Exposes the X API as MCP tools, enabling posting, searching, and managing content on X (formerly Twitter).
Review before connecting
The server requires authorization, so only its authentication surface was graded. Review that posture — and the tools it exposes once authenticated — before connecting.
Scanned 25 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The X API MCP server requires authorization, so its tools were not enumerated during the automated scan. Its published description reads: "Exposes the X API as MCP tools, enabling posting, searching, and managing content on X (formerly Twitter)". It communicates over Streamable HTTP, and requires authorization before its tools can be called. MCPGrade currently rates X API N — the server requires authorization, so only its authentication surface was graded and the tool surface could not be assessed without a valid token. Its most notable finding was "PKCE S256 enforced". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check X API's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add X API to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://api.x.com/mcpStreamable HTTP transport. It requires authorization before its tools can be called. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
The authorization server enforces PKCE with S256.
Zoom integration for meetings, chat, docs, recordings, and AI-generated collaboration content.
Zoom integration for meetings, chat, docs, recordings, and AI-generated collaboration content.
Zoom integration for meetings, chat, docs, recordings, and AI-generated collaboration content.
Creates, updates, assigns, and synchronizes Zoom task workflows for AI agents.
Provides meeting search, recordings, transcripts, summaries, and meeting assets for Zoom Meetings.