Back to Browse

Xflux MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

X/Twitter search, profiles, timelines, and Smart Money discovery via XFlux.

About

X/Twitter search, profiles, timelines, and Smart Money discovery via XFlux.

Security Report

4.2
Use Caution4.2High Risk

The MCP server is a well-structured Twitter/X API proxy with proper authentication via API keys and reasonable permission scope for its purpose. However, there are moderate concerns around environment variable handling in the MCP entry point, lack of input validation on some API parameters, and broad network access without explicit rate limiting or request signing verification. The code quality is generally good, but a few security practices could be strengthened. Supply chain analysis found 9 known vulnerabilities in dependencies (3 critical, 2 high severity). Package verification found 1 issue (1 critical, 0 high severity).

5 files analyzed · 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

What You'll Need

Set these up before or after installing:

API key from https://www.xfluxapi.com/dashboard/api-keysRequired

Environment variable: XFLUX_API_KEY

Optional API base URL (default https://www.xfluxapi.com/api/v1)Optional

Environment variable: XFLUX_API_BASE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-yxs1640-png-xflux": {
      "env": {
        "XFLUX_API_KEY": "your-xflux-api-key-here",
        "XFLUX_API_BASE": "your-xflux-api-base-here"
      },
      "args": [
        "-y",
        "xflux"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

XFlux

Affordable & stable X/Twitter API proxy service — MVP built with Next.js 15, TypeScript, Prisma, and PostgreSQL.

Features (MVP)

  • Landing page — Marketing site with pricing and feature overview
  • User auth — Email/password registration and login (NextAuth)
  • API Keys — Generate and manage xflux_* API keys
  • REST API proxy — User profiles, tweets, search (mock + optional live Twitter API v2)
  • MCP server — Official Registry + npm (@xflux/xflux-mcp-server) for Claude Desktop & Cursor
  • Dashboard — Usage stats, API logs, quota tracking
  • Monitors — KOL tweet monitoring task management
  • Billing — Stripe Checkout subscriptions (Starter / Growth / Pro / Scale); see docs/STRIPE.md

MCP (Claude / Cursor)

Published on the MCP Registry as io.github.yxs1640-png/xflux and on npm as @xflux/xflux-mcp-server.

export XFLUX_API_KEY=xflux_your_key_here
npx -y @xflux/xflux-mcp-server

Docs: https://www.xfluxapi.com/docs/integrations/mcp

Tech Stack

  • Next.js 15 (App Router)
  • TypeScript
  • Tailwind CSS 4
  • Prisma + PostgreSQL
  • NextAuth.js
  • Recharts

Architecture

  • Vercel — Next.js app, auth, dashboard, public /api/v1/*
  • Fly.io — api-server/ (Consumer API proxy) + Dockerfile.worker (Monitor 轮询)
  • Supabase — PostgreSQL

See docs/DEPLOYMENT.md for Vercel + Fly.io deployment.

Quick Start

Prerequisites

  • Node.js 20+
  • PostgreSQL database (local, Neon, Supabase, or Vercel Postgres)

Supabase 数据库配置

Supabase 新版界面里,连接串不在 Project Settings → Database,而在:

项目首页顶部 → 点击 Connect 按钮

只有 DIRECT_URL 时(本地开发够用)

Project Overview 里若已有 DIRECT_URL(端口 5432),在 .env 里 两个变量都填同一个值 即可:

DATABASE_URL="你的DIRECT_URL完整连接串"
DIRECT_URL="你的DIRECT_URL完整连接串"

示例格式:

DATABASE_URL="postgresql://postgres:你的密码@db.abcdefgh.supabase.co:5432/postgres"
DIRECT_URL="postgresql://postgres:你的密码@db.abcdefgh.supabase.co:5432/postgres"

然后执行:

npx prisma db push
npm run dev

需要 DATABASE_URL(6543 池化连接)时

  1. 项目首页 → Connect
  2. 选择 ORMs → Prisma,或选 Transaction pooler(端口 6543)
  3. 复制 Transaction 连接串 → 填入 DATABASE_URL,末尾加 ?pgbouncer=true
  4. DIRECT_URL 仍用 5432 直连(Connect → Direct connection 或 Overview 里的值)
变量从哪里找端口
DIRECT_URLConnect → Direct connection,或 Project Overview5432
DATABASE_URLConnect → Transaction pooler / ORMs → Prisma6543

