under Apache 2.0, which allows commercial use, modification, and distribution, with attribution and preservation of the Apache 2.0 licence notice. The last push to the repository was on 2026-09-24. The package.json shows version 3.5.0, and the repository includes a CHANGELOG.md and a ROADMAP.md.

The README documents recent additions including a searchSweep.js browser script for bulk actions on any X search result, an engageProfile.js script for liking and replying to all posts on a profile, tab completion, and cookie import from installed browsers.

One capability specific to XActions is the AI Voice Agent for Spaces. The README comparison table describes it as the ability to join an X Space, listen, and speak. This is not present in any of the eight other tools listed in the comparison. Whether this feature is stable or experimental is not stated in the README.

The repository ships multiple deployment options: npm package, Docker image (using Node.js 20 with Chromium for Puppeteer), Vercel, Fly.io, Railway, and Coolify configurations are all present in the top-level file listing.

Editorial conclusion

XActions is a practical option for developers who need X/Twitter data or automation and have been blocked by the cost or restrictions of the official X API. The absence of an API key requirement is the core trade-off: it gives broad access but relies on browser session cookies and unofficial request patterns, which means X can change behavior without notice and sessions may be invalidated. Before deploying it in production, read the human approval gate documentation for write operations, verify that your intended actions stay within the daily caps the tool enforces, and assess your organization's risk tolerance for operating outside the official API terms.

Frequently asked questions

Are Twitter bots allowed under X's terms of service?

X's terms of service prohibit unauthorized scraping, automation through unofficial means, and operating bots that violate platform policies. XActions works through browser session cookies rather than the official API, which falls outside the official developer terms. The README acknowledges this by implementing an approval gate on all write operations and daily action caps, but the terms of service risk remains.

How do Twitter bots work with XActions?

XActions authenticates using browser session cookies imported from an installed browser or provided as a cookie file. It constructs requests that match what the x.com web client sends, including dynamically discovered GraphQL query IDs and the x-client-transaction-id header. Write operations like posting or following are held as drafts pending human approval before execution.

How can I automate tweets with XActions?

XActions provides the engageProfile.js browser script and the xactions engage CLI command for automated interaction with posts, including liking, reposting, and commenting. All write operations are held as drafts and require manual approval before execution. The xactions completion command adds shell tab completion for all 56 CLI commands.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. nirholas/XActions on GitHub
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/nirholas-xactions.svg)](https://hysenlabs.com/projects/nirholas-xactions)