{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/late.json",
        "name": "Zernio (formerly Late) API + MCP",
        "score": 67.5,
        "shared": [
          "social.analytics"
        ],
        "slug": "late"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/buffer.json",
        "name": "Buffer API + MCP",
        "score": 62,
        "shared": [
          "social.analytics"
        ],
        "slug": "buffer"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/postiz.json",
        "name": "Postiz API + MCP",
        "score": 59.3,
        "shared": [
          "social.analytics"
        ],
        "slug": "postiz"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/upload-post.json",
        "name": "Upload-Post API + MCP",
        "score": 58.7,
        "shared": [
          "social.analytics"
        ],
        "slug": "upload-post"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/ayrshare.json",
        "name": "Ayrshare API + MCP",
        "score": 57.2,
        "shared": [
          "social.analytics"
        ],
        "slug": "ayrshare"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/mixpost.json",
        "name": "Mixpost API + MCP",
        "score": 49.5,
        "shared": [
          "social.analytics"
        ],
        "slug": "mixpost"
      }
    ],
    "tool": {
      "slug": "x-mcp",
      "name": "X MCP",
      "vendor": "X Corp.",
      "vendorUrl": "https://docs.x.com/tools/mcp",
      "kind": "mcp",
      "category": "social-media",
      "summary": "X MCP is X Corp.'s hosted Model Context Protocol server for the X API at api.x.com/mcp. It lets a model search posts, look up users, manage bookmarks, read trends and news, and draft Articles.",
      "url": "https://www.anchorterminal.com/tools/x-mcp",
      "markdownUrl": "https://www.anchorterminal.com/tools/x-mcp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/x-mcp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/x-mcp.json",
      "repo": "https://github.com/xdevplatform/xurl",
      "license": "Proprietary hosted server under the X Developer Agreement. The xurl bridge on GitHub and npm is MIT",
      "transports": [
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://api.x.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@xdevplatform/xurl"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an app in the X Developer Portal, on the Pay-per-use package in Production. Reads work with the app-only Bearer token in an `Authorization` header sent straight to https://api.x.com/mcp. User-context tools (bookmarks, Articles, the current user) need OAuth 2.0 authorisation code with PKCE through the local `xurl mcp` bridge, which takes CLIENT_ID and CLIENT_SECRET, needs the redirect URI http://localhost:8080/callback registered, opens a browser once, then caches and refreshes tokens in ~/.xurl. No dynamic client registration. Self-serve, with no review step documented.",
      "pricing": "usage",
      "pricingNotes": "Pay-per-use credits bought in advance in the Developer Console, with no subscription and no free tier. Reads are charged per resource returned ($0.005 a post, $0.010 a user, $0.001 for the app owner's own data) and writes per request ($0.005 a bookmark, $0.010 a trends request). A one-time $20 credit needs a saved payment card. The MCP page doesn't say MCP calls are billed at these API rates, though it requires a Pay-per-use app (https://docs.x.com/x-api/getting-started/pricing.md).",
      "priceSummary": "$0.005 / call",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the MCP page, the pricing page, the docs index or the OpenAPI spec (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1352,
        "npmWeekly": 6027,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.x.com/tools/mcp",
      "llmsTxt": "https://docs.x.com/llms.txt",
      "openapi": "https://api.x.com/2/openapi.json",
      "capabilities": [
        "social.analytics"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "usage-priced",
        "prepaid",
        "card-required",
        "openapi",
        "llms-txt",
        "closed-source",
        "cli",
        "go"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.4,
        "grade": "C",
        "agentReady": false,
        "rank": 451,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 45,
          "maintenance": 70,
          "payments": 20,
          "reliability": 72,
          "schema": 65,
          "security": 48,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 72,
            "points": 14.4,
            "reason": "Read with the hosted lines, since the server runs at api.x.com and the bridge only relays. A status page exists at developer.x.com/status but needs JavaScript and showed our reader nothing. The dated incident history at docs.x.com/incidents.md lists incidents by title, with no component view and no MCP entry (15 of 20). That history has no incident dated after 1 July 2026, so the 90 days to 8 October are clean, apart from a 'Missing entities.annotations' entry marked ongoing since 24 March 2026 (25 of 30). API rate limits are published per endpoint, such as 300 per 15 minutes and 1 a second for full-archive search and 50 per 15 minutes for bookmark writes. The MCP page gives no numbers of its own and says only that writes are stricter than reads (12 of 15). 429s come with `x-rate-limit-reset` and the docs advise waiting for it and backing off. No Retry-After and no idempotency keys for writes were found (10 of 15). No SLA found for Pay-per-use (0). The MCP page carries no beta or preview label (10). 72."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 65,
            "points": 10.56,
            "reason": "A public OpenAPI spec covers the API behind it (version 2.169, 175 paths, 218 operations). The MCP tool list and input schemas aren't published, and tools/list answers 401 without a token, so we didn't read them (18 of 25). llms.txt, llms-full.txt, skill.md and Markdown for every page (10). The MCP page describes six groups of tools and names one tool, `article_publish`, with no per-tool guidance on when to use which (6 of 20). The API parameters are typed in the spec. Whether the MCP tools carry the same enums and constraints is unread (8 of 15). Client configs for five clients, a troubleshooting table of eight symptoms and a documented problem+json error format with eleven error types (12 of 15). The API is versioned in the path and has a dated changelog with an RSS feed, latest entry 2 October 2026, but the changelog has no entry for the hosted MCP server and the server publishes no version history (11 of 15). 65."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 45,
            "points": 7.31,
            "reason": "The number of tools isn't published. One docs page lists six groups and another says XMCP exposes 200+ endpoints as tools, so we scored context cost as not established (5 of 25). The API has `max_results`, `pagination_token`, field selection and expansions. Whether each MCP tool passes them through is unread (12 of 20). Errors are problem+json with a type URI, title and detail, and the bridge turns transport and token failures into JSON-RPC errors keyed to the request (15 of 20). No idempotency keys, and no readOnlyHint or destructiveHint documented. The bridge refreshes the token and retries after a 401 (4 of 20). One npx line starts the bridge and the URL has a default, but each user first creates an app, registers a redirect URI and sets a 300-second startup timeout. Official XDKs exist for Python and TypeScript (9 of 15). 45."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 48,
            "points": 8.4,
