The technical brief
What Quotum reads on your Mac
An app that reads your Keychain and your credential files should say which ones, what for, and where the result goes. This page names every source, every address and every schedule — and gives the commands that let you prove it wrong.
Survey dated September 30, 2026, made by reading Quotum's code as of that date. The line numbers cited shift with the first commit that adds a line above them; the classification holds. The commands in section 06 are there so that you can check it rather than take our word for it.
01 What it shows, line by line
A bare percentage is ambiguous. So each account in the panel shows, to the right of its name, the age of its measurement — because a figure measured three hours ago is not worth a figure measured just now; on an account folded under “Recharging”, that age shows on hover and to VoiceOver —, then one line per quota window that its provider publishes: the length of the window, a ten-box gauge whose filled cells show what is left, the share used, and the time at which it recharges.
All of an account's windows are written on its card. The shortest one it publishes takes the first line, in large type — 5 hours for Claude, 5 hours or 7 days for Codex depending on the plan, the month for Cursor —, and the others follow, more discreetly. No window is made up: a provider that publishes only one has only one line. The recharge time is written in its shortest form: the time alone within the day, preceded by the day up to six days ahead, the date beyond that.
| Account | Window | Gauge | What is written |
|---|---|---|---|
| Travail · Max20 | 5 h | 22% used · 11:41 The short window, in large type, on the account's card. |
|
| Travail · Max20 | 7 d | 74% used · Sat 09:01 A longer window, on the same card, more discreet. Less than half of it is left: the gauge turns amber. |
|
| Perso · Max20 | 5 h | 91% used · in 25 min A single cell: ember red. The age, “measured 2 h ago”, is set in a heavier weight: past one hour, it is the figure most likely to have changed. |
|
| Veille · Max20 | 5 h | exhausted until 10:21 No filled cell, red outline: that is what “exhausted” means, not an invented value. |
|
| Équipe · Team | — | — | No measurement yet No gauge at all. An empty gauge would announce an account that has run dry, and nobody has observed that. |
An account whose token has expired shows “Sign in again” under its name, with no gauge: an expired token says nothing about the quota, and the account may be full. An account refused for quota with no window published, on the other hand, keeps an empty gauge, with no length, and “exhausted”, with the return time written under its name: without that gauge, the emptiest account would pass for an account never measured.
02 What it reads on disk and in the Keychain
Quotum asks you for no password and signs in to nothing. It reads back the credentials that the command-line tools have already placed on the machine, each where its own tool keeps it.
| Tool | Where the credential is read |
|---|---|
| Claude | Keychain, item |
| Warp | Keychain, items |
| Codex |
|
| Windsurf |
|
| Cursor | Cursor's |
| Codebuff |
|
| Augment |
|
| opencode |
|
| Grok |
|
A check that opens nothing, before any tracking
To tell you whether a tool has left its sign-in on this Mac, the “Add an account” sheet
only checks that these files exist, without opening them, before you even
turn tracking on: ~/.local/share/devin/credentials.toml,
~/Library/Application Support/Windsurf/User/globalStorage/state.vscdb,
~/Library/Application Support/Devin/User/globalStorage/state.vscdb,
~/Library/Application Support/Cursor/User/globalStorage/state.vscdb,
~/.config/manicode/credentials.json, ~/.augment/session.json,
~/.local/share/opencode/auth.json and ~/.grok/auth.json — or wherever
$XDG_DATA_HOME, $GROK_AUTH_PATH and $GROK_HOME move them.
It also looks at whether the GROK_DEPLOYMENT_KEY variable is set, without keeping
or sending its value. No content is read, the Keychain is not queried, and nothing goes out
over the network. A file being there therefore does not mean the sign-in is still valid: only
a measurement, once the tool is tracked, lets Quotum call an account signed in.
And six sources read without any tool being tracked
These do not depend on tracking a tool: Quotum reads them at every measurement, whether tools are tracked or not, including on a fresh installation. None of them is used to query a provider.
