Omahub
← All plugins
J

Token Maxxer Hub

by jalv13

A local-first multi-account usage hub for sessions, quotas, balances, and alerts across 17 AI integrations.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
75f34d6
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
75f34d6
Reviewed
1 month ago

Token Maxxer Hub is a local-first AI usage widget: it reads local session databases, polls provider APIs with user-supplied credentials, and stores secrets in the keyring or environment variables. The deterministic 'obfuscation' finding is a false positive — scripts/audit_release.py uses PNG magic bytes to validate image assets. No malicious behavior, hidden persistence, or destructive actions were found in the sampled code.

  • The plugin reads local session databases and, for Cursor, a locally stored login token and sends it to Cursor's API; this is disclosed but is broad access to sensitive local data.
  • The bundled ai-hub-worker is a large Python script with network, subprocess, and keyring access; the full file was not in the sample, so a maintainer should confirm the allowlist and keyring handling match the documentation.
  • The only deterministic finding is a false positive (PNG magic bytes in audit_release.py), not actual obfuscation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Jalv13/token-maxxer-hub --enable
Developer Tools #bar #quickshell #ai
<div align="center">

Token Maxxer Hub

One bar glyph. Seventeen AI accounts. Zero dashboards.

A local-first, multi-account Omarchy bar widget for AI coding agents — local sessions plus read-only usage, quota, balance, and spend, with no cloud account of its own and no telemetry.

License Version Integrations Omarchy plugin

Install · The panel · Providers · Privacy · Security

<br> <img src="assets/overview.png" alt="Token Maxxer Hub overview panel listing 17 configured AI integrations" width="420"> </div> <br>

Why

Running a handful of AI coding agents means a handful of places to check usage: local session history for the ones on this machine, and a different dashboard for every remote API key. Token Maxxer Hub puts all of it — local and remote — behind one bar icon, with one consistent panel to check it in.

The panel

Four tabs, one keypress apart (1–4, or h/l to step through them).

<table> <tr><td width="45%">

1 · Overview — every configured provider in one scannable list, account counts and live status at a glance, with a running "N agents working" count in the header.

</td><td> <img src="assets/overview.png" alt="Overview tab listing 17 configured integrations and account metrics"> </td></tr> <tr><td>

2 · Sessions — search and filter, walk the list with j/k, and expand a session to see its last exchange. One action from there: reopen it in its provider's real terminal, in its original working directory.

</td><td> <img src="assets/sessions.png" alt="Sessions tab listing four OpenCode, Codex, and Claude sessions, two currently working"> </td></tr> <tr><td>

3 · Usage — a day/week/30-day chart of tokens and an API-equivalent cost estimate, with a plain disclosure whenever a model's price isn't known, never a silent guess.

</td><td> <img src="assets/usage.png" alt="Usage tab with a 30-day token and cost chart plus quota and balance history bars"> </td></tr> <tr><td>

4 · Integrations — add an account straight into the system keyring or an environment variable, in seconds.

</td><td> <img src="assets/integrations.png" alt="Integrations tab listing all 17 providers with the Go usage toggle and reset date"> </td></tr> </table>

Features

  • 17 integrations across local session history, polled remote APIs, and local-usage CLIs
  • Local-first: OpenCode, Codex, and Claude read directly from their own local history — no API key required for those three
  • Session handoff, not remote control: one action, reopen a session in its provider's native terminal — no prompts sent, no queue kept
  • Credentials in the system keyring: stored via Secret Service or a user-managed environment variable, never written to plugin state
  • Bounded background polling: five-minute interval, fixed host allowlist, timeouts, and backoff on failure
  • Opt-in OpenCode Go estimate against a configurable reset date
  • Notifications that know when to stop: completions, errors, approvals, and quota thresholds (70/90/100%), suppressed automatically while that provider's terminal is already focused
  • Keyboard-first throughout: vim-style or arrow navigation, / to search, r to refresh

Requirements

  • Omarchy with omarchy-shell (Quickshell-based bar)
  • Python 3, standard library only — no pip dependencies
  • secret-tool (part of libsecret), only if storing remote API keys in the system keyring

Installation

omarchy plugin add https://github.com/Jalv13/token-maxxer-hub.git --enable

When prompted, choose where the icon should appear in the bar; the right section is a reasonable default.

