Xquik

Server MCP yang dihosting untuk alur kerja data X (Twitter): pencarian tweet, pencarian pengguna, ekspor pengikut, tindakan media, pemantauan, dan webhook.

Dokumentasi

X Twitter scraper & API alternative MCP server

Use Xquik as an X Twitter scraper and Twitter API alternative through MCP. Search posts, replies, profiles, followers, lists, communities, Spaces, and trends.

For the complete documentation index, see llms.txt.

Xquik API MCP exposes the REST API through Model Context Protocol. Code Mode is the default. Native mode exposes one tool per OpenAPI operation. Full credentials see 119 JSON or text routes. Private support media downloads use REST. Guest paid_reads keys see exactly 30 GET routes.

Note

Public reads need no connected X account. This covers tweets, profiles, followers, replies, timelines, communities & lists. Every X write requires one. Private reads also require one: DMs, bookmarks, notifications, home timeline, likes, likers & mutual followers. See Connect X account.

This page covers the API MCP server at https://xquik.com/mcp for authenticated account actions and guest paid reads. For public documentation search, use the Docs MCP server at https://docs.xquik.com/mcp.

Warning

Codex CLI 0.147.0 and newer keep the RFC 9207 iss value. Older Codex and affected Goose releases may discard it before token exchange. Follow Codex and Goose OAuth issuer validation to upgrade Codex or use an environment-backed API key.

Supported browsers expose a read-only WebMCP tool on the homepage. It searches the public OpenAPI contract without calling an endpoint.

Connection

Model Context Protocol over Streamable HTTP. Connect clients to `https://xquik.com/mcp`. `server/discover` returns the deployed server version. Prefer OAuth 2.1. API keys remain available for clients with secure header storage.

GET and POST on /.well-known/mcp.json return a compatibility document derived from the MCP Registry manifest. /server.json and /.well-known/mcp/server-card.json return the same document. Its standard remotes entry identifies the streamable-http endpoint. Extra top-level convenience fields support older clients. They are not MCP Registry or experimental MCP Server Card fields. OAuth clients read GET /.well-known/oauth-protected-resource/mcp for protected-resource metadata. Compatibility clients can also read GET /.well-known/oauth-protected-resource/.well-known/mcp.json. It redirects to the canonical metadata URL.

Registry-compatible clients receive a streamable-http remote for https://xquik.com/mcp. OAuth-capable clients discover authentication from the endpoint. Clients without OAuth may send an API key as Authorization: Bearer {XQUIK_API_KEY} or x-api-key: {XQUIK_API_KEY}. Create API keys at https://dashboard.xquik.com/en/account?tab=api-keys. The direct client examples below use OAuth. Use the API-key fallback only when the client documents secure request headers.

Discover Xquik through https://xquik.com/.well-known/ard.json or https://xquik.com/.well-known/agents.json. ARD lists the MCP server and the REST API, each with example queries and its https://xquik.com identity. The agent catalog adds the public A2A docs agent, capabilities, OAuth metadata, and https://xquik.com/auth.md. auth.md covers Client ID Metadata Documents (CIMD), Dynamic Client Registration (DCR), PKCE, and the mcp:tools & mcp:read scopes. MCP connection metadata also lives at https://xquik.com/.well-known/mcp.json.

DCR at https://xquik.com/api/oauth/register is the supported anonymous OAuth client registration path when a client cannot use CIMD.

Agent Skills discovery is available at https://xquik.com/.well-known/agent-skills/index.json. It publishes a SHA-256 digest for Xquik's hosted SKILL.md. Compatible agents can verify the downloaded instructions.

MCP 2026-07-28

Xquik supports MCP 2026-07-28 at the same Streamable HTTP endpoint. Current clients start with server/discover. They do not call initialize or create a session for a modern connection.

Use a current MCP SDK. It adds the request _meta envelope and required HTTP headers automatically. Modern requests must advertise both application/json and text/event-stream.

