X TwitterSAFE
X/Twitter MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@rafaljanicki/x-twitter-mcp-server) [](https://badge.fury.io/py/x-twitter-mcp)
A Model Context Protocol (MCP) server for interacting with Twitter (X) via AI tools. This server allows you to fetch tweets, post tweets, search Twitter, manage followers, and more, all through natural language commands in AI Tools.
Features
- Fetch user profiles, followers, and following lists.
- Post, delete, and favorite tweets.
- Search Twitter for tweets and trends.
- Manage bookmarks and timelines.
- Built-in rate limit handling for the Twitter API.
- Uses Twitter API v2 with proper authentication (API keys and tokens), avoiding the username/password hack to minimize the risk of account suspensions.
- Provides a complete implementation of Twitter API v2 endpoints for user management, tweet management, timelines, and search functionality.
Prerequisites
- Python 3.10 or higher: Ensure Python is installed on your system.
- Twitter Developer Account: You need API credentials (API Key, API Secret, Access Token, Access Token Secret, and Bearer Token) from the Twitter Developer Portal.
- Optional: Claude Desktop: Download and install the Claude Desktop app from the Anthropic website.
- Optional: Node.js (for MCP integration): Required for running MCP servers in Claude Desktop.
- A package manager like
uvorpipfor Python dependencies.
Installation
Option 1: Installing via Smithery (Recommended)
To install X (Twitter) MCP server for Claude Desktop automatically via [Smithe
4154be1f3287OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add x-twitter-mcp --env TWITTER_ACCESS_TOKEN=${TWITTER_ACCESS_TOKEN} --env TWITTER_ACCESS_TOKEN_SECRET=${TWITTER_ACCESS_TOKEN_SECRET} --env TWITTER_API_KEY=${TWITTER_API_KEY} --env TWITTER_API_SECRET=${TWITTER_API_SECRET} -- uvx x-twitter-mcp{
"mcpServers": {
"x-twitter-mcp": {
"command": "uvx",
"args": [
"x-twitter-mcp"
],
"env": {
"TWITTER_ACCESS_TOKEN": "${TWITTER_ACCESS_TOKEN}",
"TWITTER_ACCESS_TOKEN_SECRET": "${TWITTER_ACCESS_TOKEN_SECRET}",
"TWITTER_API_KEY": "${TWITTER_API_KEY}",
"TWITTER_API_SECRET": "${TWITTER_API_SECRET}"
}
}
}
}Exposed tools (18)
13 read · 2 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
bookmark_tweet | read | Bookmarks a tweet. |
create_poll_tweet | write | Creates a poll tweet. |
delete_all_bookmarks | destructive | Permanently deletes all of the authenticated user |
delete_bookmark | destructive | Removes a bookmark. |
delete_tweet | destructive | Deletes a tweet. |
favorite_tweet | read | Favorites a tweet. |
get_bookmarks | read | Fetches the authenticated user |
get_trends | read | Fetches trending topics (uses Twitter API v1.1 as v2 trends require specific location WOEID). |
get_tweet_details | read | Fetches tweet details. |
get_user_by_id | read | Fetches user by ID. |
get_user_by_screen_name | read | Fetches user by screen name. |
get_user_followers | read | Retrieves a list of followers for a given user. |
get_user_following | read | Retrieves a list of users whom the given user is following. |
get_user_mentions | read | Fetches tweets mentioning a specific user. |
get_user_profile | read | Fetches user profile by user ID. |
post_tweet | write | Posts a tweet. |
search_twitter | read | Searches Twitter for recent tweets. |
unfavorite_tweet | read | Unfavorites a tweet. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
delete_all_bookmarks, delete_bookmark, delete_tweet
raw = base64.b64decode(unquote(enc))
fastmcp, python-dotenv, tweepy
- **Twitter Developer Account**: You need API credentials (API Key, API Secret, Access Token, Access Token Secret, and Bearer Token) from the [Twitter Developer Portal](https://developer.twitter.com/)
Gates applied: no_behavioural_pass.
4154be1f3287full audit observations/trust-audit/mcp-server/rafaljanicki__x-twitter-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4154be1f3287 | SAFE | B | 89 | first audit |
Questions
What is the X Twitter MCP server?
X/Twitter MCP server
What tools does X Twitter expose?
18 in total: 13 read-only, 2 that write, and 3 that can delete or overwrite (delete_all_bookmarks, delete_bookmark, delete_tweet). Every one is listed on this page with its risk.
Is X Twitter safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does X Twitter need?
It reads TWITTER_ACCESS_TOKEN, TWITTER_ACCESS_TOKEN_SECRET, TWITTER_API_KEY, TWITTER_API_SECRET, TWITTER_BEARER_TOKEN and TWITTER_OAUTH2_USER_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does X Twitter run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as x-twitter-mcp.
How current is this page?
The grade is for one exact copy of the source (4154be1f3287), read on 2026-10-08. The repository is watched and re-audited when it changes.