            "reason": "OAuth 2.0 authorisation code with PKCE (S256), scopes and refresh tokens, and the resource metadata accepts bearer tokens in the header only. Less 6 because xurl 1.3.4 requests a fixed set of 24 scopes including tweet.write and dm.write with no flag to narrow them, and the bridge config holds the client secret in plain text (24 of 30). The app-only Bearer route is read-only per the docs. No confirmation step is documented for `article_publish` or for removing bookmarks, so approval rests with the MCP client (10 of 20). Posts, profiles and news text come from anyone on X, and the security section has no guidance on prompt injection (0 of 15). The Developer Console shows usage and spend live and /2/usage/tweets returns daily counts. No per-call log was found (6 of 15). x.com's security.txt points to HackerOne but expired on 1 January 2024, and we found no SOC 2 or ISO 27001 statement in what we read (8 of 20). 48."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 (0). Per-resource and per-request prices are published without a login, such as $0.005 a post read, $0.010 a user read and $0.005 a bookmark write (20). No free tier. Credits are bought in advance, and the one-time $20 credit needs a saved payment card (0). A person signs in to the developer portal, creates an app and completes a browser login (0). 20."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 70,
            "points": 6.13,
            "reason": "The xurl bridge reached 1.3.4 on 29 September 2026 and the platform changelog's latest entry is 2 October 2026 (30). Six xurl releases since 16 July 2026, and ten platform changelog entries since 21 July (20). The xurl changelog credits fixes to numbered issues, and the repository showed 7 open issues and 8 open pull requests on 8 October. We couldn't read the threads or the developer forum, which answered 403 (12 of 25). No X entry in the official MCP registry under searches for xmcp, xdevplatform and com.x (0). Go 1.24 with build, test, gofmt and release-build jobs in CI (8 of 10). 70."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 70,
            "points": 6.13,
            "note": "editorial 50, provenance 89",
            "reason": "The hosted server is closed, under a Developer Agreement last updated 27 April 2026, and the bridge is MIT (18 of 30). The privacy policy, effective 15 January 2026, describes retention by data type and names the controllers. The terms of service let X use content to train its AI models. No DPA or subprocessor list for developers was found in what we read (14 of 30). The versioning page limits breaking changes to major versions, at most yearly, with migration guides. Dated notices exist but can be short, such as five days for the Account Activity replay endpoint in March 2026 and four days for the removal of follows, likes and quote posts from self-serve tiers in April 2026 (14 of 20). Controllers for the US and Europe are named. No subprocessor or data location list found (4 of 20). 50."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The number of tools isn't published. One docs page lists six groups and another says XMCP exposes 200+ endpoints as tools, so we scored context cost as not established (5 of 25). The API has `max_results`, `pagination_token`, field selection and expansions. Whether each MCP tool passes them through is unread (12 of 20). Errors are problem+json with a type URI, title and detail, and the bridge turns transport and token failures into JSON-RPC errors keyed to the request (15 of 20). No idempotency keys, and no readOnlyHint or destructiveHint documented. The bridge refreshes the token and retries after a 401 (4 of 20). One npx line starts the bridge and the URL has a default, but each user first creates an app, registers a redirect URI and sets a 300-second startup timeout. Official XDKs exist for Python and TypeScript (9 of 15). 45.",
            "maintenance": "The xurl bridge reached 1.3.4 on 29 September 2026 and the platform changelog's latest entry is 2 October 2026 (30). Six xurl releases since 16 July 2026, and ten platform changelog entries since 21 July (20). The xurl changelog credits fixes to numbered issues, and the repository showed 7 open issues and 8 open pull requests on 8 October. We couldn't read the threads or the developer forum, which answered 403 (12 of 25). No X entry in the official MCP registry under searches for xmcp, xdevplatform and com.x (0). Go 1.24 with build, test, gofmt and release-build jobs in CI (8 of 10). 70.",
            "payments": "No x402, MPP or L402 (0). Per-resource and per-request prices are published without a login, such as $0.005 a post read, $0.010 a user read and $0.005 a bookmark write (20). No free tier. Credits are bought in advance, and the one-time $20 credit needs a saved payment card (0). A person signs in to the developer portal, creates an app and completes a browser login (0). 20.",
            "reliability": "Read with the hosted lines, since the server runs at api.x.com and the bridge only relays. A status page exists at developer.x.com/status but needs JavaScript and showed our reader nothing. The dated incident history at docs.x.com/incidents.md lists incidents by title, with no component view and no MCP entry (15 of 20). That history has no incident dated after 1 July 2026, so the 90 days to 8 October are clean, apart from a 'Missing entities.annotations' entry marked ongoing since 24 March 2026 (25 of 30). API rate limits are published per endpoint, such as 300 per 15 minutes and 1 a second for full-archive search and 50 per 15 minutes for bookmark writes. The MCP page gives no numbers of its own and says only that writes are stricter than reads (12 of 15). 429s come with `x-rate-limit-reset` and the docs advise waiting for it and backing off. No Retry-After and no idempotency keys for writes were found (10 of 15). No SLA found for Pay-per-use (0). The MCP page carries no beta or preview label (10). 72.",
            "schema": "A public OpenAPI spec covers the API behind it (version 2.169, 175 paths, 218 operations). The MCP tool list and input schemas aren't published, and tools/list answers 401 without a token, so we didn't read them (18 of 25). llms.txt, llms-full.txt, skill.md and Markdown for every page (10). The MCP page describes six groups of tools and names one tool, `article_publish`, with no per-tool guidance on when to use which (6 of 20). The API parameters are typed in the spec. Whether the MCP tools carry the same enums and constraints is unread (8 of 15). Client configs for five clients, a troubleshooting table of eight symptoms and a documented problem+json error format with eleven error types (12 of 15). The API is versioned in the path and has a dated changelog with an RSS feed, latest entry 2 October 2026, but the changelog has no entry for the hosted MCP server and the server publishes no version history (11 of 15). 65.",
            "security": "OAuth 2.0 authorisation code with PKCE (S256), scopes and refresh tokens, and the resource metadata accepts bearer tokens in the header only. Less 6 because xurl 1.3.4 requests a fixed set of 24 scopes including tweet.write and dm.write with no flag to narrow them, and the bridge config holds the client secret in plain text (24 of 30). The app-only Bearer route is read-only per the docs. No confirmation step is documented for `article_publish` or for removing bookmarks, so approval rests with the MCP client (10 of 20). Posts, profiles and news text come from anyone on X, and the security section has no guidance on prompt injection (0 of 15). The Developer Console shows usage and spend live and /2/usage/tweets returns daily counts. No per-call log was found (6 of 15). x.com's security.txt points to HackerOne but expired on 1 January 2024, and we found no SOC 2 or ISO 27001 statement in what we read (8 of 20). 48.",
            "transparency": "The hosted server is closed, under a Developer Agreement last updated 27 April 2026, and the bridge is MIT (18 of 30). The privacy policy, effective 15 January 2026, describes retention by data type and names the controllers. The terms of service let X use content to train its AI models. No DPA or subprocessor list for developers was found in what we read (14 of 30). The versioning page limits breaking changes to major versions, at most yearly, with migration guides. Dated notices exist but can be short, such as five days for the Account Activity replay endpoint in March 2026 and four days for the removal of follows, likes and quote posts from self-serve tiers in April 2026 (14 of 20). Controllers for the US and Europe are named. No subprocessor or data location list found (4 of 20). 50."