~/.claude.json— theoauthAccountobject, which names the account signed in to Claude Code. It holds no token: it is used to place the Keychain measurement on the right line.~/.claude/cc-proxy.url,~/.claude/cc-proxy.secretand their~/.codex-comptes/equivalents — where to reach the local proxies, when they are installed. The secret file is itself an identifier: Quotum puts it in the path of the address it queries, and only sends it over your machine's loopback interface.~/Applicationsand Chrome'sLocal Statefile — which account apps exist, and which browser profile each one is attached to.ps -axo command— which of those apps are running right now, so as to write “Switch to the app” rather than “Launch the app”.<app data>/plan-usage-history.json— the usage history that Claude Code writes itself next to its configuration. It holds no token.<CODEX_HOME>/sessions/YYYY/MM/DD/rollout-*.jsonl— the Codex CLI session logs, of which Quotum reads only the end, looking for the quota headers the server left there. ⚠️ These files are the transcripts of your sessions: we open them to look for a percentage, nothing from them leaves the machine, and we would rather tell you so than keep quiet about it because they hold no token.
What it writes to the Keychain
A single item, which it creates itself: “Quotum — trial”, service
app.quotum.mac.essai; its name follows the language of the app when it is created (“Quotum — essai” in French), the service does not change. It holds the start date of the trial and the 32-byte code,
drawn at random, that opens it, and nothing else; it is not synced with iCloud, and it stays
after the app is deleted, so that erasing the preferences does not restart the trial.
Deleting it as well as the preferences does not restart it either: the mark that Apple keeps
for this Mac prevents it — section 05. No item belonging to another tool is written or
modified.
The token only passes through. It is read, placed in the header of a
request, and nothing more: it is not copied into any file, written to any log or kept in
any cache. The network session is declared ephemeral, its cache is set to
nil and its policy ignores any local cache — which one command can confirm,
section 06.
03 Where it connects — every address, listed
The command grep -rn 'https\?://' Sources/ returns every line of the source code
that contains an address. They are all listed below, sorted into three groups.
We deliberately do not give their number: a count frozen on a page would be
out of date at the first commit, whereas a list can be compared line by line. An address you
found that was in none of the three tables would be exactly what to report to us.
A · The lines where the app connects by itself
| Line | Address | What happens there |
|---|---|---|
| QuotaAnthropic.swift:75 | https://api.anthropic.com | The quota windows of the Claude account, and the profile that names it. |
| QuotaCodex.swift:48 | https://chatgpt.com | The quota window of the ChatGPT account. |
| QuotaWindsurf.swift:59 | https://server.codeium.com | The Windsurf quota. The host may come from the user's file; it is then only accepted under |
| QuotaCursor.swift:288 | https://cursor.com | Cursor's monthly cycle and its on-demand spend. |
| QuotaWarp.swift:197 | https://app.warp.dev/graphql/v2 | Warp's cycle. |
| QuotaCodebuff.swift:138 | https://www.codebuff.com | Codebuff's five-hour block and week. |
| QuotaOpencode.swift:153 | https://opencode.ai | opencode usage. |
| QuotaGrok.swift:240 | https://cli-chat-proxy.grok.com | Grok credits. |
| LecteurProxy.swift:17 | http://127.0.0.1:8787 | The status of the Claude proxy, on your own machine. It never leaves the computer. |
| LecteurProxy.swift:25 | http://127.0.0.1:8788 | The status of the Codex proxy, likewise. |
| AdressesLicences.swift:9 | https://licences.quotum.app | The publisher's license service, with two routes: |
| AdressesLicences.swift:5 | https://quotum-licences-test.brickback.workers.dev | The same service in test mode. This line only exists in the program if it is compiled with the |
The two loopback ports cannot become anything else. Their address is read
from a file on disk, and nothing in the format of a URL would stop that line from naming a
remote machine. So the code accepts only three spellings — 127.0.0.1,
::1, localhost — and rejects everything else without having to
imagine it. It is a list of what is allowed, not a list of what is forbidden: a list of
that kind would always let through the form nobody had thought of.
