Skip to content

The technical brief

What Quotum reads on your Mac

An app that reads your Keychain and your credential files should say which ones, what for, and where the result goes. This page names every source, every address and every schedule — and gives the commands that let you prove it wrong.

Survey dated September 30, 2026, made by reading Quotum's code as of that date. The line numbers cited shift with the first commit that adds a line above them; the classification holds. The commands in section 06 are there so that you can check it rather than take our word for it.

01 What it shows, line by line

A bare percentage is ambiguous. So each account in the panel shows, to the right of its name, the age of its measurement — because a figure measured three hours ago is not worth a figure measured just now; on an account folded under “Recharging”, that age shows on hover and to VoiceOver —, then one line per quota window that its provider publishes: the length of the window, a ten-box gauge whose filled cells show what is left, the share used, and the time at which it recharges.

All of an account's windows are written on its card. The shortest one it publishes takes the first line, in large type — 5 hours for Claude, 5 hours or 7 days for Codex depending on the plan, the month for Cursor —, and the others follow, more discreetly. No window is made up: a provider that publishes only one has only one line. The recharge time is written in its shortest form: the time alone within the day, preceded by the day up to six days ahead, the date beyond that.

What a line can say, read off the screenshot opposite, where the app is set to French.
Account Window Gauge What is written
Travail · Max20 5 h

22% used · 11:41

The short window, in large type, on the account's card.

Travail · Max20 7 d

74% used · Sat 09:01

A longer window, on the same card, more discreet. Less than half of it is left: the gauge turns amber.

Perso · Max20 5 h

91% used · in 25 min

A single cell: ember red. The age, “measured 2 h ago”, is set in a heavier weight: past one hour, it is the figure most likely to have changed.

Veille · Max20 5 h

exhausted until 10:21

No filled cell, red outline: that is what “exhausted” means, not an invented value.

Équipe · Team — —

No measurement yet

No gauge at all. An empty gauge would announce an account that has run dry, and nobody has observed that.

An account whose token has expired shows “Sign in again” under its name, with no gauge: an expired token says nothing about the quota, and the account may be full. An account refused for quota with no window published, on the other hand, keeps an empty gauge, with no length, and “exhausted”, with the return time written under its name: without that gauge, the emptiest account would pass for an account never measured.

The Quotum panel, with the app set to French: seven accounts from four tools, one line per quota window with its ten-box gauge, and the age of each measurement.
panel, 320 × 646 pt, actual size

02 What it reads on disk and in the Keychain

Quotum asks you for no password and signs in to nothing. It reads back the credentials that the command-line tools have already placed on the machine, each where its own tool keeps it.

One source per tool. None of them is written: Quotum opens them read-only.
Tool Where the credential is read
Claude

Keychain, item Claude Code-credentials, through /usr/bin/security.

Warp

Keychain, items dev.warp.Warp-Stable and dev.warp.Warp-Stable.tui, through /usr/bin/security.

Codex

~/.codex/auth.json, or $CODEX_HOME/auth.json.

Windsurf

~/.local/share/devin/credentials.toml, and the state.vscdb database of Windsurf or Devin in ~/Library/Application Support.

Cursor

Cursor's state.vscdb database in ~/Library/Application Support, key cursorAuth/accessToken.

Codebuff

~/.config/manicode/credentials.json.

Augment

~/.augment/session.json.

opencode

~/.local/share/opencode/auth.json, entry opencode-go.

Grok

~/.grok/auth.json, or the file designated by $GROK_AUTH_PATH and $GROK_HOME. The environment variable GROK_DEPLOYMENT_KEY, if it is set, is used only when the file holds no session.

