X login: sign in at x.com on any browser
X login in one minute: sign in at x.com, clear 2FA, and fix the real blockers - the key migration, verification loops, and the new country age rules.
On this page · 15 sections
- Quick answer
- TL;DR
- How to log in to X on the web (step by step)
- Signing in from a phone browser
- Where you log in changes what happens
- The security-key change that still locks people out
- When the X login fails: the real fixes
- Settings links worth bookmarking
- Forgot which email or username the account uses
- When you are stuck in a verification loop
- Signed in to more than one account
- Log out, and log out everywhere
- Web vs the app: what you actually get
- Keep your session safe (and skip the "special browser" upsell)
- Bottom line
The short version
- ▸The X login lives at x.com: click Sign in, enter your username, email or phone plus your password, then clear any 2FA prompt. Sign in with Google or Apple also works, and twitter.com redirects to x.com.
- ▸You never need the app. The web app in any modern browser does the timeline, posting, DMs, analytics and settings.
- ▸If you used a hardware security key or passkey for 2FA, X required you to re-enroll it under x.com by November 10, 2025. Missing that is the single most common hard lockout.
- ▸Most failures are boring: a rate-lock from too many attempts, blocked cookies, a stale cache, or a bad 2FA code. Switch browser, allow cookies, clear cache, or wait an hour. Settings, Security and account access, Apps and sessions is where you kill a session you do not recognise.
- ▸Where you log in now changes the answer. Since 10 December 2025 X has to take reasonable steps to stop Australians under 16 creating or keeping an account, and UK, Irish and EU accounts meet age checks on sensitive content after sign-in.
Quick answer
To do an X login, go to x.com in any modern browser, click Sign in, and enter your username, email or phone number along with your password. Clear the two-factor prompt if you have one turned on, and you are in. Sign in with Google or Apple works too, and the old twitter.com address redirects to x.com, so both land in the same place.
Last updated: September 2026
TL;DR
X (formerly Twitter) runs fine in any browser on desktop or mobile, and you do not need to install anything. The sign-in itself is three fields. What trips people up in 2026 is everything around it: a security-key change that locked out passkey users, cookie and cache problems that throw vague errors, an account switcher people never find, and a search results page stuffed with tools selling you a "safer" way to log in that you do not need. Below is the plain version, plus the fixes that actually work when sign-in fails.
How to log in to X on the web (step by step)
- Go to x.com. Type it into the address bar or use a saved bookmark. Do not click a login link from an email or DM you did not expect. That is how phishing kits harvest passwords. If you land on the old address, it redirects to x.com automatically.
- Click Sign in. On the x.com landing page the button is top-right on desktop and in the sign-in card on mobile web.
- Enter your identifier. Your @username, the email on the account, or the phone number all work. Username is the one to use if you have forgotten which email the account was opened with.
- Enter your password, or choose Sign in with Google or Sign in with Apple if that is how the account was created. Picking the wrong one of those three is a surprisingly common cause of "wrong password".
- Clear two-factor authentication if you have it on. X will ask for an authenticator code, an SMS code, or a passkey or security key, depending on what you enrolled.
- You are in. The web feed loads with the same timeline, DMs and settings you get in the app.
That is the whole thing. If it did not work, the reason is almost always one of a short list, which is the next section but one.
Signing in from a phone browser
You do not need the app on a phone either. Open x.com in Safari or Chrome on the handset and the same sign-in card appears, sized for the screen. Two things are worth knowing.
First, mobile browsers are much more aggressive about blocking cookies, and X's sign-in flow needs them. If Safari's Prevent Cross-Site Tracking or a content blocker is on, the login page can reload endlessly without an error message. Turn the blocker off for x.com and try again.
Second, you can pin it. On iOS, tap Share then Add to Home Screen; on Android, tap the browser menu then Install app or Add to Home screen. That gives you an icon that opens X full-screen with your session already live, which is most of what the native app was doing for you. Our guide to using X in a web browser covers what the web version can and cannot do.
