> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xquik.com/llms.txt
> Use this file to discover all available pages before exploring further.

# X account reauthentication API & login recovery

> Restore a connected X account with its current password. Xquik reuses the saved Authenticator App TOTP secret unless you send a replacement. The call is free.

<Panel>
  <Tabs defaultTabIndex={0} sync={false}>
    <Tab title="200" id="response-x-accounts-reauth-200">
      ```json theme={null}
      {
        "id": "42",
        "xUserId": "9876543210",
        "xUsername": "elonmusk",
        "status": "active",
        "health": "healthy",
        "createdAt": "2025-01-15T12:00:00Z"
      }
      ```
    </Tab>

    <Tab title="400" id="response-x-accounts-reauth-400">
      ```json theme={null}
      {
        "error": "invalid_input",
        "message": "Invalid input. Check the request body."
      }
      ```
    </Tab>

    <Tab title="401" id="response-x-accounts-reauth-401">
      ```json theme={null}
      {
        "error": "unauthenticated",
        "message": "Authentication required. Provide a valid API key or bearer token."
      }
      ```
    </Tab>

    <Tab title="404" id="response-x-accounts-reauth-404">
      ```json theme={null}
      {
        "error": "account_not_found",
        "message": "X account not found."
      }
      ```
    </Tab>

    <Tab title="422" id="response-x-accounts-reauth-422">
      ```json theme={null}
      {
        "error": "login_failed",
        "message": "Login failed. Check credentials and try again."
      }
      ```
    </Tab>

    <Tab title="429" id="response-x-accounts-reauth-429">
      ```json theme={null}
      {
        "error": "login_cooldown",
        "message": "Login is temporarily paused"
      }
      ```
    </Tab>

    <Tab title="503" id="response-x-accounts-reauth-503">
      ```json theme={null}
      {
        "error": "service_unavailable",
        "message": "Service temporarily unavailable. Try again later."
      }
      ```
    </Tab>
  </Tabs>
</Panel>

<blockquote className="agent-llms-directive">
  For the complete documentation index, see <a href="/llms.txt">llms.txt</a>.
</blockquote>

<Callout icon="circle-check" color="#16a34a">
  **Free.** This endpoint does not consume credits.
</Callout>

<Note>
  Use this when an account session expires or X requires re-verification.
</Note>

Omit `totp_secret` to reuse the saved key. Send a replacement only if X
changed or rejected the saved key.

Re-authentication does not guarantee the same public IP. Xquik does not support custom,
dedicated, or user-supplied proxies.

<CodeGroup>
  ```bash cURL theme={null}
  curl -X POST https://xquik.com/api/v1/x/accounts/3/reauth \
    -H "x-api-key: xq_YOUR_KEY_HERE" \
    -H "Content-Type: application/json" \
    -d '{
      "password": "<ACCOUNT_PASSWORD>"
    }' | jq
  ```

  ```javascript Node.js theme={null}
  const accountId = "3";
  const response = await fetch(`https://xquik.com/api/v1/x/accounts/${accountId}/reauth`, {
    method: "POST",
    headers: {
      "x-api-key": "xq_YOUR_KEY_HERE",
      "Content-Type": "application/json",
    },
    body: JSON.stringify({
      password: "<ACCOUNT_PASSWORD>",
    }),
  });
  const data = await response.json();
  ```

  ```python Python theme={null}
  import requests

  account_id = "3"
  response = requests.post(
      f"https://xquik.com/api/v1/x/accounts/{account_id}/reauth",
      headers={"x-api-key": "xq_YOUR_KEY_HERE"},
      json={
          "password": "<ACCOUNT_PASSWORD>",
      },
  )
  data = response.json()
  ```

  ```go Go theme={null}
  package main

  import (
      "bytes"
      "encoding/json"
      "fmt"
      "net/http"
  )

  func main() {
      body, _ := json.Marshal(map[string]interface{}{
          "password": "<ACCOUNT_PASSWORD>",
      })

      accountID := "3"
      req, err := http.NewRequest("POST", "https://xquik.com/api/v1/x/accounts/"+accountID+"/reauth", bytes.NewReader(body))
      if err != nil {
          panic(err)
      }
      req.Header.Set("x-api-key", "xq_YOUR_KEY_HERE")
      req.Header.Set("Content-Type", "application/json")

      resp, err := http.DefaultClient.Do(req)
      if err != nil {
          panic(err)
      }
      defer resp.Body.Close()

      var data map[string]interface{}
      if err := json.NewDecoder(resp.Body).Decode(&data); err != nil {
          panic(err)
      }
      fmt.Println(data)
  }
  ```
</CodeGroup>

<Accordion title="Replace the saved TOTP secret">
  Send `totp_secret` only when the saved key no longer works.

  ```bash cURL theme={null}
  curl -X POST https://xquik.com/api/v1/x/accounts/3/reauth \
    -H "x-api-key: xq_YOUR_KEY_HERE" \
    -H "Content-Type: application/json" \
    -d '{
      "password": "<ACCOUNT_PASSWORD>",
      "totp_secret": "<REPLACEMENT_TOTP_SECRET>"
    }' | jq
  ```
</Accordion>

| X account recovery column | Request or response source | Recovery rule |
| - | - | - |
| Account ID | Path `{id}` and response `id` | Require both IDs to match. |
| Current password | Request `password` | Send it only to this reauthentication request. |
| Saved TOTP key | Omitted `totp_secret` | Reuse the stored authenticator secret. |
| Replacement TOTP key | Request `totp_secret` | Send the base32 key, never a 6-digit code. |
| X username | Response `xUsername` | Confirm the recovered profile. |
| X user ID | Response `xUserId` | Store it. It stays the same when the username changes. |
| Account state | Response `status` | Require `active` before write actions. |
| Login health | Response `health` | Require `healthy` before durable actions. |

