junhoyeo/tokscale
57.6
Adequate · 30 September 2026
241.6k
lines of production code
Rust
with TypeScript
2
measurements over time
What this system is
Tokscale is a cross-platform CLI and web platform for tracking, aggregating, and visualizing AI coding assistant usage. The Rust-based CLI collects local session data from various IDEs and tools, while the Next.js frontend provides a public leaderboard, user profiles, and group-based analytics. It handles complex data reconciliation, cost calculation, and secure authentication to offer detailed insights into token consumption and spending.
How it got here
2025 — Tokscale rebrand and Rust migration
33 changes.
The project was rebranded to Tokscale and underwent a major architectural shift from TypeScript to a Rust-based CLI with multi-platform binary support. Concurrently, the frontend was rebuilt using Next.js and styled-components, introducing comprehensive authentication, usage tracking, and public profile features.
2026 — Rust CLI rewrite and group features
51 changes.
The project underwent a major architectural shift by rewriting the CLI in Rust, introducing a feature-rich TUI with multi-language support and native Apple AI integration. Concurrently, the platform expanded its social capabilities by implementing comprehensive group management, scoped leaderboards, and self-service account controls. This period also saw significant enhancements to the core aggregation engine, pricing subsystem, and frontend SEO and moderation infrastructure.
Features
Add GitHub profile badge API endpoint
A new API route at /api/badge/\[username\]/svg has been added to generate shields.io-style SVG badges for GitHub profiles. Users can request badges by providing a GitHub username, with optional query parameters to customize the displayed metric (tokens, cost, or rank), visual style (flat or flat-square), sort order, compact mode, label, and color. The endpoint validates the username, fetches embed statistics, and returns the generated SVG with appropriate caching headers.
packages/frontend/src/app/api/badge · high confidence
Add Local Data Viewer page with client-side styling
A new Local Viewer page has been added at /local, allowing users to inspect token usage data exports directly in their browser without uploading files. The page uses a client component for interactivity and styled-components for layout, featuring a data input section and a summary view with cost and activity metrics. The page is marked as non-indexable to prevent search engine indexing of the empty shell.
packages/frontend/src/app/local · high confidence
Add SEO metadata, sitemap generation, and canonical URL helpers
The frontend now includes a dedicated SEO library that provides Open Graph and Twitter card metadata for the home page, generates a structured sitemap.xml covering core pages (home, leaderboard, legal pages) and dynamic user/group profiles, and centralizes canonical URL construction to ensure consistency between sitemaps and page-level canonical tags. This ensures search engines receive accurate, verifiable last-modified timestamps based on actual submission activity rather than build times, and prevents indexing of non-indexable or redirect-only routes.
packages/frontend/src/lib/seo · high confidence
Add TypeScript support for static image imports
A new TypeScript declaration file has been added to allow importing static image assets (specifically .png files) with correct type checking, ensuring they are recognized as Next.js StaticImageData.
packages/frontend/src/types · high confidence
Add device authorization page with styled-components UI
The device authorization flow is now available via a new client-side component (DeviceClient) and a corresponding Next.js page that sets dynamic metadata. The UI is built using styled-components instead of utility classes, featuring a card-based layout for GitHub sign-in, a numeric code input field, and success/error states.
packages/frontend/src/app/device · high confidence
Add device code authentication flow for CLI access
The frontend now includes a new device code authentication API under /api/auth/device, enabling users to generate device codes for CLI or headless tool access. This flow consists of three endpoints: generating a device and user code pair, authorizing the code via the web interface, and polling for completion to receive a personal access token. The implementation ensures atomic claim of device codes to prevent race conditions and serializes polling to avoid duplicate token issuance.
packages/frontend/src/app/api/auth/device · high confidence
Add frontend static assets and PWA configuration
The frontend now includes a set of new static assets in the public directory to support branding and progressive web app (PWA) functionality. This includes a \site.webmanifest\ file that configures the app as a standalone PWA with specific Android Chrome icons, a custom \tokscale-logo.svg\, and standard Next.js placeholder assets (file, globe, next, vercel, window SVGs). Additionally, a \sample-data.json\ file has been added, containing mock usage statistics and token cost data for various AI models and sources, likely intended for demonstration or testing purposes.
packages/frontend/public · high confidence
Add group creation, detail, and invite acceptance pages with scoped leaderboards
Users can now create new groups, view detailed group pages with scoped leaderboards, and accept join invitations via unique tokens. The previous standalone /groups listing page has been removed and now redirects to the leaderboard's group view. Group detail pages include Open Graph cards for social sharing, and private groups are protected from non-members.
packages/frontend/src/app/(main)/groups · high confidence
Add local session parsers for Amp, Antigravity, Augment, Cline, CodeBuddy, and Codebuff
The sessions module now includes dedicated parsers for several new local session sources: Amp (Sourcegraph), Antigravity, Augment (Auggie CLI), Cline, CodeBuddy, and Codebuff. These parsers read local JSON/JSONL files and SQLite stores to extract token usage, model identity, and session metadata, integrating them into the unified message format for consistent tracking and reporting.
crates/tokscale-core/src/sessions · high confidence
Add placeholder for Android ARM64 CLI binary
A .gitkeep file has been added to the bin directory of the cli-android-arm64 package. This serves as a placeholder to ensure the directory structure is tracked in version control, likely in preparation for future inclusion of the actual prebuilt binary for the Android ARM64 architecture.
packages/cli-android-arm64 · medium confidence
Add self-service account deletion endpoint
Users can now permanently delete their account and all associated data (sessions, API tokens, submissions, group memberships) via a new DELETE endpoint at /api/settings/account. The operation requires session authentication, clears the session cookie, and invalidates relevant caches (leaderboards, user profiles) to ensure consistency.
