Repository navigation
feat(quota): stamp when each shared window was last observed - #471
Merged
MagicalTux merged 2 commits intoSep 29, 2026
Merged
Conversation
Status readers could not tell a 5-hour or weekly reading taken a minute ago from one restored off disk after a week idle. Each account's quota now carries unified5hSeenAt and unified7dSeenAt beside the values in /teamclaude/status, for Claude and Codex accounts. A stamp moves only with its own window's value: a response header or usage probe that states that window's utilization sets it. An empty payload, a failed probe, a reset time alone, or a model-scoped weekly bucket leaves it alone. A window that resets clears its stamp. The stamps persist across a restart; a value restored from an older state file keeps a null stamp until upstream states the window again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Shared quota values and timestamps can still be overwritten on reset-only or missing-utilization usage payloads.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds persisted timestamps for the last observed shared Claude and Codex quota windows, exposed through status output.
Changes:
- Tracks and clears
unified5hSeenAtandunified7dSeenAt. - Persists timestamps across restarts.
- Adds tests and usage documentation.
| File | Summary |
|---|---|
src/account-manager.js |
Implements timestamp tracking and persistence; requires guarding value/stamp writes when utilization is absent or unparseable. |
test/quota-seen-at.test.js |
Covers provider updates, resets, persistence, and status output. |
docs/usage.md |
Documents the new status fields. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
3920
to
3924
| if (usage.fiveHour) { | ||
| q.unified5h = usage.fiveHour.utilization; | ||
| q.unified5hReset = usage.fiveHour.resetAt ?? null; | ||
| q.unified5hSeenAt = Date.now(); | ||
| } |
Merged
MagicalTux
added a commit
that referenced
this pull request
Sep 29, 2026
Thirty-two commits since 1.1.21. Two change routing on an existing config without an opt-in (#480, #481); the rest is opt-in, additive, or display. Behaviour changes #481 an API-key account's 401 is a cooldown, not a permanent `error`: 1 min, then 5, 15 and 60 for every further rejection with no success in between; any 2xx/3xx resets it. The request still fails over and the client never sees the 401. OAuth accounts are unchanged #480 with session distribution on, requests carrying no session id stay within the top priority tier, so a fallback gateway no longer answers Claude Code's bootstrap and connector calls #470 a 200 whose SSE stream reports a provider failure before any output (`server_is_overloaded`, `response.failed`) fails over once, like a status-shaped failure would #465 a reload removes running accounts whose config entry is gone from disk, so `teamclaude remove` from another shell takes effect at once #460 `import` refuses an account whose token upstream has definitively rejected (401/403), even with `--name`; a 5xx or timeout still imports Rename #483 the project is being renamed to TeamRouter (#72). This release accepts the new name everywhere the old one is read and changes nothing an install has on disk: `teamrouter` runs the same CLI, every `TEAMCLAUDE_*` variable is also read as `TEAMROUTER_*` (which wins when both are set), every `/teamclaude/…` control route also answers at `/teamrouter/…`, and `~/.config/teamrouter.json` is used when it exists Features #441 per-account egress proxy (`accounts[].routing`: http, socks4/4a, socks5/5h) for refresh, probes and requests; `login --routing`, `teamclaude routing set/show/clear`, a connection check before it is relied on, and a short hold when the proxy is unreachable #427 `accounts[].allowExtraUsage: true` lets a paid extra-usage account serve once every account is past its threshold, instead of a 429 #466 `accounts[].maxSpend`, a money cap judged against the month-to-date extra-usage spend upstream reports; the TUI shows what an account has billed #436 `autoRedeemResets` spends a free Codex rate-limit reset credit when the Codex pool runs dry (off by default) #482 `advisorEligibility: "strict" | "prefer"`; when the advisor model narrows selection to a subset of the fleet the log says so, and status carries the reading (`advisorNarrowing`) #478 `stripOverageHeaders` drops another org's per-organization billing headers from responses, for a pool spanning several orgs (#476) #471 `quota.unified5hSeenAt` / `unified7dSeenAt` in status: when upstream last stated each shared window #446 client and dimension usage for the last 5h and 24h in status and the dashboard, resumed across restarts #458 #459 #461 the dashboard sets the switch threshold, enables/disables and reprioritizes an account, and has a light theme remembered per browser #464 `l` in the TUI signs an account in `error` in again from the dashboard #457 status records which Codex limit meters each model (`quota.codexModelLimits`) #442 `quotaBarPercent` drops the percentage beside a TUI bar's countdown #451 `stripRequestFields` takes `content.<block type>` to drop content blocks a strict Anthropic-compatible upstream rejects #469 `proxy.mcp` schemas declare their item types, the write audit line records what happened, and the write queue has a depth (#447–#450) Fixes #477 a refused WebSocket handshake whose headers all drop is relayed as a well-formed head instead of a blank line and body bytes #474 two members of one ChatGPT workspace are told apart by user id, so a second `login --codex` no longer replaces the first #469 a Codex Responses stream with no Content-Type is relayed as a stream and booked; thread repair on the global upstream; TUI settings and status gaps; a hint when a local login would have served #463 a Codex row with no session window draws one wide weekly bar Tests #484 #485 #486 the suite asserts behaviour, not the scheduler: wall-clock upper bounds are gone, and subprocess tests spawn the server through `test-helpers/spawn-server.js`, which verifies the server it reached by `server.pid` (new in status) instead of trusting a port Tooling #452 #453 #454 #455 docker workflow actions bumped
