CONNECTING YOUR ACCOUNTS

X (Twitter)

Two ways to connect X: Managed X uses SocFlow's own developer app — one click, included on Pro/Business, billed pay-per-use against your spend caps. Bringing your own X Developer App gives you a dedicated rate limit and lets X bill you directly instead.

Which one do I need?

On the Free plan, or on a self-host-priced Pro/Business subscription, Managed X isn't available — connecting X always uses your own developer app. On a standard (non-self-host) Pro or Business subscription, either path works; pick Managed X to skip setup entirely, or bring your own app for a rate limit and API cost that's isolated to your account. Both paths reach the same set of actions — which actions X allows (see below) doesn't change based on which app owns the connection.

The steps below are only needed if you're bringing your own app — Managed X connects in one click from the Accounts page with no setup.

App portal: developer.x.com · App type: Web App, Automated App or Bot (confidential client)

Callback / redirect URL

https://actions.socflow.io/oauth/twitter/callback
  1. 1Sign in at developer.x.com and apply for a developer account if you don't have one yet — the free tier is enough.
  2. 2Create a Project, then create an App inside it.
  3. 3Open the app's “User authentication settings” and turn on OAuth 2.0.
  4. 4Set App permissions to Read and Write (add Direct Messages too if you plan to use DM actions).
  5. 5Set Type of App to “Web App, Automated App or Bot” — this is the confidential client type; SocFlow needs the client secret, so a public/native app type won't work.
  6. 6Paste the callback URL below as the Callback URI / Redirect URL, and any valid URL as the Website URL.
  7. 7Save, then open “Keys and tokens” → OAuth 2.0 Client ID and Client Secret — generate/reveal them.
  8. 8Copy both into SocFlow's connect dialog for this account.

What this permission grants

Read + Write lets SocFlow read your timeline/mentions and post replies or standalone tweets on your behalf, only through rules you create. Adding Direct Messages scope additionally allows DM actions. Nothing is posted or sent unless a rule you built matches and fires.

Actions X doesn't allow, on either connection path

Like, DM, follow/unfollow, and block actions aren't offered for X — automated likes are banned outright by X's own automation rules, DMs need a consent signal no trigger can establish, and follow/unfollow/ block were removed from every self-serve API tier in 2026 (Enterprise-only now). None of this changes whether you're on Managed X or your own developer app — it's an X platform restriction, not an app-tier one.

Reply/quote actions have a mention restriction

A reply action can only post to a tweet that mentions your connected account or that your account posted itself — this is a permanent X API rule, not something a higher-tier or paid developer app lifts. Rules built on triggers like Keyword match or Someone quotes my tweet — where the target tweet may not mention you — will always fail with a 403 from X. Rules built on Someone mentions me always work, since the target tweet mentions you by definition.

Rule actions also include a standalone “New post” action (publishes a fresh tweet, not a reply — useful for keyword-triggered promo posts where replying isn't valid). It works with the same Read and Write permission above — no extra scope needed.