feat(usage): Limits tab with provider quota windows and Codex banked resets - #9421
feat(usage): Limits tab with provider quota windows and Codex banked resets#9421StiensWout wants to merge 18 commits into
Conversation
…x banked resets Users had no way to see how much of their Codex or Claude Code subscription quota was left, or when it resets. Both providers already emitted a rate-limits runtime event, but its payload was untyped and the server dropped it. Adapters now normalise those payloads into typed limit windows. Codex is also read on demand through a short-lived app-server, and Claude Code through the claude.ai usage endpoint with the CLI's stored sign-in, so the numbers show without an open thread. A small in-memory service keeps the latest snapshot per provider instance and streams it to clients. The Usage page gains a Limits tab with one section per provider: a bar per window in use, a marker for even pacing, a pace icon, countdowns, and Codex banked resets with a confirmed redeem action. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR introduces a cross-cutting Limits product feature with new provider account integrations, OAuth credential access, live RPC state, and an irreversible Codex reset-credit redemption action. Its authorization and account-affecting behavior require reviewer validation beyond an auto-approval assessment. You can add or adjust custom eligibility rules. Learn more. |
Time out Codex account requests and fall back to a fresh app-server when a stale session cannot answer, refresh before the first limits snapshot so an empty boot map never reads as nothing reported, prune limits for removed instances, accept scoped weekly Claude event types so turns merge onto the rows the on-demand read created, surface failed environment subscriptions, and share one ProviderMark between the usage page and the Limits tab. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Mirrors the web Limits tab: one block per provider with a bar per window in use, a marker at the elapsed share of the window, the pace against the clock, the reset countdown, and banked Codex resets. Redeeming stays web-only for now. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Live Codex sessions get an 8 second budget before the read falls through to a fresh app-server, which has its own 20 second budget and a stable error detail. Reset redemption is single-flight per instance. Slow reads no longer overwrite windows an event updated meanwhile, events cannot resurrect a removed instance, the service interface lives inline on its tag, and the web page only subscribes to limits while the Limits tab is mounted. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The window stamp check and the state write were separate Ref operations with a yield between them, so two concurrent applies could interleave and a stale read could still overwrite a newer event. Stamps now live beside the limits in one Ref and the check and write are a single update. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…er's limits Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…newer plan and credits Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…d limits The registry's continuation identity changes with the configured home, so the service stores it per instance and starts clean whenever it differs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ilures, instance-aware Claude credentials Reset redemption is serialised per instance and keeps one idempotency key until Codex reports an outcome, and it never falls through to a fresh app-server after a session failure, so a retry re-sends the same attempt rather than spending a second credit. Full account reads now delete windows the account no longer reports while sparse turn events keep merging. A failed on-demand read is recorded on the snapshot next to the last good numbers instead of vanishing into the log. The Claude credential reader honours the instance's CLAUDE_CONFIG_DIR and HOME like the CLI it mirrors. Tests cover each of these. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…bile One shared module defines elapsed share and pace for both clients, with its own tests. Both views name environments still reading or failed, show a read failure beside the last good numbers, and the mobile heading wraps instead of clipping. The web bar is keyboard focusable with an accessible summary, and mobile pull-to-refresh holds until limits are re-read. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 3953dca. Configure here.
