TiboTattle
Community checking Connecting

Local evidence dashboard

Your Codex allowance, made measurable.

Compare content-free token metadata with observed quota movement, see what the model can and cannot explain, and improve the estimate over time.

Latest observation Checking… Local companion

01 · Overview

Where your allowance stands

Current quota observations and API-price-equivalent usage from your local evidence.

API-price equivalent

Replay-safe usage cost

This applies public API prices to non-overlapping local token increments. It is not a subscription charge or a published dollar limit.

Recorded period Awaiting local evidence

This activity total can exceed the inferred weekly limit: it spans a calendar period, while the weekly estimate describes one observed reset track and may cross resets, credits, or account changes.

Measured versus calculated

Does token cost explain the quota change?

No evidence
Observed quota movement
Cost-implied movement

More observations are required before a useful comparison can be made.

Central fitted rate
Not estimable
Plausible 80% range
Not estimable
Example translation
Not estimable

This fit uses API prices as a measuring stick. It is not a provider-published dollar allowance.

02 · Timeline

Usage and allowance over time

API-price-equivalent usage over time

Replay-safe local increments · browser-local time · current API prices

API-cost estimate 7-day allowance remaining
No real usage timeline loaded

Analyze local usage to build recent content-free usage buckets.

Advanced calibration: measured quota change versus calculated change

Observed quota change versus cost-implied change

Browser-local chart axis · exact local and UTC times are listed below

Calibration window
Observed quota Expected from API cost Missing quota bracket Reset or track change Ambiguous movement
No timeline loaded

Connect the local companion or choose the labeled demo.

Residuals

Where the estimate misses

Residual = observed quota change minus cost-implied change. Positive values mean the allowance fell faster than the token model predicted.

No residual evidence loaded.

Inspect exact periods

Exact windows and evidence state

Largest unexplained quota movement periods
Exact local / UTC time Observed Expected Difference Evidence state
No periods loaded.

03 · Weekly allowance

Our best estimate of the seven-day limit

Historical reset-series fits, plotted when each estimate became observable and with partial extrapolations kept visibly separate.

Historical median estimate No evidence interval available
Evidence strengthInsufficient

The estimate will appear when enough quota transitions can be matched to priced usage.

History

Seven-day allowance estimates by observation date

Historical median Across-reset 80% range Fit observed across ≥80 pp Partial diagnostic extrapolated to 100 pp
No weekly estimates loaded.

Points are independent reset-series fits, not a continuous balance. The shaded band is variation across reset series; per-row sensitivity remains in the evidence table. Scroll horizontally on a narrow screen.

Validation

How wrong was the estimate?

Has the inferred limit changed?

There is not yet enough comparable weekly evidence to call a change.

The change statement follows the date and evidence filters above. Error metrics use all qualifying held-out observations when available.

View week-by-week evidence and caveats

Each row matches API-price-equivalent usage to a decrease in the provider-reported seven-day allowance, then scales that movement to an inferred full 100 percentage-point allowance. Partial rows are diagnostics and must not be read as completed weeks.

Week-by-week evidence

What changed, and how certain are we?

Weekly allowance estimates and uncertainty
Evidence available / reset due Observed API equivalent Quota decrease Implied full allowance Within-reset sensitivity Usable observations Coverage quality Caveats
No weekly evidence loaded.

04 · Cost accounting

How the estimate was calculated

API pricing is a measuring stick, not your bill.

Every local usage increment is repriced with the public Standard API rate card. Subscription Fast mode remains a separate observed attribute.

Token components

Non-overlapping token components

Output text excludes reasoning tokens. Combined output is used only when a source does not provide that split, and is never added again.

Models

Recognized and unknown model usage

Replay-safe usage grouped by recognized model
ModelUsage incrementsTokensAPI equivalent

Any unrecognized model is kept as an explicit overflow row. Its tokens remain visible, but no price is invented.

Subscription speed

Standard, Fast and not recorded

Percentages are API-price-equivalent cost shares; counts are non-overlapping usage increments. Not recorded means an older rollout did not retain this setting and is not inferred as Standard.

Surface

Where replay-safe usage ran

Percentages are API-price-equivalent cost shares; counts are non-overlapping usage increments, not messages, turns, or every raw log row.

Advanced metadata coverage

These fields audit the estimator; they are not provider billing categories and may be absent in current logs.

Lineage

Root and child-rollout coverage

Tool classes

Coarse calls, not token usage

API service tier

Not exposed by subscription logs

Reasoning effort

Not exposed in usage snapshots

05 · Monitoring gaps

What this monitor can actually see

Honest coverage is part of the result. Blind spots, unknown models, missing prices, resets, and unobserved surfaces remain explicit.

Signal coverage

Metadata coverage by signal

Each row is an independent signal. The badge is a count of signals, not an overall percentage score.

Needs investigation

Known blind spots

No quality artifact loaded.
Archived technical reports

These links open separately generated diagnostic HTML in a new tab. They stay on this computer and do not collect additional telemetry.

Help improve the estimate

Help map Codex limits

Contribute content-free pseudonymous metadata so the community can measure how Codex limits differ over time. Prompts, responses, commands, paths, account names and credentials never leave this Mac.

What would be contributed?

Timestamps, token counts, model declarations or opaque model fingerprints, subscription speed, coarse tool and surface categories, and observed quota percentages.

No message content, reasoning text, filenames, URLs, commands, account names, email addresses, raw identifiers or credentials.

