Changelog

What shipped

Newest first. Only what merged — no roadmap dressed up as release notes.

  1. Findings that say what to do — and when to stop

    Every finding now carries a verdict (STOP, FIX, WATCH) and a concrete next step. New detectors catch what actually drives a long session's cost: context re-read on every request, and command cycles whose arguments drift (sed -n 858,866p … 331 times). A live runaway gets one in-session prompt to stop, with the reason. Sessions sort by recency or spend and filter by lane. Subscription seats are now detected from the plan your login reports — Max machines were being labelled API billing.

    • spend
    • guard
    • replay
    • cli
  2. Ask the docs from any public page

    A research assistant now rests at the bottom of the homepage and docs, answering product questions from the docs themselves. It is mounted on public pages only — never inside the app, where a URL can carry a customer's session id.

    • site
  3. Waitlist signups that actually land

    Signups were silently failing to reach the database; they now do, deduplicated on a normalized address and rate-limited per client so the one unauthenticated endpoint can't be hammered for free.

    • site
    • platform
  4. CLI prepared for npm

    Packaging for the tokenoscopy CLI: bundled build, bin entry, README, and install guidance that prefers a global binary so the guard skips package resolution on every tool call.

    • cli
  5. First Flight: setup that verifies itself

    The Setup screen hands you one command with your ingest key already in it, then waits for your first session and shows it to you as it lands — so 'is it working?' is answered by watching it work.

    • cli
    • replay
  6. Two lanes: seat capacity and billed spend

    Each machine now reports how it pays for tokens. API-key and Console-billed spend is real money; subscription usage is shown as what it would have cost, and is never added to money. OAuth no longer implies subscription. Unknown machines say so instead of guessing.

    • spend
  7. Loop alerts that fire before the bill

    A session that repeats an identical call and edits code that runs unattended — a workflow, a cron, a scheduler — raises one alert linking to the replay, before the schedule it just wired starts billing.

    • spend
    • replay
  8. Guard latency: 1190ms → 77ms

    An allow verdict is now cached locally, so a typical guarded tool call costs a process start rather than a network round trip. Deny and ask are never cached, and every failure path still allows.

    • guard
    • cli
  9. One design, marketing to product

    The site, sign-in and dashboard now share one warm editorial look. The replay stays a dark instrument panel — the recording reads as captured evidence, not another dashboard.

    • site
    • replay
  10. Attribution and the Flight Report

    Spend attributed per session, repo, branch, developer and model, and a weekly report that answers what happened, what it cost, and what to do next.

    • spend
  11. OTLP intake

    Point Claude Code's native OpenTelemetry logs exporter at Tokenoscopy for per-request spend, including Bedrock and Vertex deployments. The same request from any surface is counted exactly once.

    • platform
  12. Budgets and the guard

    Budgets per session, repo or org with 50/80/100% alerts, and a PreToolUse guard that stops the next tool call at the cap — fail-open, with every block recorded on the timeline.

    • guard
    • spend
  13. Session replay

    Every Claude Code session becomes a scrubbable timeline of prompts, model calls, tool I/O and diffs, redacted on the machine before upload.

    • replay
    • cli