Tools
LiveSensitiveSpends creditsAudit an X account's followers for fakes
/data-api/v2/tools/follower-audit- Scope
- tools:use
- Freshness
- live read
- Group
- Tools
- Platforms
- 1 of 7
What this endpoint answers
Samples the follower graph and classifies each sampled account as real, suspicious, bot or inactive, then reports the split, the signals that drove the flags, and four component scores (follower quality, engagement, account health, sample quality).
This is a live read: it goes to the platform at request time, returns cache_age_s = 0, and is metered against a separate live-per-minute bucket on top of your tier. It needs the tools:use scope (Tools): Run the analysis tools: valuation, follower audit, scoring, and more.
Good to know
- Costs money: this endpoint bills twitterapi.io credits per call. Metered as a live call.
- Returns 503 not_configured when TWITTERAPI_IO_KEY is unset, and 502 upstream_error when the credit pool is exhausted or the upstream fails. It never returns an empty 200.
- Ignores NEXT_PUBLIC_USE_MOCK_DATA: the X tools always read live data and have no mock path.
- The website's captcha and per-visitor daily caps do not apply here; your API key's tier limits do.
- sample_size is what the upstream returned, typically the first page of followers. It is a sample, not a census; treat the percentages as estimates with sampling error.
Parameters
This endpoint takes no path or query parameters.
Request body
handlestringrequiredX handle. Accepts a bare name, @name, or a profile URL. Also accepted as `username`.
{
"handle": "elonmusk"
}
Call it
Authenticate with a bearer token or the x-api-key header. Keys are server-to-server credentials. Never embed one in front-end code - call the API from your own backend and forward the result.
curl -X POST "https://crmsolid.com/data-api/v2/tools/follower-audit" \
-H "Authorization: Bearer psk_live_..." \
-H "Content-Type: application/json" \
-d '{"handle":"elonmusk"}'
const res = await fetch("https://crmsolid.com/data-api/v2/tools/follower-audit", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.CRM_SOLID_DATA_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"handle": "elonmusk"
}),
});
if (!res.ok) {
const { error } = await res.json();
throw new Error(`${error.code}: ${error.message} (${error.request_id})`);
}
const { data, meta } = await res.json();
import json
import os
import requests
body = json.loads("""
{
"handle": "elonmusk"
}
""")
res = requests.post(
"https://crmsolid.com/data-api/v2/tools/follower-audit",
headers={"Authorization": f"Bearer {os.environ['CRM_SOLID_DATA_API_KEY']}"},
json=body,
timeout=30,
)
res.raise_for_status()
payload = res.json()
data, meta = payload["data"], payload["meta"]
Keys look like psk_live_... for production keys, psk_test_... for test keys and are minted in the panel.
What comes back
Success is { data, meta }. Failure is { error: { code, message, request_id } }. The body below is the spec's own example: the values in it are illustrative readings, not live numbers.
- Profile handle
- vercel
- Profile twitter id
- 1531841848
- Profile name
- Vercel
- Profile avatar url
- https://pbs.twimg.com/profile_images/1767351110131445760/9nAA4mQ0.jpg
- Profile verified
- yes
- Profile followers
- 412,903
- Profile following
- 361
- Profile total posts
- 8,912
- Profile created at
- 6/18/2013, 2:22:11 PM
- Profile account age days
- 4,814
- Composition real percent
- 71.4
- Composition suspicious percent
- 14.2
- Composition bot percent
- 6.8
- Composition inactive percent
- 7.6
- Engagement engagement rate
- 0.086
- Engagement avg likes
- 214
- Engagement avg retweets
- 31
- Engagement avg replies
- 12
- Engagement avg views
- 41,200
- Scores quality
- 72
- Scores engagement
- 48
- Scores account health
- 91
- Scores follower sample
- 80
- Verdict
- good
- Sample size
- 200
- Top signals
- 3 items
{
"data": {
"profile": {
"handle": "vercel",
"twitter_id": "1531841848",
"name": "Vercel",
"avatar_url": "https://pbs.twimg.com/profile_images/1767351110131445760/9nAA4mQ0.jpg",
"verified": true,
"followers": 412903,
"following": 361,
"total_posts": 8912,
"created_at": "2013-06-18T14:22:11.000Z",
"account_age_days": 4814
},
"composition": {
"real_percent": 71.4,
"suspicious_percent": 14.2,
"bot_percent": 6.8,
"inactive_percent": 7.6
},
"engagement": {
"engagement_rate": 0.086,
"avg_likes": 214,
"avg_retweets": 31,
"avg_replies": 12,
"avg_views": 41200
},
"scores": {
"quality": 72,
"engagement": 48,
"account_health": 91,
"follower_sample": 80
},
"verdict": "good",
"sample_size": 200,
"top_signals": [
{
"signal": "no_avatar",
"count": 24,
"label": "Default profile picture"
},
{
"signal": "never_posted",
"count": 19,
"label": "Has never posted"
},
{
"signal": "follow_ratio",
"count": 11,
"label": "Follows far more than it is followed"
}
]
},
"meta": {
"request_id": "req_9f2c41a8b3d5",
"generated_at": "2026-08-23T09:14:02.317Z",
"took_ms": 42,
"cache_age_s": 0
}
}
The meta block
request_idstringrequiredUnique id for this request. Quote it in a support ticket.
