✳ X Prune PRIVATE

ACTIVATE YOUR PRIVATE TOOL

Connect once. Keep control.

Archive review works before setup. Live deletion requires your own X developer app and one allowed account. Never paste passwords, browser cookies or access tokens into this page.

1. Create your X developer app

Open the X developer console ↗. Create an app and enable OAuth 2.0 user authentication with read and write permissions. Choose a web app if you want a confidential client with a Client Secret.

Register this exact callback URL:

https://x-prune.me1978.com/auth/callback

Use https://x-prune.me1978.com as the website URL. This tool requests only tweet.read, users.read and tweet.write. It does not request DMs, email, likes or offline access.

2. Identify your allowed account

The allowlist uses your numeric X user ID, not a changeable username. Open data/account.js from your extracted X archive as text and read account.accountId. Alternatively, after enabling your app, follow X’s OAuth setup and request GET https://api.x.com/2/users/me with a user access token. The returned data.id is your account ID. If you already know the ID, use that. Do not use a third-party account-ID lookup that asks for credentials.

3. Configure Cloudflare

In the x-prune-private Worker, set these variables under Settings → Variables and Secrets:

Keep APP_ORIGIN set to https://x-prune.me1978.com. Sign-in stays disabled until the required settings are present. Changing the encryption key invalidates existing connections.

4. Check X access and cost

Your X app needs access to account lookup, post lookup and post deletion. Verify endpoint access and API costs in your developer account. Start with a small set of tweets created for testing. This tool does not bypass X’s pricing or limits.

What is stored?

Your archive and backup stay in your browser. The backend reads live tweet text from X to verify it, then retains selected IDs, timestamps, text hashes and deletion results. It stores your access token encrypted, with a maximum two-hour connection lifetime. No refresh token is requested.

Job receipts expire after 24 hours; download yours. Disconnect removes stored credentials and attempts to revoke the token at X. An in-flight request may finish after you pause or disconnect. Closing the tab does not pause a confirmed job.

X OAuth instructions ↗ · X deletion API ↗

← Return to your cleanup list