mrkeyoor.com_
Wed 30 Sept 15:09 UTC
Dev Toolsevaluationupdated 30 Sept 2026

TokenTracker review

TokenTracker reads usage records left by AI coding tools and turns them into a local dashboard for tokens, estimated cost, quotas, and activity. It covers 42 tools through hooks, plugins, SQLite databases, and session logs, with optional desktop apps, cloud sync, and a public leaderboard.

Verdict

Our TokenTracker run installed 60 packages in 10 seconds with 0 known vulnerabilities, but 36 of 2,726 tests failed, so it is useful personal telemetry rather than a billing ledger. Use it if your coding work is spread across several tools and approximate cost trends are enough. Avoid using its totals for reimbursement, customer billing, or enforcement until the integrations you rely on pass your own reconciliation checks.

We ran it

Lab card: what happened when we ran TokenTrackerScreenshot of TokenTracker (www.tokentracker.cc)
Install✓ · 10s60 packages · 43 MB
Buildn/ano build script
Tests✗ · 78s2690 passed · 36 failed of 2726 (node:test)
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo1343 files~312,411 lines of source · 29.6 MB · 11 CI workflows · tests dir

Answers from our run

Does TokenTracker build from source?

Dependencies installed in 10 seconds (60 packages), and the project has no separate build step. We cloned commit daa6c55 into a clean Debian container with 3 CPUs and no project-specific setup.

Do TokenTracker's tests pass?

Not all of them: 2690 of 2726 passed and 36 failed when we ran the project's own test command (node:test). Some failures need services or credentials a bare container does not have.

Does TokenTracker have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use TokenTracker?

Finance teams using token totals for invoices or chargebacks: the README labels some providers as estimates, and open issues report OmO double counting and a Kiro undercount.

What are the alternatives to TokenTracker?

ccusage, Tokscale, LiteLLM. Our TokenTracker run installed 60 packages in 10 seconds with 0 known vulnerabilities, but 36 of 2,726 tests failed, so it is useful personal telemetry rather than a billing ledger.

Setup4/5A 10-second install is easy, though desktop packages have OS caveats
Docs5/5Provider methods, privacy, setup, platform limits, and cleanup are explicit
Community4/51,910 stars, a September 30 push, and active issue responses
Maturity3/5v1.1.3 spans three desktops, but our suite had 36 failures

Who it’s for

Developers who switch among Claude Code, Codex, Cursor, Gemini, OpenCode, and other coding tools and want one personal usage view.
Local-first users who want token and cost estimates without sending prompts or code to another service.
Engineers who want a dashboard, tray app, widgets, or JSON status output instead of a terminal-only report.

Who it’s NOT for

Finance teams using token totals for invoices or chargebacks: the README labels some providers as estimates, and open issues report OmO double counting and a Kiro undercount.
Locked-down fleets that require notarized or fully signed desktop software: the macOS app is ad-hoc signed, and issue 720 reports the Windows executable was unsigned when Kaspersky flagged it.
Security policies that forbid tools from reading other applications' local databases or credentials for quota checks, even when prompts and code stay local.
Contributors who require a green test gate before adoption: our run ended with 36 failures out of 2,726 tests.

Setup reality

Our commit daa6c55 checkout installed 60 npm packages in 10 seconds, used 43 MB on disk, and reported 0 known vulnerabilities. There was no build script to run. Tests finished in 78 seconds with 2,690 passing and 36 failing out of 2,726.

The CLI needs Node.js 20 or newer, then npx tokentracker-cli installs hooks, syncs local records, and opens port 7680. Passive integrations read existing SQLite, JSONL, or log files. Quota checks may reuse credentials already stored by provider apps; cloud sync and the leaderboard are optional.

Desktop details vary. Debian 12 users are directed to the AppImage because the .deb dependency is unavailable there. GNOME needs an AppIndicator extension for the tray, macOS Gatekeeper blocks the ad-hoc signed app on first launch, and some Windows plus WSL setups need scan-mode choices.

TokenTracker unifies usage records from 42 coding tools

TokenTracker is for the developer whose AI usage has escaped a single provider dashboard. It reads local records from 42 coding tools, normalizes token counts and model names, and presents trends, project attribution, estimated cost, quota windows, and an activity heatmap. Claude Code and Codex can trigger managed hooks. Other integrations read existing SQLite databases, JSONL sessions, telemetry files, or provider APIs.

The product has more personality than a usage report usually gets. There are native apps for macOS, Windows, and Linux, four desktop widgets, a pixel pet, and 15 achievement tracks. The browser dashboard opens locally, while tokentracker status --json gives scripts and agents something easier to consume. Optional cloud sync and a leaderboard can combine machines, but the normal tracking path stores 30-minute buckets in local SQLite.