packages/frontend/src/app/api/settings/account · high confidence
Add usage tracking for Amp, Antigravity, Claude, Codex, Copilot, Grok, Kimi, and MiniMax providers
The \tokscale-cli\ usage command now supports fetching subscription quotas and usage metrics for a wide range of AI coding tools. This includes reading credentials from local files or system keychains (Amp, Claude, Kimi, MiniMax), querying cloud APIs (Grok, MiniMax), and communicating with local language servers (Antigravity). It also handles multi-account scenarios (Codex) and Windows-specific credential stores (Copilot).
crates/tokscale-cli/src/commands/usage · high confidence
Added API routes for session retrieval and logout
New API endpoints have been introduced to manage user authentication state. The \/api/auth/session\ route allows clients to retrieve the current user session via a GET request, while the \/api/auth/logout\ route enables session termination via a POST request. These changes provide the frontend with explicit server-side mechanisms to check login status and log out users.
packages/frontend/src/app/api/auth/logout, packages/frontend/src/app/api/auth/session · high confidence
Added Contact, Privacy, and Terms of Service pages
The Tokscale frontend now includes dedicated pages for Contact, Privacy Policy, and Terms of Service. Users can find contact information for bug reports and privacy inquiries, review details on data collection (specifically that prompts and source code are never collected), understand the public nature of the leaderboard data, and learn about acceptable use and cost estimate limitations. These pages are accessible via the main application layout and link to the settings page for data deletion options.
packages/frontend/src/app/(main)/contact, packages/frontend/src/app/(main)/privacy, packages/frontend/src/app/(main)/terms · high confidence
Frontend library refactoring and new client support
The frontend library has been restructured with new modules for handling client metadata, formatting, and settings. A comprehensive list of supported AI clients is now defined in constants, including display names, logos, and colors for tools like Devin, Kilo, and DeepSeek Harness. New utility functions handle date formatting with local timezone support, compact number/currency display, and relative time strings. User preferences for color palettes, leaderboard sorting, and display timezones are now managed via a centralized settings hook with localStorage persistence. Additionally, new API endpoints provide public profile data and per-device usage breakdowns, while UI enhancements include squircle border support and responsive breakpoint utilities.
packages/frontend/src/lib · high confidence
Frontend scaffolding and embed template gallery tooling
The frontend package has been initialized with a Next.js configuration that enables styled-components for styling, standalone output for Docker/Node deployments, and security headers. It includes a middleware to protect the /settings route, a Drizzle ORM configuration for PostgreSQL, and an ESLint setup. Additionally, a new gallery tooling script has been added to generate a standalone HTML preview of all embed card templates, allowing users to visualize and test template variations locally.
packages/frontend · high confidence
Introduce Rust CLI with TUI and comprehensive client integrations
The CLI has been rewritten in Rust, replacing the previous TypeScript implementation with a unified command-line interface and a terminal user interface (TUI). This release adds support for a wide range of AI coding clients, including Cursor, Antigravity, Trae, Hindsight, and Claude, enabling local session parsing and usage tracking. The new CLI features configurable model grouping strategies, date filtering, and a \--light\ mode for static reports. It also introduces new commands for authentication (login/logout/whoami), QR code token transfer, and scheduled autosubmit, while consolidating configuration and cache directories under \\~/.config/tokscale\.
crates/tokscale-cli/src · high confidence
Introduce TUI data models and loader for usage analytics
The TUI now includes a dedicated data layer (\tokscale-cli/src/tui/data\) that aggregates usage metrics into structured views for the interface. This change introduces specific data models for daily, hourly, minutely, and monthly usage breakdowns, as well as per-session and per-project rollups. Users will see these new data structures powering the Sessions, Projects, and time-based tabs in the CLI, enabling detailed tracking of token counts, costs, and message turns across different clients and models.
crates/tokscale-cli/src/tui/data · high confidence
Introduce new TUI tabs and usage breakdown views
The TUI now includes dedicated tabs for Agents, Daily, Hourly (with a profile view), and Minutely usage breakdowns, along with a stacked bar chart for model-level token visualization. These views provide granular insights into token consumption, costs, and usage patterns over time, with responsive layouts that adapt to terminal width and support multi-language headers.
crates/tokscale-cli/src/tui/ui · high confidence
Introduce parallel aggregation and incremental daily folding for session data
The core library now uses Rayon for parallel map-reduce operations to aggregate session messages into daily and per-session contributions, significantly improving performance for large datasets. An incremental \DailyFold\ structure allows callers to fold messages one at a time, reducing peak memory usage by avoiding the need to materialize the entire message corpus in memory. The aggregation logic also includes fixes for integer overflow saturation in token totals and normalizes floating-point cost sums to prevent \-0.00\ rendering in reports.
crates/tokscale-core/src · high confidence
Introduce scoped group leaderboards with invite-based membership
Users can now create and join groups to see personalized, filtered leaderboards. This change adds the core backend logic for group management, including creating and accepting secure invites, enforcing role-based permissions (owner, admin, member), and generating unique group slugs. It also introduces a new group-specific leaderboard query that aggregates usage data per group member, allowing users to view rankings scoped to their specific group rather than the global platform.
packages/frontend/src/lib/groups · high confidence
Introduce submit API route with robust usage merging and device-aware reconciliation
Added the \packages/frontend/src/app/api/submit/route.ts\ file, which implements the backend logic for processing usage submissions. This route handles authentication via personal tokens, validates incoming data, and manages complex merging of client breakdowns while preventing double-counting from legacy aliases (e.g., 'kilocode' to 'kilo'). It includes safeguards for device-aware reconciliation, parser high-water mark tracking, and cost completeness assertions to ensure data integrity across daily breakdowns and device snapshots.
packages/frontend/src/app/api/submit · high confidence
Introduces Ratchet Census report generation for reconciliation gates
Added a new \ratchetCensus.ts\ module that builds Phase 1 reconciliation gate inputs from a PostgreSQL snapshot. This component defines Zod schemas for validating census reports and provides a \getRatchetCensusReport\ function to query coverage, divergence bands, and candidate metrics. It also includes a \normalizeRatchetCensusCandidateLimit\ utility to safely parse candidate limits, enabling the frontend to expose reconciliation census gate inputs.