… complete reads carry extra usage, web shows a loading state Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
#9507) Users on Codex or Claude Code subscriptions could not see how much quota was left or when it resets without leaving T3 Code. A user whose CLIs route through a CLIProxyAPI hub could not see it at all. Each driver now returns `usageLimits` on its own snapshot (Codex from `account/rateLimits/read`, Claude from the SDK's `get_usage`), adapters normalise turn-driven rate-limit events at the boundary, and a driver-blind ingestion layer folds them onto the owning instance. The Usage page gains a Limits tab (mobile a card) with a bar per window, elapsed marker, pace, and reset countdown. CLIProxyAPI hubs can be added as read-only usage-limit sources; their accounts show badged "via CLIProxyAPI" with emails blurred. Distilled from #1732 (server model, provider rows) and #9421 (Limits tab, window bars, pace maths). Closes #228. Co-authored-by: Aditya Mer <101453576+Aditya190803@users.noreply.github.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Claude Code <noreply@anthropic.com>
|
Superseded by #9507, which landed the usage Limits tab (distilled from this PR's Limits-tab placement, window bars, and pace maths). Closing as superseded — thank you @StiensWout. |
Codex grants a reset credit when it has rate-limited an account unfairly; redeeming one clears the current windows. The credit count and soonest expiry now ride on the provider's usageLimits, and a confirmed "Use a reset credit" action on the Limits tab redeems one. Redemption is an account-level operation, so it lives on ProviderInstance (beside refreshModels) rather than on the thread-routed adapter. The Codex driver opens a short-lived app-server through the opener the status and skills probes now share, sends account/rateLimitResetCredit/consume, and re-probes so the cleared windows show. It is single-flight per instance and keeps one idempotency key until Codex reports an outcome, so a retry after a timeout re-sends the same attempt. Design from #9421. Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-Authored-By: Claude Code <noreply@anthropic.com>
Follow-up to #9507, carrying over the reset-credit redemption from #9421. Codex grants a reset credit when it has rate-limited an account unfairly (`"Thanks for using Codex! You've been granted one free rate limit reset."`). Redeeming one clears the current 5h/weekly windows. The Limits tab now shows how many are banked and when the next expires, with a confirmed **Use a reset credit** action. ## How it works - `ServerProviderUsageLimits.resetCredits` carries the count and soonest expiry; the Codex probe reads it from the same `account/rateLimits/read` it already makes. - `ProviderInstance.consumeResetCredit` is a new optional hook — account-level, so it sits beside `refreshModels` rather than on the thread-routed adapter. The Codex driver implements it over a short-lived app-server (via `withCodexAppServerClient`, factored out of the status and skills probes which duplicated the setup), then re-probes. - Single-flight per instance with one idempotency key kept until Codex reports an outcome, so a retry after a timeout does not open a second attempt. - New `provider.consumeResetCredit` RPC under the operate scope; the outcome (`reset` / `nothingToReset` / `noCredit` / `alreadyRedeemed`) is shown inline. Only Codex reports credits today. A provider without the hook gets a clear "does not bank reset credits" error; one without credits shows nothing. ## Screenshots The local Codex row with one banked credit (the same account via the CLIProxyAPI hub above it shows no credit, as expected — the hub does not relay them):  Close-up of the row:  Clicking it opens the confirmation; nothing is sent until **Use credit**:  ## Verification - Mapper tests for the credit summary; provider, contract, and Usage page suites pass; typecheck clean. - Verified against a real Codex Pro account holding one credit: summary and expiry render, the confirm dialog opens. **Not redeemed** — that would spend the credit. Written by Claude Fable 5 via Claude Code; design and single-flight approach from @StiensWout's #9421. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Redemption spends real account credits over a new RPC; correctness depends on per-account locking and idempotency, though disabled instances and non-Codex providers are rejected explicitly. > > **Overview** > Adds **end-to-end redemption of banked Codex rate-limit reset credits** from the Limits UI on web and mobile, backed by a new operate-scoped `provider.consumeResetCredit` RPC. > > **Contracts and server:** `ServerProviderUsageLimits` can include `resetCredits` (count + next expiry). Codex probes attach that from `account/rateLimits/read`. Optional `ProviderInstance.consumeResetCredit` is implemented for Codex via a scoped app-server call to `account/rateLimitResetCredit/consume`, then a limits refresh. `CodexResetCreditCoordinator` serializes redemptions per Codex account directory, reuses one idempotency key until Codex returns an outcome, and times out hung requests. `withCodexAppServerClient` is extracted so status, skills, and redemption share the same short-lived app-server setup. > > **Clients:** Limits rows show banked credits and a confirmed **Use a reset credit** action that calls `serverEnvironment.consumeResetCredit` and surfaces outcomes (`reset`, `nothingToReset`, etc.) or errors. > > **Web usage sources (same PR):** Adding/removing CLIProxyAPI hubs and the add dialog target a **selected connected environment** (with picker when several are connected), gated by operate access—not only the primary environment. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 98f32e6. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Claude Code <noreply@anthropic.com>
…resets Squash of upstream pingdotgg#9421 (StiensWout, head 3e02d2e).
