emusks
v2.3.15
Published
Reverse-engineered Twitter API client. Log in and interact with the unofficial X API using any client identity - web, Android, iOS, or TweetDeck
Maintainers
Readme
Log in and interact with the unofficial X API using any client identity - web, Android, iOS, or TweetDeck. Covers tweets, drafts, users, DMs, communities, spaces, articles, Community Notes, the immersive video feed, delegate/act-as, Grok (X's built-in AI), and XChat (X's end-to-end encrypted chat): send encrypted DMs in one call.
officially dmca'd by twitter™ 🏆 • includes a few leaked ads bearers
password login
client.login({ type: "password", username, password }) drives X's Jetfuel login over pure HTTP. The one piece that can't be done in Node is the Castle device token: X now rejects any token minted headless or off a real browser (it comes back as "We've temporarily limited your login"). So by default emusks mints it in a real headful Chrome driven over CDP (castle: "browser"), which needs Chrome/Chromium installed (EMUSKS_CHROME_PATH to point at it). A browser window flashes briefly per token.
Other castle sources: "node" runs the SDK in a node:vm sandbox (no browser, but currently rejected by X — kept for reference), and getCastleToken(action) lets you supply tokens yourself. See The Castle gate for the full write-up.