Automatic contribution Off

Off until you explicitly consent. No daemon or login item is installed; checks run only while TiboTattle is open.

06 · Data & privacy

Local by default. Contribute by choice.

Raw logs are read by the loopback companion, not the webpage. A contribution must be a privacy-stripped export and is validated again by the server. Hosted participation requires signing in with Google or Apple; the service stores only an irreversible hash of that sign-in, never your email or name. Local-only use needs no account.

Pre-upload inspection Exact metadata categories a contribution may contain Closed schema

Permitted metadata

  • Observation, event and reset timestamps
  • Uncached input, cached input, cache write, text output, reasoning output and combined-output token counts
  • Recognized model declaration or safe opaque model fingerprint
  • Subscription speed and separately observed API service tier
  • Coarse surface, agent scope and child-rollout lineage classes
  • Coarse tool-class counts
  • Quota percentage, window duration, slot and reset timing
  • Domain-separated participant, account, session, event and snapshot pseudonyms where the selected contract permits them
  • Schema, pricing, parser and consent provenance plus fixed diagnostics

Never collected or uploaded

  • Prompts, responses or reasoning text
  • Tool names, arguments, commands or command output
  • URLs, files, paths, repositories, branches or working directories
  • Email addresses, account names, hostnames or usernames
  • Raw participant, device, account, session or request identifiers
  • Credentials, cookies, API keys, tokens or authorization material
  • Arbitrary labels, unknown fields or free-form metadata

Browser validation is a preflight. The Worker decrypts into bounded memory, validates the same closed schema again, rejects content canaries, and recalculates API-price-equivalent values before D1 ingestion.

Optional next step Review or contribute privacy-safe community evidence Closed until you choose it

Local collector

Source and analysis status

Unknown
Last analysis
Safe records
Source bytes
Not exposed to browser
Identity
Pseudonymous
Included
  • Timestamps and models
  • Token components and quota observations
  • Coarse tool and surface categories
Excluded
  • Prompts and responses
  • Files, paths, commands and arguments
  • Email and account names

Review before the first send

Review a content-free contribution

Checking service

Preparation reads the latest bounded interval locally and performs no upload. Inspect the concise summary, expand the exact JSON if wanted, then confirm the first send.

Prepare and review evidence

Preparation identity Checking
Evidence to prepare

Analyze local usage to estimate the number of privacy-safe records and upload batches before preparation.

Nothing is sent until you separately inspect and choose a send action. A dense seven-day selection may exceed the single reviewed-set safety cap; if so, choose 24 hours instead.

Advanced: use an existing TiboTattle export

Choose a .json file created by TiboTattle. Do not choose a .jsonl file, a sessions folder, or a raw Codex log.

Contribution activity

Advanced queue and exact review

Checking queue

The local queue contains metadata about committed, privacy-verified batches only. It never contains prompts, responses, source paths, account names, browser sessions, or device secrets.

Waiting
In flight
Accepted
Needs attention
Next attempt
Last accepted

Next verified upload

Inspect before sending

Not inspected
Covered period
Safe records
API-price estimate
Upload reservation

Sending stays disabled until you open the exact local review for the current queued contribution.

Inspection uses loopback only: it performs no service request, key fetch, authorization, or upload. The send action consumes a ten-minute, single-use local authorization and can claim only the exact reviewed queue job. The broader foreground CLI retains its independent bounded multi-job and upload-byte limits.

Automatic checks run at most every 6 hours while TiboTattle is open and only after explicit consent. No login item, LaunchAgent, daemon or silent background process is installed.

Optional community service

Community backend readiness and data lifecycle

Checking backend

This optional service is separate from the local collector above. Live readiness verifies database and encrypted-object access, fresh retention and restore replay, object reconciliation, and aggregate rebuild state. The repeatable backend suite covers the complete ingestion, isolation, export, and deletion lifecycle.

Database
Checking
Deletion ledger
Checking
Encrypted quarantine
Checking
Retention & restore replay
Checking
Object reconciliation
Checking
Aggregate rebuild
Checking
Collection state
Checking
Enrollment
Checking
Upload registration
Checking
Ingestion processing
Checking
Aggregate publication
Checking
Participant rights
Checking
Accepted upload contract
Checking
  1. 1Browser validationReject raw or oversized files before upload
  2. 2Encrypted transportOne-use upload authorization and envelope encryption
  3. 3Server validationClosed schema, content-field rejection, and canonical repricing
  4. 4Transactional ingestIdempotent deduplication into participant-isolated records
  5. 5Private analysisPersonal cost, quota movement, and calibration results
  6. 6Delayed aggregateThresholded, clipped, rounded community snapshots
  7. 7User controlExplicit hosted deletion remains available
  8. 8Lifecycle enforcementSeven-day quarantine cleanup and deletion-safe restore replay
Account-scoped v0.2 ingest is disabled by default. A separately configured loopback-only preview can exercise the complete HTTP path; external participants remain unauthorized.

Your contributed evidence

Your contribution receipt

Accepted intervals and private calculations appear here. Personal reporting remains in this local app; contribution helps improve the delayed community view.

No accepted contribution is associated with this browser yet.

Contribution history

Delayed community evidence

Published weekly snapshot

Checking for the latest delayed weekly snapshot…

Community values use a fixed delay, independent per-cell support, participant-level clipping, and coarse rounding. A sealed revision is never rewritten; privacy-affecting deletion withdraws it and schedules a replacement revision without the deleted source.