* fix(web): send cited messages with Cmd+Enter (pingdotgg#9307) * fix(web): preserve explicit preview navigation URLs (pingdotgg#8902) * fix(web): prevent loading ssh environments from overriding navigation (pingdotgg#9168) * fix(mobile): skip unsupported shared settings targets (pingdotgg#9381) * fix(web): avoid duplicate Antigravity install status (pingdotgg#9419) * fix(composer): mute fast icon when collapsed (pingdotgg#9451) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): unify skeleton loading animations on one pulse (pingdotgg#9448) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): prioritize authored pull requests (pingdotgg#9453) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): make project icons the default (pingdotgg#9457) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(server): reuse pr state when settling threads (pingdotgg#9459) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): keep agent images collapsed (pingdotgg#9460) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): banner buttons no longer expand the resting composer (pingdotgg#9452) * fix(web): stop clipping the traits chevron on long Codex effort labels (pingdotgg#9433) Co-authored-by: Cursor <cursoragent@cursor.com> * fix(web): make right panel tabs easier to scroll (pingdotgg#9461) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): render transparent previews on white (pingdotgg#9463) * fix(mobile): show loading and syncing in the working pill (pingdotgg#9466) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(server): keep a/ and b/ prefixes in rendered git patches (pingdotgg#9438) * fix(server): full-access OpenCode threads no longer ask for approvals (pingdotgg#9282) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(web): reuse pull request list data while loading (pingdotgg#9467) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * feat(web): let users turn off composer collapse on blur and scroll (pingdotgg#9469) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(web): move workflow approval beside checks (pingdotgg#9465) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(desktop): refresh generated annotation styles (pingdotgg#9488) * fix(web): let the PR reviewer and label search boxes take keystrokes (pingdotgg#9479) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(web): dont collapse composer when interacting with bottom row (pingdotgg#9490) * fix(desktop): restore second-press quit fallback (pingdotgg#9485) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): keep opencode icon hollow in collapsed composer (pingdotgg#9492) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): keep agent browser preview visible (pingdotgg#9484) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(mobile): keep the machine glyph next to the environment label (pingdotgg#9486) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(mobile): let back swipe pop from horizontal scroll edges (pingdotgg#9493) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(antigravity): discover legacy workspace skills (pingdotgg#9410) Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com> * fix(mobile): resolve Antigravity provider icon and normalize driver matching (pingdotgg#9495) * fix(antigravity): forward Google sign-in URLs from browser helper (pingdotgg#9425) * feat(desktop): import browser cookies into a profile (pingdotgg#7255) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(desktop): import from Chrome, Edge, Brave, Vivaldi, Opera, Arc and Firefox (pingdotgg#7260) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(desktop): resolve Chromium cookie keys on Linux (pingdotgg#7261) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(antigravity): allow slow runtime startup during setup (pingdotgg#9510) * fix(antigravity): keep model choices up to date (pingdotgg#9511) * fix(antigravity): handle native sign-in URLs on stderr (pingdotgg#9514) * fix(antigravity): update managed runtime to 1.1.1 (pingdotgg#9509) * fix(desktop): address the browser import review left over from the stack (pingdotgg#9516) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com> * feat(antigravity): show subagent calls and results (pingdotgg#9515) * fix(web): let paste expand a resting composer (pingdotgg#9498) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(web): keep the composer open while selecting timeline text (pingdotgg#9499) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(web): return focus to the composer after closing a media preview (pingdotgg#9513) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(server): keep events during thread subscription startup (pingdotgg#9521) * chore: forward issue/PR/discussion events to Cursor hygiene (pingdotgg#9518) Co-authored-by: macroscopeapp[bot] <170038800+macroscopeapp[bot]@users.noreply.github.com> * fix(auth): keep pairing credentials out of access read models (pingdotgg#9523) * chore: drop comment events from Cursor hygiene forwarder (pingdotgg#9527) * feat(codex): support async questions (pingdotgg#9512) * fix(web): keep right panel controls clickable (pingdotgg#9517) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * feat(usage): show Codex and Claude subscription limits on a Limits tab (pingdotgg#9507) Users on Codex or Claude Code subscriptions could not see how much quota was left or when it resets without leaving T3 Code. A user whose CLIs route through a CLIProxyAPI hub could not see it at all. Each driver now returns `usageLimits` on its own snapshot (Codex from `account/rateLimits/read`, Claude from the SDK's `get_usage`), adapters normalise turn-driven rate-limit events at the boundary, and a driver-blind ingestion layer folds them onto the owning instance. The Usage page gains a Limits tab (mobile a card) with a bar per window, elapsed marker, pace, and reset countdown. CLIProxyAPI hubs can be added as read-only usage-limit sources; their accounts show badged "via CLIProxyAPI" with emails blurred. Distilled from pingdotgg#1732 (server model, provider rows) and pingdotgg#9421 (Limits tab, window bars, pace maths). Closes pingdotgg#228. Co-authored-by: Aditya Mer <101453576+Aditya190803@users.noreply.github.