Read X-Request-Id on MCP responses, including authentication and protocol errors. Include it and the UTC time when reporting failures. It identifies the HTTP request, not the JSON-RPC message or authenticated session. Allowed browser clients can send and read this header.

server/discover and tools/list include private cache hints with a 5-minute TTL. Code Mode advertises tool-list changes. Native catalogs stay static. Cache only within the same authorization context.

Xquik also accepts stateless 2025-era clients at the same endpoint. This keeps existing integrations working while current SDKs adopt 2026-07-28.

Note

Modern Xquik connections are request-scoped. Ignore legacy session IDs and resume state. Let the client SDK negotiate the protocol.

Unauthenticated requests to https://xquik.com/mcp return 401 with a WWW-Authenticate: Bearer challenge. The challenge includes resource_metadata="https://xquik.com/.well-known/oauth-protected-resource/mcp", scope="mcp:tools", and the OAuth realm. The JSON body is { "error": "Authentication required" }. OAuth-capable clients use the challenge to discover the authorization metadata. API-key clients should send x-api-key on the first request. A supplied invalid bearer token adds error="invalid_token" and error_description="Invalid access token" to the challenge.

Authentication

The MCP server supports 2 authentication methods:

  • OAuth 2.1 (recommended): Compatible clients discover Xquik, open the browser login and consent flow, then store and refresh Bearer tokens. Xquik supports CIMD and DCR. Normal client setup needs no manual client ID, client secret, or API key.
  • API key (x-api-key or Authorization: Bearer xq_your_api_key_here): This is an Xquik-specific fallback, not an OAuth token. Do not apply OAuth discovery or refresh rules. Use it only with secure header storage. Full account keys expose 119 catalog routes. Active guest keys expose 30 paid_reads GET routes.

See OAuth 2.1 authorization for discovery URLs, token lifetimes, client registration, and implementation details.

Choose a tool mode

Use the default endpoint for Code Mode:

https://xquik.com/mcp

Code Mode uses 3 tools. API discovery and execution run in isolated sandboxes:

Search X/Twitter scraper & API documentation. Read-only. No credits. Search the X/Twitter API catalog. No network calls or credits. Call authenticated X/Twitter APIs. Cost follows the endpoint.

server/discover sends no global model instructions. Tool descriptions identify the X/Twitter domain and explain code mechanics. docs searches public documentation. search accepts an async arrow function. spec is global and its first argument. Its examples show endpoint and operation lookup. execute accepts the same form. xquik is global and its first argument. OpenAPI and these docs define endpoint behavior.

ToolTitleSafety annotations
docsSearch Xquik documentationRead-only, idempotent, open-world, non-destructive
searchSearch Xquik API specificationRead-only, idempotent, closed-world, non-destructive
executeExecute Xquik API requestsMay mutate data, may access live services, not idempotent

For a guest paid_reads session, execute is read-only, idempotent, and limited to live calls across the 30 eligible GET routes.

Use native mode when a client cannot run Code Mode or needs ordinary MCP tools:

https://xquik.com/mcp?codemode=false

Native mode serves an OpenAPI-derived catalog. It validates only the called tool. Full credentials receive docs, readSavedResult, and 119 OpenAPI operations. Guest keys receive docs, readSavedResult, and 30 eligible GET operations.

Each native tool uses its OpenAPI operationId as its stable name. Its input schema, title, description, HTTP method, path, query parameters, and JSON body come from the same OpenAPI contract as REST and the generated SDKs. The server injects authentication and required idempotency headers. It rejects unknown routes, custom headers, redirects, traversal, and unsupported binary responses.

docs searches canonical Xquik documentation. Pass a non-empty query string. readSavedResult reads a saved oversized answer in free pages.

search tool

Searches the 119-route full account catalog. The call uses no credits. MCP authentication remains required. The sandbox provides:

With a guest paid_reads key, spec.paths contains only 30 eligible GET routes.