A check that opens nothing, before any tracking

To tell you whether a tool has left its sign-in on this Mac, the “Add an account” sheet only checks that these files exist, without opening them, before you even turn tracking on: ~/.local/share/devin/credentials.toml, ~/Library/Application Support/Windsurf/User/globalStorage/state.vscdb, ~/Library/Application Support/Devin/User/globalStorage/state.vscdb, ~/Library/Application Support/Cursor/User/globalStorage/state.vscdb, ~/.config/manicode/credentials.json, ~/.augment/session.json, ~/.local/share/opencode/auth.json and ~/.grok/auth.json — or wherever $XDG_DATA_HOME, $GROK_AUTH_PATH and $GROK_HOME move them. It also looks at whether the GROK_DEPLOYMENT_KEY variable is set, without keeping or sending its value. No content is read, the Keychain is not queried, and nothing goes out over the network. A file being there therefore does not mean the sign-in is still valid: only a measurement, once the tool is tracked, lets Quotum call an account signed in.

And six sources read without any tool being tracked

These do not depend on tracking a tool: Quotum reads them at every measurement, whether tools are tracked or not, including on a fresh installation. None of them is used to query a provider.

What it writes to the Keychain

A single item, which it creates itself: “Quotum — trial”, service app.quotum.mac.essai; its name follows the language of the app when it is created (“Quotum — essai” in French), the service does not change. It holds the start date of the trial and the 32-byte code, drawn at random, that opens it, and nothing else; it is not synced with iCloud, and it stays after the app is deleted, so that erasing the preferences does not restart the trial. Deleting it as well as the preferences does not restart it either: the mark that Apple keeps for this Mac prevents it — section 05. No item belonging to another tool is written or modified.

The token only passes through. It is read, placed in the header of a request, and nothing more: it is not copied into any file, written to any log or kept in any cache. The network session is declared ephemeral, its cache is set to nil and its policy ignores any local cache — which one command can confirm, section 06.

03 Where it connects — every address, listed

The command grep -rn 'https\?://' Sources/ returns every line of the source code that contains an address. They are all listed below, sorted into three groups. We deliberately do not give their number: a count frozen on a page would be out of date at the first commit, whereas a list can be compared line by line. An address you found that was in none of the three tables would be exactly what to report to us.

A · The lines where the app connects by itself

Line Address What happens there
QuotaAnthropic.swift:75https://api.anthropic.com

The quota windows of the Claude account, and the profile that names it.

QuotaCodex.swift:48https://chatgpt.com

The quota window of the ChatGPT account.

QuotaWindsurf.swift:59https://server.codeium.com

The Windsurf quota. The host may come from the user's file; it is then only accepted under codeium.com, windsurf.com or devin.ai.

QuotaCursor.swift:288https://cursor.com

Cursor's monthly cycle and its on-demand spend.

QuotaWarp.swift:197https://app.warp.dev/graphql/v2

Warp's cycle.

QuotaCodebuff.swift:138https://www.codebuff.com

Codebuff's five-hour block and week.

QuotaOpencode.swift:153https://opencode.ai

opencode usage.

QuotaGrok.swift:240https://cli-chat-proxy.grok.com

Grok credits.

LecteurProxy.swift:17http://127.0.0.1:8787

The status of the Claude proxy, on your own machine. It never leaves the computer.

LecteurProxy.swift:25http://127.0.0.1:8788

The status of the Codex proxy, likewise.

AdressesLicences.swift:9https://licences.quotum.app

The publisher's license service, with two routes: /essai, which EssaiEnLigne.swift appends to it — opening the trial, at first launch —, and /activer, which ActivationEnLigne.swift appends — activating your license, once per Mac, when you ask for it. Nothing else goes there — section 05.

AdressesLicences.swift:5https://quotum-licences-test.brickback.workers.dev

The same service in test mode. This line only exists in the program if it is compiled with the LICENCES_TEST condition, reserved for development copies.

The two loopback ports cannot become anything else. Their address is read from a file on disk, and nothing in the format of a URL would stop that line from naming a remote machine. So the code accepts only three spellings — 127.0.0.1, ::1, localhost — and rejects everything else without having to imagine it. It is a list of what is allowed, not a list of what is forbidden: a list of that kind would always let through the form nobody had thought of.

B · The lines a browser opens, and that the app never queries

These are the destinations of commands such as “Open claude.ai” and “Open cursor.com”. They go to the browser you have chosen. Quotum sends them no request and reads nothing of what they return.