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

/teamclaude/statusnow says when upstream last stated each account's shared 5-hour and weekly readings. Every account'squotacarriesunified5hSeenAtandunified7dSeenAt(epoch ms) besideunified5handunified7d, for Claude and Codex accounts alike.Why: a status reader can't tell a reading taken a minute ago from one restored off disk after the account sat idle for a week. Both show up as the same number. The Fable and Sonnet buckets already carry a
SeenAtfor the staleness check, and Codex model buckets carryseenAt. The two shared windows, which every account has, carried no age at all. I read status from a dashboard that refuses to forecast from a reading whose age it can't prove, so right now every shared reading there is marked unverified.What moves a stamp
A stamp moves only in the same branch that writes its window's value:
anthropic-ratelimit-unified-5h/7d-utilization) and the OAuth usage probe.x-codex-*headers and the/wham/usageread.So these leave both stamps alone: an empty payload, a failed probe (
usage.error), a bucket with a reset time and no utilization, an unparseable value, a zeroed Codex window, and a model-scoped weekly bucket (7d_oi,sevenDayFable, a named Codex family's weekly window). A partial update stamps only the window it stated.One case reads like a model bucket but isn't: a Codex subscription states its only 5-hour window inside a model-named family, and
parseCodexQuotaalready takes that as the account'sunified5h. The value changes, so the 5-hour stamp moves with it. There's a test for it.When a window resets in
_clearExpiredQuotas, its stamp is cleared along with the value, so a stamp never outlives the number it vouches for.Restarts
Both stamps are in
PERSISTED_QUOTA_FIELDS, so a real time survives a restart unchanged.restoreQuotaStateonly copies non-null fields ontoemptyQuota(), so a row from a state file written before this change comes back with its value and anullstamp. It staysnulluntil upstream states that window again. Nothing starts a clock on restore. That's deliberate: the family buckets start a local grace clock when their stamp is missing, but that clock drives revalidation and isn't evidence of an upstream reading, so the shared stamps don't copy it.Nothing gates on the new fields. Rotation, thresholds and the TUI behave exactly as before.
Notes for review
emptyQuota()entries carry a/** @type {number|null} */cast. Without it, strict mode infers the typenulland the ratchet grows by six diagnostics onsrc/account-manager.js. With it, the count stays at the base (1703 both sides).applyUsageDataalready read the clock once, asconst nowabove the family buckets. That line moves to the top of the method, so the shared stamps and the family stamps use the same reading.codexModelBucketsisn't persisted, so model buckets and theirseenAtstart empty after a restart (nothing is invented, they just aren't kept). The Anthropic header path still accepts whateverparseFloatreturns, so a negative orInfinityutilization is stored, and now stamped with it. Value and stamp still agree. The Anthropic per-modelscopedWeeklyreadings carry no time either; this change doesn't add one.Tests
test/quota-seen-at.test.js, seven tests:nullstamps, and stillnullafter a second restart.GET /teamclaude/statusshows each stamp beside its value inside the request's time window, withnullstamps on an idle account.All seven fail on
6c3bdc0and pass on this branch. I also broke each piece on a throwaway copy (dropped persistence, kept a stamp through a reset, stamped on reset-only, left the Codex header writes unstamped, left the Codex usage-read writes unstamped, stamped on any Codex payload, stamped on any Anthropic response). Each mutation failed a named test.docs/usage.mddocuments the two fields next to the existingstatus --jsonnotes.What I walked
A side server on
127.0.0.1:3458, run from this branch with a scratchTEAMCLAUDE_CONFIGholding one Claude account, one idle Claude account and one Codex account. It had access tokens only, no refresh tokens, plusupstreamProxy: false,autoUpdate: false,quotaProbeSeconds: 0,TEAMCLAUDE_DISABLE_AUTOUPDATE=1and the proxy env unset. Nothing live was touched.Before any request, every stamp read
null. Then I sent oneclaude-haiku-4-5-20251001request pinned toclaude-served(sent 14:55:01.48Z, HTTP 200, answeredok) and one real Codex CLI request (codex-cli 0.156.0),gpt-5.6-luna, pinned tocodex-served(14:55:02.16Z to 14:55:03.97Z, answeredok). Status right after:The Codex response stated a weekly window and no 5-hour window, so only the weekly stamp moved. After a SIGTERM and a restart on the same state file, the times came back unchanged (
1790348102100,1790348103153) and the idle account still readnull.🤖 Generated with Claude Code