Every app you ever authorized on X still holds keys to your account. Twillot shows you exactly which apps can post, read your DMs, or see your email — and lets you cut access in one click.
Free to use · Your data never leaves your browser
Most account “hacks” aren't password leaks. They're apps you authorized and forgot about.
You clicked a “claim your airdrop” link and connected an app. The next day it posted contract addresses to all your followers — under your name.
That analytics tool you tried in 2019? If it could post tweets and read DMs back then, it still can — until you revoke it.
X buries connected apps under Settings → Security → Apps and sessions, and never tells you which ones hold sensitive permissions.
No password changes, no spreadsheets. Just a clear, filterable list.
Create a free Twillot account with a magic link — no password needed.
The extension reads your connected apps directly from x.com, inside your own browser.
Filter by sensitive permissions, see what each app can do, and revoke anything you don't recognize.
Everything you need to decide what stays and what goes.
Apps that can post tweets, access DMs, or read your email are flagged in red — exactly the permissions scammers abuse.
Search by name or organization, narrow down by authorization date, OAuth type, or individual permissions.
Cut access instantly for both OAuth 1.0a and OAuth 2.0 apps, without digging through X's settings.
Your app list is fetched from x.com straight into your browser. Nothing is uploaded to Twillot servers.
FAQ
Two minutes today can save your reputation tomorrow.