packages/frontend/src/lib/reconciliation · high confidence
Introduces reusable Open Graph card components for image generation
Added \OgCard.tsx\ to provide shared building blocks for generating Open Graph images via Satori. This component introduces a branded card shell featuring the Manrope and Pretendard font families, the tokscale.ai wordmark, and a dedicated \OgStat\ component for displaying metrics, ensuring consistent visual styling for profile and group cards.
packages/frontend/src/components/og · high confidence
Native Rust Apple Foundation Models FFI bindings added
The \tokscale-cli\ vendor directory now includes a native Rust implementation for interacting with Apple's Foundation Models framework via C FFI, replacing the previous Python-based approach. This change adds the \foundation-models-c\ Swift package (licensed under Apache 2.0) which exposes a C ABI for system language models, session management, prompt composition, and tool bridging. Users on macOS can now leverage these native bindings when the \apple-fm\ Cargo feature is enabled, allowing the CLI to call Apple's AI capabilities directly from Rust without requiring a Python runtime.
crates/tokscale-cli/vendor · high confidence
New /api/me/stats endpoint for multi-device usage aggregation
A new GET /api/me/stats API route has been added to provide usage statistics aggregated across all devices associated with the authenticated user. This endpoint, designed for the CLI TUI, returns total tokens, total cost, a list of registered devices with their last submission timestamps, and a daily breakdown of token usage (input, output, and cost). It requires a valid personal API token for authentication and includes a schema version to ensure compatibility with clients.
packages/frontend/src/app/api/me · high confidence
New API endpoint for validating personal access tokens
A new GET endpoint at /api/auth/token has been added to support non-interactive authentication. Users can now send a Bearer token in the Authorization header to validate their personal access token. The endpoint returns user details (username, display name, avatar URL) for valid tokens, and returns specific error messages for missing, invalid, or expired tokens, enabling programmatic access without interactive login flows.
packages/frontend/src/app/api/auth/token · high confidence
New API endpoint to fetch individual user leaderboard rank
A new API route at \/api/leaderboard/user/\[username\]\ has been added, allowing clients to retrieve the specific rank of a single user. This endpoint supports filtering by time period (all, month, last-month, week, or custom date ranges) and sorting by tokens or cost, with a 60-second revalidation cache to optimize performance.
packages/frontend/src/app/api/leaderboard/user · high confidence
New API endpoint to rename device display names
A new PATCH endpoint at /api/settings/devices/\[deviceId\] has been added, allowing users to update or clear the display name of their registered devices. The implementation enforces ownership by matching the device ID against the authenticated user's ID, ensuring cross-user rename attempts fail silently with a 404. It validates input to prevent control characters and limits names to 120 characters, then updates the database and immediately invalidates relevant cache tags to ensure the new name appears on profile and settings pages without delay.
packages/frontend/src/app/api/settings/devices · high confidence
New API endpoint to retrieve a user's groups
A new API route at /api/users/\[username\]/groups has been added, allowing clients to fetch the list of groups associated with a specific user. The endpoint supports private group visibility for the user themselves, while public groups are visible to others, and includes details such as group name, slug, description, avatar, and member count.
packages/frontend/src/app/api/users/\[username\]/groups · high confidence
New API endpoints for managing personal access tokens
The application now exposes dedicated API routes for personal token management within the settings area. Users can create new tokens with optional names via a POST request to the tokens collection endpoint, retrieve a list of existing tokens with their metadata via GET, and revoke specific tokens using a DELETE request to the individual token endpoint. These endpoints enforce session-based authentication and handle token lifecycle operations such as issuance, listing, and revocation.
packages/frontend/src/app/api/settings/tokens · high confidence
New SVG embed API with customizable templates and 3D views
Users can now generate customizable SVG profile embeds via the new \/api/embed/\[username\]/svg\ endpoint. This feature supports multiple visual templates (such as graph, vitals, blueprint, and terminal styles), allows configuration of themes (light/dark), colors, and number formats, and introduces a new isometric 3D view for contribution graphs. The API also includes query parameters for sorting (by cost or tokens), compact mode, and date range selection, providing flexible options for displaying usage statistics and ranks.
packages/frontend/src/app/api/embed · high confidence
New SVG embed templates and 3D contribution graph
The embed system now supports a wider variety of visual styles and data views. Users can choose from new card templates including Blueprint, Graph, Orbit, Receipt, and Terminal, in addition to the existing Classic and Minimal designs. A new isometric 3D contribution graph view is available, allowing users to visualize activity with 3D cubes. The embeds also support weekly and monthly time periods, compact display modes, and customizable color themes.
packages/frontend/src/lib/embed · high confidence
New TUI dialogs for grouping, client selection, and language settings
The TUI now includes a set of modal dialogs for key configuration tasks. Users can change how data is grouped using the Group By Picker (supporting Model, Client, Session, and Workspace strategies), toggle which clients appear in reports via the Client Picker (including a Synthetic option), and switch the interface language among English, Korean, Japanese, Simplified Chinese, and French. A ConfirmDialog is also provided for account management actions like switching, removing, or resetting Codex accounts. These dialogs are managed by a new DialogStack that handles overlay rendering, keyboard navigation, and mouse interactions.
crates/tokscale-cli/src/tui/ui/dialog · high confidence
New admin moderation and reconciliation census API endpoints
This change introduces three new API routes under the admin area to support moderation workflows and reconciliation reporting. The \/admin/moderation/\[username\]\ endpoint allows administrators to view a user's moderation history and apply actions (such as hiding a user from the leaderboard) with a mandatory reason, while the \/admin/moderation/candidates\ endpoint lists users flagged for moderation review. Additionally, the \/admin/reconciliation/census\ endpoint exposes a ratchet census report, accepting an optional candidate limit parameter to filter the results.
