Skip to content

Tokenmax 0.1.12

Choose a tag to compare

@danieldrinhausen danieldrinhausen released this 28 Aug 11:45
· 67 commits to main since this release

What's new

Both changes are about the same thing: how often Tokenmax has to ask macOS for
the Claude Code credential, and therefore how often you see the consent dialog.

A rejected token no longer costs a keychain read every five minutes

When the quota endpoint refused the saved credential, Tokenmax dropped it and
read the keychain again on the next tick — but until Claude Code writes a new
token, the item still holds the one that was just refused, so the read could
only return the same credential and, for anyone who answered the dialog with
Allow, raise another one. Measured across a week of real logs, 64 of 176
reads were this loop, stacking dialogs minutes apart while the app looked idle.

Tokenmax now notes when Claude Code last wrote the item and waits for that to
move before reading again. The modification date is an attribute rather than
the secret, so watching it needs no consent and raises no dialog. The wait ends
by itself the moment Claude Code renews; Refresh ends it early, and a
relaunch clears it.

A token past its expiry no longer forces a read either

Same argument from the other side. An expired credential used to be dropped on
sight, assuming the keychain held something newer — when Claude Code has not
written since, it does not. Tokenmax now serves the token it has and lets the
endpoint judge it, which is what the expiry timestamp was always treated as: a
hint, never a reason to refuse to try.

Both rules are one sentence: go back to the keychain when, and only when,
Claude Code has written to it.

What this does not fix

The dialog you get roughly once or twice a day is Claude Code rotating its own
token: that write evicts the grant, and the read that follows is one Tokenmax
genuinely needs. This release removes the extra dialogs around it — about one
in six — not that one. If you want none at all, Settings → Data Source →
Status line only
never touches the keychain; install the shim first, and note
that automatic task runs pause in that mode.

Install or upgrade

brew install --cask danieldrinhausen/tap/tokenmax

Tokenmax is signed but not notarized, so first launch requires System
Settings → Privacy & Security → Open Anyway
. Because this is a new binary,
Keychain monitoring will ask once for access; choose Always Allow, which is
the only button that records a grant.