Repository navigation
Read unencrypted X Chat messages in the X MCP guide - #541
Merged
vaulpannx merged 13 commits intoOct 11, 2026
Merged
Conversation
- Drop the encrypted-only / "classic DMs are a different product" framing: decrypt now returns older unencrypted messages like any other message, and replies are still always encrypted. - Drop the hint that empty `data` with `result_count: 0` can mean an empty thread, and the advice to keep `max_results` small. - Never claim all chats were checked unless every thread was read to the end. - Pull an existing xchat-lite clone so boxes pick up helper fixes.
- decrypt returns unencrypted messages marked `unencrypted`, still verifies encrypted events strictly, and marks encrypted messages it can't verify `unverified`. Tell the owner about both and name the senders in `unverified_senders`. - Before decrypting, collect every sender across the fetched pages plus group members and call get_users_public_keys (up to 100 ids per call, all key versions). Pass the entries as returned. - A page with `result_count: 0` that still has a `next_token` is not an empty thread: keep paging until `next_token` is absent, with `max_results` of at least 20.
Each message still carries a status. Drop the instruction to flag unencrypted or unverified messages.
Do not estimate cost or check credits for X Chat calls. Page the inbox and each relevant thread at max_results 100 until next_token is absent.
Every time the guide secret-requests the Chat PIN, it asks in the same prompt whether to remember the X Chat key on this computer, with one sentence that anyone with access to the computer could then read the owner's X Chats. The default is no: --remember-key is passed only on a yes, and the question is never asked at any other time. Session bootstrap runs unlock-check before asking for the PIN. When the helper reports key_source "saved", the guide uses the saved key, does not ask for the PIN, and tells the owner that `forget` removes it.
Replace "X Chat is free in Grok Bot." in the guide, pricing reference and changelog.
- Read every conversation and both message request inboxes, not only the relevant ones. A request carries its latest events and key events; page older ones with get_chat_conversation_events. Do not use get_chat_message_request, which marks messages as delivered. - Use conversation ids exactly as returned instead of rebuilding them. - Retry a chat 503 with the same pagination_token up to 3 times and never treat a thread as complete after one. - Answer from each message's display text and content, and describe the helper's readable text and placeholder rows. - List get_chat_message_requests with the free X Chat calls.
When a saved key no longer matches and no PIN is stored, unlock-check stops because CHAT_PIN is not set, so the PIN request with the remember question applies.
Keep "X Chat is free for this plugin." and add that X Chat reads (GET /2/chat/*) and public key lookups are free everywhere, in Grok Bot and in Cursor, in the cost section, the X Chat section and the pricing reference.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
Bugbot Autofix is ON, but it could not run because the branch was deleted or merged before autofix could start.
Reviewed by Cursor Bugbot for commit 9421ece. Configure here.
Those list events are the prefix get_chat_conversation_events returns, so collect them only when has_more_events is absent.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

The X MCP guide now reads X Chat threads that include older unencrypted messages, and
decryptaccepts every event.statusofverified,unencrypted, orunverified. An unverified message still includes its text when decryption succeeded. A message that cannot be decrypted has empty text.get_users_public_keys(up to 100 ids, all versions). The helper takes the entries as returned and skips incomplete ones.result_count: 0that still has anext_tokenis not an empty thread. Keep paging untilnext_tokenis absent, at least 20 events per page.Companion PR:
Note
Medium Risk
Updates agent instructions for optional on-disk X Chat key storage and full DM/inbox paging; misimplementation could affect privacy or over-fetch chat data, but the diff is docs and version metadata only.
Overview
Bumps the X Cursor plugin to 2.6.0 and expands the X MCP guide and pricing reference so agents handle X Chat more completely and stop treating chat as always encrypted or billable.
X Chat unlock & keys: Adds a saved key flow (
unlock-checkwith optional--remember-key,forget), including the remember prompt on every PIN secret-request and skipping the PIN when"key_source": "saved". Clone setup now fast-forwards the localxchat-grokbot-helperrepo when present.Reading chats: Agents must page all inbox conversations and both message-request inboxes (
get_chat_message_requests), use conversation ids as returned, retry 503s with the same pagination token (up to 3×), and not claim full coverage unless every thread is read to the end. Decrypt guidance covers mixed threads (verified/unencrypted/unverified), richer displaytext, andsigning_keysas{"data":[...]}from batchedget_users_public_keys.Billing copy: Documents that X Chat reads and related chat/key APIs are free for this plugin—no cost estimates or credit gates—and removes
GET /2/chat/*from the paid DM pricing list inpricing.md.Reviewed by Cursor Bugbot for commit e39c24f. Bugbot is set up for automated code reviews on this repo. Configure here.