packages/frontend/src/app/api/admin · high confidence
New admin moderation interface for hiding suspect accounts
Administrators now have a dedicated moderation page at /admin/moderation to review and manage suspect accounts. This interface allows admins to hide accounts from the public leaderboard without deleting their profiles or badges, with every action requiring a selected reason (e.g., "Abuse," "Under investigation," or "Data issue on our side") to maintain a clear audit trail. The feature specifically addresses false positives caused by internal ratchet inflation bugs by distinguishing between genuine abuse and data issues in the recorded reasons.
packages/frontend/src/app/admin · high confidence
New benchmark infrastructure for measuring CLI performance
Added a new benchmarking package that provides tools to measure and compare the performance of the Tokscale CLI's graph command. The suite includes a synthetic data generator (generate.ts) that creates realistic test data for OpenCode, Claude, Codex, and Gemini clients, and a benchmark runner (runner.ts) that measures wall-clock time and peak memory usage. The infrastructure supports running benchmarks against real user data or synthetic datasets, allows for configurable iterations and warmup periods, and outputs detailed JSON results for CI integration and performance tracking.
packages/benchmarks · high confidence
New database schema and submission reconciliation logic for usage tracking
The \packages/frontend/src/lib/db\ module has been significantly expanded with a new Drizzle ORM schema (\schema.ts\) and a suite of new TypeScript modules to handle complex usage data reconciliation. Key additions include \parserHighWater.ts\ for managing per-client lifetime high-water marks, \antigravityStateCoverage.ts\ and \antigravityTransition.ts\ to atomically reconcile overlapping usage from the Antigravity desktop, CLI, and IDE extension, and \micodeTransition.ts\ for similar family-based reconciliation for MiMo sources. The module also introduces \deviceClientTotals.ts\ for tracking per-device, per-client high-water marks in a shadow table, \dailyBreakdownReported.ts\ for an unguarded last-write-wins shadow of daily breakdowns, and \helpers.ts\ with updated merge logic that preserves provenance and handles regression guards. The database connection singleton (\index.ts\) has been hardened for serverless environments with optimized pool settings.
packages/frontend/src/lib/db · high confidence
New group management API endpoints
This change introduces a comprehensive set of API routes for managing groups, including creating groups, listing public or user-specific groups, and handling group membership. Key capabilities include inviting users with role-based access control, transferring ownership with race-condition protection, updating member roles, and leaving groups. It also adds a scoped leaderboard endpoint with pagination and filtering, as well as endpoints for accepting group invites. All endpoints enforce authentication, authorization checks, and input validation to ensure secure group operations.
packages/frontend/src/app/api/groups · high confidence
New landing page at / with integrated leaderboard previews
The root route now serves a dedicated landing page that displays real-time GitHub stargazer counts and previews of the top 5 users from the leaderboard, sorted by both cost and tokens. This change introduces server-side data fetching for these metrics and establishes the canonical URL for the site.
packages/frontend/src/app/(main) · high confidence
New landing page component with integrated sections
A new LandingPage component has been added to the frontend, serving as the main container for the home page experience. It orchestrates several sub-sections including Hero, Quickstart, Worldwide (displaying leaderboard data), Description, Sponsor, Follow, and Footer. The component accepts props for GitHub stargazer counts and top users by cost/tokens, passing them to the relevant sections to display real-time or cached data.
packages/frontend/src/components/landing · high confidence
New moderation system for leaderboard visibility and review
This change introduces a new moderation subsystem that allows administrators to hide user accounts from the leaderboard without deleting them, while providing transparent notices to both the account owners and the public explaining the status and how to appeal. The system includes a review queue built on heuristics (such as token attribution completeness and model usage patterns) to identify suspicious accounts, and enforces strict admin-only access to moderation endpoints by returning 404s to non-admins to prevent probing.
packages/frontend/src/lib/moderation · high confidence
New pricing subsystem with robust model aliasing and custom overrides
The pricing logic in \tokscale-core\ has been restructured into a dedicated module (\crates/tokscale-core/src/pricing\) that introduces a comprehensive model aliasing system to resolve IDE-reported identifiers (such as Antigravity placeholders and Cursor tier names) to canonical pricing keys, ensuring accurate cost calculation. The system now supports custom pricing overrides via a \custom-pricing.json\ file, allowing users to define rates for models not covered by upstream datasets or to explicitly mark models as free. Additionally, the pricing cache has been hardened with atomic file writes to prevent data loss on crash, and the lookup engine includes stricter validation to reject unusable or zero-priced entries that do not cover the required usage buckets.
crates/tokscale-core/src/pricing · high confidence
New public API endpoints for listing and viewing per-device usage details
This change introduces two new public API routes under \/api/users/\[username\]/devices\. The first endpoint lists all devices associated with a public user profile, while the second provides detailed per-device usage statistics, including daily contribution breakdowns, total tokens, costs, and active days. These endpoints enable frontend components to display compact usage analysis and per-device breakdowns on public profiles and settings pages without requiring authentication for read access.
packages/frontend/src/app/api/users/\[username\]/devices · high confidence
New public profile API endpoint
A new API route at /api/users/\[username\] has been added to serve public profile data. This endpoint delegates to the existing getPublicProfileResponse function and includes a 60-second revalidation cache to optimize performance for public profile requests.
