Read Claude Code's own quota endpoint, not just its status line

Decision 0015 rejected the account usage endpoint because AGENTS.md forbade
reading a harness's credential. The rule was written to stop one program
helping itself to another's secrets, and it was catching a legitimate use with
it: the user asking about their own subscription, through software they
installed to do that. AGENTS.md now states the narrow allowance instead of an
absolute the project does not hold, and 0016 records it.

The status line stays. It is free and it speaks every turn. What it cannot do
is report the per-model weekly limits a Max plan meters separately, or answer
at all before a session has taken a turn. The first live reading found the
account-wide seven-day window at 38% left and a per-model weekly window at 77%
left — a second ceiling the footer previously could not see.

Constraints the credential is read under, all enforced in code: access token
only, never the refresh token; zeroed on drop, along with the file buffer it
was borrowed out of; unprintable by construction, since HarnessError carries no
owned strings and AccessToken's Debug is hand-written; identified as
lumbridge/<version>, because sending claude-code/2.1.0 would make our traffic
indistinguishable from the harness's in Anthropic's logs; and off entirely
under LUMBRIDGE_CLAUDE_OAUTH=0.

The request runs on a detached thread with a slow refresh and a 429 backoff, so
a ten-second round trip cannot stall the transcript follower or make quitting
wait on the network, and one surface failing does not fault the other two.

Footer polish on top: the harness name prints once per group instead of in
front of each of its four windows, each quota carries a short scope pill
(5h, 7d, Fable wk, tokens) where an invisible BORDER-weight label used to be,
quotas sort ahead of spend, and a window under ten percent turns its headline
amber — value colour on the number, provenance colour on the meter, never
mixed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Metal Agent
2026-08-31 22:04:34 -07:00
co-authored by Claude Opus 5
parent ef52aa7ce2
commit 219c674aea
13 changed files with 1674 additions and 73 deletions
+12 -1
View File
@@ -5,9 +5,20 @@ These rules apply to the entire Lumbridge repository.
## Product boundary
Lumbridge is a terminal/workspace runtime and ACP client. It may host, supervise,
and observe coding harnesses, but must not silently impersonate them, scrape their
and observe coding harnesses, but must not silently impersonate them, harvest their
private credentials, or claim provider quota data that cannot be verified.
**Credential use is narrow and named.** A harness's stored credential may be read
only to ask that same provider a documented question about the user's own account,
and only where the answer cannot be obtained another way. Under that allowance a
credential must never be persisted, logged, copied into application state, written
to a crash report, or passed as a command-line argument; it must be released as
soon as the request it authorises has been made; and any request it authorises must
identify Lumbridge as the caller. A refresh token is never used — renewing a
credential is the harness's job, not Lumbridge's. Every such use is named in a
decision record, and each is switchable off by the user. Reading a credential for
anything other than a use recorded that way is out of bounds. See decision 0016.
## Research boundary
Upstream repositories are cloned outside this Git repository under the desktop