Lines Addresses What happens there
Compte.swift:40, 41, 45–51 claude.ai · chatgpt.com · devin.ai · cursor.com · app.warp.dev · www.codebuff.com · augmentcode.com · opencode.ai · grok.com

Each tool's home page, one per provider.

Compte.swift:124, 125 claude.ai/download · chatgpt.com/download

Where to get the desktop app, offered when it is not installed.

VueFinEssai.swift:13, 14 quotum.app/fr/achat · quotum.app/pricing

This site's purchase page, in French if the app speaks French to you, in English in any other language. The button that offers it, at the end of the trial, opens it in your default browser.

C · The lines that are not destinations

Lines Text What it is
VueReglages.swift:687 https://exemple.test

A throwaway URL, never opened: it is used to ask macOS which browsers are installed, to fill the menu in the settings. The .test domain is reserved and resolves nowhere.

QuotaGrok.swift:87, 89, 101 https://auth.x.ai::… · https://accounts.x.ai/sign-in

OAuth scopes, that is, labels compared with those in the local file to tell which sign-in a token comes from. They look like addresses; none of them is contacted.

IdentifiantsCodex.swift:159 https://api.openai.com/auth

The name of a section inside the Codex token, read on the machine: it is where the token names the account it belongs to. A label shaped like an address; no request goes there.

QuotaAugment.swift:9, 160, 161 in comments

Documentation: the form of the tenant address, and the trailing-slash pitfall measured while writing it.

QuotaWindsurf.swift:312 in a comment

An attack counterexample, cited to explain why checking only the scheme of a URL is not enough.

A destination this command does not show

Augment. Its address is written nowhere in the code: it is read from ~/.augment/session.json, in the form https://<tenant>.api.augmentcode.com, and is only accepted if it stays under the augmentcode.com domain. A grep for addresses therefore cannot bring it up — and that is why we give you this list instead of letting you conclude that one command is enough to establish everything.

04 How often

A measurement cycle starts when the app launches, each time the panel opens, when you ask for a refresh, after an account is created, and when you change the tools you track — then every five minutes. That interval can be set in the settings to one, five or fifteen minutes; it does not go below one minute, out of restraint and not because any provider would require it.

And no tool is queried as long as you track none. None of the nine is tracked at installation, and each one is chosen separately: at installation, no token is read and no request goes to any provider. Only the update check and the request that opens the trial at first launch, which do not depend on that choice, and, once per Mac after purchase, the license activation, reach the publisher's server — section 05. What follows therefore describes the cycle of a tool you have chosen to track.

A cycle, at most, is:

“At most” is the key phrase. Each reader first looks for its credential on the machine, and only goes out to the network if it found one. On a computer where Cursor is not installed, no request goes to Cursor — not an empty request, not a call that fails: nothing. The same holds when the Keychain is locked or a read is blocked. A setup with two tools therefore makes two or three requests per cycle, not ten.

05 What never leaves your Mac

None of your measurements, none of your account names and none of your tokens are sent to Quotum's publisher. There is no account to create, no analytics in the app — the website's own is described in the legal notice —, and no automatic crash report. What the app measures stays on the machine that measured it.

Three exceptions, and they are real. Quotum checks the publisher's update feed to find out whether a newer version exists — that is what allows a copy already installed to be told about it. Nothing else goes back that way: no account, no measurement, no statistics. At first launch, it opens the trial. And, once per Mac after purchase, it activates the license. The two subsections below describe these last two. Writing “there is no publisher server” would be false, and we do not write it.