packages/frontend/src/app/api/users/\[username\] · high confidence
New release automation scripts and 9Router usage bridge
This change introduces a suite of new scripts in the \scripts/\ directory to support the release process and integrate 9Router usage data. It adds \calculate-release-version.sh\, \check-npm-release-state.sh\, \check-release-base-fresh.sh\, \check-version-coherence.sh\, and \prepare-release-provenance.sh\ to handle version bumping, npm state validation, release base staleness checks, and provenance management. It also includes \generate-release-notes.ts\ and \post-discord-release.sh\ for generating and posting release notes, \publish-npm-package.sh\ for publishing, and \check-workflow-toolchain-paths.py\ to ensure CI workflows respect toolchain changes. Additionally, it adds \9router\_tokscale\_bridge\_gjc.py\ and \9router\_custom\_pricing.json\ to bridge 9Router usage history into tokscale via gjc-format JSONL files, along with corresponding systemd service and timer units for scheduled execution.
scripts · high confidence
New settings page with API token management, device usage breakdown, and account deletion
Users can now access a dedicated settings page (/settings) to manage their account. This page allows users to view and create API tokens, see a per-device usage breakdown (including token counts, costs, and active days), set a display timezone for profile charts, and rename devices. It also introduces a 'Danger Zone' section for self-service data and account deletion. The implementation migrates the settings UI from Tailwind CSS to styled-components.
packages/frontend/src/app/settings · high confidence
Project renamed to Tokscale with new documentation and licensing
The project has been renamed from 'token-tracker' to 'tokscale', reflected in the new AGENTS.md, CONTRIBUTING.md, and localized README files. An MIT License file has been added to the repository, and the documentation has been updated to reflect the new name and structure.
(repo-wide) · high confidence
Redesigned public profile pages with usage breakdowns and embeddable stats
Public profiles now feature a comprehensive redesign that includes a usage-over-time chart, a token mix breakdown (input, output, cache, reasoning), per-device usage statistics, and a model usage table. The profile overview displays ranks and last-updated timestamps in the viewer's local timezone, while a new embed dialog allows users to generate customizable, themeable stat cards for sharing. The entire profile UI has been migrated from Tailwind CSS to styled-components.
packages/frontend/src/components/profile · high confidence
Rust CLI implementation with scheduled autosubmit, usage import, and Apple Intelligence summarization
The CLI now features a complete Rust implementation with new commands for managing scheduled usage submissions (autosubmit), importing historical usage from Clawdboard and ccusage exports, and generating reports. On macOS, the report summarizer uses native Apple FoundationModels FFI for on-device AI classification, falling back to a deterministic heuristic on other platforms. The autosubmit command integrates with OS schedulers (launchd, systemd, cron, Windows Task Scheduler) to automate periodic usage uploads, while the import command normalizes third-party data into the platform's native format for review or backfill submission.
crates/tokscale-cli/src/commands · high confidence
Self-service deletion of submitted usage data
Users can now permanently delete their submitted usage data and associated device records via a new API endpoint. This action removes all submissions linked to the user's account and triggers immediate cache invalidation for leaderboards, user profiles, and related public tags to ensure the changes are reflected instantly across the application.
packages/frontend/src/app/api/settings/submitted-data · high confidence
Tokscale TUI receives a major overhaul with new tabs, caching, and layout-independent hotkeys
The Tokscale TUI has been significantly updated to improve usability and performance. A new background data loading system with disk caching ensures instant startup, showing cached data while fresh data loads in the background. The interface now includes several new tabs: Sessions, Projects, Stats, and Agents, alongside existing ones like Overview, Usage, Models, Daily, Hourly, Minutely, and Monthly. To support a growing number of AI clients, the TUI now features layout-independent hotkeys that map physical key positions to Latin equivalents, allowing users on Cyrillic or Greek keyboard layouts to use shortcuts without switching languages. Additionally, the TUI now supports multiple display languages (English, Korean, Japanese, Simplified Chinese, French) and allows users to customize provider and client colors and display names via a configuration file.
crates/tokscale-cli/src/tui · high confidence
Security
Constrain GitHub OAuth return paths to prevent open redirect vulnerabilities
The GitHub authentication flow now validates and sanitizes the 'returnTo' parameter before redirecting users after login. By using a dedicated sanitization utility and storing the intended destination in an HTTP-only cookie rather than passing it directly in the URL query string during the callback, the application prevents attackers from redirecting users to malicious external sites after successful authentication.
packages/frontend/src/app/api/auth/github · high confidence
Behavioural changes
Add custom SVG icon components to the UI library
The UI component library now includes a new Icons module (Icons.tsx) providing custom SVG-based icon components such as PersonIcon, GearIcon, SignOutIcon, CopyIcon, CheckIcon, SearchIcon, XIcon, and KeyIcon. These components replace the previous reliance on the @primer/react icon set, allowing for more flexible styling and reduced external dependencies within the frontend application.
packages/frontend/src/components/ui · high confidence
CLI package restructured as a standalone workspace with NodeNext module support
The CLI is now a separate workspace package designed for publishing to GitHub npm. This change introduces a new entry point (bin.js) that dynamically imports the compiled distribution, and updates the TypeScript configuration to target ES2022 with NodeNext module resolution. These adjustments ensure the CLI outputs standard .js files and aligns with modern Node.js module standards, replacing previous build configurations.
packages/cli · high confidence
Database schema migrations for usage tracking, security, and groups
This update applies a series of database migrations that introduce several key capabilities and fixes. It adds support for per-device usage tracking and session metrics, including new columns for active time and session counts, while also introducing a groups feature with scoped leaderboards and invite management. Security is enhanced by rehashing plaintext API tokens and hashing browser session tokens at rest, which requires users to re-login. Data integrity is improved by widening cost columns to prevent overflow, fixing token total calculations to include cache and reasoning tokens, and adding robust deduplication logic for daily breakdowns during device changes. Additionally, the schema now supports MCP server statistics in user profiles and includes moderation tools to hide suspect accounts from leaderboards.
packages/frontend/src/lib/db/migrations · high confidence
Frontend components migrated to styled-components
The frontend components in packages/frontend/src/components have been rewritten to use styled-components instead of the previous styling approach (Tailwind CSS). This migration introduces CSS variables for theming, improves mobile responsiveness across the hero section, graph, and profile panels, and adds accessibility features such as ARIA labels and keyboard navigation for tabs and switches.
