Is X Token Login safe?
X Token Login is high risk. Typing a token into the popup and clicking Login makes the extension set the auth_token cookie on x.com to that value, one-year expiry, via the scripting API, then navigate to x.com. This bypasses login: no OAuth, password, or validation.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Popup UI injects arbitrary auth_token cookie directly into x.com
Typing a token into the popup and clicking Login makes the extension set the auth_token cookie on x.com to that value, one-year expiry, via the scripting API, then navigate to x.com.
This bypasses login: no OAuth, password, or validation.
You type a token into the extension popup and click Login.
The extension injects a Login function into your active x.com tab and sets the auth_token cookie to the value you entered.
The cookie is set with domain=x.com, path=/, a one-year expiry, and the Secure flag. The tab is then redirected to https://x.com.
The extension's full source, popup listener and injected function
// Runs when user clicks the Login button in the popup.
// Reads whatever text is in the #token input, then injects the Login()
// function into the currently active tab (which must be open on x.com).
document.querySelector('#submit').addEventListener('click', function () {
const token = document.querySelector('#token').value; // raw user input, unvalidated
chrome.tabs.query({ active: true, currentWindow: true }, function (tabs) {
chrome.scripting.executeScript({
target: { tabId: tabs[0].id },
func: Login, // the function defined below is injected into the x.com page
args: [token] // user-supplied token is passed as an argument
});
});
});// Runs inside the x.com tab, not the popup.
// Sets the auth_token session cookie directly using document.cookie,
// bypassing any OAuth or server-side authentication.
function Login(token) {
const expirationTime = new Date();
expirationTime.setFullYear(expirationTime.getFullYear() + 1); // 1 year from now
// Writes auth_token to the x.com cookie jar:
// domain=x.com → applies to all of x.com
// path=/ → applies to all paths
// Secure → only sent over HTTPS
// expires → session persists for 1 year unless explicitly cleared
document.cookie = `auth_token=${token.replace('"', '')};domain=x.com;path=/;expires=${expirationTime.toUTCString()};Secure`;
window.location.replace('https://x.com'); // navigate to x.com immediately after
}| Field | Value | Why it matters | |
|---|---|---|---|
Cookie name | auth_token | auth_token is the primary session cookie used by x.com to authenticate requests. Overwriting it replaces your existing session. | |
Cookie value | BEHAVIORAL_TEST_TOKEN_XYZ_12345 | Whatever you typed into the popup. No validation is performed, any string is accepted and written. | |
Cookie domain | x.com | Set to x.com, so the cookie is sent to all of x.com. | |
Cookie expiry | Fri, 17 Apr 2027 06:36:51 GMT | Set to one year from the moment of injection. The session persists until the cookie is manually cleared or overwritten. |
Paste this into DevTools on an x.com tab to confirm how the Login function works: it reads the current auth_token cookie before and after a simulated injection, showing that document.cookie is the only mechanism used.
// verify-x-token-login.js
// Reproduces the cookie injection performed by the X Token Login extension.
// Run in DevTools on any x.com tab (you must be on https://x.com or a subdomain).
(function () {
// Helper: read the current auth_token cookie value
function getAuthToken() {
const match = document.cookie.match(/(?:^|;\s*)auth_token=([^;]*)/);
return match ? decodeURIComponent(match[1]) : null;
}
console.log('[BEFORE] auth_token =', getAuthToken());
// This is the exact function the extension injects:
function Login(token) {
var expirationTime = new Date();
expirationTime.setFullYear(expirationTime.getFullYear() + 1);
document.cookie = `auth_token=${token.replace('"', '')};domain=x.com;path=/;expires=${expirationTime.toUTCString()};Secure`;
// NOTE: window.location.replace is intentionally omitted here so you can
// observe the cookie change without a page reload.
}
// Inject a test token (replace with a real token to test actual login)
const testToken = 'VERIFY_TOKEN_12345';
Login(testToken);
console.log('[AFTER] auth_token =', getAuthToken());
console.log('Cookie is now:', document.cookie);
console.log('Observe: auth_token was overwritten without any request to x.com\'s auth endpoint.');
})();
- 1Open Chrome, go to https://x.com.
- 2Open DevTools (F12), Console tab.
- 3Paste this script, press Enter.
- 4Console logs the auth_token value before/after injection.
- 5Check Application > Cookies > https://x.com to confirm it changed.
What it can do
Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on x.com
https://x.com/*
Run its own code inside the pages you visit
scripting