Herald social suite · X.COM Publisher
Draft it anywhere. Nothing reaches X without your tap.
X.COM Publisher is the governed connection between QuoxCORE and your X account. Wherever a draft comes from, an agent, the quox x CLI or you, it files an approval card in your inbox first. Only a human tap publishes it, signed, inside a posting budget, with a record of who approved what.
In plain words
What it is, where it lives, when to reach for it
- What is it
- A governed connection between QuoxCORE and your X account: drafts go in, a human approves, and only then does it publish.
- Where do I use it
- In the dashboard's inbox, and from the CLI with the quox x verbs.
- When would I use it
- When you want an agent to draft a post, reply or thread, but a person to decide before anything goes out.
- How do I use it
- Buy it in the store for $10, an org admin connects an X account, then every draft waits for a human tap.
QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE
Four steps, and a human in the middle of them.
The same path whether the draft came from an agent, a terminal or the compose box. There is no second route that skips the card.
- the draft
A post, reply or thread gets drafted. It does not matter where from: an agent working on something,
quox x postin a terminal, or the compose box in the dashboard. All three routes end in the same place. - the card
The draft becomes an approval card in the QuoxCORE inbox, carrying the exact text, any images attached, who drafted it, and the budget left. Nothing has reached X at this point.
- the tap
You open the card and tap. The publish is verified against the recorded approval before it runs, and refused if the bound credential changed since. An approver composing in the dashboard can also approve and schedule: the tap happens up front, the publish fires later through the same checks.
- the receipt
The post goes out signed with your vault-held credentials, and the decision writes an AEE envelope, the open record format Quox logs agent actions in. What went out, and who let it, is a record rather than a memory.
Watched from draft to a live post
Driven end to end on 11 September 2026, not a mockup. Three screenshots, in the order it actually happened.



What the plugin looks like once it is installed.
The /x view in QuoxCORE, captured on 12 September 2026. Overview, Compose, Activity, Engagement, Budget, Account health and About are the tabs it ships with. Three of them below.



Six things the plugin actually does.
Every item below has been driven end to end on the same build that produced the screenshots above. Things that are shipped but not yet fully driven are listed further down as beta, not here.
Vault-held credentials
OAuth 1.0a credentials stored in QuoxVault, with a live verification check against your X account before anything can post.
Human approval on everything
Every agent-drafted post, reply, thread and delete waits in the inbox for a human decision, with no way around it. The only thing that can publish on a timer is a post a human approver already approved at compose time.
A posting budget
A daily and a monthly cap, both rolling windows rather than midnight resets, org-scoped and checked before a draft is even created. Capacity is claimed atomically, so approving the same card twice never posts twice.
Still images, up to four
Attach up to four still images (PNG, JPEG or WebP) to a post, so the reviewer sees exactly what will publish. Files must sit inside your organisation’s own media root, and symlinks out of it are refused.
Reading, inside its own budget
CLI verbs
Shipped, but still beta
These work and are in the build. They have not been driven end to end, so they are named here rather than counted above.
- Scheduling. A workflow schedule can file a fresh approval card on a timer (drafting only; a cron-fired run has not been driven live yet). A human approver can also approve and schedule from the dashboard: approval up front, the publish fires at the chosen time through the same verified path. A successful timed publish has not been driven live yet.
- Composing in the dashboard. The
/xview renders and gates correctly, and its engagement panel reads real numbers on an explicit click. Composing through to a published post in the browser has not been driven end to end yet. The CLI path has. - The licence gate. Verified fail-closed in code, but not yet proven against a genuinely unlicensed install.
- The mentions poller. Shipped but dark by default, and never run against live data.
What is not here yet
- Anything but still images. No video, no alt text, no polls, no quote posts and no reply controls. The uploader accepts a
.gif, but nothing sets an X media category for it, so how an animated GIF behaves is unproven and we do not claim it. - OAuth 2.0 and multi-account. The OAuth 1.0a path supports one connected account per organisation. Multi-account is not built.
- Writing the posts for you. This is a governed connector, not a content engine. It carries a draft safely from wherever it came from to X, and does not generate one.
What posting costs
The plugin is a one-off licence. Posting itself is billed by X to your own account, not to Quox: roughly $0.015 for a plain post, about $0.20 for a post containing a link, and about $0.005 per read. The posting and read budgets are a guard against that bill as much as a rate limit, and the approval card shows the remaining budget before you tap.
Posting to a public network cannot be taken back. So here, every post, reply, thread and delete goes through the same approval machinery as a production deploy: an approval card a human has to tap, a budget that refuses, and an evidence record of the decision.
How the plugin is governed
How you get it
QUOX STORE
x.com publisher · herald social suite
Licence key activation. Requires an X account with an OAuth 1.0a access token, stored in QuoxVault. X is a trademark of X Corp; Quox is not affiliated with X.