Chrome extension

The extension is manual only.

X's April 2026 Automation Rules expressly prohibit non-API automation such as scripting the X website. The former read/inject/prefill lane is disabled. We use official APIs where available and leave unsupported website actions entirely to you.

No Chrome Web Store release is planned while this policy boundary remains. The source stays preserved so the decision and prior implementation remain auditable.

Policy boundary

No X content script. No page scraping. No injected controls. No composer prefill. No automated website clicks.


The supported handoff.

01

Use official reads

GrowSocialelion reads X content only through official API endpoints and the scopes granted to the connected account.

02

Review in GrowSocialelion

Drafts and the exact approved payload stay visible in the dashboard before any supported API action.

03

Hand off manually

Where no permitted API action exists, the product may open X or show copyable text. You perform every website input and click yourself.


Why it is paused

The rule is explicit, so the product is too.

Human presence does not turn browser scripting into an official API. These boundaries are enforced in the manifest, public copy, and capability audit.

No X page access

The current manifest requests no x.com host access and loads no X content script.

API credentials stay separate

The manual companion holds no X password or OAuth token. API-connected credentials remain server-side and can be disconnected from the Brands page.

Open source, end to end

The former X content script remains readable as archived implementation evidence, but the manifest deliberately does not load it.

Written permission is the gate

DOM reading, injection, prefill, click, or submit must not return unless X grants written permission or its official rules change.


Release status

Not installable for X automation.

The archived code is not a supported X action path. Use the dashboard's official API features and manual first-party handoffs.

  1. Connect X through the official OAuth flow.
  2. Use API-backed publishing, engagement, discovery, analytics, profiles, and moderation.
  3. Review every approval-bound payload before execution.
  4. For unsupported actions, copy the reviewed text and act manually on X.

Re-enabling DOM behavior requires written permission from X and a new policy review.