You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Floating this as a thought to gauge whether it fits scope before writing a full design.
The use case
Plenty of us run more than one Claude identity on the same machine, and codeburn blends them into one total. A few common shapes:
two subscriptions — a personal Max plan and a separate work login;
a personal login + a work service-id token injected as an env var (ANTHROPIC_API_KEY / ANTHROPIC_AUTH_TOKEN), billed to a different (often corporate) workspace;
two API keys for two projects/clients.
They all write to the same ~/.claude/projects/… transcripts, so codeburn's totals mix them. I'd love the bill split by identity — "this was my personal plan, that was the work token" — which is really a question of who pays for what. Since codeburn's core is measuring and attributing usage, this felt in-theme.
What I checked first
Transcripts carry no per-session identity. The only identity-ish fields in the session JSONL are userType (constant "external") and entrypoint ("cli"); service_tier is a constant "standard". Nothing records which account or token produced a session.
Account identity exists as a live snapshot in ~/.claude.json → oauthAccount (accountUuid, emailAddress, organizationUuid, billingType, org role) plus a top-level userID — but it reflects whoever is logged in now.
No per-key trace is stored — no approved-key hash or token record anywhere in config. An env-var token overrides OAuth per-process at runtime and leaves the config untouched.
Paths that work — and that don't
Fully automatic, retroactive split isn't possible; the signal isn't in the data. Forward-looking is, in two tiers:
✅ Works — telling OAuth accounts apart (the two-subscriptions case). codeburn reads ~/.claude.json → accountUuid on each scan, snapshots a hash, and logs a diff when it flips (a real login switch). Sessions observed after a switch get attributed to the new account. Reuses config it can already see; privacy-safe (hash the id, no email needed).
✅ Works — telling an env-var token apart from a login (the token case), via a launch hook. An env token is traceless after the fact, so it has to be captured at session start — a guard-style hook that hashes the active ANTHROPIC_API_KEY/AUTH_TOKEN (SHA prefix, never the raw key) and records "session at time T used auth-hash X." The parser then correlates the timestamp with the session. Opt-in, forward-only, no secret at rest.
❌ Doesn't work — config snapshot alone for the token case. Setting the env var does not change ~/.claude.json, so a config-only diff sees no change during token sessions — it catches account logins, not token overrides.
❌ Doesn't work — attributing the past. No identity is recorded historically, so anything before instrumentation stays unattributed.
Ask
@iamtoruk, does the two-tier shape (config snapshot for account logins + an opt-in launch hook for env-token identity) feel right? Let me know if this clicks; would be happy to raise a full design issue and prototype it.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Floating this as a thought to gauge whether it fits scope before writing a full design.
The use case
Plenty of us run more than one Claude identity on the same machine, and codeburn blends them into one total. A few common shapes:
ANTHROPIC_API_KEY/ANTHROPIC_AUTH_TOKEN), billed to a different (often corporate) workspace;They all write to the same
~/.claude/projects/…transcripts, so codeburn's totals mix them. I'd love the bill split by identity — "this was my personal plan, that was the work token" — which is really a question of who pays for what. Since codeburn's core is measuring and attributing usage, this felt in-theme.What I checked first
userType(constant"external") andentrypoint("cli");service_tieris a constant"standard". Nothing records which account or token produced a session.~/.claude.json → oauthAccount(accountUuid,emailAddress,organizationUuid,billingType, org role) plus a top-leveluserID— but it reflects whoever is logged in now.Paths that work — and that don't
Fully automatic, retroactive split isn't possible; the signal isn't in the data. Forward-looking is, in two tiers:
✅ Works — telling OAuth accounts apart (the two-subscriptions case). codeburn reads
~/.claude.json → accountUuidon each scan, snapshots a hash, and logs a diff when it flips (a real login switch). Sessions observed after a switch get attributed to the new account. Reuses config it can already see; privacy-safe (hash the id, no email needed).✅ Works — telling an env-var token apart from a login (the token case), via a launch hook. An env token is traceless after the fact, so it has to be captured at session start — a
guard-style hook that hashes the activeANTHROPIC_API_KEY/AUTH_TOKEN(SHA prefix, never the raw key) and records "session at time T used auth-hash X." The parser then correlates the timestamp with the session. Opt-in, forward-only, no secret at rest.❌ Doesn't work — config snapshot alone for the token case. Setting the env var does not change
~/.claude.json, so a config-only diff sees no change during token sessions — it catches account logins, not token overrides.❌ Doesn't work — attributing the past. No identity is recorded historically, so anything before instrumentation stays unattributed.
Ask
@iamtoruk, does the two-tier shape (config snapshot for account logins + an opt-in launch hook for env-token identity) feel right? Let me know if this clicks; would be happy to raise a full design issue and prototype it.
All reactions