Skip to content

Read unencrypted X Chat messages in the X MCP guide - #541

Merged
vaulpannx merged 13 commits into
cursor:mainfrom
santiagomed:cursor/xchat-legacy-dms-fe3c
Oct 11, 2026
Merged

vaulpannx merged 13 commits into
cursor:mainfrom
santiagomed:cursor/xchat-legacy-dms-fe3c

Conversation

@santiagomed

@santiagomed santiagomed commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

The X MCP guide now reads X Chat threads that include older unencrypted messages, and decrypt accepts every event.

  • Bump the X plugin to 2.5.2.
  • Drop the encrypted-only framing. Each message has a status of verified, unencrypted, or unverified. An unverified message still includes its text when decryption succeeded. A message that cannot be decrypted has empty text.
  • Fetch signing keys for every sender and group member with get_users_public_keys (up to 100 ids, all versions). The helper takes the entries as returned and skips incomplete ones.
  • A page with result_count: 0 that still has a next_token is not an empty thread. Keep paging until next_token is absent, at least 20 events per page.

Companion PR:


Note

Medium Risk
Updates agent instructions for optional on-disk X Chat key storage and full DM/inbox paging; misimplementation could affect privacy or over-fetch chat data, but the diff is docs and version metadata only.

Overview
Bumps the X Cursor plugin to 2.6.0 and expands the X MCP guide and pricing reference so agents handle X Chat more completely and stop treating chat as always encrypted or billable.

X Chat unlock & keys: Adds a saved key flow (unlock-check with optional --remember-key, forget), including the remember prompt on every PIN secret-request and skipping the PIN when "key_source": "saved". Clone setup now fast-forwards the local xchat-grokbot-helper repo when present.

Reading chats: Agents must page all inbox conversations and both message-request inboxes (get_chat_message_requests), use conversation ids as returned, retry 503s with the same pagination token (up to 3×), and not claim full coverage unless every thread is read to the end. Decrypt guidance covers mixed threads (verified / unencrypted / unverified), richer display text, and signing_keys as {"data":[...]} from batched get_users_public_keys.

Billing copy: Documents that X Chat reads and related chat/key APIs are free for this plugin—no cost estimates or credit gates—and removes GET /2/chat/* from the paid DM pricing list in pricing.md.

Reviewed by Cursor Bugbot for commit e39c24f. Bugbot is set up for automated code reviews on this repo. Configure here.

- Drop the encrypted-only / "classic DMs are a different product"
  framing: decrypt now returns older unencrypted messages like any
  other message, and replies are still always encrypted.
- Drop the hint that empty `data` with `result_count: 0` can mean an
  empty thread, and the advice to keep `max_results` small.
- Never claim all chats were checked unless every thread was read to
  the end.
- Pull an existing xchat-lite clone so boxes pick up helper fixes.
- decrypt returns unencrypted messages marked `unencrypted`, still
  verifies encrypted events strictly, and marks encrypted messages it
  can't verify `unverified`. Tell the owner about both and name the
  senders in `unverified_senders`.
- Before decrypting, collect every sender across the fetched pages plus
  group members and call get_users_public_keys (up to 100 ids per call,
  all key versions). Pass the entries as returned.
- A page with `result_count: 0` that still has a `next_token` is not an
  empty thread: keep paging until `next_token` is absent, with
  `max_results` of at least 20.
Each message still carries a status. Drop the instruction to flag
unencrypted or unverified messages.
Do not estimate cost or check credits for X Chat calls. Page the inbox
and each relevant thread at max_results 100 until next_token is absent.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread third_party/x/skills/x-api-mcp-guide/SKILL.md Outdated
Every time the guide secret-requests the Chat PIN, it asks in the same
prompt whether to remember the X Chat key on this computer, with one
sentence that anyone with access to the computer could then read the
owner's X Chats. The default is no: --remember-key is passed only on a
yes, and the question is never asked at any other time.

Session bootstrap runs unlock-check before asking for the PIN. When the
helper reports key_source "saved", the guide uses the saved key, does
not ask for the PIN, and tells the owner that `forget` removes it.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread third_party/x/skills/x-api-mcp-guide/SKILL.md
Replace "X Chat is free in Grok Bot." in the guide, pricing reference and changelog.
- Read every conversation and both message request inboxes, not only the
  relevant ones. A request carries its latest events and key events;
  page older ones with get_chat_conversation_events. Do not use
  get_chat_message_request, which marks messages as delivered.
- Use conversation ids exactly as returned instead of rebuilding them.
- Retry a chat 503 with the same pagination_token up to 3 times and never
  treat a thread as complete after one.
- Answer from each message's display text and content, and describe the
  helper's readable text and placeholder rows.
- List get_chat_message_requests with the free X Chat calls.
When a saved key no longer matches and no PIN is stored, unlock-check stops because CHAT_PIN is not set, so the PIN request with the remember question applies.
Keep "X Chat is free for this plugin." and add that X Chat reads (GET /2/chat/*) and public key lookups are free everywhere, in Grok Bot and in Cursor, in the cost section, the X Chat section and the pricing reference.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

Bugbot Autofix is ON, but it could not run because the branch was deleted or merged before autofix could start.

Reviewed by Cursor Bugbot for commit 9421ece. Configure here.

Comment thread third_party/x/skills/x-api-mcp-guide/SKILL.md Outdated
Those list events are the prefix get_chat_conversation_events returns,
so collect them only when has_more_events is absent.
@vaulpannx
vaulpannx merged commit 4bf3e08 into cursor:main Oct 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants