How to get an X (Twitter) API key, and how to skip needing one.

Last updated October 1, 2026

To get an X (Twitter) API key, sign in at console.x.com with your X account and accept the Developer Agreement and Policy. Complete your profile, then click New Appand give it a name, description and use case. X generates an API key and secret, a bearer token, an access token and secret, and an OAuth 2.0 client ID and secret. They are shown once, so save them right away. Then add a prepaid balance, because every X API request is paid. If you'd rather not manage keys at all, twitr.sh lets a USDC wallet pay per call with no key, and that option is covered at the end. Steps below follow docs.x.com as of October 1, 2026.

How do I get an X API key, step by step?

StepWhat to do
1. Sign inGo to console.x.com and sign in with the X account that will own the app.
2. Accept the termsReview and accept the Developer Agreement and Policy.
3. Complete your profileAdd the requested details about how you will use the API.
4. Create an appClick New App and give it a name, description and use case.
5. Save the credentialsX shows them only once. Store them in a password manager or secrets vault.
6. Add a balanceBuy a prepaid balance in the Developer Console. Optionally turn on auto-recharge and set a spending limit.
7. Make a requestUse the bearer token for public data, or OAuth for actions as a user.

Two practical tips. Create the app under an X account your team controls rather than one person's personal account, because the app and its billing belong to that sign-in. And add a spending limit before the first request, not after. A loop that retries a failing call can burn through a balance faster than you expect.

Which credentials do you get, and what are they for?

CredentialWhat it doesUse it for
API key and secretIdentify your app; generate tokens and sign OAuth 1.0a requestsServer-side apps
Bearer tokenApp-only authenticationReading public data
Access token and secretMake requests as your own account (OAuth 1.0a)Personal automation
OAuth 2.0 client ID and secretUser-context authenticationActing for other users (X's recommended method)

A simple rule: reading public posts needs only the bearer token. Posting, liking or following needs user-context auth. That means OAuth 2.0, or the access token and secret if you only ever act as yourself.

What does the X API cost once you have a key?

The official API is now pay-per-use with no subscriptions. Each request deducts from your prepaid balance:

OperationPrice
Post read$0.005 per post
User read / followers read$0.010 per user
Likes read$0.001
Create a post$0.015
Create a post with a link$0.200
User interaction (create)$0.015

Pay-per-use accounts are capped at 3 million post reads per month. Reads are deduplicated within a UTC day, and reads of your own account's data cost $0.001. The full breakdown is on X API pricing, and the side-by-side with twitr.sh is on Twitter API vs twitr.sh.

How do I keep an API key safe?

Put credentials in environment variables or a secrets manager, never in source code or a public repo. Never paste them into an AI chat either: anything in a model's context can end up in logs and transcripts. Set a spending limit in the Developer Console so a leaked key can't drain your balance. If a key does leak, treat it as compromised and replace it. That last risk is the reason twitr.sh never asks an agent to hold X credentials at all (see agent security).

Should you get an official key or skip it?

Get the official keyif you want access X itself sanctions, if you publish lots of plain posts (X charges $0.015 against twitr.sh's $0.036), or if you mostly read likes or your own account's data. Its same-day deduplication also helps apps that refresh the same posts many times a day. And if you expect to outgrow 3 million post reads a month, the Enterprise path starts there.

Skip the key if the caller is an AI agent with no person to create a developer app, if your volume is small or bursty, or if most of your spend is reads. twitr.sh charges about 4× less per post read and about 8× less per user or follower read. It is also the better deal if you post links, at $0.036 a post against $0.200. You can also use both: keep an official app for plain posting, and give your agent a wallet for research and monitoring.

Can I use X data without an API key?

Yes. On twitr.sh the wallet is the account. You send the request with no credentials and get HTTP 402 with the exact price. A USDC wallet pays, the request is retried and the data comes back. There is no developer account, no app and no key to leak.