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Claude Code <noreply@anthropic.com> * feat(web): reorganize settings pages (pingdotgg#9354) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(server): settle branch threads immediately on pull request merge (pingdotgg#9528) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(server): back off relay client restarts after rapid exits (pingdotgg#8788) * fix(codex): accept rate limit errors on thread resume (pingdotgg#8897) * fix(desktop): preview CDP sessions no longer hard-crash the app (pingdotgg#9068) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * Fix worktree removal timing out on large install trees (pingdotgg#3902) * fix(web): settle the resting composer layout with a pixel of slack (pingdotgg#9482) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(web): keep automatic project icons consistent (pingdotgg#9535) * fix(server): include SQLite conditions in persistence errors Include SQLite conditions and schema issue tags without copying query data. Continue @Sy-D's [pingdotgg#4837](pingdotgg#4837). Add the missing Bun error codes and test the real SQL client. Created with GPT-6 Astra (preview) in Codex. Co-authored-by: Sy-D <8460326+Sy-D@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * fix(dev): keep shared dev reloads and hot updates working (pingdotgg#9543) * feat(providers): add context compaction command (pingdotgg#9293) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(mobile): keep store screenshots free of system banners and show dictation (pingdotgg#9548) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(web): restore composer controls as space becomes available (pingdotgg#9539) * fix(web): measure collapsed model labels at their visible width (pingdotgg#9540) * fix(web): close composer menus when their controls hide (pingdotgg#9541) * fix(web): thread error banner no longer shifts the chat (pingdotgg#9473) * fix(server): reveal normalized paths in File Explorer (pingdotgg#9551) * feat(marketing): fresh screenshot and floating marks on the homepage (pingdotgg#9547) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * feat(usage): redeem Codex reset credits from the Limits tab (pingdotgg#9534) Follow-up to pingdotgg#9507, carrying over the reset-credit redemption from pingdotgg#9421. Codex grants a reset credit when it has rate-limited an account unfairly (`"Thanks for using Codex! You've been granted one free rate limit reset."`). Redeeming one clears the current 5h/weekly windows. The Limits tab now shows how many are banked and when the next expires, with a confirmed **Use a reset credit** action. ## How it works - `ServerProviderUsageLimits.resetCredits` carries the count and soonest expiry; the Codex probe reads it from the same `account/rateLimits/read` it already makes. - `ProviderInstance.consumeResetCredit` is a new optional hook — account-level, so it sits beside `refreshModels` rather than on the thread-routed adapter. The Codex driver implements it over a short-lived app-server (via `withCodexAppServerClient`, factored out of the status and skills probes which duplicated the setup), then re-probes. - Single-flight per instance with one idempotency key kept until Codex reports an outcome, so a retry after a timeout does not open a second attempt. - New `provider.consumeResetCredit` RPC under the operate scope; the outcome (`reset` / `nothingToReset` / `noCredit` / `alreadyRedeemed`) is shown inline. Only Codex reports credits today. A provider without the hook gets a clear "does not bank reset credits" error; one without credits shows nothing. ## Screenshots The local Codex row with one banked credit (the same account via the CLIProxyAPI hub above it shows no credit, as expected — the hub does not relay them):  Close-up of the row:  Clicking it opens the confirmation; nothing is sent until **Use credit**:  ## Verification - Mapper tests for the credit summary; provider, contract, and Usage page suites pass; typecheck clean. - Verified against a real Codex Pro account holding one credit: summary and expiry render, the confirm dialog opens. **Not redeemed** — that would spend the credit. Written by Claude Fable 5 via Claude Code; design and single-flight approach from @StiensWout's pingdotgg#9421. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Redemption spends real account credits over a new RPC; correctness depends on per-account locking and idempotency, though disabled instances and non-Codex providers are rejected explicitly. > > **Overview** > Adds **end-to-end redemption of banked Codex rate-limit reset credits** from the Limits UI on web and mobile, backed by a new operate-scoped `provider.consumeResetCredit` RPC. > > **Contracts and server:** `ServerProviderUsageLimits` can include `resetCredits` (count + next expiry). Codex probes attach that from `account/rateLimits/read`. Optional `ProviderInstance.consumeResetCredit` is implemented for Codex via a scoped app-server call to `account/rateLimitResetCredit/consume`, then a limits refresh. `CodexResetCreditCoordinator` serializes redemptions per Codex account directory, reuses one idempotency key until Codex returns an outcome, and times out hung requests. `withCodexAppServerClient` is extracted so status, skills, and redemption share the same short-lived app-server setup. > > **Clients:** Limits rows show banked credits and a confirmed **Use a reset credit** action that calls `serverEnvironment.consumeResetCredit` and surfaces outcomes (`reset`, `nothingToReset`, etc.) or errors. > > **Web usage sources (same PR):** Adding/removing CLIProxyAPI hubs and the add dialog target a **selected connected environment** (with picker when several are connected), gated by operate access—not only the primary environment. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 98f32e6. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Claude Code <noreply@anthropic.com> * fix(server): find newly opened pull requests after agent turns (pingdotgg#9125) Refresh missing PR associations after agent turns on the thread's current branch. Preserve background policy, known PR caches, and failed-lookup backoff. Serialize status loads and refreshes to prevent stale responses from hiding a PR. Find branches pushed under their own name while still tracking the default branch. Original work by Theo Browne with Claude Fable 5.1 in Claude Code. Takeover fixes created with GPT-6 Astra (preview) in Codex. Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * ci: add on-demand Windows test workflow (pingdotgg#9538) Co-authored-by: Claude Code <noreply@anthropic.com> * fix(web): simplify expanded tool details (pingdotgg#9549) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): keep the last message visible when the resting composer expands (pingdotgg#9553) Scrolling a long thread to the end with the composer at rest landed flush against the short composer. The expansion that followed then covered the last rows, because the timeline reserves only the live overlay height and does not move for footer growth. The timeline now keeps the expanded composer's height clear while the composer rests, so expanding it again changes nothing above the composer. The composer reports its resting flag from a layout effect and publishes a fresh overlay height whenever that flag changes, so the reservation is always computed from a height that belongs to the same layout. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * test(web): fix flaky startup and Tailwind tests (pingdotgg#9558) * fix(web): keep codex restart responses continuous (pingdotgg#9560) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): make settings sidebar sub-section buttons full width (pingdotgg#9562) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(web): render settings sidebar immediately (pingdotgg#9563) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * chore: vouch august contributors (pingdotgg#9557) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): stabilize right panel transitions (pingdotgg#9554) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix: better shell syntax handling for labels (pingdotgg#9371) * fix(web): align the sidebar wordmark by baseline (pingdotgg#9578) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(antigravity): keep subagent batches active after launch (pingdotgg#9579) * fix(mobile): render workspace images in markdown file previews (pingdotgg#8769) * fix(usage): deduplicate CLI proxy subscription accounts (pingdotgg#9584) * fix(web): bound disconnected send toasts (pingdotgg#9592) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(desktop): restore panel titlebar interactions (pingdotgg#9591) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(connect): refresh authorization without disconnecting (pingdotgg#9582) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): show context meter in compact composer (pingdotgg#9430) * fix(pull-requests): refresh data after thread turns (pingdotgg#9496) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): render draft PRs in gray (pingdotgg#9537) * refactor(web): move usage provider controls to settings (pingdotgg#9599) * fix: show idle subagent batches without completion marks (pingdotgg#9616) * fix(web): group image views like other tool calls (pingdotgg#9597) Co-authored-by: Claude Code <noreply@anthropic.com> * fix: preserve tool icons on failed calls (pingdotgg#9606) * fix(connect): diagnose incomplete headless server setup (pingdotgg#9602) * fix(web): keep command palette above composer menus (pingdotgg#9613) * fix(web): snooze menu no longer overlaps thread details (pingdotgg#9601) * fix(web): match composer pull request state icons (pingdotgg#9375) * fix(server): load OpenCode workspace skills via SDK to avoid 64KB CLI pipe truncation (pingdotgg#9585) * fix(web): mute sidebar branch name to match worktree icon (pingdotgg#9622) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web,mobile): fold context compaction under settled turn folds (pingdotgg#9623) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * feat(mobile): make chat text selectable on Android (pingdotgg#8779) Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> * fix(web): toggle a single stashed prompt with Cmd+S (pingdotgg#9644) Cmd+S opened the stash menu even when the composer was empty and only one prompt was stashed. It now restores that prompt directly, so repeated presses toggle between the draft and stash. Multiple entries and images that are still saving open the menu. The stash badge still opens the menu. Validation: 94 focused stash, shortcut, and attachment tests pass. Web typecheck and formatting pass. Targeted lint has no new warnings or errors. Browser checks were skipped at Theo's request. Original implementation by Theo Browne. No code changes were needed during the takeover audit. Audited with GPT-6 Astra (preview) in Codex. * fix(server): prevent duplicate desktop clients after restart Replace stale local desktop sessions in one transaction. Preserve paired clients and browser sessions, and keep the previous credential valid if replacement fails. Closes pingdotgg#6283. Original implementation by seeb1337. Reviewed and verified with GPT-6 Astra (preview) in Codex. Co-authored-by: seeb1337 <63622047+seeb1337@users.noreply.github.com> Co-authored-by: Theo Browne <me@t3.gg> * fix(web): resume Antigravity threads without repeated sign-in (pingdotgg#9647) Allow Antigravity threads to resume while saved Google sign-in is unchecked after a server restart. Keep confirmed authentication failures and installation errors visible. Validated with 136 focused tests, web typecheck, targeted lint, and CI. Browser verification was omitted at the maintainer's request. Created with GPT-6 Astra (preview) in Codex. * feat(mobile): paste the phone clipboard into the terminal (pingdotgg#9199) Co-authored-by: Jake Leventhal <jakeleventhal@me.com> Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> * feat(web): show which sidebar threads hold an unsent draft (pingdotgg#9658) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * fix(server): unblock OpenCode approvals and stop (pingdotgg#9653) OpenCode could show an Approval badge with no controls, appear stuck on TodoWrite, and keep showing a running turn after Stop. - Show every permission, including old saved requests. Keep failed replies retryable and close completed requests even when reply events are lost. - Keep OpenCode output pipes drained and automatic replies out of the event loop. Handle disconnects, reconnects, and confirmed stops without stale requests or running states. - Show native task progress and command results. Do not treat TodoWrite or approval history as file edits or executed commands. - Ignore late aborts and task updates after a turn finishes. Fixes pingdotgg#4795 Fixes pingdotgg#7113 Fixes pingdotgg#5760 Created with GPT-6 Astra (preview) in Codex. Reviewed and merged with Claude Fable 5.1 in Claude Code. * fix(desktop): quit immediately on a second shortcut press (pingdotgg#9657) * fix(server): update Claude Agent SDK to 0.3.260 (pingdotgg#9135) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * perf(server): stop loading message bodies for thread summaries (pingdotgg#9662) * perf(web): speed up terminal snapshots (pingdotgg#9663) * Complete upstream sync adaptations and validate Claude authentication * Fix reviewed Coder sync regressions and add focused coverage * Include orchestration regression suites in Coder tests --------- Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com> Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com> Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com> Co-authored-by: Simone <lucenz@proton.me> Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com> Co-authored-by: maria <maria@kuuro.net> Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: Zortos <zortosdev@proton.me> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Igor Makowski <56691628+Mnigos@users.noreply.github.com> Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com> Co-authored-by: Invictine <72551038+Invictine@users.noreply.github.com> Co-authored-by: WellyngtonF <59291417+WellyngtonF@users.noreply.github.com> Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: macroscopeapp[bot] <170038800+macroscopeapp[bot]@users.noreply.github.com> Co-authored-by: Aditya Mer <101453576+Aditya190803@users.noreply.github.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Derek Trimm <275381468+derektrimm@users.noreply.github.com> Co-authored-by: Seth Webster <sethwebster@gmail.com> Co-authored-by: Jake Leventhal <jakeleventhal@me.com> Co-authored-by: Matheus Timbó Pereira <matheusfild4@hotmail.com> Co-authored-by: Sy-D <8460326+Sy-D@users.noreply.github.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com> Co-authored-by: Guilherme Vieira <46866023+GuilhermeVieiraDev@users.noreply.github.com> Co-authored-by: Guillermo Casanova <75276669+Gigioxx@users.noreply.github.com> Co-authored-by: Barry <43803274+BarryHenryJr@users.noreply.github.com> Co-authored-by: seeb1337 <63622047+seeb1337@users.noreply.github.com> Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>

Users on Codex or Claude Code subscriptions had no way to see how much of their quota was left or when it resets without leaving T3 Code. Both providers already emit a rate-limits event during turns, but its payload was untyped and the server dropped it on the floor.