Where you log in changes what happens
Two rules now decide whether an X login works before your password is even checked, and both depend on where you are.
Australia. Since 10 December 2025, age-restricted platforms have had to take reasonable steps to stop Australians under 16 from "creating or keeping an account" (OAIC). X sits on that restricted list next to Facebook, Instagram, TikTok, Snapchat, YouTube, Reddit and Twitch, and the obligation covered accounts that already existed, not just new signups (Legal Aid WA). So if a teenager's login stopped working around then and password resets change nothing, this is the reason, and no browser fix touches it. The account was deactivated by policy.
UK, Ireland and the EU. Here the check lands after sign-in rather than at the door. X runs age assurance to work out whether an account belongs to someone over 18 and can therefore see sensitive media. Its own age assurance page lists the signals it reads: age you declared previously, an ID verification you already completed, legacy verified status, and whether the account was created in 2012 or earlier. Accounts estimated as under 18 get defaulted into restricted settings, and X says you can challenge a wrong estimate through X Support. Your login still works. What you can see changes.
Everywhere else. If x.com will not load at all, that is the network, not the account. Test it on mobile data with wifi off. A page that never renders points at a DNS filter, a school or corporate network, a VPN exit X rate-limits, or a country-level block, and none of those are fixed by resetting a password.
The security-key change that still locks people out
Here is the part most login guides skip. In late 2025, X finished moving the platform off its original domain onto x.com. Passwords and authenticator-app codes were unaffected, but passkeys and hardware security keys are cryptographically bound to the domain they were created on, so keys enrolled under the old domain stopped being valid on x.com.
X told every account using a security key as its 2FA method to re-enroll the key, or enroll a new one, by November 10, 2025, or lose access until they did (Engadget, Oct 2025; the notice came from @Safety on X). Accounts that missed the date got locked until the owner re-enrolled a key, switched to another 2FA method such as an authenticator app, or turned 2FA off.
If you are reading this because you are suddenly locked out and you use a YubiKey or a passkey, that is very likely the cause. The fix: recover access through a backup method, then go to Settings and privacy, Security and account access, Security, Two-factor authentication, and re-enroll the key under x.com. If you only ever used a password or an authenticator app, none of this applies to you.
When the X login fails: the real fixes
Most sign-in failures on the web are dull and fixable. X's own log-in help page lists the same handful of causes we see over and over:
| Symptom | Likely cause | Fix |
|---|---|---|
| "Could not log you in" after several tries | Rate-lock from too many attempts | Wait about an hour, then try again on x.com. X blocks repeated attempts to slow down guessing. |
| Login page reloads or throws a vague error | Cookies blocked, or a stale cache | Allow cookies for x.com, clear your browser cache, or try a different browser. Firefox is a common fallback. |
| 2FA code rejected | Wrong or expired code, or clock drift | Use a fresh code, set your device clock to automatic, or fall back to a backup code. |
| Passkey or key not accepted | The 2025 domain migration | Re-enroll the key under x.com, or switch to app-based 2FA to get back in. |
| Password not working at all | Forgotten or changed password | Use Forgot password on the sign-in page to reset via email, phone or username. |
| Signed out again minutes later | An extension or privacy mode clearing cookies on close | Allow x.com in the extension, or stop using a private window for the account you stay signed in to. |
If the password itself stopped working and you did not change it, treat that as an X account hacked situation and secure your email before you reset anything. A weak connection can also interrupt the login handshake, so if nothing else is wrong, restart your router and let the connection settle. If you are genuinely stuck after all of this, X's account-access recovery form is the escalation path.
Settings links worth bookmarking
Once you are actually in, three addresses save a lot of menu-hunting. They only resolve while signed in.
| What you want | Go straight to |
|---|---|
| Re-enroll a passkey or hardware key | x.com/settings/account/login_verification/security_keys |
| Two-factor settings and backup codes | x.com/settings/account/login_verification |
| Every live session, and the kill switch | x.com/settings/sessions |
Forgot which email or username the account uses
Losing the email address does not lock you out. Your @username works as the identifier, and so does the phone number on the account. If all three have slipped your mind, the Forgot password flow accepts any one of them and shows you the email it is sending to, partially masked, which is usually enough to jog the memory. If that masked address is one you no longer control, you are in account-access recovery rather than a password reset, and X will ask you to prove ownership another way.
