X-Twitter ScraperBLOCK
X (Twitter) scraper API & X API alternative with REST, MCP, SDKs & webhooks. Not affiliated with X Corp.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.bestpractices.dev/projects/13731)
English · Español · Türkçe · 简体中文 · 日本語 · 한국어 · Deutsch · Français · Italiano
Search Tweets, profiles, followers & replies. Use REST, MCP, SDKs, CLI, webhooks & Apify.
Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.
Framer demo
Watch Connect Framer to Claude Code, Codex, Cursor, and more at 6:07 for the Xquik MCP connection.
You need an XQUIK_API_KEY for the request below. Public reads need no official X developer account or connected X account.
Private reads and X account actions require a connected X account. Never send an X password, cookie, session export, or 2FA code to Xquik or an agent.
Run one request
Create an API key in the Xquik dashboard. Then run:
export XQUIK_API_KEY='xq_replace_me'
curl --get 'https://xquik.com/api/v1/x/tweets/search' \
--header "x-api-key: ${XQUIK_API_KEY}" \
--data-urlencode 'q=machine learning' \
--data-urlencode 'language=en' \
--data-urlencode 'minLikes=100' \
--data-urlencode 'replies=exclude' \
--data-urlencode 'retweets=exclude' \
--data-urlencode8bf0166595f9OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add x-developer -- npx -y [email protected]
{
"mcpServers": {
"x-developer": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
docs | read | Search Xquik scraper and API documentation. The stub returns setup guidance. |
execute | write | Send confirmed Xquik API requests. The stub returns setup guidance. |
search | read | Search the credential-scoped OpenAPI catalog. The stub makes no API request. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
- Send credentials only to `https://xquik.com/api/v1` or `/mcp` on that host.
`x-api-key` header, read from the `XQUIK_API_KEY` environment variable or the
- Never collect X passwords, 2FA codes, cookies, or session tokens. Users
distinction only for setup, access, credentials, or API comparison questions.
streamable-http
When the user says not to follow a cursor, send one request only.
same secrets, so this Skill never calls it. Never collect or send X passwords,
Load `XQUIK_API_KEY` from a password manager or operating-system secret store.
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
8bf0166595f9full audit observations/trust-audit/mcp-server/xquik-dev__x-twitter-scraper.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 8bf0166595f9 | BLOCK | D | 69 | first audit |
Questions
What is the X-Twitter Scraper MCP server?
X (Twitter) scraper API & X API alternative with REST, MCP, SDKs & webhooks. Not affiliated with X Corp.
What tools does X-Twitter Scraper expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is X-Twitter Scraper safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does X-Twitter Scraper need?
No credential environment variables were found in its source, so it appears to need none.
How does X-Twitter Scraper run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as x-developer at 2.6.7.
How current is this page?
The grade is for one exact copy of the source (8bf0166595f9), read on 2026-10-06. The repository is watched and re-audited when it changes.