X
Connect X to your Workspace to publish posts and threads, keep an eye on mentions and conversations, search recent posts, and send direct messages — all as your own X account.
What Luo can do
- Post — publish posts, threads, polls, and posts with images, GIFs, or video, and control who can reply
- Delete — remove posts made by the connected account
- Repost — repost a post, or undo a repost
- Read — specific posts, any account’s recent posts, and the connected account’s mentions, with full text for long posts
- Search — public posts from the last 7 days, using X search operators (e.g.
from:yourbrand -is:retweet,"exact phrase" lang:en,has:media) - Look up accounts — profile, bio, and follower counts by handle
- Direct messages — send DMs (text and media) and read recent DMs, across all conversations or with one person
Luo asks for your confirmation before it posts, reposts, sends a direct message, or deletes a post. You can choose to always allow an action — for posts and reposts that covers every future one; for direct messages, only that recipient; for deletes, only that post.
What Luo can’t do
X only offers some features to its most expensive API tier, so Luo can’t like posts, follow accounts, or create quote posts. Bookmarks and full-archive search (older than 7 days) aren’t supported either.
Replies to other people’s posts only work when that person mentioned or quoted your account — X blocks other API replies. Replies within your own threads always work.
Before you start: costs
X charges for API usage per call. You pay X directly, from your own developer account — nothing goes through Luo.
- Every post Luo publishes and every post, account, or message Luo reads is billed to your developer account’s credits.
- Posts containing a link cost noticeably more than plain posts (over ten times as much at the time of writing).
- Check current prices and add credits in the X Developer Console. Setting a monthly spending cap there is a good idea.
How to connect
You’ll create an app in the X Developer Console and paste four keys from it into Luo.
Sign up with the X account you want Luo to act as. The keys you generate belong to the account that owns the developer account. Luo posts, reposts, and sends DMs as that account, and there’s no way to switch to a different account later. To post as your company’s brand account, log in to X as the brand account before you open the Developer Console.
1. Create your developer account and app
- Log in to x.com as the account Luo should act as.
- Open the X Developer Console at console.x.com and sign up for a developer account. Choose the pay-per-use option and add some credits.
- Create an app (e.g. Luo). It’s created inside your default project.
2. Set the app’s permissions
This step must come before you generate the Access Token. X stamps the permissions onto the token when it’s created, so a token generated before this step stays read-only and posting fails.
- Open your app and go to the Keys & Tokens tab.
- Under User authentication settings, click Set up.
- Set App permissions to Read and write and Direct message.
- For Type of App, choose Web App, Automated App or Bot.
-
Fill in Callback URI / Redirect URL and Website URL — X requires both, but Luo doesn’t use them. Your company website works for both, e.g.:
https://luo.app - Click Save.
3. Generate the keys
X shows each secret only once, right after you generate it. Copy each value as it appears — if you lose one, regenerate it.
On the Keys & Tokens tab:
- Next to Consumer Key, click Regenerate and copy the API Key and API Key Secret.
- Next to Access Token, click Generate and copy the Access Token and Access Token Secret.
Check that the Access Token row now says For @youraccount with Read and write and Direct message. If it only says Read, go back to step 2, then generate the Access Token again.
4. Connect X in Luo
- Open your workspace in Luo, go to Settings → Integrations, and click Add Integration.
- Select X.
- Choose to connect as a user integration (your personal connection) or a workspace integration (shared across members).
- Paste the four values from step 3:
- API Key (Consumer Key)
- API Key Secret
- Access Token
- Access Token Secret
- Click Create Integration. Luo checks the keys with X and shows the connected account’s name and handle.
Troubleshooting
- “X rejected the connected keys” — one of the four values is wrong or was regenerated after you copied it. Regenerating any key invalidates the old one; copy the current values and reconnect.
- “The connected Access Token lacks permission” — the token was generated before the app had Read and write and Direct message permission. Fix the permissions (step 2), generate a new Access Token, and reconnect.
- “Credits depleted” or “spending cap” — add credits or raise your cap in the X Developer Console.
- “Duplicate of a recent post” — X rejects text identical to a recent post. Vary recurring or scheduled posts.
- Rate limits — X limits how often each feature can be used. Direct messages are the tightest (about 15 reads per 15 minutes). Luo retries short waits automatically and tells you when a longer limit resets.
Privacy and data handling
Your keys only authorize your own app on your own account, and Luo stores them encrypted. Posts and messages from other people that Luo reads are treated as untrusted content — the assistant won’t follow instructions found in them. Data flowing through Luo is governed by Luo’s security and privacy practices.
To revoke access, regenerate the Access Token (or the Consumer Key) in the X Developer Console — the old keys stop working immediately. Then remove the integration in Luo.