A Discord bot that tracks the earliest followers of any Twitter/X account, checks username & bio history, and identifies smart followers β all without the official Twitter API. Built in Go using Twitter's internal GraphQL API + Frontrun.
- Features
- Commands
- Embed Previews
- Prerequisites
- Installation
- Configuration
- Running
- Architecture
- How It Works
- Security
- FAQ
- License
- Deep Crawl Followers β Paginates through all followers (up to 10k) to find the earliest 20
- Username History β Fetches all historical usernames via Frontrun API
- Bio History β Tracks bio changes over time (latest 5 shown)
- Smart Followers β Identifies high-value followers ranked by their own follower count
- Profile Overview β Followers count, account location, source, creation date
- X GraphQL API β Uses Twitter's internal API with cookie authentication (no official API key needed)
- Cookie Pool Rotation β Round-robin rotation across multiple X sessions with auth error fallback
- Transaction ID Generation β Generates valid
X-Client-Transaction-Idheaders for API requests - Parallel Fetching β
.cekfetches all data sources in parallel for fast response times - Progress Updates β Real-time status updates during long-running
.firstcrawls - Cooldown System β Configurable per-user cooldown to prevent abuse
- Rich Embeds β Gold-themed embeds with requester avatar in footer, clickable profile links
- Guild & Channel Allowlists β Restrict bot to specific servers and channels
| Command | Description |
|---|---|
.first <handle> |
Deep crawl all followers, find the earliest ~20 |
.cek <handle> |
Full profile check: username history, bio changes, smart followers, profile stats |
Crawls all followers of the target account (newest β oldest), deduplicates, and returns the 20 oldest followers. Shows:
- Target's display name, @handle, follower count, and profile picture
- Top 20 earliest followers with links to their profiles
- Crawling time
Example: .first elonmusk
Parallel fetches data from Frontrun API + X GraphQL. Shows:
- π Followers count
- π§ Smart followers count (high-value accounts that follow them)
- π Account location (based in)
- π± Source (Twitter client used)
- π Account creation date
- π Total username changes
- π Bio changes count
- π Full username history with timestamps
- π Latest 5 bio changes
- π Top smart followers ranked by their follower count
Example: .cek elonmusk
Both commands return a gold-themed Discord embed with:
- Thumbnail β Target's profile picture (400Γ400)
- Title β Command-specific (π for
.first, π for.cek) - Description β Profile stats and data
- Fields β Formatted results with clickable links
- Footer β Requester's Discord avatar + "Requested by {name} β’ {X}m cooldown | Today at {time}"
- Go 1.21+ installed (download)
- Discord Bot Token from Discord Developer Portal
- Twitter/X Cookies (
auth_tokenandct0) from a logged-in browser session - Frontrun Session Token (for
.cekcommand features)
- Log in to x.com in your browser
- Open DevTools β Application β Cookies β
https://x.com - Copy
auth_tokenandct0values
- Log in to frontrun.pro
- Open DevTools β Application β Cookies β
https://frontrun.pro - Copy the
__Secure-frontrun.session_tokenvalue
git clone https://github.com/DezXBT/first-followers-bot.git
cd first-followers-bot
go mod tidy
cp .env.example .env
# Edit .env with your credentials (see Configuration below)
go build -o first-followers ../first-followersscreen -dmS followers ./first-followers
# Reattach: screen -r followers
# Detach: Ctrl+A, DAll configuration is done via environment variables (.env file). See .env.example for a complete template.
| Variable | Required | Default | Description |
|---|---|---|---|
DISCORD_BOT_TOKEN |
β | β | Discord bot token |
ALLOWED_GUILD_IDS |
β | (all) | Comma-separated guild IDs (deny-all if empty) |
DISCORD_CHANNEL_IDS |
β | (all) | Global channel allowlist |
FIRST_CHANNEL_IDS |
β | (all) | Channel allowlist for .first only |
CHECK_CHANNEL_IDS |
β | (all) | Channel allowlist for .cek only |
| Variable | Required | Description |
|---|---|---|
X_AUTH_TOKEN |
β * | Single auth_token cookie |
X_CT0 |
β * | Single ct0 cookie |
X_AUTH_TOKENS |
β * | Comma-separated auth_tokens for pool rotation |
X_CT0S |
β * | Comma-separated ct0s for pool rotation |
Use either single (
X_AUTH_TOKEN/X_CT0) or pool (X_AUTH_TOKENS/X_CT0S), not both. Pool entries must have equal counts.
