The X API v2 lives at https://api.x.com/2. Reads like user lookup and search work with an app-only bearer token; anything done as a user — reading your own account, posting — needs a user access token.
Create an app in the X developer portal. Its Bearer Token is the app-only token ({{X_BEARER_TOKEN}} in the examples). Acting as a user needs an OAuth 2.0 user access token ({{X_USER_TOKEN}}). Both go in Authorization: Bearer <token>.
Full reference: https://docs.x.com/x-api
By username. Extra fields are opt-in via user.fields.
curl "https://api.x.com/2/users/by/username/XDevelopers?user.fields=description,public_metrics,created_at" \
-H "Authorization: Bearer {{X_BEARER_TOKEN}}"
The last seven days. Same operators as X search: from:, -is:retweet, lang:. max_results is 10–100.
curl "https://api.x.com/2/tweets/search/recent?query=from:XDevelopers%20-is:retweet&max_results=10&tweet.fields=created_at,public_metrics" \
-H "Authorization: Bearer {{X_BEARER_TOKEN}}"
Needs a user access token; an app-only bearer token gets a 403.
curl https://api.x.com/2/users/me \
-H "Authorization: Bearer {{X_USER_TOKEN}}"
Needs a user access token with tweet.write scope. Returns the new post's id.
curl -X POST https://api.x.com/2/tweets \
-H "Authorization: Bearer {{X_USER_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"text": "Hello from PostTaco"}'