packages/frontend/src/components · high confidence
Groups browsing is now integrated into the Leaderboard page
The standalone Groups listing page has been replaced by a Groups browser component within the /leaderboard route. Users can now toggle between the global user leaderboard and a public group directory using a segmented control at the top of the page, with filters and pagination preserved across view switches. This change consolidates navigation, removing the separate Groups tab while keeping individual group detail pages accessible via their existing URLs.
packages/frontend/src/app/(main)/leaderboard · high confidence
Improved macOS stability and TUI usability documentation
The CLI now prevents crashes on older macOS versions by dynamically loading the Apple Foundation Models library at runtime instead of linking it statically, ensuring the binary remains compatible with systems prior to macOS 26. Additionally, a new Mouse Selection Guide has been added to document how to use Shift+drag for text selection in the TUI, including specific configuration tips for Ghostty users.
crates/tokscale-cli · high confidence
Introduce styled-components integration with SSR support and global CSS normalization
The frontend now uses styled-components for styling, replacing the previous dependency on @primer/react. A new Providers component applies a global style sheet that includes styled-reset for CSS normalization, sets default font families (Figtree for body, JetBrains Mono/Inconsolata for code), and enforces consistent box-sizing and button resets. To support Next.js App Router, a StyledComponentsRegistry component handles server-side rendering by collecting and injecting styled-components styles during the server phase, ensuring correct hydration and style delivery.
packages/frontend/src/lib/providers · high confidence
Introduces dark-only theme, SEO metadata, and self-hosting support
The frontend now enforces a dark-only theme with a blue-tinted color palette defined in CSS variables, replacing previous light-mode and Tailwind-based styling. To improve search visibility and self-hosting compatibility, the app generates dynamic sitemap and robots.txt files that index public groups and active user profiles while excluding sensitive paths, and includes Vercel Analytics and a top-loading progress bar in the root layout.
packages/frontend/src/app · high confidence
Landing page assets optimized and updated
The landing page assets have been updated to improve performance and content. Images and videos were converted to more efficient formats (PNG to WebP, videos to VP9/H.264), reducing total size from \~12MB to \~2.6MB. The trusted-by section now includes a Hashed logo and individual logos with cursor tooltips. A new client-logos-grid.svg was added, and unused assets were removed.
packages/frontend/public/assets/landing · high confidence
Landing page redesigned with new sections and interactive UI components
The landing page has been rebuilt with a new visual structure and interactive elements. A new HeroSection displays a hero video and a 'Trusted by' section with a cursor-following tooltip. The QuickstartSection now features command cards with copy-to-clipboard functionality and a 'Quickstart' label that scrolls to the commands. The WorldwideSection includes a leaderboard widget with tabs for 'Tokens' and 'Cost', displaying top users with rank badges and formatted values. A new DescriptionSection showcases client logos with fade effects. The FollowSection promotes the maintainer's GitHub profile, and a new SponsorSection encourages GitHub Sponsors. The FooterSection provides links to GitHub and sponsorship. The redesign also introduces reusable components like SquircleBorder for rounded corners with gradient borders and hooks like useCopy and useSquircleClip to support these interactions.
packages/frontend/src/components/landing/sections · high confidence
Leaderboard API endpoint with safe parameter parsing and caching
The leaderboard API route now validates input parameters (period, sortBy, page, limit, search) using safe parsing functions to prevent invalid values from breaking the request, and returns JSON responses with explicit cache-control headers (60s public cache, 300s stale-while-revalidate) to improve performance and reliability for frontend consumers.
packages/frontend/src/app/api/leaderboard · high confidence
Leaderboard logic refactored with new sorting, filtering, and date-range utilities
The leaderboard library has been restructured to support more precise user interactions and data handling. Users can now sort the leaderboard by either tokens or cost, with the preference persisted via a cookie to prevent display flashes. Search functionality has been enhanced to support specific directives (client: and model:) alongside standard username matching, and the system now correctly scopes token and cost sums to only the filtered clients and models using source breakdown data. Additionally, the leaderboard now supports custom date ranges for period filtering, replacing previous rigid time windows.
packages/frontend/src/lib/leaderboard · high confidence
New authentication infrastructure for web sessions, API tokens, and admin access
The frontend's authentication layer has been restructured into a dedicated module (\packages/frontend/src/lib/auth\) to support non-interactive API token authentication and stricter security controls. This change introduces a new personal token system (\personalTokens.ts\) that issues, stores, and validates hashed tokens for CLI and programmatic access, while ensuring these tokens cannot be used for administrative actions. Web session management (\session.ts\) now hashes browser session tokens at rest and distinguishes between web and CLI sources. Security is further hardened with \requestSession.ts\, which enforces CSRF origin validation for mutating requests, and \returnTo.ts\, which sanitizes OAuth redirect paths to prevent open-redirect vulnerabilities. Additionally, a new admin identity system (\admin.ts\) restricts moderator privileges to specific GitHub numeric IDs configured via environment variables, preventing account takeover risks associated with username changes.
packages/frontend/src/lib/auth · high confidence
New migration safety checks and automated production migration execution
This change introduces a suite of scripts in \packages/frontend/scripts\ to harden database migration reliability. \check-migrations.ts\ validates the Drizzle migration journal for integrity issues—such as duplicate indices, timestamp gaps, orphaned SQL files, or mismatched snapshots—that could cause silent skips or build failures. \migrate-prod.ts\ automatically applies these migrations during the Vercel build process (before the Next.js build) to ensure the deployed code always matches the database schema, guarded by a \VERCEL\_ENV\ check to prevent accidental application on preview branches. \migrate-docker.ts\ provides a corresponding entrypoint for self-hosted Docker deployments. Both production paths rely on \migrate-core.ts\, which implements a robust retry strategy for transient connection drops and deadlocks using PostgreSQL advisory locks to serialize concurrent migration runs. Additionally, \seed-dev.ts\ provides idempotent synthetic data for local development.
