Skip to main content
Xquik is a hosted service for tweet search, follower exports, profile lookup, monitors, webhooks, and X account actions. You interact through the REST API, MCP server, SDKs, or dashboard. You do not deploy Xquik infrastructure or configure X API credentials.

Architecture overview

Components

REST API

Documented operations at https://xquik.com/api/v1/* for apps, backends, scripts, and fine-grained pagination.

MCP server

3 tools, docs, search, and execute, at https://xquik.com/mcp for ChatGPT, Claude, Cursor, and agent workflows.

Dashboard

Manage API keys, connected X accounts, monitors, extractions, draws, webhooks, media, billing, and support.

Monitoring & webhooks

Track accounts or keywords, store events, and deliver HMAC-signed webhook payloads with retry history.

Extractions & draws

Run stored jobs for followers, replies, quotes, retweeters, favoriters, search, articles, and giveaway draws.

Write actions

Post tweets and replies, upload media, send DMs, follow, like, retweet, update profiles, and poll write status.
See integration workflows for end-to-end code examples using these components.

Security model

Authentication

Xquik REST uses API key authentication. API MCP accepts OAuth 2.1 or an Xquik API key when the client supports secure request headers. ChatGPT custom apps require OAuth and cannot present custom API keys.

API header

Send x-api-key on every REST API request. MCP clients can authenticate with the same Xquik API key.

Key format

Keys start with xq_ followed by 64 hex characters. The dashboard shows the full key only once.

One-time display

Xquik returns the full key only during creation. Store it in a secret manager.

Revocation

Revoked or inactive keys stop authenticating immediately and return 401.

Audit trail

Account audit views show API-key activity.

OAuth 2.1

MCP also supports OAuth 2.1 with S256 PKCE for clients that require delegated authorization.

Key management

Create and revoke keys through the authenticated dashboard.
Xquik shows API keys once at creation. Store them in a secret manager. You cannot retrieve a key after creation.

Data isolation

Every API key belongs to a single user account. No key can read another user’s data.

Monitors

Account and keyword monitors belong to the user account that created them.

Events

Stored events resolve through account or keyword monitor ownership before returning data.

Webhooks

Webhook endpoints, signing configuration, and delivery logs belong to one user.

Extractions

Extraction jobs, result pages, and exports belong to the user that created the job.

Draws

Giveaway draws, entries, and winner lists belong to the user that created the draw.

API keys

API-key listing, creation, and revocation filter by the authenticated user ID.
A request for another user’s resource returns 404 Not Found, not 403. Attackers cannot use the response to enumerate IDs.

Authorization

Xquik uses a flat permission model. It has no roles, no RBAC, and no team workspaces.
  • One user, one account. Each account has full access to all its own resources
  • API key scope. A valid account API key can perform API-key-authorized operations for that account
  • API key management. Listing, creating, and revoking keys require a same-origin dashboard session. API keys and OAuth bearer tokens cannot manage keys
  • Credit gates. Creating extractions, draws, active monitors, media downloads, and X lookups require enough available credits. All webhook operations are free. Reading and managing stored jobs, monitors, and events is free. Active monitors cost 21 credits per hour.

Rate limits

Xquik enforces rate limits per user account with a fixed-window counter algorithm. Each tier has an independent counter. Read counters reset every 1 second. Write and delete counters reset every 60 seconds.

Read bucket

GET, HEAD, and OPTIONS share a standard user limit of 500 requests per 1 second.

Write bucket

POST, PUT, and PATCH share a standard user limit of 120 requests per 60 seconds.

Delete bucket

DELETE requests have a limit of 60 requests per 60 seconds.

Retry window

Throttled reads return Retry-After: 1. Throttled writes and deletes return Retry-After: 60.
When you reach the limit, requests return 429 Too Many Requests with a Retry-After header. Read throttles return Retry-After: 1. Write and delete throttles return Retry-After: 60. See the Rate Limits guide for detailed explanations, backoff strategies, and client-side rate limiter code examples.

Usage & billing

Subscriptions

Starter, Pro, and Business plans run from USD 20 to USD 199 per month and include monthly credits.

Active monitors

Monitor slots are unlimited. Active monitors check every 1 second and cost 21 credits per active monitor-hour.

Credit top-ups

Top up from USD 10. Credits cost USD 0.00015 each. See Billing & Usage.

What counts as usage

Credit-metered work

Paid X reads, media downloads, trends, extraction estimates, extraction creation, monitor creation, active monitor hours, and draw execution can consume credits.

Credit access

Tweet search, user and follower lookup, article lookup, media download, trends, draw creation, and publish actions require enough available credits.

Free management paths

List, read, update, delete, export, test, and delivery-history paths stay free for draws, extractions, monitors, events, and webhooks.

Free utilities

Compose, cached styles, drafts, radar, account, API keys, X accounts, support, credit balance, and credit top-up endpoints are free.
See Billing & Usage for credit costs and billing.

Monitoring architecture

Xquik checks active account and keyword monitors every second.

Event types

Account monitors emit 10 tweet and 11 profile event types. Keyword monitors emit tweet types only.

Signed delivery

Xquik sends an HMAC-SHA256 signed HTTPS POST to each active webhook endpoint. Verify X-Xquik-Signature, X-Xquik-Timestamp, and X-Xquik-Nonce.

Retry schedule

Failed deliveries retry until your endpoint returns 2xx. A failing endpoint gets 1 retry at a time, at least every 15 minutes. A rejected delivery can delay new events by up to 15 minutes. Return 2xx for events you skip.

Receiver timeout

Webhook receivers should return 2xx within 10 seconds. Xquik records slow or non-2xx responses as failed attempts.

Event propagation

Events usually appear within seconds to minutes, depending on X stream timing and webhook receiver availability.

Platform limitations

Bookmarked tweets

Bookmarks and bookmark folders require a connected X account. Use bookmarks and bookmark folders.

Export caps

Extraction exports stop at 100,000 rows. PDF exports stop at 10,000 rows. Supported formats: CSV, JSON, MD, MD Document, PDF, TXT, and XLSX.

Webhook retries

Webhook deliveries have no attempt limit. Xquik retries each failure until it succeeds. Only you can pause or delete a webhook. Xquik keeps queued events until all deliveries finish. Events expire 30 days after Xquik creates them.

Monitor slots

Monitor slots are unlimited. Active monitors check every 1 second and cost 21 credits per active monitor-hour.

Next steps

Quickstart

Make your first API call.

Authentication

API key format, header requirements, and dual auth.

Rate limits

Fixed-window limits, backoff strategies, and code examples.

Billing & usage

Pricing, credit allowances, and billing.