Mark Ku's Blog
MIT · Self-hosted team edition

Open Token Monitor

Your whole team's AI coding usage, on your own server. Tokens and equivalent cost from Claude Code, Codex, Cursor and Copilot on every employee's machine report to a hub you host every 30 minutes, compared by company, department and person.

Install the clientSource on GitHub
★ Free · MIT▢ Self-hosted hub on Docker · Windows / macOS / Linux clients
hub · usage dashboard
Usage dashboard: tokens, equivalent cost, active people and active devices, each compared with the previous period, plus a weekly trend split by department. Filter by period, tool, company and department. Sample data.
NordVPN
Sponsored

Public Wi-Fi and travel, handled by NordVPN

One tap encrypts everything, with servers in 137 countries. 10 devices per account, 30-day money-back guarantee.

Contains affiliate links

What it solves

The questions managers actually ask once a team starts coding with AI.

🧾

Where is the money going

Everyone's Claude Code, Codex and Cursor usage lives on their own machine. The hub turns it into one set of tokens and equivalent cost, sliceable by company, department, person, model and tool.

🏢

Keep the data in-house

Usage logs reveal projects, accounts and working hours. The hub runs on your intranet and stores everything in your own PostgreSQL, with no third-party service in between.

👥

Match devices to people

Import a roster (employee ID, name, email, department) and devices whose reported email matches are assigned automatically. Moves between people or departments keep history; monthly reports apply each day's assignment.

⏱

When will the quota run out

Claude 5-hour and weekly quotas and Codex quotas are on the dashboard, including accounts shared across several machines.

📊

Feed company reporting

Reports API v1 lets cost systems or BI pull monthly, weekly and daily usage as JSON or Excel-ready CSV. It ships with OpenAPI 3.1 and llms.txt, so an AI agent can wire it up too.

🖥

Zero effort for employees

The company installer comes with the hub URL and key baked in: it connects on first launch, starts at login and uploads every 30 minutes. Nothing to configure.

Three parts

Built on the open-source Token Monitor without changing a line of upstream code; everything a company needs sits on top.

🗄

Hub

hub/ · docker/

  • PostgreSQL storage with admin, client and API token permission tiers
  • Roster editing in the browser or Excel import, automatic device ownership by email
  • Usage dashboard, reports API, daily backups and history purge
  • Runs in front of the upstream hub; one Docker Compose command
📦

Electron client

client/ · packaging/

  • The upstream desktop widget, packaged with your hub URL and client key
  • Connects on first launch and starts at login
  • Uploads every 30 minutes and shows only this machine's usage
  • Swap the icon and window logo for your company's
🦀

Rust/Tauri client

tauri/

  • A lightweight Rust rewrite that installs without admin rights
  • Uploads field-for-field the same records as the upstream client, so the hub is unchanged
  • Includes the headless tm-agent for schedulers and servers
  • Floating, desktop and tray window modes

Design details worth knowing

Turning usage into company data needs more care than a personal widget.

💵

Cost is labeled "equivalent"

Amounts are converted at each provider's API list price, not real bills; subscription users actually pay a flat monthly fee. That caveat is on the dashboard and in every report response.

🔐

Three key tiers

Admin, client and API tokens each get only what they need. Admins trade the key once for an HttpOnly cookie, so the browser never stores it; API tokens are read-only, scoped and revocable.

🌳

The org is a tree

Company → BU → department → team. Each day's usage goes to that day's unit and rolls up; unassigned usage becomes an "Other" row instead of quietly disappearing.

🧪

Upstream stays untouched

upstream/ is a pristine copy of one upstream release, and npm run verify fails if anyone edits it. Every seam is covered by tests or listed, so pulling a new upstream version tells you exactly what to update.

🤖

Upgrades can be handed to AI

A weekly job checks upstream and opens a PR with a checklist. Comment @claude on the PR to finish the upgrade, or run /upstream-update in Claude Code locally.