Inputs resolve inline. Response $ref values point into spec.components.schemas. The catalog includes only response schemas reachable from your allowed operations. Follow references to inspect shared fields and recursive types.

interface OperationInfo {
  operationId: string;
  summary?: string;
  description?: string;
  tags?: string[];
  parameters?: unknown[];
  requestBody?: unknown;
  responses?: Record<string, unknown>;
}

interface PathItem {
  get?: OperationInfo;
  post?: OperationInfo;
  put?: OperationInfo;
  patch?: OperationInfo;
  delete?: OperationInfo;
}

declare const spec: {
  paths: Record<string, PathItem>;
  components: { schemas: Record<string, unknown> };
};

execute tool

Executes API calls. The sandbox provides:

Call xquik.request({ path, method?, query?, body? }). It returns success, status, result, errors, and messages. result contains the endpoint body. Pass result_id to project saved data through xquik.result. Recover oversized results without repeating paid requests. See the complete execute contract.

The server injects authentication and required idempotency headers. The server reuses each generated key for bounded transient retries. Verify unresolved writes. Retry only when safe_to_retry is true.

An execute call can run for up to 55 seconds. Sandbox API requests stop after 54 seconds. The reserve lets completed work return. Disconnecting cancels the call. Timeouts do not cancel durable extraction jobs. Find the job through GET /extractions, then resume with its stored ID. Rejections include error.status when available.

MCP operation boundary

The REST contract documents 130 operations. Full credentials expose 119 JSON or text routes. These 11 stay outside:

  • Create, list, or revoke account API keys
  • Start account top-ups or charge a saved payment method
  • Create, poll, or top up a guest wallet
  • Download support attachments or draw and extraction exports

Guest wallet credential routes remain direct REST only. MCP cannot execute POST /api/v1/guest-wallets, POST /api/v1/guest-wallets/topups, or GET /api/v1/guest-wallets/status. Follow the accountless guest wallet guide for confirmation, checkout, polling, and top-up steps.

A guest paid_reads MCP session exposes exactly the 30 eligible paid-read routes. It cannot execute writes or any other route.

Never start checkout, top-up, subscription, or billing actions because another call returned 402. Report the choices, ask the user to select an amount and option, then wait for explicit confirmation. After confirmation, MCP may execute only an account checkout action present in the full catalog. Guest wallet actions remain direct REST.

MCP vs REST API

MCP follows REST authentication, authorization, billing, and response contracts for every exposed operation.

Use MCP for agents and IDE integrations. Full credentials expose 119 catalog routes. Guest keys expose 30 GET reads. Use REST for binary downloads. Use REST for backend services, automation scripts, guest wallet credential routes, and direct access. The REST contract documents all 130 operations and file download responses.

Website WebMCP

Supported browsers discover search_xquik_api on https://xquik.com. Pass a non-empty query and optionally set maxResults from 1 to 50. The tool returns matching methods, paths, inputs & response statuses. It sends no credentials, calls no API operation, and spends no credits. The page uses the current document.modelContext API.

Tip

Start with Claude.ai for OAuth login or Claude Code for terminal setup.

Client compatibility

Choose the authentication path that your current client can complete. Xquik keeps OAuth issuer, redirect, resource, and Proof Key for Code Exchange (PKCE) validation enabled for every client.

ClientAPI MCP authentication todayRegistration and behavior
Claude CodeOAuth 2.1Uses Client ID Metadata Documents (CIMD), secure token storage, and automatic refresh
OpenCodeOAuth 2.1Uses Dynamic Client Registration (DCR) and refreshes tokens
Gemini CLIOAuth 2.1Uses automatic OAuth discovery and DCR. Streamable HTTP configuration uses httpUrl
CursorOAuth 2.1Supports remote MCP OAuth and cursor-agent mcp login
GitHub Copilot CLIOAuth 2.1Uses the browser authorization code flow and DCR
ClineOAuth 2.1Completes OAuth from its MCP configuration flow
Qwen CodeOAuth 2.1Uses DCR and its httpUrl Streamable HTTP field
CodexOAuth 2.1 or environment-backed API keyCodex CLI 0.147.0 and newer keep RFC 9207 iss. Older or failing builds use an environment-backed key
GooseEnvironment-backed API keyAffected releases can discard the required RFC 9207 iss callback value
Roo CodeEnvironment-backed API keyRoo Code's archived final release has Streamable HTTP but no MCP OAuth provider
PiNo native MCP pathPi requires a separately installed and tested MCP adapter

Clients that ignore the optional RFC 9207 iss response parameter can still complete OAuth. Codex CLI 0.147.0 and newer keep the value. Older Codex and affected Goose releases may require the parameter after discarding it. Retrying OAuth cannot repair those callbacks. Xquik does not weaken issuer validation.