B · The lines a browser opens, and that the app never queries
These are the destinations of commands such as “Open claude.ai” and “Open cursor.com”. They go to the browser you have chosen. Quotum sends them no request and reads nothing of what they return.
| Lines | Addresses | What happens there |
|---|---|---|
| Compte.swift:40, 41, 45–51 | claude.ai · chatgpt.com · devin.ai · cursor.com · app.warp.dev · www.codebuff.com · augmentcode.com · opencode.ai · grok.com | Each tool's home page, one per provider. |
| Compte.swift:124, 125 | claude.ai/download · chatgpt.com/download | Where to get the desktop app, offered when it is not installed. |
| VueFinEssai.swift:13, 14 | quotum.app/fr/achat · quotum.app/pricing | This site's purchase page, in French if the app speaks French to you, in English in any other language. The button that offers it, at the end of the trial, opens it in your default browser. |
C · The lines that are not destinations
| Lines | Text | What it is |
|---|---|---|
| VueReglages.swift:687 | https://exemple.test | A throwaway URL, never opened: it is used to ask macOS which browsers are installed, to fill the menu in the settings. The |
| QuotaGrok.swift:87, 89, 101 | https://auth.x.ai::… · https://accounts.x.ai/sign-in | OAuth scopes, that is, labels compared with those in the local file to tell which sign-in a token comes from. They look like addresses; none of them is contacted. |
| IdentifiantsCodex.swift:159 | https://api.openai.com/auth | The name of a section inside the Codex token, read on the machine: it is where the token names the account it belongs to. A label shaped like an address; no request goes there. |
| QuotaAugment.swift:9, 160, 161 | in comments | Documentation: the form of the tenant address, and the trailing-slash pitfall measured while writing it. |
| QuotaWindsurf.swift:312 | in a comment | An attack counterexample, cited to explain why checking only the scheme of a URL is not enough. |
A destination this command does not show
Augment. Its address is written nowhere in the code: it is read from
~/.augment/session.json, in the form
https://<tenant>.api.augmentcode.com, and is only accepted if it stays
under the augmentcode.com domain. A grep for addresses therefore
cannot bring it up — and that is why we give you this list instead of letting you conclude
that one command is enough to establish everything.
04 How often
A measurement cycle starts when the app launches, each time the panel opens, when you ask for a refresh, after an account is created, and when you change the tools you track — then every five minutes. That interval can be set in the settings to one, five or fifteen minutes; it does not go below one minute, out of restraint and not because any provider would require it.
And no tool is queried as long as you track none. None of the nine is tracked at installation, and each one is chosen separately: at installation, no token is read and no request goes to any provider. Only the update check and the request that opens the trial at first launch, which do not depend on that choice, and, once per Mac after purchase, the license activation, reach the publisher's server — section 05. What follows therefore describes the cycle of a tool you have chosen to track.
A cycle, at most, is:
- two requests to
api.anthropic.com— usage and profile, sent together; - one request to each of the eight other providers;
- two reads over the loopback interface, which do not leave the computer.
“At most” is the key phrase. Each reader first looks for its credential on the machine, and only goes out to the network if it found one. On a computer where Cursor is not installed, no request goes to Cursor — not an empty request, not a call that fails: nothing. The same holds when the Keychain is locked or a read is blocked. A setup with two tools therefore makes two or three requests per cycle, not ten.
05 What never leaves your Mac
None of your measurements, none of your account names and none of your tokens are sent to Quotum's publisher. There is no account to create, no analytics in the app — the website's own is described in the legal notice —, and no automatic crash report. What the app measures stays on the machine that measured it.
Three exceptions, and they are real. Quotum checks the publisher's update feed to find out whether a newer version exists — that is what allows a copy already installed to be told about it. Nothing else goes back that way: no account, no measurement, no statistics. At first launch, it opens the trial. And, once per Mac after purchase, it activates the license. The two subsections below describe these last two. Writing “there is no publisher server” would be false, and we do not write it.
The trial, opened by Apple
At first launch, Quotum sends a request to licences.quotum.app/essai: a code
drawn at random on this Mac, and a token that Apple issues to this Mac through DeviceCheck,
an Apple service — short-lived, single-use, and readable only by Apple. Nothing else: no
serial number, no machine name, no measurement. The code is 32 bytes long; it is written to
the preferences and to the “Quotum — trial” item before the request goes out. The request
carries no cookie and follows no redirect. The license service passes the token on to Apple,
which keeps for each Mac the mark of a trial already granted; if the mark is absent, the
service sets it and returns a signed ticket, then verified on this Mac, offline: no further
request for the trial. If the mark is already set, the trial does not open. If the service
does not respond, the same request goes out again on its own one minute later, then at
doubling intervals, six hours at most, as long as trial time remains; in the meantime, no
account is measured. Without Apple's answer, there is no trial. In a virtual machine, where
DeviceCheck does not exist, nothing goes out.
