ccusage answers the question every Claude Code user eventually asks: how much am I actually using? It reads the session logs that coding agents already write to your disk and turns them into tables of input, output and cache tokens with a cost in US dollars, grouped by day, week, month or session. A blocks report tracks Claude's five-hour usage windows, and a status line mode puts the current numbers in Claude Code's own status bar.
It began with Claude Code and now reads the logs of 18 agents, including Codex, OpenCode, Amp, Gemini CLI, GitHub Copilot CLI, goose, Kimi and Qwen, together in one report or one at a time. Costs are worked out from the model pricing data maintained by the LiteLLM project, with an offline mode and per-model overrides. There is nothing to configure: run it with npx and it finds the logs on its own.
ccusage was started by the developer ryoppippi in May 2025, is MIT licensed, and has about 18,800 stars. Every report can also be written out as JSON for your own dashboards.
- Repository: github.com/ccusage/ccusage
- Licence: custom (Other)
- Language: Rust. Stars: 18.8K. Forks: 862. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit bb24af0
Who it is for
People on a Claude Pro or Max plan who want to see how close they run to the limits or what their use would cost on the API, developers on pay-as-you-go keys tracking spend, and anyone comparing several coding agents.
Getting started
1. Run it with no install (bunx ccusage and pnpm dlx ccusage also work)
npx ccusage@latest2. Usage by month, or by session
npx ccusage@latest monthly && npx ccusage@latest session3. Track Claude's current five-hour window
npx ccusage@latest blocks4. Just Codex, as JSON
npx ccusage@latest codex daily --jsonccusage only reads local log files and needs no API key or login. The cost column is an estimate at API list prices, so on a subscription it shows what your usage would have cost, not what you were billed.
Safety scan
We cloned ccusage/ccusage at commit bb24af0 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious patterns, no bare-IP URLs and no committed binaries across 501 files and about 134,000 lines, now mostly Rust. The npm package is a thin launcher whose optional platform packages carry a binary compiled by the project's release workflow, so what runs is built in CI rather than from source on your machine.
- Network use is small and readable: unless you pass --offline, it downloads LiteLLM's model price list from raw.githubusercontent.com and falls back to models.dev for models that list misses. Your usage data is never uploaded.
- Hooks are a pnpm-only check on preinstall, a prepack build, and three Rust build scripts, one of which embeds the pricing snapshot at compile time.
- pnpm-lock.yaml pins 253 packages with seven advisories (5 high, 2 moderate), all denial-of-service bugs in brace-expansion, js-yaml and markdown-it from the build and docs tooling; rust/Cargo.lock's 152 crates have one moderate, in rustls.
- 11 workflows. ci.yaml checks out PR code but runs on pull_request with read-only permissions, which is normal; the scanner matched a comment. pr-gate.yaml uses pull_request_target but checks out only the default branch and passes the PR diff to a review bot as data. All 20 third-party actions are pinned to commits. CodeQL, Renovate and a contributing guide present; the MIT licence file is at the root, though the scanner missed it; no security policy.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 8 npm lifecycle scripts. 3 Cargo build scripts |
| Committed binaries | None. |
| CI workflows | 11 workflows. 2 use pull_request_target, 1 of which check out the pull request head. 0 of 20 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 13 distinct hosts referenced from source; most often github.com, ccusage.com, www.npmjs.com, models.dev. No URLs to bare IP addresses. |
| Known vulnerabilities | 8 advisories across 405 pinned packages: 0 critical, 5 high, 3 moderate, 0 low. pnpm-lock.yaml: 253 packages, 7 advisories; rust/Cargo.lock: 152 packages, 1 advisories. |
| Project hygiene | Has automated dependency updates, CodeQL, contributing guide. Missing security policy, licence file. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
npm lifecycle scripts (8)
apps/ccusage/package.jsonprepack:pnpm run buildpackage.jsonpreinstall:npx only-allow pnpmpackages/ccusage-darwin-arm64/package.jsonprepack:../../apps/ccusage/scripts/verify-native-package.nu && publintpackages/ccusage-darwin-x64/package.jsonprepack:../../apps/ccusage/scripts/verify-native-package.nu && publintpackages/ccusage-linux-arm64/package.jsonprepack:../../apps/ccusage/scripts/verify-native-package.nu && publintpackages/ccusage-linux-x64/package.jsonprepack:../../apps/ccusage/scripts/verify-native-package.nu && publintpackages/ccusage-win32-arm64/package.jsonprepack:../../apps/ccusage/scripts/verify-native-package.nu && publintpackages/ccusage-win32-x64/package.jsonprepack:../../apps/ccusage/scripts/verify-native-package.nu && publint
Worst known vulnerabilities (8 of 8)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@5.0.8 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@5.0.8 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-rgw5-rvv9-x895 | high | brace-expansion@5.0.8 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| GHSA-2883-xcg3-v3hh | high | js-yaml@4.3.0 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| GHSA-5p4m-2wfm-xmqj | high | js-yaml@4.3.0 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) - CVE-2026-59870 fix not backported |
| GHSA-q2hr-2g5m-vwhr | moderate | brace-expansion@5.0.8 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service |
| GHSA-253c-mchw-3w2r | moderate | markdown-it@14.3.0 | markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of sec… |
| GHSA-2mjx-qc3c-rqvc | moderate | rustls@0.23.42 | TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries |
Workflows worth a look
- .github/workflows/ci.yaml: pull_request_target, checks out the PR head
- .github/workflows/pr-gate.yaml: pull_request_target
By the numbers
| Stars | 18.8K |
|---|---|
| Forks | 862 |
| Contributors | 82 |
| Commits | 2,327 |
| Open issues | 2 |
| Open pull requests | 9 |
| Releases | 139 |
| Latest release | v20.0.26 |
| Licence | custom |
| Main language | Rust |
| Project age | 1 year |
| Last push | Oct 3, 2026 |
| Tracked files | 501 |
| Lines of code | 134.1K |
| Checkout size | 11 MB |
Lines by language: Rust 67.7K, JSON 50.1K, Markdown 10.8K, YAML 2,676, TypeScript 1,758, TOML 719.
Questions
Is ccusage free?
Yes. It is MIT licensed, free, and runs entirely on your machine. It needs no account or API key, since it reads logs your coding agents have already written.
Is the cost ccusage shows what I actually paid?
Not necessarily. It multiplies your token counts by each model's API price. If you pay per token, that is close to your bill. On a Claude or ChatGPT subscription it is what the same usage would have cost on the API, which helps you judge whether the plan is worth it.
Does ccusage send my usage data anywhere?
It does not upload your usage. By default it downloads current model prices, LiteLLM's public price list from GitHub with models.dev as a fallback, and --offline uses the snapshot built into the binary instead.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