🌐

Chinese and English

The dashboard, admin page, install guide and clients all ship in Traditional Chinese and English, picked from the browser language and switchable by hand.

💾

Backups built in

The hub runs a rotating daily pg_dump, and admins can back up, download or delete on demand. Purging history always takes a backup first.

🧭

Try it without Docker

npm run smoke:hub starts a throwaway hub with sample data, so you can click around the dashboard before setting up a database.

AI coding tools it reads

Claude CodeCodexCursor IDE / CLIGitHub CopilotOpenCodeAntigravityHermes Agent

This is the Rust client's list; the Electron client inherits upstream Token Monitor and supports even more tools.

What it looks like

Screenshots use the repo's built-in sample data; reproduce them with npm run smoke:hub.

Usage dashboard: tokens, equivalent cost, active people and active devices, each compared with the previous period, plus a weekly trend split by department. Filter by period, tool, company and department. Sample data.
Usage dashboard: tokens, equivalent cost, active people and active devices, each compared with the previous period, plus a weekly trend split by department. Filter by period, tool, company and department. Sample data.
Account ranking and token mix: input, output, cache read and cache write at a glance. Usage is attributed to the AI account each device reports, so shared accounts are visible too.
Account ranking and token mix: input, output, cache read and cache write at a glance. Usage is attributed to the AI account each device reports, so shared accounts are visible too.
Devices and AI tool quotas: hostname, client version, today and this month, last report time for every machine, plus remaining quota for Claude and Codex accounts.
Devices and AI tool quotas: hostname, client version, today and this month, last report time for every machine, plus remaining quota for Claude and Codex accounts.
Org roster: one per company (employee ID, name, email, department). Edit it in the browser, or download the Excel template, fill it in and drop it back.
Org roster: one per company (employee ID, name, email, department). Edit it in the browser, or download the Excel template, fill it in and drop it back.
Preview the diff before importing: added, changed and deactivated people are listed separately, and nothing is written until you confirm. People missing from the roster are deactivated, never deleted.
Preview the diff before importing: added, changed and deactivated people are listed separately, and nothing is written until you confirm. People missing from the roster are deactivated, never deleted.
Rust/Tauri employee widget: today, this month and all-time usage with equivalent cost, Claude 5-hour and weekly quotas, model share and an activity heatmap.
Rust/Tauri employee widget: today, this month and all-time usage with equivalent cost, Claude 5-hour and weekly quotas, model share and an activity heatmap.
Widget settings: launch at startup, floating / standard / desktop / tray window modes, collapse into a floating bubble, edge quota bar, glass effect and a hotkey.
Widget settings: launch at startup, floating / standard / desktop / tray window modes, collapse into a floating bubble, edge quota bar, glass effect and a hotkey.
The widget usage dashboard: total tokens, total spend, active days and streak, with daily usage as bars or candlesticks, by tool or by model.
The widget usage dashboard: total tokens, total spend, active days and streak, with daily usage as bars or candlesticks, by tool or by model.
The install guide (/install): a tab each for Windows, macOS and Linux, preselected for the visitor. Every step shows a drawing of that window with the button to press circled in orange.
The install guide (/install): a tab each for Windows, macOS and Linux, preselected for the visitor. Every step shows a drawing of that window with the button to press circled in orange.

Five things to know first

Better to state the limits up front than explain them later.

  1. 1

    It is for organizations, not individuals

    If you only want to see your own machine, install upstream Token Monitor directly. This repo adds the hub, database, org structure and reports for people who need to roll up a whole team.

  2. 2

    Amounts are not real bills

    costUsd is an equivalent cost at API list prices (USD). People on subscriptions such as Claude Max or ChatGPT Plus actually pay a monthly fee; use your own cost data for licenses and subscriptions.

  3. 3

    The public installer has no hub settings

    Installers on GitHub Releases contain no hub URL or key; you enter them once in settings. For installers that connect automatically, package your own with npm run build:client.