## Path parameters

<ParamField path="id" type="string" required>
  The unique account ID.
</ParamField>

## Headers

<ParamField header="x-api-key" type="string" required>
  Your API key. Session cookie authentication is also supported. Generate a key from the [dashboard](https://xquik.com/dashboard).
</ParamField>

<ParamField header="Content-Type" type="string" required>
  Must be `application/json`.
</ParamField>

## Body

<ParamField body="password" type="string" required>
  Current password for the X account.
</ParamField>

<ParamField body="totp_secret" type="string">
  Replacement Authenticator App TOTP secret. Omit it to reuse the saved key.
  Send the base32 secret, not the 6-digit code.
</ParamField>

<ParamField body="email" type="string">
  Email for the X account. Updates the stored email during re-authentication.
</ParamField>

## 2FA re-authentication

Xquik reuses the saved TOTP secret by default. Send `totp_secret` only when
replacing that key. Never send a 6-digit code, backup code, passkey, or security
key prompt.

If you never saved the secret key, or X rejects the current one, reset the authenticator app setup before re-authenticating:

<CardGroup cols={1}>
  <Card title="Saved key still works" icon="clipboard-check">
    Omit `totp_secret`. Xquik reuses the encrypted key saved during connection.
  </Card>

  <Card title="Key is missing" icon="rotate-ccw">
    X shows the text secret only during Authentication App setup. Turn Authentication App off, then on again. Copy the new key, then finish setup on X.
  </Card>

  <Card title="Key was rejected" icon="triangle-alert">
    Treat the old TOTP secret as stale. Reset Authentication App setup on X and save the new long key. Finish 2FA confirmation, then re-authenticate.
  </Card>
</CardGroup>

1. Open X **Settings and Privacy > Security and Account Access > Security**.
2. Open **Two-Step Verification > Authentication App**.
3. Turn Authentication App off, then turn it on again.
4. When the QR code appears, choose **Can't scan the QR code?** to reveal the text secret.
5. Copy the long secret key and store it in a password manager before leaving the setup screen.
6. Add that key to your authenticator app if you are setting it up fresh.
7. Finish enabling 2FA on X by entering the current 6-digit code from your authenticator app.
8. Send the new long key in `totp_secret` when you call Xquik.

<Warning>
  Finish the X-side 2FA confirmation after copying the secret key. If you abandon setup before confirmation, re-authentication cannot use that key.
</Warning>

<Note>
  See [2FA secret key setup](/api-reference/x-accounts/connect#2fa-secret-key-setup) for the full connection checklist.
</Note>

## Response

### 200 OK

<ResponseField name="id" type="string">Account ID.</ResponseField>
<ResponseField name="xUsername" type="string">X username.</ResponseField>
<ResponseField name="xUserId" type="string">X user ID.</ResponseField>
<ResponseField name="status" type="string">Account status (for example `active`).</ResponseField>
<ResponseField name="health" type="string">Derived login and cookie health. One of `healthy`, `locked`, `needsReauth`, `recovering`, `suspended`, `temporaryIssue`. See [Account health](/api-reference/x-accounts/list#account-health) for meanings.</ResponseField>
<ResponseField name="createdAt" type="string">ISO 8601 creation timestamp.</ResponseField>

```json theme={null}
{
  "id": "3",
  "xUsername": "elonmusk",
  "xUserId": "44196397",
  "status": "active",
  "health": "healthy",
  "createdAt": "2026-02-20T08:15:00.000Z"
}
```

### 400 Invalid input

```json theme={null}
{ "error": "invalid_input", "message": "Missing required password field" }
```

Missing `password` field or invalid format.

```json theme={null}
{ "error": "invalid_id", "message": "Invalid account ID format" }
```

The provided account ID is not a valid format.

### 401 Unauthenticated

```json theme={null}
{ "error": "unauthenticated", "message": "Missing or invalid API key" }
```

Missing or invalid API key.

### 404 Not found

```json theme={null}
{ "error": "account_not_found", "message": "X account not found." }
```

No account exists with this ID, or it belongs to a different Xquik account.

### 429 Login cooldown

```json theme={null}
{
  "error": "login_cooldown",
  "message": "Login is temporarily paused",
  "reason": "automated",
  "retryAfterMs": 3600000
}
```

A prior login attempt triggered a cooldown (for example, X flagged the session). Wait for `retryAfterMs` before retrying. The response includes a `Retry-After` header in seconds.

### 429 Rate limited

```json theme={null}
{
  "error": "rate_limit_exceeded",
  "message": "Too many requests. Try again later.",
  "retryAfter": 60
}
```

Wait for the `Retry-After` value before starting another re-authentication request.

### 422 Login failed

```json theme={null}
{ "error": "login_failed", "message": "Login failed. Check credentials and try again." }
```

X rejected the submitted password or TOTP secret. Retry with the current password and the saved Authenticator App secret key, not a 6-digit code.

```json theme={null}
{
  "error": "passkey_required",
  "message": "X asked this account to sign in with a passkey. Delete the passkey in X's security settings, keep Authentication app 2FA, then try again."
}
```

X showed this account a passkey sign-in, which Xquik can't complete. Delete the passkey in X **Settings and Privacy > Security and Account Access > Security > Passkey**, keep Authenticator App 2FA on, then re-authenticate.

### 503 Service unavailable

```json theme={null}
{ "error": "service_unavailable", "message": "Service temporarily unavailable. Try again." }
```

The X re-authentication service is temporarily unavailable. Retry after a short delay.

<Note>
  **Related.** [Get X Account](/api-reference/x-accounts/get) to check account status, or [Connect X Account](/api-reference/x-accounts/connect) if you need to add a new account instead.
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.