# no key: the first request returns the price
curl -i -X POST https://twitr.sh/api/tools/x_search \
  -H 'Content-Type: application/json' \
  -d '{"q":"from:nasa","queryType":"Latest","resultsLimit":20}'
# -> 402  "amount": "0.024000"  (20 results × $0.001200)

# a USDC wallet pays and retries (x402 on Base/Solana, MPP on Tempo)
npx agentcash fetch https://twitr.sh/api/tools/x_search -m POST \
  -b '{"q":"from:nasa","queryType":"Latest","resultsLimit":20}'

If you prefer a card, sign in with Google, add a balance and create a twitr.sh key (tw_live_…). It is not an X key. It only charges your twitr.sh balance, at the same prices. AI agents can call the same tools through the MCP server at https://twitr.sh/api/mcp or the skills.

Official X API keytwitr.sh with a wallettwitr.sh API key
Sign-upX account, Developer Agreement, appNoneGoogle sign-in
What you holdAPI key, secret, tokensA USDC walletOne tw_live_ key
FundingPrepaid balance in the ConsoleUSDC per callCard-funded balance
Post read$0.005$0.0012$0.0012
Plain post$0.015$0.036$0.036
Posting as a userOAuth user contextConnect the account in your browserSame
Autonomous agentsA person sets it up firstWorks with no setupWorks once a key exists

Plain posts are cheaper on the official API. Reads, and posts with links ($0.036 vs $0.200), are cheaper on twitr.sh. Browse every tool, read the docs or compare more options on X API alternatives. Before you buy anything, you can test an account with the free shadowban checker and X algorithm checker.

FAQ

How do I get a Twitter API key?

Sign in at console.x.com with your X account, accept the Developer Agreement and Policy, complete your profile, then click New App and enter a name, description and use case. X generates the API key and secret, a bearer token, access tokens and OAuth 2.0 credentials for the app.

Is the X API key free?

X's getting-started guide lists no fee for creating an app and its keys, but using them is paid. X's pricing page lists no free usage, and every request draws from a prepaid balance you buy in the Developer Console.

Where do I find my X API key?

Credentials are generated when you create the app in the X Developer Console. X shows them only once, so save them to a password manager or secrets vault right away.

What is the difference between an API key and a bearer token?

The API key and secret identify your app; they are used to generate tokens and sign OAuth 1.0a requests. The bearer token is app-only authentication for reading public data.

Which credentials do I need to post a tweet?

Posting acts as a user, so it needs user-context authentication: OAuth 2.0 (X recommends it) or OAuth 1.0a. For your own account, the access token and secret generated with the app make requests on your behalf.

How long does it take to get X API access?

X's getting-started guide describes signing in, accepting the agreement, completing a profile and creating an app. It doesn't describe a separate review step. You still need a prepaid balance before requests go through.

How much does the X API cost?

As of October 2026 the X API is pay-per-use: $0.005 per post read, $0.010 per user read, $0.001 per like read, $0.015 per post, $0.200 per post with a link and $0.015 per user interaction. Pay-per-use accounts are capped at 3 million post reads a month.

Can an AI agent get an X API key by itself?

Not cleanly. Getting a key means signing in with an X account and accepting X's Developer Agreement, which is a step for a person. An agent with a USDC wallet can use twitr.sh instead, with no key: it pays each call as it makes it.

Can I get Twitter data without an API key?

Yes. Send a request to twitr.sh with no credentials. It answers HTTP 402 with the exact price, your wallet pays in USDC (x402 on Base or Solana, MPP on Tempo), and the data comes back on the retry.

Is a twitr.sh API key the same as an X API key?

No. A twitr.sh key (tw_live_…) only charges a card-funded twitr.sh balance. It is optional, you get it by signing in with Google, and it can't be used against X's own API.

What's the safest way to give an agent access to my X account?

Don't paste keys or passwords into the chat. On twitr.sh the agent sends only your handle and gets a link back. You open it and sign in to X in your own browser, and the agent never sees the password.