Setup

Web and terminal clients

1. Open [Claude Connectors](https://claude.ai/settings/connectors) or **Customize > Connectors**. 2. Select **+**, then **Add custom connector**. 3. Enter `https://xquik.com/mcp`. 4. Select **Add**. 5. In a chat, select **+ > Connectors**, enable Xquik, then select **Connect** and approve access.
Leave the advanced client ID and client secret fields empty. Custom remote
connectors require Pro, Max, Team, or Enterprise. On Team and Enterprise,
an Owner or Primary Owner must add the connector first.
Claude Desktop uses the same remote custom connectors as Claude.ai. Open **Customize > Connectors**, add `https://xquik.com/mcp`, then complete the browser authorization flow. Add the remote server:
```bash theme={null}
claude mcp add --transport http xquik https://xquik.com/mcp
```

Run `/mcp` inside Claude Code, select `xquik`, then authenticate.
Follow the [ChatGPT app guide](/mcp/chatgpt).

OpenAI

Codex CLI 0.147.0 and newer support Xquik OAuth. Remove `bearer_token_env_var`, then add Xquik and complete OAuth:
```bash theme={null}
codex mcp add xquik --url https://xquik.com/mcp
codex mcp login xquik
codex mcp list
```

Codex CLI, the IDE extension, and the ChatGPT desktop app share the same
`config.toml` MCP configuration.

Older releases affected by [openai/codex#31573](https://github.com/openai/codex/issues/31573)
use the [Codex API key fallback](#codex-api-key-fallback) below.
Open **Settings > MCP servers**. Add `https://xquik.com/mcp` as Streamable HTTP, select **Authenticate**, then restart. If the build reports the issuer error, use the [environment-backed API key fallback](#codex-api-key-fallback) through the shared `config.toml`. Codex CLI 0.147.0 and newer use this OAuth configuration in `~/.codex/config.toml` or a trusted project's `.codex/config.toml`:
```toml theme={null}
[mcp_servers.xquik]
url = "https://xquik.com/mcp"
```

Then run `codex mcp login xquik`.

Older releases use the `bearer_token_env_var` configuration in
[Codex API key fallback](#codex-api-key-fallback).

Codex API key fallback

Use an environment-backed API key if Codex reports Authorization server response missing required issuer: expected https://xquik.com:

export XQUIK_API_KEY="xq_your_api_key_here"

Add this configuration to ~/.codex/config.toml or a trusted project's .codex/config.toml:

[mcp_servers.xquik]
url = "https://xquik.com/mcp"
bearer_token_env_var = "XQUIK_API_KEY"

Restart Codex, then run codex mcp list. Do not run codex mcp login xquik while using the bearer-token fallback. Never commit the key or place its value directly in config.toml. See Codex OAuth issuer validation error for recovery steps. Issue #31573 records the fix in Codex CLI 0.147.0.

Editor clients

Add to `~/.cursor/mcp.json` (global) or `.cursor/mcp.json` (project):
```json theme={null}
{
  "mcpServers": {
    "xquik": {
      "url": "https://xquik.com/mcp"
    }
  }
}
```

Cursor starts OAuth when the server first returns `401`. You can also run
`cursor-agent mcp login xquik`. Cursor lists MCP access on its
paid Individual, Teams, and Enterprise plans.
Add to `.vscode/mcp.json` (project) or use **MCP: Open User Configuration** (global):
```json theme={null}
{
  "servers": {
    "xquik": {
      "type": "http",
      "url": "https://xquik.com/mcp"
    }
  }
}
```