          },
          "sources": [
            {
              "what": "MCP page (setup, auth routes, tool groups, troubleshooting, security)",
              "url": "https://docs.x.com/tools/mcp.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Agent Resources page",
              "url": "https://docs.x.com/tools/ai.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP endpoint, unauthenticated initialize (401 with resource_metadata)",
              "url": "https://api.x.com/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth protected resource metadata",
              "url": "https://api.x.com/.well-known/oauth-protected-resource",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth authorisation server metadata",
              "url": "https://api.x.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI spec 2.169",
              "url": "https://api.x.com/2/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://docs.x.com/x-api/getting-started/pricing.md",
              "seen": "2026-10-08"
            },
            {
              "what": "free credit incentives",
              "url": "https://docs.x.com/x-api/getting-started/free-credits.md",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limits and 429 handling",
              "url": "https://docs.x.com/x-api/fundamentals/rate-limits.md",
              "seen": "2026-10-08"
            },
            {
              "what": "response codes and errors",
              "url": "https://docs.x.com/x-api/fundamentals/response-codes-and-errors.md",
              "seen": "2026-10-08"
            },
            {
              "what": "versioning policy",
              "url": "https://docs.x.com/x-api/fundamentals/versioning.md",
              "seen": "2026-10-08"
            },
            {
              "what": "platform changelog",
              "url": "https://docs.x.com/changelog.md",
              "seen": "2026-10-08"
            },
            {
              "what": "incident history",
              "url": "https://docs.x.com/incidents.md",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://docs.x.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Developer Agreement",
              "url": "https://docs.x.com/developer-terms/agreement.md",
              "seen": "2026-10-08"
            },
            {
              "what": "xurl repository (README, CHANGELOG, auth/auth.go, CI workflows, tags), cloned",
              "url": "https://github.com/xdevplatform/xurl",
              "seen": "2026-10-08"
            },
            {
              "what": "xmcp repository (older local server), cloned",
              "url": "https://github.com/xdevplatform/xmcp",
              "seen": "2026-10-08"
            },
            {
              "what": "xurl on npm, version 1.3.4",
              "url": "https://registry.npmjs.org/@xdevplatform/xurl/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads, 28 September to 4 October",
              "url": "https://api.npmjs.org/downloads/point/last-week/@xdevplatform/xurl",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=xdevplatform",
              "seen": "2026-10-08"
            },
            {
              "what": "X terms of service",
              "url": "https://x.com/en/tos",
              "seen": "2026-10-08"
            },
            {
              "what": "X privacy policy",
              "url": "https://x.com/en/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (expired 1 January 2024)",
              "url": "https://x.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP record for x.com",
              "url": "https://rdap.verisign.com/com/v1/domain/x.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the MCP tool list, input schemas, descriptions and annotations. tools/list needs a token from a Pay-per-use app, which we don't have",
            "unchecked: the live status page at developer.x.com/status, which needs JavaScript. Incident history was read from docs.x.com/incidents.md",
            "unchecked: issue and pull request threads on xdevplatform/xurl (the GitHub API was rate-limited) and devcommunity.x.com, which answered 403",
            "unchecked: the HackerOne programme page, which is a JavaScript app. The only pointer read is the expired security.txt",
            "How many tools the server exposes. The MCP page lists six groups and the Agent Resources page says 200+ endpoints",
            "Whether MCP calls are billed at the published API rates and whether failed calls are charged. The MCP page requires a Pay-per-use app but doesn't say",
            "When the hosted server launched. The docs give no date, and the first dated evidence is `xurl mcp` on 25 June 2026",
            "The docs say the endpoint has no MCP OAuth discovery, yet it serves protected resource metadata. We didn't test whether a client can sign in directly with a pre-registered client ID",
            "Whether the developer.write and developer.billing.write scopes listed for the MCP resource back tools that create apps or buy credits",
            "The category has no capability for searching or reading a network. We used social.analytics as the nearest and left out social.post, since the only publishing tool documented is for Articles",
            "No deduction was made for the short-notice API changes of February and April 2026, which predate the hosted server and concern posting endpoints it doesn't document"
          ]
        },
        "negative": 0,
        "verdict": "First-party access to full-archive post search, user lookup, trends and news, with OAuth 2.0 PKCE scopes and per-resource prices published without a login. Every user must create a paid X developer app, the tool list isn't published, and the documented tools don't create posts.",
        "bestFor": "Research and monitoring on X by an agent whose owner already has, or will pay for, an X developer app, such as searching the archive, reading timelines and mentions, and filing bookmarks.",
        "strengths": [
          "Hosted by X on api.x.com, with full-archive post search, user search and news search among the documented tools",
          "OAuth 2.0 with PKCE (S256), refresh tokens and header-only bearer tokens, per the server's published metadata",
          "Per-resource prices are public, such as $0.005 a post read and $0.001 for reads of the app owner's own data",
          "The xurl bridge is MIT, at 1.3.4 from 29 September 2026, with six releases since 16 July",
          "llms.txt, Markdown for every docs page and a public OpenAPI spec (version 2.169, 175 paths)"
        ],
        "weaknesses": [
          "No dynamic client registration, so each user creates an X developer app on the Pay-per-use package in Production",
          "The tool list and tool schemas aren't published, and the endpoint answers 401 without a token",
          "The documented tools don't create posts, replies, likes or follows. Writes cover bookmarks and Articles",
          "xurl 1.3.4 asks for a fixed set of 24 scopes, including tweet.write and dm.write, with no flag to narrow them",
          "No guidance on prompt injection, though every post returned is text written by strangers",
          "Not in the official MCP registry, and the platform changelog has no entry for the hosted server"
        ],
        "agentNotes": [
          "Use the app-only Bearer header for read-only work. Bookmarks, Articles and any tool working in the user's name need the xurl bridge",
          "Set the client's startup timeout to 300 seconds or more, because the bridge holds the handshake until the first browser login ends",
          "On a headless host run `xurl auth oauth2 --headless` first, with CLIENT_ID and CLIENT_SECRET exported in that shell",
          "On `client-not-enrolled`, move the app to Pay-per-use and Production in the developer portal",
          "On 429, wait until the Unix time in `x-rate-limit-reset`. No Retry-After header is documented"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.4
          }
        ],
        "editorialScores": {
          "ergonomics": 45,
          "maintenance": 70,
          "payments": 20,
          "reliability": 72,
          "schema": 65,
          "security": 48,
          "transparency": 50
        },
        "provenanceScore": 89
      },
      "connect": {
        "install": "npm install -g @xdevplatform/xurl",
        "config": {
          "mcpServers": {
            "xapi": {
              "args": [
                "-y",
                "@xdevplatform/xurl",
                "mcp",
                "https://api.x.com/mcp"
              ],
              "command": "npx",
              "env": {
                "CLIENT_ID": "YOUR_X_APP_CLIENT_ID",
                "CLIENT_SECRET": "YOUR_X_APP_CLIENT_SECRET"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/social.analytics",
