The safe way to let your AI run your X.
One MCP server for Claude Code, Cursor, Codex & Windsurf. Your X token never touches the agent — and every post clears an enforced guardrail before it ships.

Why it's different
Every other "let your AI post" tool has the same flaw: to let an agent post, you paste your X token into a plaintext config right next to an autonomous agent that reads untrusted web pages, issues, and code. One prompt-injection and your account tweets a scam. capx café is the only one that structurally can't be.
Your token never lands on your machine
OAuth completes on a hosted callback; the token lives encrypted in a server-side vault. Your agent holds only a short-lived, revocable session handle.
A deterministic guardrail, at the only door
casserole — a six-layer, non-AI guardrail — runs server-side and checks every post. A blocked post never even decrypts your token. It can't be prompt-injected.
Token, guard & send are one unit
Skip the client and call the server directly — you still hit the guard. The plugin's checks are cosmetic; the server's are load-bearing. The AI writes; casserole decides what ships.
How it works
Your agent can only ask. The token, the guardrail, and the send live together on the server — the one path to X.
↑ the token never crosses back to your machine — a blocked post never even unlocks it.
vs. X's official MCP
X ships a solid hosted MCP for reading X from an agent. For posting, the differences are the whole point:
| Compared feature | XMCP — X's official | capx café |
|---|---|---|
| Your credential | API keys pasted into the client config — right next to the agent | Sealed in a server-side vault — never on your machine |
| Guardrail | None — every call posts instantly | casserole: six deterministic layers, enforced at the only door |
| Scheduling | None — the X API has no scheduled posts | Queued loops that post while your laptop is off |
| X developer account | Required — pay-per-use credits | BYO lane: yours · creator lane: none needed |
| Reading & research | Excellent — 100+ read endpoints | Posting only, by design |
Lives in the agent you already use
One MCP server, every coding agent. Connect X once, then create, schedule & post from inside your session.
Your work becomes your content
capx lives inside a coding agent — so it has what no social scheduler does: your repo, commits, PRs, releases. Skills turn that into posts, automatically, always through the guardrail.
Pick your pour
The creator lane — post through capx's X app, no developer account needed. Opening as a paid beta; join the waitlist and we'll pour when it's ready.
- Includes: 70 posts a month
- Includes: 10 media posts
- Includes: 1 account
- Not included: link posts
- Not included: threads
- Not included: scheduled loops
- Includes: 200 posts a month
- Includes: 25 link posts
- Includes: 10 threads · up to 10 posts each
- Includes: 30 media posts
- Includes: 3 active loops
- Includes: 2 accounts, shared quota
- Includes: 500 posts a month
- Includes: 50 link posts
- Includes: Threads within your post quota
- Includes: 100 media posts
- Includes: Unlimited* loops — up to 21 active
- Includes: 5 accounts, shared quota
Beta pricing · no trials, no lock-in · a thread = up to 10 posts, on every plan · link posts are limited because X bills a URL post ~13× a plain one — we pass that structure through honestly · quotas are per plan, shared across its accounts.
*Quotas are monthly — no daily quota. Gentle anti-spam velocity caps (10 posts/hour · 40/day) protect your account from X's spam enforcement.
Let your agent run your X — safely.
Open source. Self-hostable. Your token, your rules — and a guardrail it can't route around.
capx café