generated_atstringrequiredServer time the response was produced.
took_msintegerrequiredMilliseconds spent server-side.
pagePageoptionalsourcestringoptionalWhich backend served the payload, for endpoints with more than one.
cache_age_sintegeroptionalAge of the underlying data in seconds. 0 for live reads.
When it fails
POST /tools/follower-audit documents 7 failure statuses. Branch on error.code, which is stable and enumerated; message is prose and may change.
- 401Unauthorized
unauthorized | invalid_keyNo key was presented, or the key is unknown, revoked or expired.
- 402PaymentRequired
payment_required | subscription_inactiveThe key is valid but the plan behind it cannot serve the call: the included requests are spent and overage is switched off, capped or unfunded (payment_required), or the billing period lapsed and was not renewed (subscription_inactive). Retrying does not help; paying does. The X-Plan-* headers on this response say how far past the line you are.
Carries X-Plan, X-Plan-Limit, X-Plan-Overage, X-Plan-Period-End, X-Plan-Remaining.
- 403Forbidden
forbidden_scope | forbidden_ipThe key is valid but not allowed to make this call: it lacks the scope, or the request came from an address outside the key's allowlist.
- 422InvalidRequest
invalid_requestA parameter is malformed, out of range or mutually exclusive with another. `details` names the offending fields.
- 429RateLimited
rate_limited | quota_exceededEither the burst ceiling for the current minute or the daily quota is spent. Distinguish with the code: rate_limited clears within the minute, quota_exceeded does not clear until 00:00 UTC.
Carries Retry-After, X-Quota-Limit, X-Quota-Remaining, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, X-Request-Id.
- 500InternalError
internal_errorSomething failed on our side. Internals are never leaked; quote the request id.
- 503Unavailable
upstream_timeout | upstream_error | not_configuredThe request could not be served right now. BRANCH ON error.code, not on the status: 'upstream_timeout' means a source was too slow (this is what a catalog query hitting its 15-second statement timeout returns, so it is reachable from any endpoint that reads the corpus, not only the live-scrape ones) and the same call is worth retrying with backoff - narrowing it with a smaller limit, a filtered scope or a less popular account makes it far less likely; 'upstream_error' means a source was unreachable, so back off further; 'not_configured' means the capability has no backing service in this deployment, and retrying will never help.
Every response carries X-Request-Id and meta.request_id. Quote it in support requests.
Coverage and limits
This endpoint covers X. Rate limits come from the tier on your key.
| Tier | Requests a minute | Requests a day | Live reads a minute |
|---|---|---|---|
| free | 30 | 1,000 | 5 |
| standard | 120 | 25,000 | 20 |
| pro | 600 | 250,000 | 60 |
| unlimited | 6,000 | 10,000,000 | 600 |
Live reads count against the live column as well as the ordinary one, so a burst of them runs out of the live bucket first. Every response reports where you stand in X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset and the X-Plan headers.
Start calling it
A key takes a minute to mint in the panel, no card. The reference covers authentication, the envelope, scopes, rate limits and every error code in one page.
Reference path: /data-api/reference/tools-follower-audit