        "tool": "https://letme.dev/x-mcp"
      },
      "notable": [
        "Hosted Streamable HTTP server at https://api.x.com/mcp, protocol 2025-06-18, reporting itself as `xmcp`. Two routes are documented, a static app-only Bearer token for reads or the local `xurl mcp` bridge for OAuth 2.0 user context (https://docs.x.com/tools/mcp.md)",
        "The docs say the endpoint has no native MCP OAuth discovery. On 8 October 2026 it answered an unauthenticated request with 401 and a `resource_metadata` pointer, and https://api.x.com/.well-known/oauth-protected-resource listed 17 scopes for the resource. The authorisation server metadata has no registration endpoint, which matches the docs on dynamic client registration",
        "The scopes listed for the MCP resource include bookmark.write, list.write, block.write, dm.write, developer.write and developer.billing.write, and leave out tweet.write, like.write and follows.write (https://api.x.com/.well-known/oauth-protected-resource)",
        "The MCP page lists six groups of tools (posts, search, users, bookmarks, news and trends, Articles) and names one tool, `article_publish`. The Agent Resources page says XMCP exposes 200+ X API endpoints as tools. We couldn't list the tools without a paid app (https://docs.x.com/tools/ai.md)",
        "`xurl mcp` was added on 25 June 2026 and shipped in xurl 1.2.0 on 29 June 2026. The platform changelog has no entry for the hosted server (https://github.com/xdevplatform/xurl/blob/main/CHANGELOG.md)",
        "An older local server, xdevplatform/xmcp, builds tools from the OpenAPI spec with FastMCP. It was announced on 6 February 2026 and last changed on 9 April 2026. This listing grades the hosted server (https://github.com/xdevplatform/xmcp)",
        "A second hosted server at https://docs.x.com/mcp needs no credentials and has two tools, `search_x` and `get_page_x`, for the documentation only (https://docs.x.com/tools/mcp.md)",
        "The Developer Agreement, last updated 27 April 2026, forbids using the X API or X Content to fine-tune or train a foundation or frontier model (https://docs.x.com/developer-terms/agreement.md)"
      ],
      "area": "communication",
      "details": [
        {
          "label": "Server",
          "value": "Hosted Streamable HTTP at https://api.x.com/mcp, protocol 2025-06-18, serverInfo `xmcp`. Closed source"
        },
        {
          "label": "Tools",
          "value": "Posts (lookup, likers, reposters, quoters, counts), full-archive post search, user search, news search, user lookup and timelines, bookmarks and folders, trends by location, Article drafts and publishing. The tool count isn't published"
        },
        {
          "label": "Not covered",
          "value": "Creating posts or replies, likes, follows and direct messages aren't in the documented tool groups"
        },
        {
          "label": "Access",
          "value": "Own X developer app on Pay-per-use in Production. App-only Bearer token for reads, or OAuth 2.0 PKCE through the `xurl mcp` bridge for user context"
        },
        {
          "label": "Bridge",
          "value": "@xdevplatform/xurl 1.3.4 (MIT, Go, 29 September 2026), run with npx. Tokens cached in ~/.xurl"
        },
        {
          "label": "Pricing",
          "value": "Prepaid credits. $0.005 a post read, $0.010 a user read, $0.001 an owned read, $0.005 a bookmark write, capped at 3 million post reads a month on Pay-per-use"
        },
        {
          "label": "Rate limits",
          "value": "Per endpoint and 15-minute window on the API, such as 300 per 15 minutes and 1 a second for full-archive search and 50 per 15 minutes for bookmark writes. No MCP-specific limits published"
        },
        {
          "label": "Docs for agents",
          "value": "llms.txt, llms-full.txt, Markdown for every page, skill.md, AGENTS.md and an OpenAPI spec at https://api.x.com/2/openapi.json"
        }
      ],
      "unitPrices": [
        {
          "item": "Post read",
          "unit": "record",
          "usd": 0.005,
          "note": "per post returned, deduplicated within a UTC day"
        },
        {
          "item": "User read",
          "unit": "record",
          "usd": 0.01,
          "note": "per user returned"
        },
        {
          "item": "Owned read (the app owner's own posts, bookmarks, followers)",
          "unit": "record",
          "usd": 0.001,
          "note": "when the authenticated user owns the app"
        },
        {
          "item": "Bookmark write",
          "unit": "call",
          "usd": 0.005,
          "note": "per request"
        },
        {
          "item": "Trends request",
          "unit": "call",
          "usd": 0.01,
          "note": "per request"
        }
      ],
      "provenance": {
        "legalEntity": "X Corp.",
        "domain": "x.com",
        "domainRegistered": "1993-04-02",
        "endpointOnVendorDomain": true,
        "terms": "https://docs.x.com/developer-terms/agreement",
        "privacy": "https://x.com/en/privacy",
        "statusPage": "https://developer.x.com/status",
        "changelog": "https://docs.x.com/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The X terms of service name X Corp., 800 W Cesar Chavez St., Austin, TX 78701, and the privacy policy (effective 15 January 2026) names X Internet Unlimited Company as controller for the EU, EFTA and the UK.",
          "https://x.com/.well-known/security.txt is PGP-signed, points to hackerone.com/twitter and expired on 1 January 2024. api.x.com and docs.x.com return 404 for the file.",
          "https://developer.x.com/status needs JavaScript and showed our reader no status data. The incident history is readable at https://docs.x.com/incidents.md.",
          "RDAP for x.com gives a registration date of 1993-04-02."
        ],
        "score": 89,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "X Corp.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "x.com, registered 1993-04-02 (33 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.x.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 7.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "developer.x.com/status",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://docs.x.com/developer-terms/agreement",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-04-27",
            "words": 8254,
            "points": 7.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: April 27, 2026",
                "says": "Last updated 2026-04-27"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The laws of the State of Texas, excluding its choice of law provisions, will govern this Agreement and any dispute that arises between you and X, notwithstanding any other agreement between the parties to the contrary.",
                "says": "The law of the State of Texas"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "IN ANY CASE, X’S AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS UNDER THIS AGREEMENT WILL NOT EXCEED FIFTY DOLLARS ($50.00).",
                "says": "Capped at $50.00"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If you exceed or X reasonably believes that you have attempted to circumvent Rate Limits, controls to limit use of the X APIs, or the terms of this Agreement, then your ability to use the Licensed Material may be temporarily suspended or permanently blocked."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "X will alert you of material revisions to these terms by posting the updated terms on these sites, via a service notification, or by other suitable means (e.g., via email to an email address associated with your account).",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you do not understand the terms herein or do not accept any part of them, then you may not use or access any Licensed Material."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use or access the Licensed Material to create or attempt to create a substitute or similar service or product to the X Applications",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "X may terminate this Agreement for any reason at X’s sole discretion."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "Class Action Waiver. To the extent permitted by law, you also waive the right to participate as a plaintiff or class member in any purported class action, collective action, or representative action proceeding."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "X's total liability for all claims under the agreement is capped at 50 US dollars.",
                "quote": "IN ANY CASE, X’S AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS UNDER THIS AGREEMENT WILL NOT EXCEED FIFTY DOLLARS ($50.00)."
