You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 265feff
Browse filesBrowse the repository at this point in the historyBrowse files
</style><mainclass="wrap"><header><h1>Get a video ready to watch before usage runs out</h1><pclass="what">Verify the usage read before adding one CLI command and a short rule to the skills.</p><divclass="strip">OpenUsage @ ae49de04a2b7fc1b3cc334fcc1009276c46d82ad · 2026-10-02 · source audited, live subscription read not exercised</div></header>
46
+
<section><divclass="card breath">Subscription limits are a fuel gauge, not a trip estimate. They tell us which window is almost full, but cannot prove how many agent turns a video needs.</div></section>
47
+
<section><h2>Provisional policy</h2><divclass="card decision"><h3>1. What counts as low?</h3><p>Default: 20% or less remaining in either the shared session or weekly window triggers first-cut-first.</p><table><tr><th>Option</th><th>Consequence</th></tr><tr><td>10% remaining</td><td>Preserves optional work longer, leaves less reserve for render repair.</td></tr><tr><td>20% remaining</td><td>Earlier first cut, fewer optional drafts.</td></tr><tr><td>30% remaining</td><td>More reserve, more runs lose optional work.</td></tr></table><p>No measured run-cost distribution supports an exact threshold yet.</p></div><divclass="card decision"><h3>2. Tell the user before changing the flow?</h3><p>Default: one sentence naming the measured remaining percentage and first-cut-first plan. Silent adaptation is shorter but hides why the storyboard and fan-out were reduced.</p></div></section>
48
+
<section><h2>Where the value travels</h2><divclass="card" style="display:flex;gap:12px;flex-wrap:wrap"><span>Existing Claude login</span><b>→</b><span>OAuth usage GET</span><b>→</b><span>Window percentages</span><b>→</b><span>CLI JSON</span><b>→</b><span>Skill plan</span></div><p>The first three links are source-audited. The CLI reader and skill consumers are implemented; live subscribed proof is pending.</p></section>
49
+
<section><h2>The verified boundaries</h2><divclass="card"><h3>Login read</h3><pclass="plain">Use the existing subscription login. Do not ask for a new token.</p><pre>claudeAiOauth: { accessToken?, refreshToken?, expiresAt?, subscriptionType?, rateLimitTier?, scopes? }</pre><p>Keychain candidates precede the credential file. Custom CLAUDE_CONFIG_DIR adds a SHA-256-derived service suffix. Credentials are parsed once. Explicit inference-only tokens cannot read limits.</p><ahref="https://github.com/robinebers/openusage/blob/ae49de04a2b7fc1b3cc334fcc1009276c46d82ad/Sources/OpenUsage/Providers/Claude/ClaudeAuthStore.swift#L340-L430">Sources/OpenUsage/Providers/Claude/ClaudeAuthStore.swift:340-430</a><br><ahref="https://github.com/robinebers/openusage/blob/ae49de04a2b7fc1b3cc334fcc1009276c46d82ad/Sources/OpenUsage/Providers/Claude/ClaudeCredentials.swift#L3-L26">Sources/OpenUsage/Providers/Claude/ClaudeCredentials.swift:3-26</a><br><ahref="https://github.com/robinebers/openusage/blob/ae49de04a2b7fc1b3cc334fcc1009276c46d82ad/Sources/OpenUsage/Providers/Claude/ClaudeAuthStore.swift#L249-L270">Sources/OpenUsage/Providers/Claude/ClaudeAuthStore.swift:249-270</a><p>Exists: yes. Reachable: source verified. Read: OpenUsage reads it; this machine has no readable subscription login. The reader does not rotate or write tokens.</p></div>
50
+
<divclass="card"><h3>Usage request</h3><pclass="plain">A subscription token asks Anthropic for the current capacity windows.</p><pre>GET https://api.anthropic.com/api/oauth/usage
Accept: application/json</pre><p>OpenUsage adds cedar_ember=1 for reset grants and a Claude CLI User-Agent. Reset grants are unnecessary for this task. Its request timeout is 10 seconds.</p><ahref="https://github.com/robinebers/openusage/blob/ae49de04a2b7fc1b3cc334fcc1009276c46d82ad/Sources/OpenUsage/Providers/Claude/ClaudeUsageClient.swift#L94-L120">Sources/OpenUsage/Providers/Claude/ClaudeUsageClient.swift:94-120</a><p>Exists: OpenUsage client verified. Reachable: endpoint was not called without credentials. Written/read: upstream server implementation unavailable; runtime response shape is inferred from OpenUsage's actual consumer.</p></div>
54
+
<divclass="card"><h3>Window consumer</h3><pclass="plain">Each shared window gives percent used and a reset time. Remaining is 100 minus used.</p><pre>five_hour: { utilization, resets_at }
55
+
seven_day: { utilization, resets_at }
56
+
seven_day_sonnet: { utilization, resets_at }
57
+
limits: [{ kind: "weekly_scoped", scope: { model: { display_name } }, percent, resets_at }]</pre><ahref="https://github.com/robinebers/openusage/blob/ae49de04a2b7fc1b3cc334fcc1009276c46d82ad/Sources/OpenUsage/Providers/Claude/ClaudeUsageMapper.swift#L26-L31">Sources/OpenUsage/Providers/Claude/ClaudeUsageMapper.swift:26-31</a><br><ahref="https://github.com/robinebers/openusage/blob/ae49de04a2b7fc1b3cc334fcc1009276c46d82ad/Sources/OpenUsage/Providers/Claude/ClaudeUsageMapper.swift#L139-L175">Sources/OpenUsage/Providers/Claude/ClaudeUsageMapper.swift:139-175</a><p>These are accepting lines, not a published server schema. Model limits are separate from shared limits; choosing an unrelated model's limit would misstate the active harness budget.</p></div></section>
58
+
<section><h2>How it says no</h2><table><tr><th>Signal</th><th>Meaning</th><th>Behavior</th></tr><tr><td>No credentials, API key, inference-only</td><td>No readable subscription limit</td><td>unknown; existing skill flow</td></tr><tr><td>401 / 403</td><td>Expired or insufficient scope</td><td>unknown; no token refresh or writes</td></tr><tr><td>429</td><td>Usage read throttled</td><td>unknown; no immediate retries</td></tr><tr><td>Timeout / malformed response</td><td>Capacity unverified</td><td>unknown; continue</td></tr></table><p>The brief says “Never send usage data anywhere.” A remote authenticated GET is necessary for live windows. Interpret this as no telemetry or forwarding of usage results. Authentication goes only to the provider.</p></section>
59
+
<section><h2>Coverage, honestly</h2><p>Audited: OpenUsage auth order, request, consumer, MIT license. HyperFrames main searched for remaining-usage planning; no matching implementation found at fd2f90c7d81d4c2a57848bb21e225cbccc66ec4f. commandUsageResolution.ts resolves help subcommands, not subscription usage.</p><p>Trusting: Anthropic response fields inferred from OpenUsage consumer. Not exercised at the time of this audit: live subscription response, skill adaptation, render. Fixture verification is reported with the implementation.</p><pre>Actual local probe:
60
+
{ "status": "unknown", "reason": "no_readable_subscription_login" }</pre><p>MIT permits reuse with the license notice for substantial copied portions. Recommendation: implement the small read independently, cite the method, do not vendor the app.</p></section>
61
+
<section><h2>What would prove this wrong?</h2><p>A valid subscribed Claude login whose live response does not match these fields. A low-budget blank-agent run that spends optional work before its first MP4. A credential fixture where another profile's login supplies the budget. These need explicit verification before merge.</p></section></main></html>
0 commit comments