When you are stuck in a verification loop
One failure deserves separating from the rest, because everything in the table above does nothing for it. X accepts your password, then asks you to confirm your identity. You enter a phone number or an email, the code never lands or gets refused, and the same prompt comes back. Round and round.
The loop is usually X's side rather than yours. When the domain migration landed in November 2025, people reported exactly it: an endless verification loop while trying to confirm identity by phone, email or authenticator app, alongside pop-ups demanding a YubiKey re-enrollment (Yahoo Tech, 12 November 2025). X never acknowledged the outage publicly.
Work through it in this order:
- Use a saved backup code. The codes you stored when you turned on two-factor authentication sidestep the whole problem, because nothing has to be delivered to you.
- Change the delivery channel. SMS failing? Use the authenticator app. Authenticator failing? Set your device clock to automatic, since a drifting clock invalidates every code it generates.
- Change one variable at a time. Same account, different network: phone on mobile data, wifi off. Same network, different surface: the app if you were in a browser, the browser if you were in the app. Get in anywhere and the account is fine, which means the problem is local.
- Stop retrying. Hammering the loop stacks a rate-lock on top of the original fault, and now you have two problems.
- Check whether it is everyone. A loop that thousands hit at the same minute is an outage, and the only fix for an outage is waiting.
Signed in to more than one account
Most people never find the switcher, then complain about signing in and out all day. On desktop web, your profile picture and @handle sit at the bottom left of the sidebar. Click the three dots next to them and choose Add an existing account, sign in as normal, and both accounts stay live. Clicking the same spot switches between them without another password prompt.
That switcher holds several accounts at once but it is not unlimited, and X has capped simultaneous sign-ins for years. When it refuses to add another, you have two honest options: sign one account out, or run the extra accounts in a separate browser profile, since each profile keeps its own cookie jar and therefore its own set of sessions.
One caution worth more than the tip itself. Owning several accounts is normal, and running a work handle beside a personal one is fine. What draws enforcement is behaviour, not the count: posting the same content across accounts you control, or having them like, repost and reply to each other to inflate numbers, is platform manipulation under X's rules, and it can take all of them down together.
Log out, and log out everywhere
Signing out of the browser you are holding is the profile menu, then Log out. The more useful one is the list of every other session.
Go to Settings and privacy, Your account, Security and account access, Security, Apps and sessions, Sessions. You get every device with a live session: device type, operating system, browser, last active time and rough location. At the top sits Log out of all other sessions, which ends every one of them except the browser you are in.
Run that after you use a shared or public computer, after you stop using an old phone, and immediately if you see a session you do not recognise. The same screen lists third-party apps holding access tokens, and revoking one there cuts it off instantly. X's help page on apps and log in sessions covers both halves.
Web vs the app: what you actually get
You do not lose anything meaningful by staying in the browser. The X web experience covers the full timeline, posting and threads, replies, DMs, search, lists, bookmarks, analytics and account settings. For a lot of people the web is the better home base: a real browser tab is easier to manage, bookmark and keep signed in than the mobile app, and it is the surface most third-party tools attach to.
If you run a Professional or business profile, the web is where the dashboard lives. We cover that setup in the X business account guide, and if you are chasing the badge, how to get verified on X walks through the current tiers.
Keep your session safe (and skip the "special browser" upsell)
Search "X login" and the top results are mostly antidetect or multi-account browser vendors pitching a tool to log in "safely" or run many accounts at once. You do not need any of that to sign in to your own account, and there is a real cost to reaching for one.
The reason is simple: your logged-in session cookie is effectively your account. Anything that stores, syncs or proxies that cookie, whether a cloud tool, a shared "multi-account" browser or a random extension, can act as you, and if that service is breached your session goes with it. A few habits keep the risk down:
- Log in only at x.com, never through a link you did not initiate.