This adds a Limits tab to the Usage page, next to Cost and Tokens. Each connected environment reports the account limits its providers know about, and the page shows one section per provider: a bar per window in use, filled by the share of quota spent, with a marker at how far into the window you are. Because the bar is the whole window, that marker is also where even spending would have put the fill, so a pace icon says whether you are ahead of, on, or under pace. Hovering a bar gives the exact figures and the reset time. Codex accounts with banked reset credits show the count with a confirmed Use a reset action.
How it works
UsageLimitsUpdate. Codex mapsaccount/rateLimits/updated, Claude Code mapsrate_limit_event, and both keep window ids stable so turn-driven updates merge onto the same rows.codex app-serverprocess, so limits never need an open thread. Reads may retry on a fresh process after a session failure; a redemption never does. Redemption is single-flight per instance and keeps one idempotency key until Codex reports an outcome./usagedialog uses, with the OAuth token Claude Code stored on disk. The token never leaves the server. It reads the endpoint's structuredlimitsarray, which is where model-scoped weekly buckets such as Fable carry their real names, and falls back to the legacy named keys. On macOS the credentials live in the Keychain and reading them from another process triggers a prompt on every refresh, so macOS relies on turn events until that becomes an explicit opt-in.UsageLimitsServicekeeps the latest snapshot per provider instance, folds in runtime events, refreshes on every subscribe and on every provider instance change, and streams changes over a newsubscribeUsageLimitsRPC. Full account reads replace the window set; sparse turn events merge by id. A failed read is recorded on the snapshot beside the last good numbers. Limits are account state rather than thread history, so nothing is persisted or event-sourced.Verification
Not in this PR
After
Light:
Dark:
Built with Claude Fable 5.1 in T3 Code.
Note
Medium Risk
Touches provider adapters, OAuth token reads for Claude limits, and Codex reset consumption with idempotency; incorrect merge on complete reads could briefly drop windows, though stamps protect newer turn events.
Overview
Adds subscription quota visibility on Usage via a new Limits metric alongside Cost and Tokens (web tab + mobile card). Clients subscribe per environment only while Limits is open; pull-to-refresh also re-fetches limits.
Server: Introduces typed
usageLimitscontracts,UsageLimitsService(in-memory snapshots, merge by window id, refresh on subscribe/instance changes), and WebSocketsubscribeUsageLimitsplusserverConsumeUsageLimitReset. Codex and Claude adapters now emit normalisedUsageLimitsUpdatefrom turn events and optional on-demand reads (Codex via live or short-lived app-server; Claude via claude.ai usage API with stored OAuth, skipping macOS file creds to avoid Keychain prompts). Codex reset redemption is single-flight with stable idempotency keys.UI: Bars per active window with elapsed marker, pace vs. even spend, reset countdowns, and web-only confirmed Use a reset for banked Codex credits. Shared
@t3tools/shared/usageLimitskeeps pace math consistent across web and mobile.Reviewed by Cursor Bugbot for commit 3e02d2e. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Add Limits tab with provider quota windows and Codex banked resets
UsageLimitsServicebackend in UsageLimitsService.ts. It reads account limits from Codex and Claude adapters, merges sparse runtime events, and serves snapshots over WebSocket.UsageLimitsUpdateschema with windows, percentages, reset timestamps, and plan labels.UsageLimitsService.makestores state in memory. Themake.applymerge operation removes stale windows during complete adapter reads unless a newer runtime event touched them.Macroscope summarized 3e02d2e.