Post, quote, reply, follow, like — one clean HTTP API backed by your X session and your proxy. X changes its internals every week; your code keeps working.
# quote a tweet — from your account, through your proxy curl https://apibreaker.site/v1/twitter/create_tweet \ -H 'X-Api-Key: xk_…' \ -H 'X-Auth-Token: your_x_auth_token' \ -H 'X-Proxy: http://user:pass@host:port' \ -H 'Content-Type: application/json' \ -d '{"text":"this API is clean","quote_url":"https://x.com/elonmusk/status/1"}'
import requests r = requests.post( "https://apibreaker.site/v1/twitter/create_tweet", headers={ "X-Api-Key": "xk_…", "X-Auth-Token": "your_x_auth_token", "X-Proxy": "http://user:pass@host:port", }, json={"text": "hello from apibreaker"}, ) print(r.json()) # {"tweet_id": "…"}
const res = await fetch("https://apibreaker.site/v1/twitter/create_tweet", { method: "POST", headers: { "X-Api-Key": "xk_…", "X-Auth-Token": "your_x_auth_token", "X-Proxy": "http://user:pass@host:port", "Content-Type": "application/json", }, body: JSON.stringify({ text: "hello from apibreaker" }), }); console.log(await res.json());
Pass your X auth_token per request. Actions bill against your session — we hold nothing, we see nothing stored.
Every call routes through the proxy you supply. Our IPs never touch X — your account stays glued to your residential exit.
X renames GraphQL operations weekly. We maintain the glue layer; you call the same stable endpoints forever.
One flat surface — post, engage, read. No feature gates, no "enterprise-only" routes. Rate limits are the only difference between tiers.
Open interactive docs ↗No OAuth dance, no app review, no waiting for approval that never comes.
X-Api-KeySign up with an email — a key is minted instantly. It's your billing identity; guard it like a password.
Every request carries X-Auth-Token (your X session cookie) and X-Proxy (your residential proxy). We never call X from our network.
Stable REST paths map to whatever X is doing internally this week. Errors come back as clean HTTP codes — 401 locked, 429 rate-limited, 409 duplicate.
Self-custody watch-only wallet: subscribe, get a fresh address, send ETH, SOL or USDC. A watcher confirms on-chain and your plan flips on — no custodian, no card, no KYC.
Central desktop client: every method behind a rich UI, routed through this API. One payment, yours forever.
The questions everyone asks before they paste their first curl.
Actions bill against your token and exit through your proxy, so the risk profile matches manual use: a good residential proxy and sane pacing matter far more than the API itself. If X locks or rate-limits the account, you get a clean 401 / 429 — never a silent failure.
We make zero direct requests to X. Every call routes through the proxy in your X-Proxy header, so your account's IP history stays consistent. Mixing our datacenter IPs into your session is how accounts die — we refuse to do it.
Subscribe in the dashboard, receive a freshly derived deposit address, send ETH, SOL, or USDC on that chain. A background watcher confirms the transaction on-chain and activates the plan automatically — seconds on Solana, about a minute on Ethereum.
No. This is an independent layer that speaks X's internal protocol on your behalf. That's why it needs your session token — and why there's no app review, no $100/mo "basic" tier reading limits, and no audit trail to a registrar.
They do, constantly. Tracking those mutations is the job: we update the glue layer and your /v1/twitter/* calls keep the same shape. You ship features, we chase GraphQL doc_ids.