              },
              {
                "date": "2026-10-08",
                "text": "The X API and X Content may not be used to fine-tune or train a foundation or frontier model.",
                "quote": "use the X API or X Content to fine-tune or train a foundation or frontier model"
              },
              {
                "date": "2026-10-08",
                "text": "On termination the developer must permanently delete all Licensed Material and, if X asks, give evidence of deletion within ten business days.",
                "quote": "Upon the request of X for any reason, you will promptly (and in any event within ten (10) business days of such request) provide evidence (e.g., screenshots of deletion confirmation) of compliance with the provisions of the aforementioned subpart (b) of this Section."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://x.com/en/privacy",
            "state": "unreadable",
            "reason": "robots.txt asks readers like ours not to fetch it",
            "readAt": "2026-10-08",
            "points": 7,
            "max": 10
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/x-mcp.json",
      "live": {
        "slug": "x-mcp",
        "probe": {
          "target": "https://api.x.com/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-08T17:36:49.519084855Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 142,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 137,
          "p95ms24h": 304,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://developer.x.com/status",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T15:37:23.162937993Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "xdevplatform/xurl",
            "version": "v1.3.4",
            "released": "2026-09-29",
            "seenAt": "2026-10-08T16:35:14.575990235Z"
          },
          {
            "registry": "npm",
            "name": "@xdevplatform/xurl",
            "version": "1.3.4",
            "seenAt": "2026-10-08T16:35:13.417069401Z"
          }
        ],
        "githubStars": 1352,
        "npmWeekly": 6027,
        "securityTxt": {
          "url": "https://x.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2024-01-01T06:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:54.375297302Z"
        },
        "updatedAt": "2026-10-08T17:36:49.519084855Z"
      }
    },
    "verify": {
      "accepts": "a page on docs.x.com or one of its subdomains, or the README of github.com/xdevplatform/xurl",
      "badgeUrl": "https://www.anchorterminal.com/badges/x-mcp.svg",
      "body": {
        "slug": "x-mcp",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/x-mcp",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/x-mcp\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/x-mcp.svg\" alt=\"X MCP on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![X MCP on Anchor Terminal](https://www.anchorterminal.com/badges/x-mcp.svg)](https://www.anchorterminal.com/tools/x-mcp)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/x-mcp\"\u003eX MCP on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/x-mcp",
    "json": "https://www.anchorterminal.com/tools/x-mcp.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/x-mcp.md",
    "slim": "https://www.anchorterminal.com/tools/x-mcp.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 55.4/100 · rank #451 of 629 · #6 in Social media posting APIs · not agent-ready · confidence medium**\n\n\n## Assessment\n\nFirst-party access to full-archive post search, user lookup, trends and news, with OAuth 2.0 PKCE scopes and per-resource prices published without a login. Every user must create a paid X developer app, the tool list isn't published, and the documented tools don't create posts.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | X Corp. (https://docs.x.com/tools/mcp) |\n| Kind | MCP server |\n| Category | Social media posting APIs (https://www.anchorterminal.com/categories/social-media) |\n| Transport | Streamable HTTP, stdio |\n| Endpoint | `https://api.x.com/mcp` |\n| Auth | OAuth or key · A person creates an app in the X Developer Portal, on the Pay-per-use package in Production. Reads work with the app-only Bearer token in an `Authorization` header sent straight to https://api.x.com/mcp. User-context tools (bookmarks, Articles, the current user) need OAuth 2.0 authorisation code with PKCE through the local `xurl mcp` bridge, which takes CLIENT_ID and CLIENT_SECRET, needs the redirect URI http://localhost:8080/callback registered, opens a browser once, then caches and refreshes tokens in ~/.xurl. No dynamic client registration. Self-serve, with no review step documented. |\n| Pricing | Pay per use ($0.005 / call) · Pay-per-use credits bought in advance in the Developer Console, with no subscription and no free tier. Reads are charged per resource returned ($0.005 a post, $0.010 a user, $0.001 for the app owner's own data) and writes per request ($0.005 a bookmark, $0.010 a trends request). A one-time $20 credit needs a saved payment card. The MCP page doesn't say MCP calls are billed at these API rates, though it requires a Pay-per-use app (https://docs.x.com/x-api/getting-started/pricing.md). |\n| x402 | No · No x402, MPP or L402 in the MCP page, the pricing page, the docs index or the OpenAPI spec (checked 2026-10-08). |\n| Licence | Proprietary hosted server under the X Developer Agreement. The xurl bridge on GitHub and npm is MIT |\n| Packages | npm: `@xdevplatform/xurl` |\n| Source | https://github.com/xdevplatform/xurl |\n| Docs | https://docs.x.com/tools/mcp |\n| llms.txt | https://docs.x.com/llms.txt |\n| Last release | 2026-09-29 |\n| GitHub stars | 1,352 (as of 2026-10-08) |\n| npm downloads / week | 6,027 |\n| Server | Hosted Streamable HTTP at https://api.x.com/mcp, protocol 2025-06-18, serverInfo `xmcp`. Closed source |\n| Tools | Posts (lookup, likers, reposters, quoters, counts), full-archive post search, user search, news search, user lookup and timelines, bookmarks and folders, trends by location, Article drafts and publishing. The tool count isn't published |\n| Not covered | Creating posts or replies, likes, follows and direct messages aren't in the documented tool groups |\n| Access | Own X developer app on Pay-per-use in Production. App-only Bearer token for reads, or OAuth 2.0 PKCE through the `xurl mcp` bridge for user context |\n| Bridge | @xdevplatform/xurl 1.3.4 (MIT, Go, 29 September 2026), run with npx. Tokens cached in ~/.xurl |\n| Pricing | Prepaid credits. $0.005 a post read, $0.010 a user read, $0.001 an owned read, $0.005 a bookmark write, capped at 3 million post reads a month on Pay-per-use |\n| Rate limits | Per endpoint and 15-minute window on the API, such as 300 per 15 minutes and 1 a second for full-archive search and 50 per 15 minutes for bookmark writes. No MCP-specific limits published |\n| Docs for agents | llms.txt, llms-full.txt, Markdown for every page, skill.md, AGENTS.md and an OpenAPI spec at https://api.x.com/2/openapi.json |\n| Capabilities | social.analytics |\n| Tags | official, hosted, mcp, oauth, usage-priced, prepaid, card-required, openapi, llms-txt, closed-source, cli, go |\n| JSON | https://www.anchorterminal.com/api/v1/tools/x-mcp.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 72 | 14.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 65 | 10.6 |\n| Agent ergonomics | 13% | 16.2 | 45 | 7.3 |\n| Security \u0026 auth | 14% | 17.5 | 48 | 8.