- Turn on 2FA, keep an authenticator app as your portable second factor, and save backup codes offline.
- Be skeptical of extensions and "login helpers" that ask for broad permissions on x.com.
- Check Apps and sessions every few months and revoke what you no longer use.
- Prefer a browser you own and control over any cloud service that holds your session.
This is also the honest line on automation. If you use a tool to help post or reply, the setup with the smallest detection surface is one that works from your own logged-in browser on your own machine, where the session cookie never leaves your device. That is a smaller footprint than a cloud tool posting from a shared IP pool, though no browser-route automation is sanctioned by X's rules. We lay out that trade-off in local vs cloud X automation, and X-Autopilot is built on exactly that model: it drives X from the same browser session you just signed into, on your Mac, rather than asking you to hand your login to the cloud.
Bottom line
The X login is the easy part: x.com, your identifier, your password, clear 2FA, done, in any browser without an app. The parts worth knowing are the 2025 security-key migration that locked out passkey users, the verification loop that no password reset fixes, the short list of cookie, cache and rate-lock fixes that solve most ordinary failures, the country rules that can deactivate an account before a password is ever checked, the switcher that saves you from signing in and out all day, and the Sessions screen that lets you kick everything else off. Log in at x.com, keep 2FA on, and do not hand your session to a tool you do not control. If growing the account is the next problem, start with how to get followers on X.
Frequently asked
Answers indexed by Google + AI assistants.
What is the X login URL?+
It is x.com. Open x.com in any modern browser, click Sign in, and enter your username, email address or phone number with your password. The old twitter.com address redirects to x.com, so both land in the same place.
Can I use X in a browser without downloading the app?+
Yes. The X web app runs in any modern desktop or mobile browser and does almost everything the phone app does: read the feed, post, reply, run DMs, check analytics and change settings. You never have to install anything.
Why does my X login keep failing on the web?+
The usual causes are a rate-lock from too many attempts (wait about an hour), cookies or cache your browser is blocking (allow cookies, then clear the cache or try another browser), a wrong or expired two-factor code, or the 2025 security-key migration if you use a passkey or hardware key. A different failure is the verification loop, where X takes your password and then asks you to confirm your identity forever because the code never arrives: that one is usually X's side, so use a saved backup code, change the delivery channel, and stop retrying.
How do I log out of X on all devices?+
Go to Settings and privacy, Your account, Security and account access, Security, Apps and sessions, Sessions. The Log out of all other sessions button at the top of that list ends every session except the one you are using right now. The same path works on desktop web and in the app.
Can I be signed in to more than one X account at a time?+
Yes. Click your profile name at the bottom left of x.com, then the three dots, then Add an existing account, and the switcher keeps several accounts signed in so you can hop between them. The switcher is capped, so if it refuses a new account, sign one out or use a separate browser profile.
Is it safe to log in to X through a third-party 'multi-account' browser?+
Be careful. Many pages ranking for X login push antidetect or multi-account browsers. Anything that stores or proxies your X session can read your logged-in cookie, which is effectively your account. Prefer a browser you own and control, and treat your session as sensitive.
- X Help - Help with logging in (accessed Aug 2026)
- X Help - Authorizing and revoking third-party apps and log in sessions
- Engadget - X users have until November 10 to re-enroll their security keys (published Oct 2025, accessed Aug 2026)
- @Safety on X - security key re-enrollment notice (posted Oct 2025)
- OAIC - Social Media Minimum Age, obligations from 10 December 2025 (accessed 2026-09-14)
- Legal Aid WA - Social media age restrictions, platform list including X (accessed 2026-09-14)
- X Help - Age assurance on X, the signals X uses to estimate age (accessed 2026-09-14)
- Yahoo Tech - X users hit an infinite account verification loop (published 12 Nov 2025, accessed 2026-09-14)
Product designer and indie hacker. Runs the agent on his own X account every day and writes up what the data shows, including when it's inconvenient.
Follow on X →