Skip to main content
Glama
MunhoLau

twitter-mcp-secure

by MunhoLau

Twitter MCP Server (Secure Fork)

Security-hardened fork of EnesCinr/twitter-mcp. Fixes sensitive content leakage in stderr logs.

This MCP server allows Clients to interact with X.com (Twitter).

Changes from upstream

  • Core fix: console.error no longer logs tweet content during normal post_tweet / search_tweets operations

  • Residual fix: error handlers sanitized — log only error.message, not the full error object (prevents API response payload leakage on errors)

Related MCP server: x-post-mcp

Security Review

A full security review identified and closed residual log-leak vectors. See PR #1 for details.

Quick Start

  1. Get API keys from Twitter Developer Portal

  2. Add this to Claude Desktop config:

{
  "mcpServers": {
    "twitter-mcp-secure": {
      "command": "node",
      "args": ["build/index.js"],
      "env": {
        "API_KEY": "your_key",
        "API_SECRET_KEY": "your_key",
        "ACCESS_TOKEN": "your_key",
        "ACCESS_TOKEN_SECRET": "your_key"
      }
    }
  }
}
  1. Restart Claude Desktop

Development

git clone https://github.com/MunhoLau/twitter-mcp-secure.git
cd twitter-mcp-secure
npm install && npm run build && npm start

Credit

Forked from EnesCinr/twitter-mcp

License

MIT

A
license - permissive license
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    A minimal MCP server for posting tweets to X (Twitter) via API v2, supporting tweet creation, replies, and quote tweets.
    10
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    MCP server to read X (Twitter) posts, threads, replies, quotes, and search using your own logged-in session, no API key required.
    8
    3
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    MCP server that allows posting, deleting, and reading X (Twitter) tweets using your own browser session cookie, bypassing the official paid API. Includes tools for auth setup, tweet creation, deletion, timeline reading, and regex search.
    1
    MIT

View all related MCP servers

Related MCP Connectors

  • FastMCP server for posting formatted content to X (Twitter) — Tollbooth-monetized, DPYC-native

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

  • Hosted MCP for X/Twitter and Reddit. 12 read-only tools, no API keys, free during beta.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/MunhoLau/twitter-mcp-secure'

If you have feedback or need assistance with the MCP directory API, please join our Discord server