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 70 | 6.1 |\n| Transparency \u0026 trust (editorial 50, provenance 89) | 7% | 8.8 | 70 | 6.1 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **55.4 → C** |\n\n### Why each score\n\n- Reliability 72: Read with the hosted lines, since the server runs at api.x.com and the bridge only relays. A status page exists at developer.x.com/status but needs JavaScript and showed our reader nothing. The dated incident history at docs.x.com/incidents.md lists incidents by title, with no component view and no MCP entry (15 of 20). That history has no incident dated after 1 July 2026, so the 90 days to 8 October are clean, apart from a 'Missing entities.annotations' entry marked ongoing since 24 March 2026 (25 of 30). API rate limits are published per endpoint, such as 300 per 15 minutes and 1 a second for full-archive search and 50 per 15 minutes for bookmark writes. The MCP page gives no numbers of its own and says only that writes are stricter than reads (12 of 15). 429s come with `x-rate-limit-reset` and the docs advise waiting for it and backing off. No Retry-After and no idempotency keys for writes were found (10 of 15). No SLA found for Pay-per-use (0). The MCP page carries no beta or preview label (10). 72.\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 65: A public OpenAPI spec covers the API behind it (version 2.169, 175 paths, 218 operations). The MCP tool list and input schemas aren't published, and tools/list answers 401 without a token, so we didn't read them (18 of 25). llms.txt, llms-full.txt, skill.md and Markdown for every page (10). The MCP page describes six groups of tools and names one tool, `article_publish`, with no per-tool guidance on when to use which (6 of 20). The API parameters are typed in the spec. Whether the MCP tools carry the same enums and constraints is unread (8 of 15). Client configs for five clients, a troubleshooting table of eight symptoms and a documented problem+json error format with eleven error types (12 of 15). The API is versioned in the path and has a dated changelog with an RSS feed, latest entry 2 October 2026, but the changelog has no entry for the hosted MCP server and the server publishes no version history (11 of 15). 65.\n- Agent ergonomics 45: The number of tools isn't published. One docs page lists six groups and another says XMCP exposes 200+ endpoints as tools, so we scored context cost as not established (5 of 25). The API has `max_results`, `pagination_token`, field selection and expansions. Whether each MCP tool passes them through is unread (12 of 20). Errors are problem+json with a type URI, title and detail, and the bridge turns transport and token failures into JSON-RPC errors keyed to the request (15 of 20). No idempotency keys, and no readOnlyHint or destructiveHint documented. The bridge refreshes the token and retries after a 401 (4 of 20). One npx line starts the bridge and the URL has a default, but each user first creates an app, registers a redirect URI and sets a 300-second startup timeout. Official XDKs exist for Python and TypeScript (9 of 15). 45.\n- Security \u0026 auth 48: OAuth 2.0 authorisation code with PKCE (S256), scopes and refresh tokens, and the resource metadata accepts bearer tokens in the header only. Less 6 because xurl 1.3.4 requests a fixed set of 24 scopes including tweet.write and dm.write with no flag to narrow them, and the bridge config holds the client secret in plain text (24 of 30). The app-only Bearer route is read-only per the docs. No confirmation step is documented for `article_publish` or for removing bookmarks, so approval rests with the MCP client (10 of 20). Posts, profiles and news text come from anyone on X, and the security section has no guidance on prompt injection (0 of 15). The Developer Console shows usage and spend live and /2/usage/tweets returns daily counts. No per-call log was found (6 of 15). x.com's security.txt points to HackerOne but expired on 1 January 2024, and we found no SOC 2 or ISO 27001 statement in what we read (8 of 20). 48.\n- Payments \u0026 pricing 20: No x402, MPP or L402 (0). Per-resource and per-request prices are published without a login, such as $0.005 a post read, $0.010 a user read and $0.005 a bookmark write (20). No free tier. Credits are bought in advance, and the one-time $20 credit needs a saved payment card (0). A person signs in to the developer portal, creates an app and completes a browser login (0). 20.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 70: The xurl bridge reached 1.3.4 on 29 September 2026 and the platform changelog's latest entry is 2 October 2026 (30). Six xurl releases since 16 July 2026, and ten platform changelog entries since 21 July (20). The xurl changelog credits fixes to numbered issues, and the repository showed 7 open issues and 8 open pull requests on 8 October. We couldn't read the threads or the developer forum, which answered 403 (12 of 25). No X entry in the official MCP registry under searches for xmcp, xdevplatform and com.x (0). Go 1.24 with build, test, gofmt and release-build jobs in CI (8 of 10). 70.\n- Transparency \u0026 trust 70: The hosted server is closed, under a Developer Agreement last updated 27 April 2026, and the bridge is MIT (18 of 30). The privacy policy, effective 15 January 2026, describes retention by data type and names the controllers. The terms of service let X use content to train its AI models. No DPA or subprocessor list for developers was found in what we read (14 of 30). The versioning page limits breaking changes to major versions, at most yearly, with migration guides. Dated notices exist but can be short, such as five days for the Account Activity replay endpoint in March 2026 and four days for the removal of follows, likes and quote posts from self-serve tiers in April 2026 (14 of 20). Controllers for the US and Europe are named. No subprocessor or data location list found (4 of 20). 50.\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/x-mcp.md (JSON https://www.anchorterminal.com/fixes/x-mcp.json)\n\n### What we couldn't check\n\n- unchecked: the MCP tool list, input schemas, descriptions and annotations. tools/list needs a token from a Pay-per-use app, which we don't have\n- unchecked: the live status page at developer.x.com/status, which needs JavaScript. Incident history was read from docs.x.com/incidents.md\n- unchecked: issue and pull request threads on xdevplatform/xurl (the GitHub API was rate-limited) and devcommunity.x.com, which answered 403\n- unchecked: the HackerOne programme page, which is a JavaScript app. The only pointer read is the expired security.txt\n- How many tools the server exposes. The MCP page lists six groups and the Agent Resources page says 200+ endpoints\n- Whether MCP calls are billed at the published API rates and whether failed calls are charged. The MCP page requires a Pay-per-use app but doesn't say\n- When the hosted server launched. The docs give no date, and the first dated evidence is `xurl mcp` on 25 June 2026\n- The docs say the endpoint has no MCP OAuth discovery, yet it serves protected resource metadata. We didn't test whether a client can sign in directly with a pre-registered client ID\n- Whether the developer.write and developer.billing.write scopes listed for the MCP resource back tools that create apps or buy credits\n- The category has no capability for searching or reading a network. We used social.analytics as the nearest and left out social.post, since the only publishing tool documented is for Articles\n- No deduction was made for the short-notice API changes of February and April 2026, which predate the hosted server and concern posting endpoints it doesn't document\n\n### Sources\n\n- MCP page (setup, auth routes, tool groups, troubleshooting, security): \u003chttps://docs.x.com/tools/mcp.md\u003e (seen 2026-10-08)\n- Agent Resources page: \u003chttps://docs.x.com/tools/ai.md\u003e (seen 2026-10-08)\n- MCP endpoint, unauthenticated initialize (401 with resource_metadata): \u003chttps://api.x.com/mcp\u003e (seen 2026-10-08)\n- OAuth protected resource metadata: \u003chttps://api.x.com/.well-known/oauth-protected-resource\u003e (seen 2026-10-08)\n- OAuth authorisation server metadata: \u003chttps://api.x.