[Feature Request] Per-source token usage visibility and anomaly detection alerts
Bug Description
Feature request: per source token usage visibility and anomaly alerts
▎
▎ I'm on a paid Claude plan and use Claude Code daily. Over the past three days a local automation on my machine (an agent orchestration tool) was running headless Claude Code sessions in a 24/7 loop without my knowledge, and it consumed roughly 25% of my plan quota before I found it.
▎
▎ I'm not disputing the usage, it came from my own machine. My problem is that there was no way to see it happening.
▎
▎ Two requests:
▎
▎ 1. Usage breakdown by source. Today /usage shows a total, but not which session, working directory or process consumed it. With that, I would have caught this on day one instead of day three.
▎ 2. Anomaly alerts. A notification when consumption spikes far above my normal pattern, or when headless sessions run continuously for hours.
▎
▎ Given that this was an uncontrolled background process rather than actual work, I'd also like to know whether any consideration applies to this cycle.
Environment Info
- Platform: darwin
- Terminal: Orca
- Version: 2.1.220
- Feedback ID: d86ea876-0a0a-42d3-9645-640fb80bf0b0
Errors
[{"error":"Error: Streamable HTTP error: Error POSTing to endpoint: <html>\r\n<head><title>502 Bad Gateway</title></head>\r\n<body>\r\n<center><h1>502 Bad Gateway</h1></center>\r\n<hr><center>cloudflare</center>\r\n</body>\r\n</html>\r\n\n at send (/$bunfs/root/src/entrypoints/cli.js:2084:6002)\n at processTicksAndRejections (native:7:39)","timestamp":"2026-07-26T23:42:00.958Z"}]This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