What happened when we ran it

Our run used commit daa6c55 in a fresh unprivileged Debian container with 3 CPUs and 8 GB of RAM. npm install succeeded in 10 seconds, adding 60 packages and consuming 43 MB on disk. The audit reported 0 known vulnerabilities across critical, high, moderate, and low severities. The checkout contained 1,343 files, about 312,411 source lines, and occupied 29.6 MB.

There was no build script or target, so we skipped that step rather than inventing one. The test command finished in 78 seconds with 2,690 passing and 36 failing out of 2,726 node:test cases. Its final lines showed the ZCode-related cases around tests 2,268 through 2,275 passing, followed by generic test failed messages. That tail does not identify all 36 causes, and we will not assign one.

The repository had 11 CI workflow files, a tests directory, and no Dockerfile. That shape fits a local CLI and several native clients better than a service image. The useful signal is mixed: installation was quick and the audit was clean, while the exact commit we tested did not clear its full suite. A team packaging it internally should treat those 36 failures as a release-gate question.

Local-first still involves hooks, files, and network calls

The quick start is genuinely short. Node.js 20 or newer and npx tokentracker-cli are enough to launch a dashboard, usually on port 7680. First run detects supported tools and installs the hooks or plugins it manages. tokentracker status explains skipped integrations, doctor checks the setup, and tokentracker uninstall removes managed hooks plus local TokenTracker configuration and data.

Passive readers still need broad visibility into developer state. The documented integrations inspect files under Claude, Codex, Cursor, Kiro, Copilot, OpenCode, and many other application directories. Direct provider quota checks can use credentials already present on the machine. Default network activity also includes update checks, GitHub star counts, price refreshes, a daily heartbeat, and PostHog page views. TOKENTRACKER_NO_TELEMETRY=1 or DO_NOT_TRACK=1 disables the anonymous telemetry.

Cost totals are estimates with provider-specific failure modes

TokenTracker is more honest than many dashboards about incomplete inputs. Grok cost is estimated because its local telemetry lacks a stable prompt, output, and cache split. Models without published prices can show $0 while still consuming paid access. Kiro CLI v2 is described as approximate, and an open v1.0.7 issue reports that repeated context was not counted, leaving the reporter's total far below their recorded credits.

Another open report against v1.1.3 says OmO requests sent through an Anthropic subscription appeared in both OmO and Claude records. The reporter matched hundreds of entries and described duplicated tokens and cost. These are user reports, separate from our 2,726-test run, but they concern the central promise of accurate totals. For personal trend spotting, a known provider caveat may be acceptable. For chargebacks, it is disqualifying until reconciled.

Desktop convenience comes with packaging friction

Linux has AppImage, .deb, and .rpm options, yet they are not interchangeable. The README says the Debian 12 package will not install because Bookworm lacks its named appindicator dependency, so those users should choose the roughly 120 MB AppImage. GNOME also needs the AppIndicator extension to show the tray icon. WSL can scan native, WSL, or both environments, with exceptions documented per provider.

The macOS application is ad-hoc signed and not notarized with an Apple Developer ID. Gatekeeper therefore requires an Open Anyway step, and protected Cursor or Kiro directories may prompt for permission after upgrades. Issue 720 reports that Kaspersky classified the v1.1.2 Windows runtime as a generic Trojan heuristic and quarantined it; the reporter also noted that the Windows executable was unsigned. The report does not prove malware. It is still enough for some managed fleets to reject the package.

September activity is fast, with accuracy work still open

GitHub showed 1,910 stars, a September 30 push, and 46 open issues and pull requests combined. A separate search returned 27 open issues. Release v1.1.3 arrived September 29 with Command Code tracking, a Windows quota widget, Linux sign-in fixes, and SHA-256 checksums for six desktop artifacts. New pull requests and bug reports were active the next day.

That pace matters because every integration follows someone else's file format, database schema, authentication flow, or cost model. TokenTracker's detailed provider table and privacy policy make those dependencies inspectable. Our run still found 36 failing tests, while current issue reports show why reconciliation matters. Install it for one developer, compare a week against provider records, and keep only the integrations whose numbers make sense on your machine.

Alternatives

ProjectWhat it isPick it when
ccusageA terminal-first reporter for local coding-agent usage data.pick this instead when you want strong CLI reporting and do not need TokenTracker's desktop apps, pet, widgets, or browser dashboard.
TokscaleA TUI and CLI that tracks token use across coding agents.pick this instead when a terminal interface and optional global leaderboard cover the job.
LiteLLM gh↗An AI gateway that records cost and usage as requests pass through it.pick this instead when you control the model gateway and need centralized request records across applications rather than local coding-tool logs.

What people are saying

  1. [github-trending] xiufengsun/TokenTracker

Sources

  1. TokenTracker README
  2. TokenTracker v1.1.3 release
  3. OmO double-counting report
  4. Kiro CLI undercount report
  5. Kaspersky false-positive report

More dev tools reviews

GhostTrack · Codex-Dream-Skin · firebase-ios-sdk · awesome-cli-apps · swiftui-logo-draw · RTX40MFG-Unlock · the whole board →