
Like a post/tweet by its ID. Requires like.write scope.
Unlike a post/tweet by its ID. Removes your like from the post.
Retweet a post by its ID. Shares the post with your followers.
Undo a retweet by its original tweet ID. Removes the retweet from your profile.
Bookmark a post/tweet for later. Private bookmarks are only visible to you.
Remove a post from your bookmarks by its tweet ID.
Get your bookmarked posts. Returns up to 100 posts per page with pagination.
Get users who liked a tweet. Returns up to 100 users with pagination.
Get tweets a user has liked. Use get_me first to get your own user ID.
Get users who retweeted a post. Returns up to 100 users.
Get quote tweets of a post. Returns tweets that quote the specified tweet.
Create a new post/tweet. Max 280 chars. Supports replies (replytotweetid), quotes (quotetweet_id), and polls (2-4 options).
Delete a post/tweet by its ID. You can only delete your own posts.
Get a single post/tweet by its ID. Returns text, author, metrics, and referenced tweets.
Search posts from the last 7 days. Supports operators: from:user, to:user, -is:retweet, has:media, lang:en. Max 100 results per page.
Follow a user by their user ID. Use getuserby_username first if you only have the @handle.
Unfollow a user by their user ID. Also cancels pending follow requests.
Mute a user by their user ID. Their posts won't appear in your timeline but they can still follow you.
Unmute a user by their user ID. Their posts will appear in your timeline again.
Get your list of muted users. Muted users' posts don't appear in your timeline.
Get a user's recent tweets by user ID. Can exclude retweets/replies. Use get_me first to get your own user ID.
Get tweets that mention a user by their user ID. Use get_me first to get mentions of yourself.
Get the authenticated user's profile including ID, username, name, bio, and metrics. Use this first to get your user ID for other operations.
Get a user's profile by their unique ID. Returns username, name, bio, follower counts, and verification status.
Get a user's profile by @username (without the @ symbol). Returns ID, name, bio, metrics, and verification status.
Get a list of users who follow the specified user. Returns up to 1000 followers per request with pagination.
Get a list of users that the specified user follows. Returns up to 1000 accounts per request with pagination.
Validate X credentials. Verifies credentials during setup.

In an mcp.json file, add the configuration below, and restart Cursor.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "url": "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
5 "headers": {
6 "Authorization": "Bearer yMt*****"
7 }
8 }
9 }
10}
11Open your Claude Desktop configuration file and add the server configuration below. You'll also need to restart the application for the changes to take effect.
Make sure Claude is using the Node v20+.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "yMt*****"
14 }
15 }
16 }
17}Open your Windsurf MCP configuration file and add the server configuration below.
Click on the refresh button in the top right of the Manage MCP server page or in the top right of the chat box in the box icon.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api.merge.dev/api/v1/tool-packs/<tool-pack-id>/registered-users/<registered-user-id>/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "<ah-production-access-key>"
14 }
15 }
16 }
17 }In Command Palette (Cmd+Shift+P on macOS, Ctrl+Shift+P on Windows), run "MCP: Open User Configuration".
You can then add the configuration below and press "start" right under servers. Enter the auth token when prompted.
Learn more in the official documentation ↗
1{
2 "inputs": [
3 {
4 "type": "promptString",
5 "id": "agent-handler-auth",
6 "description": "Agent Handler AUTH_TOKEN", // "yMt*****" when prompt
7 "password": true
8 }
9 ],
10 "servers": {
11 "agent-handler": {
12 "type": "stdio",
13 "command": "npx",
14 "args": [
15 "-y",
16 "mcp-remote@latest",
17 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
18 "--header",
19 "Authorization: Bearer ${input:agent-handler-auth}"
20 ]
21 }
22 }
23}It’s an MCP server that lets your agents access data and functionality from X. This includes everything from fetching reposts to writing posts on behalf of a specific account.
X doesn’t offer an official MCP server, so you’ll need to use one that’s hosted and managed by a 3rd-party.
Here are a few common agentic use cases:
Here are a few reasons:
Yes. Agent Handler includes default security rules and allows you to build and test custom Data Loss Protection (DLP) rules. These rules can block, redact, or mask sensitive data in tool inputs and outputs.
Here are some examples:
Follow these steps:
1. Create (or open) an Agent Handler account and go to the dashboard where you can manage connectors and tool packs.
2. Create or choose a Tool Pack for the agent experience you are building (this is the bundle of tools your agent will be allowed to call).
3. Add the X MCP server / connector to that Tool Pack and select the specific tools you want enabled (start with read-only tools, then add write tools as needed).
4. Set up authentication. Decide whether X access should be shared auth (admin-managed credential reused across users) or individual auth (each end user connects their own X account). Then have the relevant user(s) complete the connection flow so tool calls can run under the right identity.
5. Configure security rules and monitoring. Turn on the preconfigured security rules and add any custom rules you need for X actions (for example, preventing sensitive data from being posted).
6. Get the MCP endpoint for your Tool Pack and registered user. You’ll use the Agent Handler MCP URL pattern that includes your {TOOL_PACK_ID} and {REGISTERED_USER_ID}.
7. Connect an MCP client to Agent Handler. Configure your MCP client (for example, Claude Desktop, Cursor, VS Code, or Windsurf) with the MCP URL plus the required auth header/token, then refresh tools in the client.
8. Test in a safe mode first. Run a few “read” prompts (e.g., fetch recent posts) and verify the logs show the right arguments and responses. Then try a small “write” action (e.g., draft a post to a private test account), and confirm your rules behave as expected.
Yes, Agent Handler for Employees lets your employees connect Claude, ChatGPT, Microsoft Copilot, Cursor, and other MCP-compatible AI tools to X without bypassing IT governance.
Instead of setting up direct connections with personal credentials that IT can't monitor or revoke, each employee authenticates through Agent Handler and gets individual credentials tied to their identity.
IT also provisions access by role or group via SCIM. A social media manager, for example, gets X access to monitor mentions and manage engagement, Slack to surface high-priority responses for team review, and Notion to track content themes and campaign notes; while a marketing analyst gets X access to pull engagement and audience data, Google Sheets to report on social performance, and HubSpot to correlate social activity with lead and pipeline data.
Every tool call an employee's AI makes to X is also inspected against your DLP rules and logged to a searchable audit trail, giving security teams full visibility into what data was accessed and by whom.
Whether you're an engineer experimenting with agents or a product manager looking to add tools, you can get started for free now