The code for this request is in Sources/Quotum/Donnees/EssaiEnLigne.swift, and
what the service keeps from it — the SHA-256 hash of the code, never the code itself, and two
dates, for thirty days, without your IP address — is set out in the
privacy policy.
Activation, once per Mac
When you choose “Activate This Mac”, Quotum sends a single request, to
licences.quotum.app/activer: your license key, the public half of a key that this
Mac's security chip creates for the occasion, and a signature proving that the request comes
from this Mac. Nothing else: no serial number, no machine name, no measurement. The public
half is 65 bytes long, the signature 64. The request carries no cookie and follows no
redirect. The response is an activation certificate, then verified on this Mac, offline: no
further request for the license. If the service does not respond, the same request goes out
again on its own one minute later, then at doubling intervals, six hours at most, for seven
days at most after you choose “Activate This Mac”; after that, nothing more goes out unless
you choose it again.
The code for this request is in Sources/Quotum/Donnees/ActivationEnLigne.swift,
and what the service keeps from it — the license identifier, the fingerprint of the public
key and the date, for 400 days, without your IP address — is set out in the
privacy policy.
The only thing Quotum writes to an account
Everything else is read-only. A single function writes anywhere: spending a reset credit on the Codex quota of a ChatGPT account. It cannot be undone — a reset once spent is lost. These credits are given by OpenAI or earned through referrals, and are valid for thirty days.
It has two paths, and neither fires on its own for a tool you do not track: without consent to measure, no quota is measured, so nothing can conclude that an account has run dry.
- By hand, from an account's drawer. The button states what the spend costs before offering it, and nothing goes out without a second confirmation.
- Without asking, if you have turned it on. That setting is off by default, it only turns on after a warning that the spend may take place at night or while you are away, and every reset it spends is announced to you by a notification.
In both cases, the same conditions apply: a ChatGPT account, a credit left, an exhaustion that the server has observed — never inferred from a percentage, never mistaken for an expired token —, a measurement at most ten minutes old, and a return time still ahead.
06 Check it yourself, without trusting us
⚠️ Quotum's code is not published as of September 30, 2026: the repository that holds it is private. These commands run at its root, and can therefore only be replayed by someone who has access to it. We give them with what they return today.
| Claim | Command | What it returns |
|---|---|---|
| No package downloaded, a single third-party library | grep -c '\.package(' Package.swift | 0 No package is pulled from a remote repository at build time. A single third-party library is embedded: Sparkle, the update framework, stored in binary form in |
| Network session without a cache | grep -n ephemeral Sources/Quotum/Donnees/Outils.swift | 65: … URLSessionConfiguration.ephemeral The neighboring lines also set |
| The addresses, all of them | grep -rn 'https\?://' Sources/ | Each of the lines it returns appears in one of the three tables in section 03, with a comment. We announce no total: it is the list that you compare, not a figure. A line that is missing from them is what you should report to us. |
07 The nine tools it reads
Windows differ from one provider to another, and their length is almost never published. Quotum shows the ones each provider exposes, without converting them into a common unit that does not exist.
| Tool | Published windows | Several accounts |
|---|---|---|
| Claude | 5 h and 7 d | yes |
| Codex | 7 d, and 5 h depending on the plan | yes |
| Windsurf | daily and weekly | yes |
| Cursor | monthly cycle | yes |
| Warp | cycle | one line |
| Codebuff | 5-hour block and weekly | one line |
| Augment | billing cycle | one line |
| opencode | depends on the provider | one line |
| Grok | enumerated | one line |
Before buying, read the warning as well. None of the nine providers makes provision for reading back the credentials that a tool has placed on the machine. What that involves is written on the pricing page, just above the button.