Metal AgentandClaude Opus 5 219c674aea Read Claude Code's own quota endpoint, not just its status line
Decision 0015 rejected the account usage endpoint because AGENTS.md forbade
reading a harness's credential. The rule was written to stop one program
helping itself to another's secrets, and it was catching a legitimate use with
it: the user asking about their own subscription, through software they
installed to do that. AGENTS.md now states the narrow allowance instead of an
absolute the project does not hold, and 0016 records it.

The status line stays. It is free and it speaks every turn. What it cannot do
is report the per-model weekly limits a Max plan meters separately, or answer
at all before a session has taken a turn. The first live reading found the
account-wide seven-day window at 38% left and a per-model weekly window at 77%
left — a second ceiling the footer previously could not see.

Constraints the credential is read under, all enforced in code: access token
only, never the refresh token; zeroed on drop, along with the file buffer it
was borrowed out of; unprintable by construction, since HarnessError carries no
owned strings and AccessToken's Debug is hand-written; identified as
lumbridge/<version>, because sending claude-code/2.1.0 would make our traffic
indistinguishable from the harness's in Anthropic's logs; and off entirely
under LUMBRIDGE_CLAUDE_OAUTH=0.

The request runs on a detached thread with a slow refresh and a 429 backoff, so
a ten-second round trip cannot stall the transcript follower or make quitting
wait on the network, and one surface failing does not fault the other two.

Footer polish on top: the harness name prints once per group instead of in
front of each of its four windows, each quota carries a short scope pill
(5h, 7d, Fable wk, tokens) where an invisible BORDER-weight label used to be,
quotas sort ahead of spend, and a window under ten percent turns its headline
amber — value colour on the number, provenance colour on the meter, never
mixed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 22:04:34 -07:00

Lumbridge

Lumbridge is a fast, local-first workspace and terminal multiplexer for agentic engineers. It will run coding harnesses side by side, preserve their sessions, connect rich agents through ACP, and show trustworthy account and usage context without forcing users into one model vendor.

The first supported desktop platforms are:

  • macOS (Apple Silicon first, Intel when CI capacity is available)
  • Ubuntu Linux
  • Omarchy and compatible Arch Linux systems

Lumbridge is free and open source under Apache-2.0. Releases will be published as installable binaries; building from source will remain supported.

Status

This repository is in architecture and vertical-slice phase. The installable binary is still a scaffold, while the isolated native UI spikes now exercise an interactive 20/60/20 workspace backed by six live comparison surfaces, and the root workspace contains the first bounded local PTY, runtime actor, VT engine, and capability-gated workspace command boundaries. The GPUI slice shows a responsive one-, three-, or five-panel workspace—five on a 3440 px ultrawide— where every panel owns its own context, work surface, and decision shelf. One panel contains a styled actor-owned VT session and five comparison surfaces remain deterministic. Retained-history navigation is wired. The usage footer is a live strip over an append-only ledger with provenance, fed by two real adapters: Codex's documented quota surface and Claude Code's session transcripts. A harness with no adapter renders an explicit gap rather than a zero. We are still validating terminal text selection and mouse input, standalone runtime IPC/durability, ACP integration, and packaging before a large implementation.

Product shape

  • A native desktop shell with tabs, panes, workspaces, worktrees, diffs, and an agent-aware footer.
  • A Rust session runtime that survives UI restarts and can later run headless.
  • ACP-native integrations where available, with supervised PTYs as the universal fallback for any CLI harness.
  • First-class harnesses for Claude Code, Codex, DeepSeek Harness, Pi, Hermes, OpenClaw, Goose, Gemini CLI, and OpenCode.
  • Subscription login owned by the upstream harness, plus separate BYOK provider profiles for OpenAI, Anthropic, Gemini, Groq, Cerebras, DeepSeek, and more.
  • Usage history, burn rate, reset windows, and forecasts with visible data provenance instead of invented precision.
  • Optional first-class Buzz channels, messages, agents, and confirmed redacted pane sharing without making Buzz a requirement.
  • An optional Lumbridge Harness that can suggest, coordinate, and—with explicit execution capability—manage agents through the same audited command plane as the human UI. Lumbridge remains useful without it.

Start with the product spec, architecture, research map, and captured upstream revisions. The native UI choice is intentionally open; see the measured decision plan.

Scaffold

bacon              # continuous check; t tests, c lints, v runs the full gate
cargo xtest         # fast isolated tests with nextest
./scripts/ci.sh     # format + strict Clippy + tests + doctests
cargo run -p lumbridge

See the testing strategy for fake harnesses, ACP replay, terminal conformance, UI driving, recovery, performance, and packaging tests.

The accepted local/remote boundary is recorded in decision 0003. The two native shell candidates live in spikes/, with results tracked in the UI scorecard. The signed-protocol and pane-sharing boundary is in the Buzz integration design. Brand masters, platform-ready raster exports, and usage rules are in assets/brand/ and the brand guide.

S
Description
A fast, local-first workspace and terminal multiplexer for agentic engineers.
Readme Apache-2.0
2.5 MiB
Languages
Rust 97.3%
Shell 1.7%
JavaScript 0.7%
Python 0.3%