X
Connect X so Ashley can draft a post, generate the images, and publish it when you tap Publish - with up to 4 media. Unyo deliberately never asks for DM, follow or like permissions.
Esta página aún no está disponible en tu idioma, mostramos la versión en inglés.
Connect X and Ashley, your social media agent, can write the post, generate the image, and hand you a finished draft card. You read it, edit it, and tap Publish. Nothing goes out before that tap.
The permissions we deliberately did not ask for
Unyo asks X only for permission to post and upload media - no DM, follow or like access. We do not request dm.write, follows.write or like.write. Unyo cannot read or send your DMs, cannot follow or unfollow anyone, and cannot like a single post. Those permissions aren't turned off in a settings screen - they were never requested, so the token X gives us physically cannot do it.
What connecting X unlocks
Publishing to X is Ashley's territory. No other agent can post to it.
| You ask | You get |
|---|---|
| "Write me an X post about our new pricing" | An editable draft card: the post text, hashtags, a generated image, and platform toggles |
| "Make 3 posts to launch the collection" | A reviewable stack of drafts, each editable on its own ("change the text of post 2") |
| "Make the image brighter" / "I don't like it, redo it" | The image is edited or replaced in place, by talking |
| "Add my logo" | Ashley pulls your real brand kit from the Neural Core and overlays it |
| "What are my X stats?" | Followers and growth, following, total posts, listed count - from X's own API |
| "What's scheduled?" | Your upcoming queue with times, platforms and text previews |
One draft, four platforms. The same card can go to X, Instagram, a Facebook Page and LinkedIn at once - each through its own correct API flow, all in parallel. If LinkedIn fails, your X post still lands, and the job reports exactly what worked with a real permalink.
The X specifics, honestly
- Up to 4 images per post. That's X's limit and Unyo enforces it. The editor itself stays generous (10 images) so the same draft can also feed Instagram - the X publisher uploads the first 4.
- 280 characters. The composer shows a live count against X's real limit. If the text still exceeds 280 at publish time, Unyo truncates it rather than failing the post - so check the counter before you tap.
- 3 hashtags. When you ask Ashley for hashtag research, she reports X's practical limit as 3 and ranks your own proven tags accordingly - not a generic benchmark list.
Ashley draws the brief. Tyron paints.
Ashley cannot call the image tools directly - that's Tyron's toolbox, and it's blocked for her at the runtime level, not just in her prompt. She writes the visual brief and the image is generated for her. You just see one finished card.
Connect X
- Open Integrations from the sidebar. (It's its own page - not inside Settings.)
- Find X under the Social filter and click Connect.
- Sign in to X and authorise Unyo. Read the permission list - it should be short.
- You land back on Integrations with your @handle shown on the card. That's how you know which account you're posting as.
If an agent needs X mid-conversation and you haven't connected it, you'll get a Connect link that takes you straight into the flow - and lands you back in the same conversation afterwards.
Permissions - what we ask for, and what we refuse
| Scope | What it lets Unyo do, in plain English |
|---|---|
tweet.write | Publish the post you approved on the card. Nothing else writes to your timeline. |
media.write | Upload the images attached to that post (up to 4). |
tweet.read | Read your own posts, so your stats and history are real numbers. |
users.read | Read your handle and profile, so the card can show you which account you're about to post as. |
offline.access | Keep the connection alive without making you re-authorise every few hours. |
Deliberately not requested:
| Scope | Why we refuse it |
|---|---|
dm.write | Unyo has no business in your direct messages. |
follows.write | We will never follow or unfollow anyone on your behalf. Growth-hacking is not a feature. |
like.write | Your likes are yours. An AI liking things as you is a lie about you. |
That's the whole grant. Five scopes to write one post with pictures.
What Unyo does with your data
- Your access token is encrypted at rest. As of 16 July 2026, a live cipher-byte-level check confirmed that 17 of 17 populated OAuth token columns across the platform are AES-256 encrypted. Zero plaintext tokens exist. The master key is unreachable by any client role.
- The token is never logged, never put in a queue payload, never returned inside an error message. It's resolved for the length of one outbound call to X and then gone.