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- OpenAPI spec 2.169: \u003chttps://api.x.com/2/openapi.json\u003e (seen 2026-10-08)\n- pricing: \u003chttps://docs.x.com/x-api/getting-started/pricing.md\u003e (seen 2026-10-08)\n- free credit incentives: \u003chttps://docs.x.com/x-api/getting-started/free-credits.md\u003e (seen 2026-10-08)\n- rate limits and 429 handling: \u003chttps://docs.x.com/x-api/fundamentals/rate-limits.md\u003e (seen 2026-10-08)\n- response codes and errors: \u003chttps://docs.x.com/x-api/fundamentals/response-codes-and-errors.md\u003e (seen 2026-10-08)\n- versioning policy: \u003chttps://docs.x.com/x-api/fundamentals/versioning.md\u003e (seen 2026-10-08)\n- platform changelog: \u003chttps://docs.x.com/changelog.md\u003e (seen 2026-10-08)\n- incident history: \u003chttps://docs.x.com/incidents.md\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://docs.x.com/llms.txt\u003e (seen 2026-10-08)\n- Developer Agreement: \u003chttps://docs.x.com/developer-terms/agreement.md\u003e (seen 2026-10-08)\n- xurl repository (README, CHANGELOG, auth/auth.go, CI workflows, tags), cloned: \u003chttps://github.com/xdevplatform/xurl\u003e (seen 2026-10-08)\n- xmcp repository (older local server), cloned: \u003chttps://github.com/xdevplatform/xmcp\u003e (seen 2026-10-08)\n- xurl on npm, version 1.3.4: \u003chttps://registry.npmjs.org/@xdevplatform/xurl/latest\u003e (seen 2026-10-08)\n- npm weekly downloads, 28 September to 4 October: \u003chttps://api.npmjs.org/downloads/point/last-week/@xdevplatform/xurl\u003e (seen 2026-10-08)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=xdevplatform\u003e (seen 2026-10-08)\n- X terms of service: \u003chttps://x.com/en/tos\u003e (seen 2026-10-08)\n- X privacy policy: \u003chttps://x.com/en/privacy\u003e (seen 2026-10-08)\n- security.txt (expired 1 January 2024): \u003chttps://x.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- RDAP record for x.com: \u003chttps://rdap.verisign.com/com/v1/domain/x.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 89/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | X Corp. | 20/20 |\n| Domain age | x.com, registered 1993-04-02 (33 years) | 15/15 |\n| Endpoint on the vendor's domain | api.x.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 |\n| Privacy policy | published, but our reader couldn't read it | 7/10 |\n| Status page | developer.x.com/status | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe X terms of service name X Corp., 800 W Cesar Chavez St., Austin, TX 78701, and the privacy policy (effective 15 January 2026) names X Internet Unlimited Company as controller for the EU, EFTA and the UK.\n\nhttps://x.com/.well-known/security.txt is PGP-signed, points to hackerone.com/twitter and expired on 1 January 2024. api.x.com and docs.x.com return 404 for the file.\n\nhttps://developer.x.com/status needs JavaScript and showed our reader no status data. The incident history is readable at https://docs.x.com/incidents.md.\n\nRDAP for x.com gives a registration date of 1993-04-02.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://docs.x.com/developer-terms/agreement), read 2026-10-08, dated 2026-04-27, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"use or access the Licensed Material to create or attempt to create a substitute or similar service or product to the X Applications\"\n- To know. Says access can be ended without notice or for any reason. \"X may terminate this Agreement for any reason at X’s sole discretion.\"\n- To know. Requires arbitration or waives class actions. \"Class Action Waiver. To the extent permitted by law, you also waive the right to participate as a plaintiff or class member in any purported class action, collective action, or representative action proceeding.\"\n- Gives the date it was last updated. Last updated 2026-04-27.\n- Names the governing law or courts. The law of the State of Texas.\n- States a limit on its liability. Capped at $50.00.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). X's total liability for all claims under the agreement is capped at 50 US dollars. \"IN ANY CASE, X’S AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS UNDER THIS AGREEMENT WILL NOT EXCEED FIFTY DOLLARS ($50.00).\"\n- Also in the text (2026-10-08). The X API and X Content may not be used to fine-tune or train a foundation or frontier model. \"use the X API or X Content to fine-tune or train a foundation or frontier model\"\n- Also in the text (2026-10-08). On termination the developer must permanently delete all Licensed Material and, if X asks, give evidence of deletion within ten business days. \"Upon the request of X for any reason, you will promptly (and in any event within ten (10) business days of such request) provide evidence (e.g., screenshots of deletion confirmation) of compliance with the provisions of the aforementioned subpart (b) of this Section.\"\n\n**Privacy policy** (https://x.com/en/privacy), read 2026-10-08. Our reader couldn't read it (robots.txt asks readers like ours not to fetch it).\n\n\n## Live (updated 2026-10-08 17:36 UTC)\n\n- Right now: up, HTTP 401, 142 ms, checked 2026-10-08 17:36 UTC (mcp-initialize on `https://api.x.com/mcp`, asks for auth)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 137 ms · p95 304 ms\n- Vendor status page: unknown, no machine-readable status found\n- github `xdevplatform/xurl` v1.3.4, released 2026-09-29\n- npm `@xdevplatform/xurl` 1.3.4\n- security.txt: expired, expires 2024-01-01T06:00:00.000Z\n- Always current: https://www.anchorterminal.com/api/v1/live/x-mcp.