packages/frontend/scripts · high confidence
New submission validation schemas and legacy client normalization
The frontend now includes formal validation schemas for usage submissions (submission.ts) and GitHub usernames (username.ts). The submission schema enforces mathematical consistency, sanity caps, and required fields, while also normalizing legacy payloads by renaming 'sources' to 'clients' and aliasing 'kilocode' to 'kilo' to ensure older CLI versions can still submit data successfully.
packages/frontend/src/lib/validation · high confidence
Open Graph cards now use Manrope and Pretendard fonts with the Tokscale wordmark
The Open Graph card generation logic has been updated to brand previews with the Manrope and Pretendard typefaces and the Tokscale wordmark. The system now dynamically loads a subsetted Manrope font for standard text and conditionally fetches the full Pretendard font only when CJK characters are detected, ensuring correct rendering of international usernames. Additionally, the Tokscale logo is now inlined as a data URI to guarantee consistent display across serverless environments without relying on external file paths or HTTP requests.
packages/frontend/src/lib/og · high confidence
Profile page now redirects based on authentication status
Visiting the /profile route no longer displays a static page; instead, it checks the user's session. If a user is logged in, they are automatically redirected to their personal profile page at /u/{username}. If no session is found, they are redirected to the GitHub authentication endpoint to log in.
packages/frontend/src/app/profile · high confidence
Redesigned layout components and navigation shell
The frontend layout system has been updated with new, styled components for the navigation bar, footers, and legal page shells. The Navigation component now features a floating pill design on desktop and a full-width slide-in panel on mobile (≤520px), using styled-components for theming. Two footer variants are introduced: a visual Footer with a spinning globe animation for the main site, and a minimal ServiceFooter for legal pages. The LegalPageShell provides a consistent structure for privacy, terms, and contact pages, ensuring proper semantic HTML and accessibility. These changes reflect a shift from previous styling approaches to a more cohesive, responsive design system.
packages/frontend/src/components/layout · high confidence
Redesigned public user profiles with per-device usage and moderation notices
Public user profiles at /u/\[username\] have been redesigned to provide a compact, detailed view of AI token usage. The new interface includes a contribution graph with configurable date ranges, a breakdown of usage by device and model, and a dedicated statistics panel that now displays connected MCP servers. Users can set a display timezone preference to ensure charts and time-based metrics align with their local time. Additionally, the profile page now surfaces moderation notices—such as hidden-from-leaderboard status or re-submit banners for early adopters—ensuring transparency for both the account owner and visitors. The visual style has shifted from Tailwind CSS to styled-components with a blue-tinted design system.
packages/frontend/src/app/u · high confidence
Standardized device display labels and timestamp handling
The frontend device library now includes shared utilities to ensure consistent display names and time formatting across device-related views. A new helper normalizes device labels, falling back to "Legacy submissions" for the legacy default device or "Unnamed device" for others when no custom name is provided. Additionally, a timestamp utility ensures all device update times are converted to stable ISO strings, preventing inconsistencies between different endpoints.
packages/frontend/src/lib/devices · high confidence
Tokscale CLI entry point updated to use ES module import
The main entry point for the Tokscale CLI has been rewritten to use a native ES module import statement (\await import\) instead of CommonJS or other loading mechanisms. This change ensures the CLI loads the \@tokscale/cli\ package correctly, which is necessary for compatibility with modern runtimes like Bun and Node.js ES module environments.
packages/tokscale · high confidence
Fixes
Improved binary detection and libc identification for CLI execution
The CLI now correctly identifies the system's C library (glibc vs. musl) to select the appropriate prebuilt binary, supporting environments like Alpine Linux and Bun. It also resolves the binary path more robustly across various installation methods, including npm, pnpm, and monorepo setups, ensuring the correct native executable is found and executed.
packages/cli/src · high confidence
Test coverage
Add fake\_codex binary for headless capture tests; Added API route tests for authentication, device authorization, and group invites; Added integration and policy tests for the CLI; Added integration tests for new client parsers and pricing invariants; Added test fixtures for token timing, DSH cache migration, and model attribution; Added tests for migration retry logic; Added unit tests for frontend profile and leaderboard components; Expanded test coverage for moderation, authentication, and data integrity logic.