- No training. Every model Unyo uses runs under a no-training guarantee. Your posts, your images and your numbers are used to do the job you asked for, and nothing else.
- Row-level security on every table. 100% coverage - 109 of 109 public tables, 291 policies, verified live 16 July 2026.
- Independent audit. A CASA Tier 2 dynamic security test (TAC Security, 6 May 2026) returned 0 Critical, 0 High, 0 Medium.
Publishing is always yours
There is no autonomous posting in Unyo. When Ashley runs unattended - inside an automation - she is hard-coded to prepare the draft and stop. She never publishes or schedules on her own. And nothing publishes by voice either: you can dictate the post, but you tap the card to send it.
Try it
Write me an X post announcing that our summer collection is live. Keep it under 280 characters, add an image, and 3 hashtags.
Scheduling
Schedule from the draft card, not from the chat: open the card, pick a date and time in your timezone, and confirm. The post is queued as a real job and published within the minute of its due time.
Once it's queued, you can talk to it: "what's scheduled?", "move Friday's post to 10am", "cancel the scheduled post" - Ashley reads, reschedules and cancels real jobs, and only ever your own.
Publishing is idempotent by design: a fingerprint of the content is the job key. Click Publish twice, or retry on a flaky connection, and you get the same job back. You will not double-post.
FAQ
Will Ashley post to X without me?
No. There is no unattended publishing anywhere in Unyo - not from chat, not from an automation, not by voice. Ashley prepares the draft; you tap Publish. An automation running at 7am can have a finished X post waiting for you, but it will still be waiting.
Can Unyo read or send my DMs?
No. We never requested the DM permission. It isn't a toggle we left off - it's a scope that was never in the grant, so the token X issues to Unyo cannot open a DM at all.
Can I see how individual posts performed on X?
Not per post. Unyo gives you account-level numbers on X - followers and growth, following, total posts, listed count - because X's API doesn't expose per-post metrics to us the way Instagram's and Facebook's do. Per-post likes, reach and saves are available for Instagram and Facebook. We'd rather tell you that than invent a number.
How many images can I attach?
Four. The Unyo editor lets you build up to 10 because the same draft may also be going to Instagram as a carousel, but the X publisher uploads the first 4 - that's X's limit, not ours.
What happens if my post is over 280 characters?
Unyo truncates it at publish time rather than dropping the post. The composer shows a live character count against X's 280 limit, so the fix is to watch the counter - or just tell Ashley to shorten it.
Does connecting X give any other agent access to it?
No. Each of the 10 agents has a toolbox enforced at runtime, not merely suggested in a prompt. Only Ashley can publish socially, and only Maya can touch your inbox. The boundary is access control, not etiquette.
Disconnecting and revoking
Open Integrations, find the X card, and click Disconnect. Unyo deletes the stored connection and its encrypted token immediately - no agent can post as you after that.
To revoke Unyo at X itself, go to X → Settings and privacy → Security and account access → Apps and sessions → Connected apps and revoke Unyo there. We're telling you this rather than claiming disconnecting does it for you.
If you delete your Unyo account entirely, the deletion flow revokes every provider grant that offers an API for it, takes any published sites offline, and purges roughly 80 tables atomically - and it completes even if a provider is unreachable.
Troubleshooting
The card says "Reconnect required" / a publish failed with a token error. X access tokens expire. Disconnect and reconnect from Integrations - it takes about 15 seconds and the draft you were working on is still there.
Publish said "not connected" but the card looks connected. Unyo pre-flights every targeted platform before publishing and fails closed rather than half-posting. Reconnect X, then tap Publish again - the idempotency key means you can't double-post by retrying.
The image didn't go out. Check the image count on the card. X takes 4; if you built a 10-image carousel for Instagram in the same draft, only the first 4 reach X.
"What's my best time to post on X?" returns nothing. Best-time and hashtag advice is computed from your posts' real engagement, not from a generic benchmark table. If X has just been connected there's no history yet - post a few times and come back.
The wrong account. The X card shows the connected @handle. If it isn't the one you meant, disconnect, then reconnect while signed into the right account.