X API v2 Samples: Official Working Code for Five Languages
Sample code for the X API v2 endpoints
At a glance
- What is it?
- xdevplatform/samples is the official repository of working code examples for the X API v2, covering posts, users, timelines, streams, lists, and more across Python, JavaScript, Ruby, Java, and R. It is the reference starting point for developers integrating with X's API.
- Who is it for?
- Teams building X API integrations from scratch will find this repository a practical starting point for Python, JavaScript, and Ruby. Java and R coverage is thinner, with 19 and 5 examples respectively.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Activity is slowing. The repository last received commits 6 months ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What the X API v2 Samples Repository Provides
The xdevplatform/samples repository holds 206 runnable code examples spread across five languages: 65 Python, 59 JavaScript, 58 Ruby, 19 Java, and 5 R. The examples cover the major endpoint categories of the X API v2: posts, users, timelines, streams, lists, spaces, bookmarks, direct messages, media upload, compliance, and usage tracking.
The repository is maintained by xdevplatform, the X platform's developer tooling team. It is intended as a reference implementation showing how to make authenticated API calls correctly. The README links to the X Developer documentation at developer.x.com and to the Developer Portal where credentials are issued.
Two machine-readable files are also provided: llms.txt, described as a context file for AI assistants, and api-index.json, a catalog of the API endpoints covered by the examples.
Repository Organization by Language and Feature Category
The repository root contains a language directory for each of the five supported languages:
python/ # 65 Python examples
javascript/ # 59 JavaScript examples
ruby/ # 58 Ruby examples
java/ # 19 Java examples
r/ # 5 R examples
llms.txt # LLM-friendly documentation
api-index.json # Machine-readable endpoint catalogWithin each language directory, examples are grouped by API category. The README documents which categories have examples in each language using a coverage table. Posts, users, timelines, and streams all have examples in Python, JavaScript, Ruby, and Java. Lists and spaces are covered in Python, JavaScript, and Ruby but not in Java. Direct messages, media upload, bookmarks, and compliance are available only in Python and partially in JavaScript. R is limited to posts, users, timelines, and spaces.
Setting Up Credentials and Running the First Example
All examples require credentials from the X Developer Portal at developer.x.com/en/portal/dashboard. The authentication type required depends on the operation. For read-only operations such as search and lookup, set the bearer token:
export BEARER_TOKEN='your_bearer_token'For user actions such as posting, liking, reposting, bookmarking, and muting, set the OAuth 2.0 PKCE credentials:
export CLIENT_ID='your_client_id'
export CLIENT_SECRET='your_client_secret'For legacy OAuth 1.0a endpoints, set these variables instead:
export CONSUMER_KEY='your_consumer_key'
export CONSUMER_SECRET='your_consumer_secret'To run the Python recent search example after setting credentials:
cd python && pip install -r requirements.txt
python posts/search_recent.pyThe equivalent JavaScript and Ruby examples are run with `node posts/search_recent.js` and `ruby posts/search_recent.rb` respectively. The Java example requires compiling against the bundled lib/ directory before running.
Authentication Types and When Each Applies
The repository uses three distinct authentication methods, and choosing the wrong one for an endpoint will produce an authorization error. Bearer token authentication is for read-only operations: searching recent posts, looking up users or timelines, and querying spaces. It does not require user consent and is the simplest to configure.
OAuth 2.0 PKCE, using CLIENT_ID and CLIENT_SECRET, is required for user-context actions: creating or deleting posts, liking or unliking, reposting, bookmarking, blocking, muting, and managing lists. This flow requires a redirect URI and user authorization, which means examples using it involve more setup than bearer token examples.
OAuth 1.0a, using CONSUMER_KEY and CONSUMER_SECRET, is listed as applicable to legacy endpoints. The README does not specify which endpoints still require it, describing it only as covering "legacy endpoints (if applicable)."
Coverage Gaps: What the Samples Do Not Include
Direct messages and media upload examples exist only in Python. A team building a multi-language application that needs to send direct messages or upload media will need to write their own implementations for JavaScript, Ruby, or Java, using the Python examples as a reference.
The R examples cover only five categories: posts, users, timelines, spaces, and one more based on the coverage table. Teams using R for data analysis of X data have a narrower starting set and will likely need to adapt Python examples.
The Java examples number only 19 compared to 65 for Python. Java lacks coverage for lists and spaces entirely. A Java-heavy backend team will encounter more gaps than a Python or JavaScript team.
The repository has no GitHub releases. Version pinning or change tracking must be done through git commit history rather than a release tag, which makes it harder to audit what changed between a known working state and the current code.
Comparison with Tweepy: Working Examples versus an Abstracted Client
Tweepy is a well-known Python library for the Twitter/X API that provides Python objects and methods wrapping the raw HTTP calls. It handles pagination, rate limit backoff, and authentication flows at the library level, so a developer using Tweepy writes less boilerplate than the xdevplatform samples require.
The trade-off is transparency. The samples in xdevplatform/samples call the API directly using standard HTTP clients, which means a developer can see exactly what request is being sent and what response comes back. This is useful when debugging authentication issues, understanding rate limits, or learning the API mechanics before committing to a higher-level library. It is also the only option for teams working in Ruby, Java, or R, where no equivalent of Tweepy exists with the same level of maintenance.
For production Python applications, Tweepy offers more built-in conveniences. For teams learning the API or working in non-Python languages, the xdevplatform samples are the more direct reference.
Maintenance State and Licence
The last push to the repository was on 2026-03-20, which is more than six months before this review. The repository is not archived. Because the last push is over six months old, it should not be assumed to reflect the current state of the X API v2 endpoints, which may have changed.
The repository is licensed under Apache 2.0, which allows use, modification, and distribution in commercial products with attribution. The repository also contains a CODE_OF_CONDUCT.md file at the root.
Editorial conclusion
Teams building X API integrations from scratch will find this repository a practical starting point for Python, JavaScript, and Ruby. Java and R coverage is thinner, with 19 and 5 examples respectively. Direct Messages and Media Upload are available only in Python, so developers working in other languages should verify those gaps against their integration requirements before choosing this repository as their primary reference. The last push to the repository was on 2026-03-20.
Frequently asked questions
How do I get credentials to run the X API v2 samples?
Credentials are issued through the X Developer Portal at developer.x.com/en/portal/dashboard. The type of credential needed depends on the operation: a bearer token for read-only calls, CLIENT_ID and CLIENT_SECRET for user actions via OAuth 2.0 PKCE, and CONSUMER_KEY and CONSUMER_SECRET for legacy OAuth 1.0a endpoints.
Which languages have the most complete X API v2 sample coverage?
Python has the most examples at 65, covering all categories including direct messages and media upload. JavaScript has 59 and Ruby 58, both covering most categories. Java has 19 examples and lacks list and space coverage. R has only 5 examples.
Are the xdevplatform samples suitable for production use?
The examples demonstrate how to call the API correctly but are reference implementations, not production-ready libraries. They do not include built-in rate limit handling or pagination helpers. Teams building production integrations in Python may prefer a library like Tweepy, which adds those conveniences on top of the same underlying API.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/xdevplatform-samples)