fix(hands): migrate Reddit auth to client_credentials, document Twitter OAuth 1.0a

Reddit:
- Remove REDDIT_USERNAME and REDDIT_PASSWORD requirements (deprecated
  password grant)
- Switch to grant_type=client_credentials (app-only auth)
- Update system_prompt and SKILL.md auth examples

Twitter:
- Add optional OAuth 1.0a credentials (API key/secret, access
  token/secret) for user-context operations
- Document Bearer Token vs OAuth 1.0a authentication modes in SKILL.md
- Note which endpoints require user-context auth
This commit is contained in:
Evan Hu committed 2026-03-22 20:28:16 +09:00
1 parent 8923c4e0c3
commit fb45e39dcb
4 files changed
+94 -43

No files matched your search

+6
View File
@@ -19,6 +19,12 @@ Authorization: Bearer $TWITTER_BEARER_TOKEN
**Environment variable**: `TWITTER_BEARER_TOKEN`
**Authentication modes**:
- **Bearer Token only** (default): Sufficient for posting tweets, reading timelines, and searching. All core functionality works with just the Bearer Token.
- **Bearer Token + OAuth 1.0a** (optional): Required for user-context operations such as liking tweets, retweeting, following/unfollowing, and accessing DMs. Set `TWITTER_API_KEY`, `TWITTER_API_SECRET`, `TWITTER_ACCESS_TOKEN`, and `TWITTER_ACCESS_TOKEN_SECRET` to enable these features.
> **Note**: The Like endpoint (`POST /2/users/:id/likes`) and Retweet endpoint (`POST /2/users/:id/retweets`) require OAuth 1.0a User Context authentication. If only Bearer Token is configured, these operations will be skipped with a warning.
### Core Endpoints
**Get authenticated user info**: