Repository navigation
Releases: danieldrinhausen/Tokenmax
Release list
Tokenmax 0.1.17
What’s new
One popover for everything, Cursor alongside Claude Code and Codex, and fewer reasons to sign in again.
- Every menu bar icon opens the same popover. Clicking any icon shows every provider you have switched on, in the icons' order, so comparing Claude with Codex no longer means clicking between two popovers.
- One menu bar icon per provider, if you want it. Settings → General → Menu bar icon → Icons gives Claude Code and Codex their own menu bar items, each showing that provider's session over its week. Each has a switch to hide it and a handle to drag it into order; the order holds across relaunches. The combined icon stays the default.
- Cursor's included usage. Settings → Data Source → Monitor Cursor usage, off by default, adds Cursor beside Claude Code and Codex: how much of the plan's included usage is left this billing cycle, on named models and through Auto. It reads the token Cursor.app already keeps on your Mac, read-only, and never looks at browser cookies.
- Claude's banked resets and cloud credit. Below Claude's meters you now see any limit resets Anthropic has banked for you, and the one-time Claude Code and Cowork credit for cloud sessions — Cloud credit · $250 of $250 left · expires Nov 5. Tokenmax only shows them; redeem a reset with
/limit-resetin Claude Code. - Every Codex reset's expiry. Instead of "3 available resets · expires Oct 4", resets with the same title share one line with each expiry, soonest first — 3× Full reset (Weekly + 5 hr) · exp. 4 Oct, 5 Oct, 22 Oct.
- An expired Claude login renews itself. Claude Code only renews its login when it runs, so a Mac where it sat idle left Tokenmax asking you to sign in. Tokenmax now starts
claudein a hidden terminal, types/status, and picks up the renewed login — at most every 15 minutes, and it gives up after two tries that did not help. No prompt is sent and no quota is spent.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxOr download Tokenmax-0.1.17.dmg below.
Tokenmax is signed but not notarized. On first launch, use System Settings → Privacy & Security → Open Anyway.
Tokenmax 0.1.16
What’s new
The keychain prompt is gone.
- No more keychain dialog. Tokenmax used to read Claude Code's saved login from its own process, and macOS tied that permission to each individual build — so it asked again after every update, and again every time Claude Code renewed its token, usually once or twice a day. Always Allow could not stop that, and neither could a signing certificate. Tokenmax now reads the login through Apple's
securitytool, the same tool Claude Code saves it with. macOS already trusts that tool for this item, so nothing asks: not on first launch, not after updating, not when Claude Code renews its login. This is not a new exposure — any program running as you can read the item the same way. If you would rather Tokenmax never read the token at all, Settings → Data Source → Status line only still does exactly that. - A 403 from the usage server is no longer shown as an expired login. Tokenmax used to treat "this login may not see usage" like "this login has expired": it discarded the credential, waited for a renewal, and asked you to sign in again — forever, because the renewed login is refused the same way. It now says the account or login does not get usage and names the usual cause: a login made with
claude setup-token, whichclaude auth loginreplaces with a full one.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxOr download Tokenmax-0.1.16.dmg below.
Tokenmax is signed but not notarized. On first launch, use System Settings → Privacy & Security → Open Anyway. There is no keychain prompt to answer any more.
Tokenmax 0.1.15
What’s new
Mostly about when Tokenmax tells you quota is worth spending, plus a smoother sign-in.
- Session reminders and the "good time to spend" highlight now check the week. A session is a slice of your weekly quota, not extra on top of it. Before, a session with 60% left inside a week with 5% left was announced as quota about to be wasted, though the week would run out long before the session did. Both signals now also require the same provider's weekly window to clear the session rule's minimum remaining quota. A reminder held back this way says "No reminder — weekly quota is below your minimum". Plans that report no weekly figure are unaffected.
- Codex's highlight follows the Codex session rule. The highlight read Claude's session lead time and minimum quota for every provider, so Codex's bars lit on timings you had only chosen for Claude. Each provider now uses its own rule, under Settings → Notifications.
- Sign in to Claude from the popover. When the saved credential is rejected, or Claude Code is signed out, the popover now offers Sign In with Claude in place of the terminal hand-off. It runs
claude auth login --claudeaiin the background and opens Claude's login page in your browser. Usage refreshes once the login lands. Claude Code still performs and stores the login itself; Tokenmax never obtains or refreshes a token of its own.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxOr download Tokenmax-0.1.15.dmg below.
Tokenmax is signed but not notarized. On first launch, use System Settings → Privacy & Security → Open Anyway. A new binary also prompts once for Claude Code keychain access; choose Always Allow to retain the grant.
Tokenmax 0.1.14
What’s new
A fix release. No new surfaces — three things that were quietly costing you.
- Tokenmax no longer pins a CPU core, and Settings opens promptly. The one-second countdown clock shared an observable object with the quota readings, and SwiftUI invalidates per object rather than per property — so every view holding that reference rebuilt once a second, four times over with two providers. General answered each one by relaying out a several-hundred-row form, which saturated the main thread and left clicks queued behind a layout pass. The clock is now its own object, observed only where a label actually counts down. Countdowns, auto-run and the session opener keep their one-second resolution.
- Side Notch settings apply immediately. Settings had been driving a parallel, unstarted copy of the app's stores, so enabling the notch or changing its colours only took effect at the next launch. Provider rings also gained headroom inside their cards, so full outer arcs no longer clip against the selected-state border.
make installbuilds Release. It followed the defaultCONFIG, which is Debug — so 0.1.13 installed itself into/Applicationsunoptimised, with assertions live. Only relevant if you build from source.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxTokenmax is signed but not notarized. On first launch, use System Settings → Privacy & Security → Open Anyway. A new binary also prompts once for Claude Code keychain access; choose Always Allow to retain the grant.
Tokenmax 0.1.13
What’s new
- Celebrate a confirmed quota reset. Optional full-screen confetti can mark session or weekly resets, respects quiet hours, and can be previewed from Settings.
- Choose your menu-bar shape. Keep compact bars or use nested rings, with freely assigned quota windows and optional escalation colours.
- Try Side Notch (Alpha). An optional, focus-free edge surface shows both providers’ live quota at the pointer.
- Tune reminders per window. Claude Code and Codex session/weekly windows each have independent on/off, timing and threshold choices.
- Clearer recovery and settings. Settings stays visible in the menu-bar right-click menu, and General now separates menu-bar, Side Notch, queue and diagnostics controls.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxTokenmax is signed but not notarized. On first launch, use System Settings → Privacy & Security → Open Anyway. A new binary also prompts once for Claude Code keychain access; choose Always Allow to retain the grant.
Tokenmax 0.1.12
What's new
Both changes are about the same thing: how often Tokenmax has to ask macOS for
the Claude Code credential, and therefore how often you see the consent dialog.
A rejected token no longer costs a keychain read every five minutes
When the quota endpoint refused the saved credential, Tokenmax dropped it and
read the keychain again on the next tick — but until Claude Code writes a new
token, the item still holds the one that was just refused, so the read could
only return the same credential and, for anyone who answered the dialog with
Allow, raise another one. Measured across a week of real logs, 64 of 176
reads were this loop, stacking dialogs minutes apart while the app looked idle.
Tokenmax now notes when Claude Code last wrote the item and waits for that to
move before reading again. The modification date is an attribute rather than
the secret, so watching it needs no consent and raises no dialog. The wait ends
by itself the moment Claude Code renews; Refresh ends it early, and a
relaunch clears it.
A token past its expiry no longer forces a read either
Same argument from the other side. An expired credential used to be dropped on
sight, assuming the keychain held something newer — when Claude Code has not
written since, it does not. Tokenmax now serves the token it has and lets the
endpoint judge it, which is what the expiry timestamp was always treated as: a
hint, never a reason to refuse to try.
Both rules are one sentence: go back to the keychain when, and only when,
Claude Code has written to it.
What this does not fix
The dialog you get roughly once or twice a day is Claude Code rotating its own
token: that write evicts the grant, and the read that follows is one Tokenmax
genuinely needs. This release removes the extra dialogs around it — about one
in six — not that one. If you want none at all, Settings → Data Source →
Status line only never touches the keychain; install the shim first, and note
that automatic task runs pause in that mode.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxTokenmax is signed but not notarized, so first launch requires System
Settings → Privacy & Security → Open Anyway. Because this is a new binary,
Keychain monitoring will ask once for access; choose Always Allow, which is
the only button that records a grant.
Tokenmax 0.1.11
What's new
Banked Codex reset credits, visible in the popover
When Codex reports promotional rate-limit resets, Tokenmax now shows the
available count and nearest expiry below the Codex meters. It stays
read-only — redeeming a reset changes your account allowance, so that still
happens in Codex, where the offer can be reviewed and confirmed.
