How to hit the X (Twitter) API

The X API v2 lives at https://api.x.com/2. Reads like user lookup and search work with an app-only bearer token; anything done as a user — reading your own account, posting — needs a user access token.

Authentication

Create an app in the X developer portal. Its Bearer Token is the app-only token ({{X_BEARER_TOKEN}} in the examples). Acting as a user needs an OAuth 2.0 user access token ({{X_USER_TOKEN}}). Both go in Authorization: Bearer <token>.

Full reference: https://docs.x.com/x-api

Look up a user

By username. Extra fields are opt-in via user.fields.

curl "https://api.x.com/2/users/by/username/XDevelopers?user.fields=description,public_metrics,created_at" \
  -H "Authorization: Bearer {{X_BEARER_TOKEN}}"
Run in PostTaco

Search recent posts

The last seven days. Same operators as X search: from:, -is:retweet, lang:. max_results is 10–100.

curl "https://api.x.com/2/tweets/search/recent?query=from:XDevelopers%20-is:retweet&max_results=10&tweet.fields=created_at,public_metrics" \
  -H "Authorization: Bearer {{X_BEARER_TOKEN}}"
Run in PostTaco

Get the authenticated user

Needs a user access token; an app-only bearer token gets a 403.

curl https://api.x.com/2/users/me \
  -H "Authorization: Bearer {{X_USER_TOKEN}}"
Run in PostTaco

Create a post

Needs a user access token with tweet.write scope. Returns the new post's id.

curl -X POST https://api.x.com/2/tweets \
  -H "Authorization: Bearer {{X_USER_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{"text": "Hello from PostTaco"}'
Run in PostTaco