  4. 4

    Installers are not code-signed

    Windows shows "Windows protected your PC": click More info → Run anyway. On macOS, go to Privacy & Security and click Open Anyway. Intel Macs are not supported yet.

  5. 5

    Not affiliated with upstream

    This project builds on Javis603/token-monitor but is not an official team edition and is not endorsed by the upstream author. Please file issues in this repo.

Tech stack

The hub adds just two runtime dependencies: dotenv (same version as upstream) and the database driver.

HubNode.js 22.15+
DatabasePostgreSQL
DeployDocker Compose
Client (upstream)Electron
Client (light)Tauri 2 + Rust + React
Usage scantokscale
Reports APIREST · OpenAPI 3.1
LicenseMIT

Install the client

GitHub Releases has installers for three platforms. After installing, get the hub URL and client key from your admin and enter them in settings; it then uploads every 30 minutes and starts at login.

Windows 10 / 11

x64-setup.exe

When "Windows protected your PC" appears, click More info → Run anyway.

macOS (Apple silicon)

aarch64.dmg

Drag the app into Applications. If it is blocked on first launch, go to System Settings → Privacy & Security and click Open Anyway.

Linux (x64)

amd64.AppImage

chmod +x it and run; no install needed.

To connect to a hub: open Token Monitor, click ⚙ at the bottom right, turn on multi-device sync, choose Connect to Hub, and enter the Hub URL and secret. Upgrading from an older version keeps your settings and data.

Run the hub

  1. 1

    You need Node.js 22.15+, plus Docker to run the hub in containers.

  2. 2

    Clone, run npm ci, copy .env.example to .env and fill in TOKEN_MONITOR_SECRET, TOKEN_MONITOR_CLIENT_SECRETS, POSTGRES_PASSWORD and TOKEN_MONITOR_DB_PASSWORD (long random hex).

  3. 3

    Build the image with docker build -f docker/Dockerfile -t token-monitor-hub . and start the hub plus PostgreSQL with docker compose -f docker/compose.yml --env-file .env up -d (port 80 by default).

  4. 4

    Open http://localhost/, click Admin and paste TOKEN_MONITOR_SECRET. Under Org roster, enter a company code, edit the roster or drop in the Excel file, preview the diff and import.

  5. 5

    Send colleagues the install guide at http://<hub>/install and they are done.

Just want a look, without Docker or a database? This line starts a hub with sample data.

When upstream ships a new version

Upgrade one version at a time. Merge when all tests pass; otherwise work through the impact list.

  • npm run upstream:status

    See which upstream version you are on and which is latest.

  • npm run upstream:update -- next

    Pull in the next version and run the tests.

  • npm run upstream:impact

    List the seams to check and update this time.

License and credits

Released under the MIT license: use it commercially, modify it and redistribute it. Upstream Token Monitor is © Javis, also MIT; see THIRD_PARTY_NOTICES.md in the repo for full notices.

Give your team's AI usage its own ledger

Self-hosted, free and MIT licensed. If it helps, star the repo or open an issue on GitHub to tell me what is missing.

Support open source

Every tool here is free and open source

No paywall, no sign-up, and the source is public on GitHub. If one of them saved you time, buy me a coffee so the updates and the next tool keep coming.

Buy me a coffee

Custom amount·Secure PayPal checkout

NordVPN

Deal

The network you code on is rarely your own

NordVPN encrypts the whole connection: café and hotel Wi-Fi stop being someone else's listening post, and while you travel your bank app, your company dashboards and the streaming services back home still work. One tap in the app, and the NordLynx protocol keeps it fast enough that you forget it is on. One account covers 10 devices, with a 30-day money-back guarantee.

  • Public Wi-Fi encrypted end to end
  • Servers in 137 countries, reach home services abroad
  • 10 devices per account, 30-day refund

Contains affiliate links