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Post read | $0.005 | per record | per post returned, deduplicated within a UTC day |\n| User read | $0.01 | per record | per user returned |\n| Owned read (the app owner's own posts, bookmarks, followers) | $0.001 | per record | when the authenticated user owns the app |\n| Bookmark write | $0.005 | per call | per request |\n| Trends request | $0.01 | per call | per request |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Hosted by X on api.x.com, with full-archive post search, user search and news search among the documented tools\n- OAuth 2.0 with PKCE (S256), refresh tokens and header-only bearer tokens, per the server's published metadata\n- Per-resource prices are public, such as $0.005 a post read and $0.001 for reads of the app owner's own data\n- The xurl bridge is MIT, at 1.3.4 from 29 September 2026, with six releases since 16 July\n- llms.txt, Markdown for every docs page and a public OpenAPI spec (version 2.169, 175 paths)\n\n## Weaknesses\n\n- No dynamic client registration, so each user creates an X developer app on the Pay-per-use package in Production\n- The tool list and tool schemas aren't published, and the endpoint answers 401 without a token\n- The documented tools don't create posts, replies, likes or follows. Writes cover bookmarks and Articles\n- xurl 1.3.4 asks for a fixed set of 24 scopes, including tweet.write and dm.write, with no flag to narrow them\n- No guidance on prompt injection, though every post returned is text written by strangers\n- Not in the official MCP registry, and the platform changelog has no entry for the hosted server\n\n## Before you call it (notes for agents)\n\n1. Use the app-only Bearer header for read-only work. Bookmarks, Articles and any tool working in the user's name need the xurl bridge\n2. Set the client's startup timeout to 300 seconds or more, because the bridge holds the handshake until the first browser login ends\n3. On a headless host run `xurl auth oauth2 --headless` first, with CLIENT_ID and CLIENT_SECRET exported in that shell\n4. On `client-not-enrolled`, move the app to Pay-per-use and Production in the developer portal\n5. On 429, wait until the Unix time in `x-rate-limit-reset`. No Retry-After header is documented\n\n## Connect\n\nInstall:\n\n```bash\nnpm install -g @xdevplatform/xurl\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"xapi\": {\n      \"args\": [\n        \"-y\",\n        \"@xdevplatform/xurl\",\n        \"mcp\",\n        \"https://api.x.com/mcp\"\n      ],\n      \"command\": \"npx\",\n      \"env\": {\n        \"CLIENT_ID\": \"YOUR_X_APP_CLIENT_ID\",\n        \"CLIENT_SECRET\": \"YOUR_X_APP_CLIENT_SECRET\"\n      }\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/x-mcp. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Zernio (formerly Late) API + MCP | B | 67.5 | 192 | social.analytics | no | https://www.anchorterminal.com/tools/late.md |\n| Buffer API + MCP | B | 62 | 311 | social.analytics | no | https://www.anchorterminal.com/tools/buffer.md |\n| Postiz API + MCP | C | 59.3 | 381 | social.analytics | no | https://www.anchorterminal.com/tools/postiz.md |\n| Upload-Post API + MCP | C | 58.7 | 396 | social.analytics | no | https://www.anchorterminal.com/tools/upload-post.md |\n| Ayrshare API + MCP | C | 57.2 | 424 | social.analytics | no | https://www.anchorterminal.com/tools/ayrshare.md |\n| Mixpost API + MCP | D | 49.5 | 529 | social.analytics | no | https://www.anchorterminal.com/tools/mixpost.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Hosted Streamable HTTP server at https://api.x.com/mcp, protocol 2025-06-18, reporting itself as `xmcp`. Two routes are documented, a static app-only Bearer token for reads or the local `xurl mcp` bridge for OAuth 2.0 user context (source: \u003chttps://docs.x.com/tools/mcp.md\u003e)\n- The docs say the endpoint has no native MCP OAuth discovery. On 8 October 2026 it answered an unauthenticated request with 401 and a `resource_metadata` pointer, and https://api.x.com/.well-known/oauth-protected-resource listed 17 scopes for the resource. The authorisation server metadata has no registration endpoint, which matches the docs on dynamic client registration\n- The scopes listed for the MCP resource include bookmark.write, list.write, block.write, dm.write, developer.write and developer.billing.write, and leave out tweet.write, like.write and follows.write (source: \u003chttps://api.x.com/.well-known/oauth-protected-resource\u003e)\n- The MCP page lists six groups of tools (posts, search, users, bookmarks, news and trends, Articles) and names one tool, `article_publish`. The Agent Resources page says XMCP exposes 200+ X API endpoints as tools. We couldn't list the tools without a paid app (source: \u003chttps://docs.x.com/tools/ai.md\u003e)\n- `xurl mcp` was added on 25 June 2026 and shipped in xurl 1.2.0 on 29 June 2026. The platform changelog has no entry for the hosted server (source: \u003chttps://github.com/xdevplatform/xurl/blob/main/CHANGELOG.md\u003e)\n- An older local server, xdevplatform/xmcp, builds tools from the OpenAPI spec with FastMCP. It was announced on 6 February 2026 and last changed on 9 April 2026. This listing grades the hosted server (source: \u003chttps://github.com/xdevplatform/xmcp\u003e)\n- A second hosted server at https://docs.x.com/mcp needs no credentials and has two tools, `search_x` and `get_page_x`, for the documentation only (source: \u003chttps://docs.x.com/tools/mcp.md\u003e)\n- The Developer Agreement, last updated 27 April 2026, forbids using the X API or X Content to fine-tune or train a foundation or frontier model (source: \u003chttps://docs.x.com/developer-terms/agreement.md\u003e)\n\n## Compare\n\n- [Ayrshare API + MCP vs X MCP](https://www.anchorterminal.com/compare/ayrshare-vs-x-mcp.md): C 57.2 vs C 55.4\n- [Buffer API + MCP vs X MCP](https://www.anchorterminal.com/compare/buffer-vs-x-mcp.md): B 62 vs C 55.4\n- [Zernio (formerly Late) API + MCP vs X MCP](https://www.anchorterminal.com/compare/late-vs-x-mcp.md): B 67.5 vs C 55.4\n- [Metricool API + MCP vs X MCP](https://www.anchorterminal.com/compare/metricool-vs-x-mcp.md): E 38.3 vs C 55.4\n- [Mixpost API + MCP vs X MCP](https://www.anchorterminal.com/compare/mixpost-vs-x-mcp.md): D 49.5 vs C 55.4\n- [OneUp API + MCP vs X MCP](https://www.anchorterminal.com/compare/oneup-vs-x-mcp.md): F 24.4 vs C 55.4\n- [Post Bridge API + MCP vs X MCP](https://www.anchorterminal.com/compare/post-bridge-vs-x-mcp.md): D 48.3 vs C 55.4\n- [Postiz API + MCP vs X MCP](https://www.anchorterminal.com/compare/postiz-vs-x-mcp.md): C 59.3 vs C 55.4\n- [Publer API + MCP vs X MCP](https://www.anchorterminal.com/compare/publer-vs-x-mcp.md): D 46.8 vs C 55.4\n- [Upload-Post API + MCP vs X MCP](https://www.anchorterminal.com/compare/upload-post-vs-x-mcp.md): C 58.7 vs C 55.4\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on docs.x.com or one of its subdomains, or the README of github.com/xdevplatform/xurl. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"x-mcp\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/x-mcp\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/x-mcp.svg\" alt=\"X MCP on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![X MCP on Anchor Terminal](https://www.anchorterminal.com/badges/x-mcp.svg)](https://www.anchorterminal.com/tools/x-mcp)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/x-mcp\"\u003eX MCP on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say X MCP is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/x-mcp-dark.png\n- Light: https://www.anchorterminal.com/assets/share/x-mcp-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Social media posting APIs",
        "url": "https://www.anchorterminal.com/categories/social-media"
      },
      {
        "name": "X MCP",
        "url": ""
      }
    ],
    "description": "X MCP is X Corp.'s hosted Model Context Protocol server for the X API at api.x.com/mcp. It lets a model search posts, look up users, manage bookmarks, read trends and news, and draft Articles.",
    "facts": [
      "rank #451 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "X MCP",
    "image": "https://www.anchorterminal.com/assets/og/tools-x-mcp.png",
    "path": "/tools/x-mcp",
    "published": "2026-10-01",
    "section": "tools",
    "title": "X MCP review for AI agents, grade C (55.4/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/x-mcp"
  },
  "tokens": {
    "markdown": 7350,
    "slim": 1480
  },
  "version": 1
}