| Variable | Required | Default | Description |
|---|---|---|---|
FRONTRUN_SESSION_TOKEN |
β | β | Frontrun session token |
FRONTRUN_BASE_URL |
β | https://loadbalance.frontrun.pro |
API base URL |
FRONTRUN_CLIENT_VERSION |
β | 0.0.216 |
Client version header |
FRONTRUN_CLIENT_LANGUAGE |
β | EN_US |
Client language header |
| Variable | Default | Description |
|---|---|---|
BOT_PREFIX |
.first |
Command prefix for first followers |
CHECK_PREFIX |
.cek |
Command prefix for username check |
DEEP_PAGE_SIZE |
50 |
Followers per API page |
DEEP_MAX_PAGES |
200 |
Max pages to crawl (50 Γ 200 = 10k followers max) |
DEEP_DELAY_MS |
1500 |
Delay between API calls (ms) β increase if rate-limited |
PROGRESS_UPDATE_MS |
15000 |
Progress update interval (ms) |
FIRST_COOLDOWN_MS |
90000 |
Cooldown per user (ms) β default 90s |
TIMEZONE |
Asia/Jakarta |
Timezone for embed timestamps |
LOG_LEVEL |
info |
Logging level |
first-followers-bot/
βββ main.go # Entry point, config loading, bot startup
βββ config.go # .env loading via godotenv, validation
βββ cookie_pool.go # Round-robin cookie rotation with auth fallback
βββ transaction.go # X-Client-Transaction-Id generator (reverse-engineered)
βββ twitter.go # Twitter internal GraphQL API client
βββ frontrun.go # Frontrun API client (username/bio history, smart followers)
βββ discord.go # Discord bot handlers, embed builders, command routing
βββ .env.example # Configuration template
βββ go.mod # Go module definition
| Package | Purpose |
|---|---|
github.com/bwmarrin/discordgo |
Discord API wrapper |
github.com/joho/godotenv |
.env file loading |
- User sends
.first @handlein Discord - Bot checks guild/channel allowlists and per-user cooldown
- Sends "π Analyzing @handle..." placeholder message
- Fetches user info via
UserByScreenNameGraphQL endpoint - Calculates total pages:
ceil(followers_count / page_size) - Deep crawls followers with cursor pagination (newest first, with configurable delay)
- Sends progress updates every 15s during crawl
- Deduplicates followers and extracts the 20 oldest
- Builds gold embed with target profile picture + oldest 20 followers
- Edits placeholder message with final result
- User sends
.cek @handlein Discord - Sends "π Checking @handle..." placeholder message
- Parallel fetch (all at once):
- Username history from Frontrun API
- Bio history from Frontrun API
- Smart followers from Frontrun API
- User info from Frontrun API (v3)
- Profile data from X GraphQL API
- Merges data from all sources
- Builds comprehensive embed with all stats, history, and top smart followers
- Edits placeholder message with final result
- Multiple X sessions rotate round-robin on each request
- If a request returns 401/403, that cookie is skipped and the next one is tried
- Cookies are stored in memory only (loaded from env vars at startup)
- No secrets in code β All credentials loaded from environment variables
- Guild allowlist β If
ALLOWED_GUILD_IDSis set, messages from other servers are ignored - Channel allowlists β Global and per-command channel restrictions
- Per-user cooldown β Configurable cooldown on
.firstto prevent abuse - Cookie rotation β Multiple X sessions rotate; auth errors trigger automatic fallback
- In-memory cookies β Cookies are never written to disk by the bot
Q: Why does the Followers endpoint hash change?
A: Twitter periodically updates their internal GraphQL endpoint hashes. The bot tries multiple known hashes automatically. If all fail, update the followersHashes slice in twitter.go.
Q: Do I need a Twitter API key?
A: No. This bot uses Twitter's internal GraphQL API with cookie authentication. You only need auth_token and ct0 cookies from a logged-in browser session.
Q: Why does .first take so long?
A: Deep crawling all followers requires many paginated API calls with delays to avoid rate limiting. For accounts with many followers, this can take several minutes. Progress updates are sent during the crawl.
Q: Can I use multiple X accounts?
A: Yes. Set X_AUTH_TOKENS and X_CT0S with comma-separated values. The bot rotates through them round-robin and automatically skips accounts that get auth errors.
Q: What are "Smart Followers"?
A: Smart Followers are accounts that follow the target and have a high follower count themselves β indicating high-value or influential followers. The .cek command shows the top ones ranked by their follower count.
Q: What happens if Frontrun API is down?
A: The .cek command gracefully handles failures β sections that fail are skipped, and whatever data was successfully fetched is still displayed. The .first command doesn't depend on Frontrun at all.
Q: How do I avoid rate limits?
A: Increase DEEP_DELAY_MS (default 1500ms). The bot also rotates cookies and uses X-Client-Transaction-Id headers to reduce rate limit triggers.
MIT