Hermoso is a marketing MCP server: 301 tools over one OAuth’d endpoint that let an agent research the ads already running in a market, generate finished image and video ads, publish them, and build the paid campaigns behind them. Codex reaches all of it through one connection. This page is about one slice of that — what Codex can actually do on X, and what X will not let it do.
Connect Hermoso to Codex
- Create an API key. In Hermoso, open Settings → Agents & API keys and press + Create API key. It looks like
hmk_…and carries real spend authority, so treat it like a password. - Add it to
~/.codex/config.toml. Codex reads TOML, not JSON — a copiedmcpServersblock will not load:[mcp_servers.hermoso] url = "https://app.hermoso.ai/mcp" http_headers = { "Authorization" = "Bearer <your key>" } - Ask Codex for something. “Pull my three closest competitors’ longest-running ads and remix the best hook into a 9:16 video,” or “post this render to the channel.” The agent picks the tools; you approve the spend.
The TOML detail is the one that trips people up: every other client in this list takes a JSON mcpServers object, and Codex takes [mcp_servers.<name>] with http_headers.
Then connect X itself, once, under Settings → Connectors in Hermoso. That is an OAuth consent screen, so it is the one step that needs a browser — everything after it is a tool call.
The X tools Codex gets
post_to_x— posts text, an image or a video with alt text, a whole thread, a reply, or a poll — and can restrict who is allowed to reply.schedule_post— queues it on the shared calendar.x_post_metrics— the public counts on a post.x_post_insights— advertiser-grade numbers — impressions, link clicks, profile visits, video views and completion quartiles — for the last 28 hours only.x_post_insights_historical— the same numbers over any date range, up to 25 posts at a time. This is the one for “how did last month go”.x_mentions— who is talking about the brand.delete_x_post— removes a post.
X is the only connector that costs money per call, and the numbers are published rather than hidden. Meta, TikTok, LinkedIn, YouTube, Threads and Drive cost nothing per request; X charges us, so those calls bill a small number of credits each. A plain post is priced at $0.015 per request and a post containing a link at $0.200 — roughly 13× more. Deletes, reads and the alt-text metadata write each carry their own price, and insights bill per post returned. Link detection deliberately errs toward assuming a link is present, because guessing wrong the other way costs us 13×. The practical consequence: on X, one good post beats five, and your agent is quoted the price before it posts. Over-length copy is also refused, never truncated — 280 characters, with the overage counted for you and a suggestion to split it into a thread.
X limits worth knowing before you automate anything
| Text | An X post is capped at 280 characters, and over-length copy is refused rather than truncated. It is enforced when the post is created or queued — refused while you are still there to fix it, rather than silently cut on the way out. |
|---|---|
| Visibility | Public only. A post on X is public the moment it exists — there is no draft and no unlisted post in the API. Protected accounts exist, but that is an account-wide setting Hermoso neither reads nor controls, not a per-post choice. |
| Carousel | Refused, by name, and for a reason that is specific rather than generic: “X has no swipeable carousel. Its API attaches up to 4 media to a post and they render as a GRID — every image visible at once, nothing to swipe to — so a numbered ‘1/6 · SWIPE’ slide deck cannot be published there as intended. Post the single strongest slide to X, or drop X from this post.” A deck that instructs the reader to swipe, published as a grid, is worse than not publishing it. |
| Which account | None — X publishes to the connected account. |
Try it in Codex
Ask for it in ordinary language — these are sentences, not a DSL:
“Non-interactive: post one X update per release, under 280 characters, with the link in that single post, and log the billed cost.”
That walks get_brand → generate_text → post_to_x → x_post_insights_historical. Interactively Codex shows the call before it runs it. Non-interactively there is nobody to ask, which is worth designing around on any step that publishes or spends.
Codex on X: the part that bites
Budget this one deliberately. Every post, delete and read is a billed request, insights bill per post returned, and a post carrying a link is priced at roughly 13× a plain one. For an unattended job that means: one post per event rather than a thread, one link rather than several, and a cap on how often the job may run. The character limit is a clean refusal, so a failing job fails loudly rather than posting something half-said.
For unattended runs, prefer the hermoso CLI with --json over the full tool manifest — it is far cheaper in context and easier to assert on.
Research X before you post
There is no X ad library to search. X research here is your own account: mentions, post metrics and the historical advertiser numbers. Everything else in the research surface — Meta, Google and LinkedIn ad libraries, organic TikTok, Instagram, YouTube, Reddit and Threads — is unaffected.
The paid half
X Ads do not exist in Hermoso, and we name that rather than leaving it ambiguous. The X Ads API is a separate product on a separate host with its own OAuth 1.0a signing and its own approval process. X is an organic channel here: Hermoso posts, threads, replies, deletes and reads post metrics, and does not create or manage X ad campaigns.
What Codex cannot do on its own
An agent with a budget is only useful if the blast radius is bounded, so the fence is in the server rather than in a prompt. Every ad campaign, ad set, ad group and ad is created paused, and the status switches that arm real money refuse to run without an explicit confirmation flag. Every render is quoted first — hermoso_capabilities publishes each model’s exact credit cost before anything spends — and credits are reserved before the first provider call and settled at the exact cost afterwards, so a failed dispatch refunds rather than leaving you billed for nothing. Deletes are confirm-gated too, and every campaign tree is read back from the ad platform before your agent tells you what it built.
One step is deliberately not headless: linking an account is an OAuth consent screen, so you connect the channel once in a browser. Everything after that is a tool call.
The rest of the matrix
From Codex, post to: Facebook · Instagram · Threads · TikTok · YouTube · LinkedIn · Pinterest — or see everything Codex can publish to.
Post to X from: Claude · ChatGPT · Claude Code · Cursor · Cline · OpenClaw · Hermes · Ads from the command line
Frequently asked questions
Can Codex post to X?
Yes, through Hermoso's MCP server. Create an API key in Hermoso under Settings → Agents & API keys, then add https://app.hermoso.ai/mcp to Codex with an Authorization: Bearer header. Codex then has 301 tools, including the ones that publish to X — and the ones that research the ads already running in your market and render the creative in the first place.
How do I connect X to Codex?
Two steps, once each. Create an API key in Hermoso under Settings → Agents & API keys, then add https://app.hermoso.ai/mcp to Codex with an Authorization: Bearer header. Then connect X inside Hermoso under Settings → Connectors, which is an OAuth consent screen in a browser. After that Codex publishes to X as an ordinary tool call.
Can Codex post a carousel to X?
No. X’s API attaches up to four media to a post and they render as a grid — every image visible at once, nothing to swipe to — so a numbered slide deck cannot be published there as intended. Codex calls the same publish tool either way, and a channel that cannot carry a carousel is refused with the real reason attached.
What does it cost to post to X from Codex?
X is the only connector that bills credits per call, because X charges per API request: roughly $0.015 for a post and $0.200 for a post containing a link — about 13 times more. Your agent is quoted the price before it posts. Plans are $19, $49 and $149 a month for 1,000, 3,000 and 10,000 credits, and every feature is on every plan including Free — the only exception is enterprise SSO.
Start free — 25 credits at signup and 250+ more to earn, and every feature on every plan.
Start free → See pricing