> Source: https://www.trackmedia.app/blog/x-twitter-management-tools · Last updated: 2026-10-06

# Twitter management tools: what to check

Twitter management tools all run on the X API, so its pricing, rate limits and automation rules set what any tool can do. Here is what to check.

*Guides · Published 2026-10-06*

Twitter management tools that post for you all work through the same X API, so you can judge one by five things: how it connects, who pays for API access, how it handles rate limits, whether it follows X's automation rules, and what it admits it cannot do. X's documentation sets those limits for every tool alike.

This guide uses X's own documentation, read on October 6, 2026, and does not name or rank other products. It ends with what TrackMedia's X connector does and does not do, based on its code.

## How do Twitter management tools connect to X?

A tool can post on your behalf with a user token from an OAuth 2.0 flow. X's [Create Posts reference](https://docs.x.com/x-api/posts/create-post) lists OAuth 2.0 user tokens for the endpoint, with the scopes `tweet.read`, `tweet.write` and `users.read`. A tool does not need your password, and X's [Developer Policy](https://docs.x.com/developer-terms/policy) says a service may not store X passwords or ask people for their account credentials.

The same page answers a common question about scheduling. The request body fields it lists include `text`, `media`, `reply`, `poll` and `reply_settings`, but none of them is a time to publish. So a scheduler holds the post itself and sends it at the chosen time. That is why a post scheduled in a third-party tool does not appear in X's own scheduled list, as covered in our guide to [scheduling and editing posts on X](https://www.trackmedia.app/blog/how-to-schedule-and-edit-posts-on-x).

## Who pays for X API access?

X's [pay-per-usage pricing page](https://docs.x.com/x-api/getting-started/pricing) says the X API uses pay-per-usage pricing with no subscriptions. Developers buy credits in the Developer Console, and credits are deducted as requests are made. Prices differ by endpoint, the page says prices are subject to change, and it points to the Developer Console for current rates. The page shows no date of its own, so this guide does not quote dollar amounts. What the page listed on October 6, 2026 is a higher rate for creating a post that contains a URL than for a plain post, which matters if you schedule links.

Two other details on that page matter for a scheduler. A developer can set a spending limit per billing cycle, and when it is reached, requests are blocked until the next cycle. The page also tells developers to add credits before the balance reaches zero to avoid interruptions, and says requests are blocked while a balance is negative. A tool that queues posts for you therefore depends on someone keeping the credits topped up, so ask whether that someone is the vendor or you.

X's Create Posts page adds that quote-posting requires an Enterprise plan and is not available on self-serve (pay-per-use) tiers.

One inconsistency is worth knowing. The Developer Policy still refers to Free, Basic and Pro plans described at developer.x.com, while the pricing page describes only pay-per-usage and Enterprise. We could not reconcile the two, so we do not say which plans a given vendor is on.

## What rate limits does X set for posting?

X's [rate limits page](https://docs.x.com/x-api/fundamentals/rate-limits) lists limits per endpoint, in a window that is usually 15 minutes or 24 hours. It separates per-user limits, which apply to user tokens, from per-app limits. These are the rows that matter for a scheduler:

| Endpoint | Per app | Per user |
| --- | --- | --- |
| POST /2/tweets (create a post) | 10,000 per 24 hours | 100 per 15 minutes |
| DELETE /2/tweets/:id | none listed | 50 per 15 minutes |
| POST /2/media/upload | 50,000 per 24 hours | 500 per 15 minutes |

The page says per-user limits apply with OAuth user tokens and per-app limits apply with an app-only Bearer Token. It does not say how the per-app figure for creating posts applies to posts made with user tokens, so we do not claim it is shared across a vendor's customers. It is still worth asking a vendor how it spreads posts across the day.

When a limit is exceeded, X returns a 429 error until the window resets. X's recovery advice is to read the `x-rate-limit-reset` header and wait until that time. The page also says rate limits and billing are separate: you can be inside the limits and still pay, or hit a limit without extra cost.

## What do X's automation rules allow?

X's [Automation rules](https://help.x.com/en/rules-and-policies/x-automation) page, marked as updated in April 2026, defines automation as accounts or apps that take repeated actions without a person actively performing them. It says you remain responsible for actions taken through your account, including by applications you authorize. These rules affect how you use any tool:

- **No duplicate posting.** You may not post duplicative or substantially similar posts on one account or across multiple accounts you operate. If you run several accounts, vary the text.
- **OAuth is not consent.** A tool may act through your account only if it describes the automated actions, gets your express consent and honors an opt-out. The page says authorizing through OAuth does not by itself count.
- **Posting from outside sources is allowed.** The page allows automated posts based on outside sources such as an RSS feed, if you are authorized to publish that information.
- **Some actions are not allowed.** Automated likes and hiding replies are prohibited, and so is following or adding to lists in bulk. Automated replies need the recipient to opt in first, and AI reply bots need written approval from X.
- **No scripting the website.** The page lists non-API automation, such as scripting the X website, as a violation that may lead to permanent suspension. A tool that asks for your X password is a red flag, because the Developer Policy bars services from requesting it.

