Is X Token Login safe?

Low risk

X Token Login writes a user-pasted token into x.com's auth_token session cookie, logging the browser in as that token's owner.

This extension takes a session token you paste into its popup and writes it directly as the auth_token cookie for x.com, then opens x.com already logged in as whoever that token belongs to. It performs no password or MFA check of its own — it only imports and applies a token you already have. It doesn't send the token anywhere; the cookie write happens entirely inside your own browser.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on x.com

    https://x.com/*

  • See the address and title of every tab you have open

    tabs

  • Read and change cookies, including the ones that keep you signed in

    cookies

Updated 30 September 2026amo-2911520