Dependencies
Migrate to Rust-based CLI and Bun runtime with multi-platform binary support
The project has shifted from a TypeScript-based tool to a Rust architecture, introducing a new \tokscale-cli\ and \tokscale-core\ workspace. This change replaces the previous Yarn/Bun-only setup with a Cargo-based build system, enabling the distribution of precompiled native binaries for eight platforms (including Linux, macOS, Windows, and Android). The Rust core utilizes \rustls\ for TLS to ensure robust certificate handling across different environments, while the frontend remains a separate Next.js package. This migration provides a significant performance boost for session parsing and cost calculation, along with improved cross-platform compatibility for the command-line interface.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 56 → 58 (+1.7)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 75 → 75 (+0.1)
- Architecture 97 → 90 (-6.6)
- Maturity 67 → 67 (-0.1)
- Readiness 43 → 43 (+0.5)
- Security 60 → 69 (+8.5)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 68 → 68 (+0.0)
- Performance 85 (new)
Resolved (118)
- Change coupling: main.rs ↔ mod.rs (crates/tokscale-cli/src/main.rs)
- Change-coupling hub: constants.ts → main.rs, client_ui.rs, lib.rs, scanner.rs, mod.rs (packages/frontend/src/lib/constants.ts)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (10 lines × 2) (crates/tokscale-core/src/pricing/lookup.rs)
- Duplicated block (11 lines × 2) (crates/tokscale-cli/src/tui/ui/stats.rs)
- Duplicated block (11 lines × 2) (crates/tokscale-core/src/lib.rs)
- Duplicated block (11 lines × 2) (crates/tokscale-core/src/sessions/mcode.rs)
- Duplicated block (13 lines × 2) (crates/tokscale-cli/src/tui/ui/usage.rs)
- Duplicated block (14 lines × 2) (crates/tokscale-cli/src/tui/ui/mod.rs)
- Duplicated block (16 lines × 2) (crates/tokscale-core/src/sessions/kiro.rs)
- Duplicated block (16 lines × 6) (crates/tokscale-cli/src/tui/ui/daily.rs)
- Duplicated block (18–19 lines × 8) (crates/tokscale-cli/src/tui/ui/agents.rs)
- Duplicated block (18–20 lines × 3) (crates/tokscale-cli/src/tui/ui/agents.rs)
- Duplicated block (23–31 lines × 9) (crates/tokscale-cli/src/tui/ui/agents.rs)
- Duplicated block (25–45 lines × 8) (crates/tokscale-cli/src/tui/ui/agents.rs)
- Duplicated block (29 lines × 2) (crates/tokscale-cli/src/tui/ui/projects.rs)
- Duplicated block (49–53 lines × 5) (crates/tokscale-cli/src/tui/ui/daily.rs)
- Duplicated block (5 lines × 2) (crates/tokscale-cli/src/tui/ui/dialog/group_by_picker.rs)
- Duplicated block (55–57 lines × 4) (crates/tokscale-cli/src/tui/ui/daily.rs)
- …and 98 more
New (105)
- Change-coupling hub: constants.ts → main.rs, client_ui.rs, clients.rs, lib.rs, scanner.rs, mod.rs (packages/frontend/src/lib/constants.ts)
- Documentation: no architecture or design documentation (docs/providers/sakana.md)
- Duplicate functionality between PricingLookup and PricingService. Both classes expose identical method signatures for cost calculation (calculate_cost and calculate_cost_with_provider). It is unclear why PricingService duplicates this logic if it likely wraps or uses PricingLookup internally. This creates two entry points for the same business logic.
- Duplicated block (10 lines × 2) (crates/tokscale-cli/src/tui/ui/daily.rs)
- Duplicated block (11 lines × 2) (crates/tokscale-core/src/pricing/lookup.rs)
- Duplicated block (12 lines × 2) (crates/tokscale-cli/src/tui/ui/daily.rs)
- Duplicated block (12 lines × 2) (crates/tokscale-core/src/sessions/mcode.rs)
- Duplicated block (12 lines × 4) (crates/tokscale-core/src/message_cache.rs)
- Duplicated block (13 lines × 2) (crates/tokscale-cli/src/tui/ui/stats.rs)
- Duplicated block (13 lines × 2) (crates/tokscale-core/src/message_cache.rs)
- Duplicated block (14 lines × 2) (crates/tokscale-core/src/sessions/junie.rs)
- Duplicated block (15 lines × 2) (crates/tokscale-core/src/sessions/mcode.rs)
- Duplicated block (15–16 lines × 2) (scripts/9router_tokscale_bridge_gjc.py)
- Duplicated block (16 lines × 2) (crates/tokscale-cli/src/tui/ui/mod.rs)
- Duplicated block (16 lines × 8) (crates/tokscale-cli/src/tui/ui/agents.rs)
- Duplicated block (18 lines × 2) (crates/tokscale-cli/src/tui/ui/agents.rs)
- Duplicated block (18 lines × 2) (crates/tokscale-core/src/message_cache.rs)
- Duplicated block (18 lines × 2) (crates/tokscale-core/src/message_cache.rs)
- Duplicated block (18 lines × 5) (crates/tokscale-cli/src/tui/ui/daily.rs)
- Duplicated block (19 lines × 2) (crates/tokscale-cli/src/tui/ui/dialog/group_by_picker.rs)
- …and 85 more
Changes since last survey
- 35 commits — 17 feature/other, 18 fixes
By area
- crates/tokscale-core — 21 commits
- crates/tokscale-cli — 6 commits
- (root) — 5 commits
- .github/badges — 2 commits
- packages/frontend — 1 commit
Notable commits
- fix: fix(antigravity-cli): date modern agy turns from steps table timestamps (#1184) (#1327)
- fix: fix(antigravity-cli): read logged ports from the head of per-session logs (#1339)
- fix: fix(claudecode): price Claude Code 1-hour cache writes at the 1-hour rate (#1374)
- fix: fix(clients): Codex tier source, Antigravity ledger reconciliation, import backfill, recovery ledger docs (#1365)
- fix: fix(clients): correct MiMo, MiniMax and Muse usage accounting (#1355)
- fix: fix(cline): resolve model identity from per-message modelInfo (#1340)
- fix: fix(devin): deduplicate CLI rows by request ID
- fix: fix(dsh): count usage from embedded assistant attempts
- fix: fix(dsh): read versioned session.v<N>.jsonl transcripts (#1328)
- fix: fix(http): trust webpki roots alongside native certs so SSL_CERT_FILE overrides stay additive (#1344)
- fix: fix(kiro): estimate input/cache split from content and price credits (#1342)
- fix: fix(mcode): parse stream-json completion envelopes
- fix: fix(openclaw): decode compressed SQLite transcript payloads
- fix: fix(pricing): let OpenRouter participate across version-separator spellings (#1338)
- fix: fix(pricing): prefer the standard service tier among an author's OpenRouter endpoints (#1336)
- fix: fix(scanner): scan WorkBuddy 5.5 sessions under ~/.workbuddy-ai (#1337)
- fix: fix(tui): preserve a symlinked settings.json when saving
- fix: fix: keep recovery-only days in import --submit and finish TUI localization (#1371)
- change: Update Oh My Pi link and image in README
- change: chore: bump version to 4.17.0
- …and 15 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
junhoyeo/tokscale was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fe72e1f9b5a2b1a927108b353a9730a5c631a196 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-505904ce13c1.