Repository navigation
Tokenmax 0.1.8
Tokenmax 0.1.8
The macOS prompt for Claude Code-credentials offers Allow as well as
Always Allow, and only Always Allow records a grant — Allow covers a
single read. Tokenmax used to read the keychain on every refresh, so anyone who
took the middle button met the dialog every 60 seconds with the popover open,
and every 300 seconds behind it.
Credentials are now held in memory for as long as the app runs, so the worst
case is one prompt per launch instead of one per refresh. Nothing is written to
disk, no token is used past its expiry, and a token the endpoint rejects is
dropped so Claude Code's rotation is picked up straight away.
Two things worth knowing. Answer the prompt with Always Allow and you
will not see it again until the next version. And installing this release costs
you one prompt: a new version is a new binary, and macOS attaches the grant to
the build's code hash. Tokenmax is signed but not notarized — that would need a
paid Apple developer account — so the same is true of every update, and the
first launch still needs System Settings → Privacy & Security → Open Anyway.
If the dialog still returns for a version you have already allowed with Always
Allow, that is a bug worth reporting; docs/TROUBLESHOOTING.md walks through it.
brew install --cask danieldrinhausen/tap/tokenmax
brew upgrade --cask tokenmax follows releases from a tap that tracks this
repository. The download is the same signed, unnotarized image, so Open Anyway
applies there too.