Show how much of the subscription is gone, without risking the session

The last of Section F, and the only thing in Panama that reads an
authentication token, so most of the design is about that rather than
about the number.

It never refreshes the token and never writes to the credentials file.
That token expires roughly hourly and Claude Code refreshes it on
demand; if this refreshed it too, two processes would be rotating one
credential, and a rotation invalidates the other holder's copy. The
failure mode is being silently signed out of Claude Code by a status
widget, which no bar indicator is worth. So it reads the token, uses it
while valid, and reports "waiting for Claude Code to refresh" when not
-- which covers the case that matters, because while you are using
Claude Code the token is fresh, and while you are not there is nothing
to watch.

The token never reaches argv either: curl takes the Authorization
header on stdin through --config, because a header passed as an
argument sits in /proc/<pid>/cmdline for the length of the request.
Same rule the password and MOK paths already follow. And it never
reaches the output: the record carries percentages and timestamps and
nothing else. Both are pinned, and both were checked by sabotaging the
collector to pass -H and watching the contract name it.

Off by default. It is a coding-tool readout, not something a
general-purpose desktop shows without being asked, and it hides unless
the collector has real numbers rather than displaying "unknown".
This commit is contained in:
Gabriel Brown
2026-08-22 08:33:39 -04:00
parent 7a5e990439
commit 8b96d907a1
10 changed files with 419 additions and 3 deletions
+1 -1
View File
@@ -135,7 +135,7 @@ docs/ Settings reference, and the design specs behind the work
## Tests
150 of them, under `tests/`. Run the lot, or a subset by pattern:
151 of them, under `tests/`. Run the lot, or a subset by pattern:
```sh
panama test # everything