Reset countdowns now show the local clock time too
Next to "Resets in 1h 56m" the popover now names the actual time that lands
at, in your Mac's timezone and hour format. The session window shows just
the time; the weekly window shows weekday plus time, since that reset is
days out rather than hours.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxTokenmax is signed but not notarized, so first launch requires System
Settings → Privacy & Security → Open Anyway. Because this is a new binary,
Keychain monitoring may ask once for access; choose Always Allow if you
want macOS to record the grant.
Tokenmax 0.1.10
What’s new
Claude credential recovery that explains the real state
A Claude Code conversation can stay active on its existing connection while Tokenmax’s older saved Keychain credential is rejected by the quota endpoint. Tokenmax now says that plainly instead of implying your working session is broken.
When a fresh status-line quota reading is available, Tokenmax uses it while waiting for the saved credential to renew. If Claude Code does not renew it on its own, Open Terminal + Copy Login opens your configured terminal and copies claude login for a deliberate recovery. Tokenmax still never refreshes or writes your Claude credential itself.
Codex quota reads restored
Codex CLI 0.149 removed the old -a untrusted approval policy. Tokenmax now uses the supported never policy for its read-only App Server query, restoring Codex quota and model reads.
Correct Keychain log path
The troubleshooting guide now points directly to the real diagnostic log:
~/Library/Application Support/Tokenmax/logs/tokenmax.log
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxTokenmax is signed but not notarized, so first launch requires System Settings → Privacy & Security → Open Anyway. Because this is a new binary, Keychain monitoring may ask once for access; choose Always Allow if you want macOS to record the grant.
Tokenmax 0.1.9
What’s new
A zero-Keychain-prompt monitoring option
Tokenmax can now monitor Claude through its documented status-line data without reading Claude Code’s Keychain item. Choose Settings → Data Source → Status line only for zero Tokenmax credential prompts.
Status-line readings update while Claude Code is active. Per-model weeklies, the plan name and usage-credit flag are unavailable, and unattended automation pauses because this source cannot safely verify spending. Manual task runs still work.
Fewer prompts in Keychain mode
- A Deny is remembered until you explicitly click Refresh; background timers and automatic verification cannot reopen the question.
- Simultaneous credential callers now share one in-flight read instead of potentially stacking duplicate dialogs.
- Allow covers one read. Always Allow records a grant for the current credential item.
Diagnosing Keychain prompts
Tokenmax now records every Keychain read so an unexpected prompt can be investigated instead of guessed at. Run:
make logsOr open:
~/Library/Application Support/Tokenmax/logs/tokenmax.log
Each Keychain entry records:
- why the read occurred, such as
nothing cached yetorcached token expired; - the result and elapsed time;
- whether it was silent or likely waited on a consent dialog;
- when Claude Code last modified the credential item;
- the Tokenmax binary’s code hash at launch, so prompts caused by a new build can be identified.
Timing is evidence rather than proof—macOS does not directly tell Tokenmax that it displayed the dialog. When reporting an unexpected prompt, include the surrounding keychain: and launch: cdhash lines.
Install or upgrade
brew install --cask danieldrinhausen/tap/tokenmaxTokenmax is signed but not notarized, so first launch still requires System Settings → Privacy & Security → Open Anyway. Keychain monitoring also asks once for the new binary; choose Always Allow if you want macOS to record the grant.
Tokenmax 0.1.8
Tokenmax 0.1.8
The macOS prompt for Claude Code-credentials offers Allow as well as
Always Allow, and only Always Allow records a grant — Allow covers a
single read. Tokenmax used to read the keychain on every refresh, so anyone who
took the middle button met the dialog every 60 seconds with the popover open,
and every 300 seconds behind it.
Credentials are now held in memory for as long as the app runs, so the worst
case is one prompt per launch instead of one per refresh. Nothing is written to
disk, no token is used past its expiry, and a token the endpoint rejects is
dropped so Claude Code's rotation is picked up straight away.
Two things worth knowing. Answer the prompt with Always Allow and you
will not see it again until the next version. And installing this release costs
you one prompt: a new version is a new binary, and macOS attaches the grant to
the build's code hash. Tokenmax is signed but not notarized — that would need a
paid Apple developer account — so the same is true of every update, and the
first launch still needs System Settings → Privacy & Security → Open Anyway.
If the dialog still returns for a version you have already allowed with Always
Allow, that is a bug worth reporting; docs/TROUBLESHOOTING.md walks through it.
brew install --cask danieldrinhausen/tap/tokenmax
brew upgrade --cask tokenmax follows releases from a tap that tracks this
repository. The download is the same signed, unnotarized image, so Open Anyway
applies there too.