TokenTracker unifies usage records from 42 coding tools
TokenTracker is for the developer whose AI usage has escaped a single provider dashboard. It reads local records from 42 coding tools, normalizes token counts and model names, and presents trends, project attribution, estimated cost, quota windows, and an activity heatmap. Claude Code and Codex can trigger managed hooks. Other integrations read existing SQLite databases, JSONL sessions, telemetry files, or provider APIs.
The product has more personality than a usage report usually gets. There are native apps for macOS, Windows, and Linux, four desktop widgets, a pixel pet, and 15 achievement tracks. The browser dashboard opens locally, while tokentracker status --json gives scripts and agents something easier to consume. Optional cloud sync and a leaderboard can combine machines, but the normal tracking path stores 30-minute buckets in local SQLite.
What happened when we ran it
Our run used commit daa6c55 in a fresh unprivileged Debian container with 3 CPUs and 8 GB of RAM. npm install succeeded in 10 seconds, adding 60 packages and consuming 43 MB on disk. The audit reported 0 known vulnerabilities across critical, high, moderate, and low severities. The checkout contained 1,343 files, about 312,411 source lines, and occupied 29.6 MB.
There was no build script or target, so we skipped that step rather than inventing one. The test command finished in 78 seconds with 2,690 passing and 36 failing out of 2,726 node:test cases. Its final lines showed the ZCode-related cases around tests 2,268 through 2,275 passing, followed by generic test failed messages. That tail does not identify all 36 causes, and we will not assign one.
The repository had 11 CI workflow files, a tests directory, and no Dockerfile. That shape fits a local CLI and several native clients better than a service image. The useful signal is mixed: installation was quick and the audit was clean, while the exact commit we tested did not clear its full suite. A team packaging it internally should treat those 36 failures as a release-gate question.
Local-first still involves hooks, files, and network calls
The quick start is genuinely short. Node.js 20 or newer and npx tokentracker-cli are enough to launch a dashboard, usually on port 7680. First run detects supported tools and installs the hooks or plugins it manages. tokentracker status explains skipped integrations, doctor checks the setup, and tokentracker uninstall removes managed hooks plus local TokenTracker configuration and data.
Passive readers still need broad visibility into developer state. The documented integrations inspect files under Claude, Codex, Cursor, Kiro, Copilot, OpenCode, and many other application directories. Direct provider quota checks can use credentials already present on the machine. Default network activity also includes update checks, GitHub star counts, price refreshes, a daily heartbeat, and PostHog page views. TOKENTRACKER_NO_TELEMETRY=1 or DO_NOT_TRACK=1 disables the anonymous telemetry.
Cost totals are estimates with provider-specific failure modes
TokenTracker is more honest than many dashboards about incomplete inputs. Grok cost is estimated because its local telemetry lacks a stable prompt, output, and cache split. Models without published prices can show $0 while still consuming paid access. Kiro CLI v2 is described as approximate, and an open v1.0.7 issue reports that repeated context was not counted, leaving the reporter's total far below their recorded credits.
Another open report against v1.1.3 says OmO requests sent through an Anthropic subscription appeared in both OmO and Claude records. The reporter matched hundreds of entries and described duplicated tokens and cost. These are user reports, separate from our 2,726-test run, but they concern the central promise of accurate totals. For personal trend spotting, a known provider caveat may be acceptable. For chargebacks, it is disqualifying until reconciled.
Desktop convenience comes with packaging friction
Linux has AppImage, .deb, and .rpm options, yet they are not interchangeable. The README says the Debian 12 package will not install because Bookworm lacks its named appindicator dependency, so those users should choose the roughly 120 MB AppImage. GNOME also needs the AppIndicator extension to show the tray icon. WSL can scan native, WSL, or both environments, with exceptions documented per provider.
The macOS application is ad-hoc signed and not notarized with an Apple Developer ID. Gatekeeper therefore requires an Open Anyway step, and protected Cursor or Kiro directories may prompt for permission after upgrades. Issue 720 reports that Kaspersky classified the v1.1.2 Windows runtime as a generic Trojan heuristic and quarantined it; the reporter also noted that the Windows executable was unsigned. The report does not prove malware. It is still enough for some managed fleets to reject the package.
September activity is fast, with accuracy work still open
GitHub showed 1,910 stars, a September 30 push, and 46 open issues and pull requests combined. A separate search returned 27 open issues. Release v1.1.3 arrived September 29 with Command Code tracking, a Windows quota widget, Linux sign-in fixes, and SHA-256 checksums for six desktop artifacts. New pull requests and bug reports were active the next day.
That pace matters because every integration follows someone else's file format, database schema, authentication flow, or cost model. TokenTracker's detailed provider table and privacy policy make those dependencies inspectable. Our run still found 36 failing tests, while current issue reports show why reconciliation matters. Install it for one developer, compare a week against provider records, and keep only the integrations whose numbers make sense on your machine.