Because the app is yours, X bills you directly for API usage and the app’s rate limits are
yours alone. OpenCX never sits between you and X’s billing.
Before you start
You need an X account with a verified email and phone number — that account will own the developer app permanently.1. Create the app on X
- Sign in at console.x.com and complete the developer signup.
- Create an app, giving it a name and a description of your support use case.
- Open the app’s User authentication settings and set:
- App type: Web App / Automated App (a confidential client)
- App permissions: Read and write and Direct Messages
- Callback URL: the value OpenCX shows you in the connection dialog
- Website URL: your company site
2. Add credit and a spending limit
X’s API is pay-per-use. In the console, add a payment method and buy credits, then set a spending limit per billing cycle and, optionally, auto-recharge.If your credits run out or your spending limit is reached, X stops accepting messages. OpenCX
surfaces this as a banner on the channel page and marks the affected replies as failed, but the
fix always happens in your X console.
3. Paste the credentials into OpenCX
In OpenCX go to Channels → X (Twitter) → Add app. All four values live on the app’s Keys & Tokens tab on X, split across two blocks:X’s naming is inconsistent: the credential we call API Key / API Key Secret appears in the
console as Consumer Key, filed under a heading that says OAuth 1.0 Keys. Use it anyway —
OpenCX authenticates accounts with OAuth 2.0, but X signs webhooks with the consumer pair, so both
blocks are needed.
- “X rejected these API credentials” — the API Key or Secret is wrong, or was regenerated after you copied it.
- “Your X developer account already has a webhook registered” — X allows one webhook per developer account on pay-per-use. Remove the existing one in the console, or use a separate developer account for OpenCX. OpenCX will never delete a webhook it did not create.
4. Connect your handles
With the app saved, choose Add account and authorize the brand handle on X. You can connect several handles to one app. If the authorization comes back missing a permission, OpenCX refuses the connection and names the missing scope — fix App permissions on X, regenerate, and try again. Direct messages start flowing immediately, and the AI answers according to your autopilot settings for the X channel.5. Public mentions (optional)
Replying publicly when someone mentions your handle is off by default. Turning it on opens a checklist you must confirm, because X places these requirements on the account, not on OpenCX:- The handle has the Automated label enabled (X → Settings → Your account → Account information → Automation).
- The account bio discloses automation, for example “AI support by @yourcompany”.
- You have X’s prior approval to deploy AI-generated replies, requested through the Policy Support form.
Encrypted messages
X moved direct messages to XChat, which is end-to-end encrypted. OpenCX sets up the encryption keys for a connected handle automatically and you will normally never see this step. If the handle already uses XChat (someone set it up in the X app), OpenCX asks you to choose:- Enter the XChat PIN — keeps the handle’s existing encrypted-chat identity.
- Generate new keys — resets encrypted chat for that handle. Earlier encrypted conversations stay unreadable to OpenCX and the X app may ask to set chat up again.