# com.jojapi/x-twitter

X (twitter): x, xapi, Twitter, twitter api, twitters ,tweets, tw, twttr, FollowerIds, friendsIds.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** com.jojapi
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.jojapi.com/x
- **Source:** https://jojapi.com/hub/api/x
- **Endpoint health:** reachable (last checked 2026-10-02T13:12:02.786Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 3 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-02T13:12:02.786Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `get_base_apitools_trends` tool: Links to undeclared domain: gist.github.com
- injection-shaped content (note) in the `get_base_apitools_unfollow` tool: Links to undeclared domain: developer.x.com
- injection-shaped content (note) in the `get_base_apitools_followingsList` tool: Links to undeclared domain: developer.x.com
- injection-shaped content (note) in the `get_base_apitools_followingsIds` tool: Links to undeclared domain: developer.x.com
- injection-shaped content (note) in the `get_base_apitools_friendshipsShow` tool: Links to undeclared domain: developer.x.com
- injection-shaped content (note) in the `get_base_apitools_followersIds` tool: Links to undeclared domain: developer.x.com
- injection-shaped content (note) in the `get_base_apitools_followersList` tool: Links to undeclared domain: developer.x.com
- injection-shaped content (note) in the `get_base_apitools_follow` tool: Links to undeclared domain: developer.x.com
- …and 16 more (full list in the JSON view)

## Tools

107 declared. Observed from a live `tools/list` probe.
- `get_base_apitools_trends` — woeid https://gist.github.com/huojiecs110/ea26377a7396a4dcda5f594c9b7838f8 Group: Search. Billing per call: 1 Credits.
- `get_base_apitools_searchBox` — Search Box Group: Search. Billing per call: 1 Credits.
- `get_base_apitools_search` — Advanced Search Group: Search. Billing per call: 1 Credits.
- `get_base_apitools_unfollow` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/post-friendships-destroy Group: follows. Bil
- `get_base_apitools_followingsList` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/get-friends-list Group: follows. Billing per
- `get_base_apitools_followingsListV2` — get followingsList by V2 Group: follows. Billing per call: 1 Credits.
- `get_base_apitools_followingsIds` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/get-friends-ids Group: follows. Billing per 
- `get_base_apitools_followersListV2` — get followersList by V2 Group: follows. Billing per call: 1 Credits.
- `get_base_apitools_friendshipsShow` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/get-friendships-show Group: follows. Billing
- `get_base_apitools_followersIds` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/get-followers-ids Group: follows. Billing pe
- `get_base_apitools_followersList` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/get-followers-list Group: follows. Billing p
- `get_base_apitools_follow` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/post-friendships-create Group: follows. Bill
- `get_base_apitools_blueVerifiedFollowersV2` — get blueVerifiedFollowers by V2 Group: follows. Billing per call: 1 Credits.
- `get_base_apitools_uerByIdRestIdV2` — Get userByIdRestId by V2 Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_homeTimeline` — HomeTimeline need your auth_token Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_uerByIdOrNameLookUp` — See details https://developer.x.com/en/docs/twitter-api/v1/accounts-and-users/follow-search-get-users/api-reference/get-users-lookup Group: userTweets. Billing 
- `get_base_apitools_UserArticlesTweets` — Get UserArticlesTweets tweets info Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_userByScreenNameV2` — Get userByScreenName by V2 Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_userLikeV2` — Get userLikeV2 Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_usersByIdRestIds` — Get usersByIdRestIds by V2 Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_userTweetReply` — get user Tweet Reply Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_userTimeline` — Get UserTimeline tweets info (same by userTweetsV2) Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_userTweetsV2` — Get UserTweets by V2 Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_accountAnalytics` — get accountAnalytics Group: userTweets. Billing per call: 1 Credits.
- `get_base_apitools_unlikeV2` — unlike tweet V2 Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_unlikeTweet` — see details https://developer.x.com/en/docs/twitter-api/v1/tweets/post-and-engage/api-reference/post-favorites-destroy Group: Tweets. Billing per call: 1 Credit
- `get_base_apitools_tweetTimeline` — get tweetDetail and reply Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_tweetSimple` — get tweet Brief information Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_tweetReply` — reply to tweet Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_retweetersV2` — Retweeters by V2 Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_retweetersIds` — Returns a collection of up to 100 user IDs belonging to users who have retweeted the Tweet specified by the id parameter. See details https://developer.x.com/en
- `get_base_apitools_quotesV2` — Quotes by V2 Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_mentionsTimeline` — See details https://developer.x.com/en/docs/twitter-api/v1/tweets/timelines/api-reference/get-statuses-mentions_timeline Group: Tweets. Billing per call: 1 Cred
- `get_base_apitools_likeV2` — likeV2 Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_likeTweet` — see details https://developer.x.com/en/docs/twitter-api/v1/tweets/post-and-engage/api-reference/post-favorites-create Group: Tweets. Billing per call: 1 Credits
- `get_base_apitools_highlightsV2` — Highlights Tweets by V2 Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_favoritesList` — See details https://developer.x.com/en/docs/twitter-api/v1/tweets/post-and-engage/api-reference/get-favorites-list Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_favoritersV2` — Favoriters by V2 Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_deleteTweet` — Delete Tweet Group: Tweets. Billing per call: 1 Credits.
- `get_base_apitools_deleteRetweet` — Delete Retweet Group: Tweets. Billing per call: 1 Credits.
- …and 67 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"x-twitter\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.jojapi.com/x\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.jojapi%2Fx-twitter
- Install plan: https://forgeregistry.com/api/v1/packages/com.jojapi%2Fx-twitter/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.jojapi%2Fx-twitter
- HTML page: https://forgeregistry.com/registry/com.jojapi%2Fx-twitter
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