The trial, opened by Apple

At first launch, Quotum sends a request to licences.quotum.app/essai: a code drawn at random on this Mac, and a token that Apple issues to this Mac through DeviceCheck, an Apple service — short-lived, single-use, and readable only by Apple. Nothing else: no serial number, no machine name, no measurement. The code is 32 bytes long; it is written to the preferences and to the “Quotum — trial” item before the request goes out. The request carries no cookie and follows no redirect. The license service passes the token on to Apple, which keeps for each Mac the mark of a trial already granted; if the mark is absent, the service sets it and returns a signed ticket, then verified on this Mac, offline: no further request for the trial. If the mark is already set, the trial does not open. If the service does not respond, the same request goes out again on its own one minute later, then at doubling intervals, six hours at most, as long as trial time remains; in the meantime, no account is measured. Without Apple's answer, there is no trial. In a virtual machine, where DeviceCheck does not exist, nothing goes out.

The code for this request is in Sources/Quotum/Donnees/EssaiEnLigne.swift, and what the service keeps from it — the SHA-256 hash of the code, never the code itself, and two dates, for thirty days, without your IP address — is set out in the privacy policy.

Activation, once per Mac

When you choose “Activate This Mac”, Quotum sends a single request, to licences.quotum.app/activer: your license key, the public half of a key that this Mac's security chip creates for the occasion, and a signature proving that the request comes from this Mac. Nothing else: no serial number, no machine name, no measurement. The public half is 65 bytes long, the signature 64. The request carries no cookie and follows no redirect. The response is an activation certificate, then verified on this Mac, offline: no further request for the license. If the service does not respond, the same request goes out again on its own one minute later, then at doubling intervals, six hours at most, for seven days at most after you choose “Activate This Mac”; after that, nothing more goes out unless you choose it again.

The code for this request is in Sources/Quotum/Donnees/ActivationEnLigne.swift, and what the service keeps from it — the license identifier, the fingerprint of the public key and the date, for 400 days, without your IP address — is set out in the privacy policy.

The only thing Quotum writes to an account

Everything else is read-only. A single function writes anywhere: spending a reset credit on the Codex quota of a ChatGPT account. It cannot be undone — a reset once spent is lost. These credits are given by OpenAI or earned through referrals, and are valid for thirty days.

It has two paths, and neither fires on its own for a tool you do not track: without consent to measure, no quota is measured, so nothing can conclude that an account has run dry.

In both cases, the same conditions apply: a ChatGPT account, a credit left, an exhaustion that the server has observed — never inferred from a percentage, never mistaken for an expired token —, a measurement at most ten minutes old, and a return time still ahead.

06 Check it yourself, without trusting us

⚠️ Quotum's code is not published as of September 30, 2026: the repository that holds it is private. These commands run at its root, and can therefore only be replayed by someone who has access to it. We give them with what they return today.

Claim Command What it returns
No package downloaded, a single third-party library grep -c '\.package(' Package.swift

0

No package is pulled from a remote repository at build time. A single third-party library is embedded: Sparkle, the update framework, stored in binary form in Tiers/ — grep -c binaryTarget Package.swift returns 1 — and credited in THIRD-PARTY-LICENSES.md. Not to be confused with grep -c dependencies, which returns 2: one links the app to Sparkle, the other links the test target to the app.

Network session without a cache grep -n ephemeral Sources/Quotum/Donnees/Outils.swift

65: … URLSessionConfiguration.ephemeral

The neighboring lines also set urlCache = nil and a policy that ignores any local cache.

The addresses, all of them grep -rn 'https\?://' Sources/

Each of the lines it returns appears in one of the three tables in section 03, with a comment. We announce no total: it is the list that you compare, not a figure. A line that is missing from them is what you should report to us.

07 The nine tools it reads

Windows differ from one provider to another, and their length is almost never published. Quotum shows the ones each provider exposes, without converting them into a common unit that does not exist.

Tool Published windows Several accounts
Claude5 h and 7 dyes
Codex7 d, and 5 h depending on the planyes
Windsurfdaily and weeklyyes
Cursormonthly cycleyes
Warpcycleone line
Codebuff5-hour block and weeklyone line
Augmentbilling cycleone line
opencodedepends on the providerone line
Grokenumeratedone line

Before buying, read the warning as well. None of the nine providers makes provision for reading back the credentials that a tool has placed on the machine. What that involves is written on the pricing page, just above the button.

Pricing