Repository navigation
-
Native extra usage. Exact-profile
provider_managedopt-in permits bounded native
OAuth extra usage under provider account controls;observe_onlyremains the default.
API-key authorization stays separate. No provider switching or billing-setting changes. -
Quota-failed continuation. Eligible tasks resume their original session, model and
retained work with atomic account-scoped admission, fresh authorization checks and durable
refusal evidence. Schema 9 preserves historical billing as unknown. -
Usage visibility. Workers and Usage expose policy, admission, native billing observations
and classification separately from estimated token costs. Live extra-usage billing remains
unqualified; seedocs/native-overage.mdfor activation and qualification guidance. -
Explicit model and effort selection. Built-in Claude and Grok task selections are
forwarded and confirmed after opening or restoring sessions, including bounded Grok
configuration transitions. -
Controlled worker recovery. Codex and the CLI can arm one explicit "Retry next task"
permit against the current account/model refusal evidence. Schema 7 records a single active
permit per shared provider availability key, with a 24-hour deadline, revocation, permanent
task association, and outcome history. Arming and revoking run no provider checks or prompts. -
Bounded initial attempts. Task creation validates grants, provider/model scope and review
independence before atomically consuming the permit. Preparation or startup failure consumes
it. Dispatch and initial prompt admission reject changed refusals and expired permits; future
quota restrictions with a reported future reset and fresh native exhaustion cannot be bypassed.
An explicitly authorized missing-reset throttle remains eligible for its one exact permit. A
successful turn clears only the evidence it tested. Existing continuations remain compatible;ignore_provider_statusis
recognized only to returnLEGACY_OVERRIDE_RETIRED. -
Durable quota windows and post-reset retries. Schema 8 retains every applicable quota window
with scope, model family, reset, source, observation and opaque fingerprint. Changed authentication
context invalidates recovery authorization without clearing restrictions. After reset, aliases of
a shared OAuth seat atomically claim one ordinary retry;QUOTA_RETRY_PENDINGprevents duplicates.
Unaffected model families retain their ordinary capacity and grant eligibility. -
Read-only recovery visibility. Cached capabilities, provider status and the Workers screen
expose evidence revisions, armed/pending recovery, deadlines, associated tasks and outcomes.
The dashboard supplies copyable CLI instructions and adds no recovery mutation endpoint.
Billing remains advisory and separate; scheduled collection stays opt-in and disabled. -
Isolated packaging smoke. MCP smoke tests now pass temporary XDG paths directly to the
child process, preventing a packaging check from opening the installed runtime's database.