本地开发用 5432 直连即可;部署 Vercel 时再把 DATABASE_URL 换成 6543 池化连接。

部署到 Vercel 时,在 Environment Variables 里添加 DATABASE_URL、DIRECT_URL、NEXTAUTH_URL、NEXTAUTH_SECRET。

Setup

cd ~/Projects/xflux
npm install

cp .env.example .env
# Default uses SQLite — no Postgres install needed

npx prisma db push
npm run dev

Local database options:

OptionCommandWhen to use
SQLite (default)DATABASE_URL="file:./dev.db"Quick local dev, no install
Docker Postgresnpm run db:up then use postgres URL in .envMatch production locally
Neon (cloud)Paste URL from neon.techNo Docker, free tier

For Docker Postgres, change prisma/schema.prisma provider back to postgresql and set: DATABASE_URL="postgresql://xflux:xflux@localhost:5432/xflux?schema=public"

Open http://localhost:3000

Environment Variables

VariableRequiredDescription
DATABASE_URLYesfile:./dev.db (local SQLite) or PostgreSQL URL (production)
NEXTAUTH_URLYesApp URL (e.g. http://localhost:3000)
NEXTAUTH_SECRETYesRandom 32+ char secret
TWITTER_BEARER_TOKENNoTwitter API v2 bearer token for live data
STRIPE_* / BILLING_CHECKOUT_ENABLEDProdLive billing on Vercel — see docs/STRIPE.md

Generate a secret:

openssl rand -base64 32

API Usage

After registering, use your API key:

curl -H "Authorization: Bearer xflux_YOUR_KEY" \
  http://localhost:3000/api/v1/users/elonmusk

Endpoints

MethodPathDescription
GET/api/v1/users/:usernameUser profile
GET/api/v1/users/:username/tweetsUser timeline
GET/api/v1/tweets/:idTweet by ID
GET/api/v1/search?q=keywordSearch tweets
POST/api/v1/tweetsPost tweet (requires OAuth setup)

Deploy to Vercel

Option A: Vercel CLI

npm i -g vercel
vercel login
vercel

Option B: GitHub Integration

  1. Push to GitHub:

    git add .
    git commit -m "Initial XFlux MVP"
    git remote add origin YOUR_REPO_URL
    git push -u origin main
    
  2. Import project at vercel.com/new

  3. Add environment variables in Vercel dashboard:

    • DATABASE_URL — from Vercel Postgres or Neon
    • NEXTAUTH_URL — your production URL (e.g. https://xflux.vercel.app)
    • NEXTAUTH_SECRET — random secret
    • TWITTER_BEARER_TOKEN — optional
  4. After first deploy, run database migration:

    npx prisma db push
    

    Or add a build step with Vercel Postgres integration.

Vercel Postgres Setup

  1. In Vercel project → Storage → Create Database → Postgres
  2. Change prisma/schema.prisma datasource provider from sqlite to postgresql
  3. Connect to project — DATABASE_URL is auto-injected
  4. Redeploy (build runs prisma db push or migrate)

Project Structure

src/
├── app/                  # Next.js App Router pages & API routes
│   ├── api/v1/           # Public REST API (proxy)
│   ├── dashboard/        # Authenticated dashboard
│   ├── docs/             # API documentation
│   └── pricing/          # Pricing page
├── components/           # React components
└── lib/                  # Auth, DB, quota, Twitter proxy
prisma/
└── schema.prisma         # Database schema

Roadmap

  • Stripe billing (Live on production — docs/STRIPE.md)
  • Real-time WebSocket monitoring
  • Telegram/Discord notifications
  • Account pool management
  • CLI tool
  • Batch DM / posting queue (Bull/Redis)

Legal Notice

This project interacts with X/Twitter data. Ensure compliance with X Developer Agreement and applicable laws. Use official APIs when possible.

License

MIT

Reviews

No reviews yet

Be the first to review this server!