Start the server from the MCP view and follow the OAuth prompt. VS Code
stores the resulting authentication state.
Add to `~/.codeium/windsurf/mcp_config.json`:
```json theme={null}
{
  "mcpServers": {
    "xquik": {
      "serverUrl": "https://xquik.com/mcp"
    }
  }
}
```

Enable the server in **Windsurf Settings > Cascade > MCP Servers**, then
complete OAuth. Enterprise users must enable MCP manually. Team policies
may disable MCP or restrict servers to an allowlist.
Add to `opencode.json`:
```json theme={null}
{
  "mcp": {
    "xquik": {
      "type": "remote",
      "url": "https://xquik.com/mcp"
    }
  }
}
```

Then run:

```bash theme={null}
opencode mcp auth xquik
opencode mcp list
```

Other terminal clients

Add the remote server:
```bash theme={null}
copilot mcp add xquik --type http --url https://xquik.com/mcp
```

If your installed build does not expose the noninteractive add flags, start
Copilot CLI and run `/mcp add`. Enter `xquik`, choose **HTTP**, enter
`https://xquik.com/mcp`, keep `*` for tools, then press **Ctrl+S**. Run
`/mcp auth xquik` after the server appears. Enterprise policy may block
servers outside the organization allowlist.
Add the remote server:
```bash theme={null}
gemini mcp add --transport http xquik https://xquik.com/mcp
```

Or add it to `~/.gemini/settings.json` for user scope or
`.gemini/settings.json` for project scope:

```json theme={null}
{
  "mcpServers": {
    "xquik": {
      "httpUrl": "https://xquik.com/mcp"
    }
  }
}
```

Run `/mcp auth xquik` to complete OAuth.
Run `cline mcp`, add a Streamable HTTP server, and enter `https://xquik.com/mcp`. Select **Authorize OAuth** when Cline reports that authentication is required. Enable encrypted token storage before adding Xquik:
```bash theme={null}
export QWEN_CODE_FORCE_ENCRYPTED_FILE_STORAGE=true
qwen mcp add --transport http xquik https://xquik.com/mcp
```

Start Qwen Code, open `/mcp`, then authorize `xquik`. Qwen Code still uses
`httpUrl` for manual Streamable HTTP configuration:

```json theme={null}
{
  "mcpServers": {
    "xquik": {
      "httpUrl": "https://xquik.com/mcp"
    }
  }
}
```

Remaining API key and adapter paths

API-key fallback is client-specific. ChatGPT custom apps require OAuth and cannot present custom API keys. Codex uses the environment-backed bearer_token_env_var configuration above. For other clients, follow that client's documented secret-input or environment-variable syntax. Never copy a generic header example into an incompatible schema, place a literal key in a configuration file, or commit a key.

Export your key, then add this entry to `~/.config/goose/config.yaml`:
```bash theme={null}
export XQUIK_API_KEY="xq_your_api_key_here"
```

```yaml theme={null}
extensions:
  xquik:
    type: streamable_http
    name: xquik
    enabled: true
    uri: "https://xquik.com/mcp"
    headers:
      Authorization: "Bearer ${XQUIK_API_KEY}"
    env_keys:
      - XQUIK_API_KEY
    envs: {}
```

Goose substitutes the environment variable before sending the header. Its
OAuth callback has an RFC 9207 issuer handling defect. Follow
[Codex and Goose OAuth issuer validation](/guides/troubleshooting#codex-oauth-issuer-validation-error).
Roo Code's archived final release supports API-key headers, not MCP OAuth. Add this to global `mcp_settings.json` or project `.roo/mcp.json`:
```json theme={null}
{
  "mcpServers": {
    "xquik": {
      "type": "streamable-http",
      "url": "https://xquik.com/mcp",
      "headers": {
        "Authorization": "Bearer ${env:XQUIK_API_KEY}"
      }
    }
  }
}
```

Export `XQUIK_API_KEY` before starting the editor. Do not place the key
value in the JSON file.
Pi's coding agent has no native MCP client. Install and audit a community MCP adapter before connecting Xquik, or call the [REST API](/api-reference/overview) from a Pi extension. Xquik does not claim native Pi compatibility.