The Developer Policy adds a rule for posting tools. Before publishing, a service must show people exactly what will be published, and a service that posts to both itself and X must get permission and explain where the content will go. If you manage several brands, the [guide to managing multiple social media accounts](https://www.trackmedia.app/blog/how-to-manage-multiple-social-media-accounts) covers keeping that text different per account.

## What can a scheduler do on X, and what can it not?

Through the documented API, a scheduler can create a post at a time you chose, attach media, reply in a chain to build a thread, and delete a post. X's Create Posts page says a Post may include up to 4 photos, 1 animated GIF or 1 video, and that a successful upload does not guarantee the media can be attached. Video limits follow the posting user's X Premium or verified status, not the developer's API plan.

Some things sit outside that. Whether a post sent by a third-party service can be edited on X afterward is unclear in X's help pages, which our scheduling guide covers. X also weights characters rather than counting them, so a counter that only measures string length can disagree with X. Our [Twitter character limit guide](https://www.trackmedia.app/blog/twitter-character-limit) shows the weights.

## Five checks before you connect a tool

The figure below turns the sections above into questions you can put to any vendor. A good answer is specific. "We handle X's limits" is not an answer, and "we retry after the reset time X returns" is.

![Table of five checks before connecting a tool to X: connection (OAuth 2.0 user token, never your password), API cost (pay-per-usage credits, add credits before the balance reaches zero), rate limits (100 posts per 15 minutes per user and 10,000 per 24 hours per app for creating posts), automation rules (no duplicative posts, no automated likes, OAuth is not consent), and scope (no send-at field in create-post, quote-posting needs Enterprise), each with a question to ask the vendor.](https://www.trackmedia.app/assets/img/blog/x-twitter-management-tools-fig1.svg)

*Five checks for an X management tool, with what X's documentation says and a question for the vendor.*

## How TrackMedia handles X

TrackMedia connects an X account with OAuth 2.0 and PKCE, requesting the scopes `tweet.read`, `tweet.write`, `users.read`, `media.write` and `offline.access`. Its code notes that X access tokens last about two hours and that `offline.access` lets them renew. By default the connect flow uses a developer app configured on the TrackMedia side, so it does not ask you to register an X developer app.

- **What it publishes.** The connector creates a post with text, up to four images, one GIF or one video, and can send alt text and a reply chain for threads. It sends no scheduling field, because X has none. TrackMedia holds the schedule and publishes at the time you set, as described in [how publishing works](https://www.trackmedia.app/#publish).
- **Repeated text.** If X rejects a post as a duplicate of recent content, the connector reports that reason instead of a generic failure, which matches X's rule against duplicative posts.
- **Analytics are pulled on request.** X bills per read, so TrackMedia does not read X metrics on a schedule. On the [Analytics](https://www.trackmedia.app/#analytics) page, X accounts show as not pulled until you press **Refresh**. Refresh reads the account's follower numbers and recent posts, with likes, replies, reposts and impressions where X returns them, and it has a cooldown.

The limits are as follows. TrackMedia's character counter counts plain text length and does not apply X's weighted counting, so check long posts against X's rules. The connector's create call sends text, media and reply fields only, so it does not set X's `made_with_ai` or `paid_partnership` disclosure fields, and it has no calls for quote posts, edits, likes, follows or Direct Messages. In the web composer, X posts are limited to 280 characters, and a Premium override and thread parts are available only through the API.

If you want one queue for X and your other networks, [start free with TrackMedia](https://go.trackmedia.app/signup).

## How we checked this

We opened each page below in a browser on October 6, 2026. We did not test posting to a live X account, and we did not contact X or any vendor. X changes these pages often, so check the live page before you rely on a figure.

- [X API pay-per-usage pricing and credits](https://docs.x.com/x-api/getting-started/pricing) (docs.x.com): pay-per-usage model, credits, spending limit, advice to add credits before zero, a higher listed rate for posts with a URL (dollar figures deliberately not quoted), Enterprise.
- [X API Rate Limits](https://docs.x.com/x-api/fundamentals/rate-limits) (docs.x.com): per-user and per-app limits, 429 handling, rate limits versus billing, Enterprise limits.
- [Create Posts](https://docs.x.com/x-api/posts/create-post) (docs.x.com): OAuth 2.0 user token and scopes, request body fields, media limits, quote-posting requirement.
- [Automation rules](https://help.x.com/en/rules-and-policies/x-automation) (X Help Center, updated April 2026): the automation rules summarized above.
- [X Developer Policy](https://docs.x.com/developer-terms/policy) (docs.x.com): automation requirements, consent before posting, password rule, plan references.

What we could not verify: which API plans or who pays X's API fees for any specific vendor, whether the Developer Policy's mention of Free, Basic and Pro plans is current, how the per-app posting limit applies to posts made with user tokens, and current prices (the pricing page points to the Developer Console, which we did not open). TrackMedia's behavior comes from its X connector code and analytics code, read the same day.