For local development, copy this directory without symlinks and rescan:

cp -a ./token-maxxer-hub ~/.config/omarchy/plugins/jalv13.token-maxxer-hub
omarchy-shell shell rescanPlugins
omarchy plugin enable jalv13.token-maxxer-hub --section right

Validate a checkout before installation:

omarchy plugin validate ./token-maxxer-hub

Update or remove it later:

omarchy plugin update jalv13.token-maxxer-hub
omarchy plugin remove jalv13.token-maxxer-hub --yes

Adding an account

Open the panel, go to Integrations, and select a provider. OpenCode, Codex, and Claude come pre-configured to read their default local install locations (overridable per account). Remote providers need a credential: choose keyring to store the key via Secret Service, or env to read it from an environment variable you manage yourself. SuperGrok, Kiro, and Cursor are auto-detected on first run if their local CLI or login is already present on the machine.

Providers

Provider Read via Data
OpenCode local session database sessions, tokens, optional Go usage estimate
Codex local session database + rollout files sessions, exact rate-limit window
Claude local session transcripts sessions, token activity
Anthropic Admin API remote, polled monthly spend
Z.AI · Kimi · MiniMax remote, polled quota
OpenRouter · DeepSeek · Kilo · Novita · Moonshot · Grok/xAI remote, polled balance
SuperGrok · Kiro local CLI quota
Cursor local login token → remote API quota
Antigravity user-configured loopback endpoint quota

Data and quota semantics

  • OpenCode: local sessions, token/cost history, pending questions, and optional OpenCode Go usage. Go usage is off by default; when enabled, its values are estimates based on requests recorded on this device against the user-selected reset date, not an authoritative remote quota.
  • Codex: local sessions and rollout events, plus the exact rate-limit window most recently reported by Codex itself.
  • Claude: local session history and token activity. Subscription quota is intentionally hidden because the local records do not contain an authoritative quota window.
  • Remote providers: balance, quota, or spend polled in the background every five minutes with four-worker concurrency, a fixed per-provider HTTPS endpoint allowlist, request timeouts, and exponential backoff on repeated failures. The last known-good value stays visible, marked stale, if a poll fails.
  • Local-usage providers: read from the provider's own local CLI or a user-configured loopback-only endpoint. Where a provider has no history API, the hub records one normalized daily snapshot from the day that account was connected; it does not backfill invented history.

The Usage tab's activity chart defaults to the past 30 days and can switch between Day, Week, and 30 Days. Its cost estimate is API-equivalent: it uses each provider's recorded/estimated tokens against known public model prices. Unknown models remain in the token total but are excluded from the cost estimate and called out as partial price coverage. It does not represent a subscription bill.

Preferences and event cursors live under $XDG_STATE_HOME/omarchy/ai-hub (normally ~/.local/state/omarchy/ai-hub).

Session handoff

The panel is intentionally read-only. Expanding a session shows its latest local exchange and offers one action: open that exact session in the provider's native terminal client (OpenCode, Codex, or Claude only). The terminal starts in the session's recorded working directory. Token Maxxer Hub does not send prompts, keep prompt queues, fork sessions, export transcripts, or open folders separately.

Keyboard shortcuts

Inside the panel:

Key Action
h / l or Left/Right Switch tabs
j / k or Up/Down Move the session cursor
1–4 Jump directly to a tab
Enter / Space Expand or activate the selected row
/ Focus the active search box
n Resume the selected session in its native terminal
r Force a refresh
Tab / Shift+Tab Switch between open bar panels
Esc Close the search box or an expanded row first, then the panel
<details> <summary><strong>Worker protocol</strong> (for scripting or debugging)</summary> <br>

Run ai-hub-worker serve and send JSON Lines over stdin; it emits JSON Lines on stdout.

Commands: refresh, resume-native, account-upsert, account-enable, account-test, account-refresh, credential-clear, account-remove (requires confirmed: true), set (for the Go plan options), acknowledge, panel, shutdown.

Events: snapshot, error, task-state, attention, account-test-result, action-result.

For a one-shot diagnostic snapshot instead of the long-running protocol:

./ai-hub-worker snapshot
</details>

Uninstallation

omarchy plugin remove jalv13.token-maxxer-hub --yes

This unloads the plugin, removes its bar registration, and deletes only its installed checkout. Locally cached account state (state.json, event-cursors.json, account-cache.json, account-history.json under $XDG_STATE_HOME/omarchy/ai-hub) is intentionally retained so a reinstall doesn't lose configured accounts. To erase that data too:

rm -rf -- ~/.local/state/omarchy/ai-hub

Any keyring-stored credentials should be cleared from each account's Integrations panel before removal, or manually via secret-tool clear application jalv13.token-maxxer-hub account <account-id>.

Dependencies and license

The source is licensed under the MIT License. Runtime dependencies are limited to the Omarchy/Quickshell APIs already present on Omarchy and Python 3's standard library — no vendored libraries, and no pip packages to install.

For data handling, vulnerability reports, and troubleshooting help, see Privacy, Security, and Support.