Example prompts

Once connected, ask:

Monitoring & events

  • Start watching @elonmusk for new tweets and replies.
  • List the accounts I am monitoring.
  • Show monitored account activity from today.
  • Replay stored events for monitor mon_123 using the last next_cursor as cursor.
  • Stop tracking @elonmusk.

Search & lookup

  • Search recent X posts about TypeScript.
  • Find recent tweets from @vercel.
  • Read this tweet: https://x.com/elonmusk/status/1893456789012345678
  • Get metrics for this tweet: https://x.com/vercel/status/1893704267862470862

User profiles & follows

  • Get @username follower count.
  • Read @openai profile bio.
  • Check whether @elonmusk follows @SpaceX.
  • Check whether @vercel and @nextjs follow each other.

Trends

  • Show current X trends.
  • Show top trending topics in the US.
  • Check whether AI is trending today.

Radar & news

  • Show current Radar trends.
  • Show current Reddit posts with text, links, media, and engagement signals.
  • Show top developer trends today.
  • Show startups ranked by available growth metrics.
  • Get technology topics from the last 12 hours.
  • Show popular knowledge topics right now.
  • Show regional trends for a selected region.
  • Find trending tech news and draft a tweet about one item.

Extractions

  • Pull all replies to this tweet: https://x.com/elonmusk/status/1893456789012345678
  • List users who retweeted this tweet: https://x.com/vercel/status/1893704267862470862
  • Estimate the cost to extract all followers of @elonmusk.
  • Get quote tweets for this post: https://x.com/openai/status/1893456789012345678
  • Extract the full thread for this tweet: https://x.com/elonmusk/status/1893704267862470862

Giveaways

  • Pick 3 random winners from this tweet: https://x.com/example_user/status/1893456789012345678
  • Run a giveaway draw where participants must have retweeted and have at least 100 followers.
  • Show the results of my last giveaway draw.

Webhooks

  • Set up a webhook at https://my-server.com/events for new tweets.
  • List configured webhook endpoints.
  • Remove the webhook pointing to my old server.

Tweet composition

  • Write a casual launch tweet for my new product.
  • Research a fresh angle from Compose's Radar recommendations.
  • Optimize the draft for engagement.
  • Score this draft: Just shipped v2.0 of our API. What do you think?
  • Improve this tweet to get more replies.

Style analysis & drafts

  • Analyze how @elonmusk tweets.
  • Compare @vercel and @nextjs tweeting styles.
  • Show cached tweet performance.
  • Save this tweet draft for later.
  • Show all saved drafts.
  • Set my X account to @myusername.

X write actions

  • Post a tweet saying: Just shipped v2.0!
  • Like this tweet: https://x.com/vercel/status/1893704267862470862
  • Retweet this: https://x.com/openai/status/1893456789012345678
  • Follow @vercel from my connected account.
  • Send a DM to user ID 44196397 saying hello.
  • Post a tweet saying: New feature! Use public image URL https://example.com/launch.png.

Account & usage

  • Show my plan and month-to-date usage.
  • Check whether I have enough budget left for a large extraction.

Framework guides

Build agents with Xquik's MCP tools in your preferred framework:

Python agents with LangChain + LangGraph Multi-agent crews with CrewAI Type-safe agents with Pydantic AI Multi-agent assistants with Google ADK TypeScript agents with Mastra Python agents with Microsoft Agent Framework Move an existing Composio workflow to Xquik

AI agent skill

The Xquik Skill documents the Xquik API for AI coding agents. It needs no MCP connection. Install it so your agent can write API integrations, set up webhooks, and configure MCP connections.

It works with Claude Code, Cursor, GitHub Copilot, Codex, Windsurf, VS Code, Gemini CLI, and other Skill-capable agents. It covers MCP tools and 130 REST API operations.

npx skills add Xquik-dev/x-twitter-scraper