TiboTattle is a local-first Mac app for understanding personal Codex
usage. It estimates your seven-day allowance in API-equivalent terms,
keeps its reset history, and shows uncertainty instead of filling gaps
with guesses.
Download security
A download you can check
For each published release, TiboTattle gives you a small set of
independent signals: public source, platform signing, and the
exact bytes for the download you chose.
Open sourceReview the app and its release tooling in the public repository.
Signed for the platformA published direct macOS download is Developer ID signed and notarized. Store subjects use their own signing and acceptance evidence. Other platforms appear here only after their own native release gates pass.
Exact bytesThe website shows the version and SHA-256 for an available download; the release page carries the matching artifact.
Release evidenceFor a specific release, the GitHub release may also publish a canonical v1 manifest, SBOM, and release-specific provenance bundles that an independent verifier can check against the artifact; fields not published are explicitly null.
Four quick checks
Open the exact GitHub release, compare its checksum with your
download, and let your operating system verify the publisher.
For a release that publishes them, the canonical
release-manifest.json, SPDX SBOM, and artifact-named
provenance bundles are release assets on GitHub and must be
independently checked against their named artifact. The website
exposes availability and digest; it is not a second evidence
store.
Use the release page for the exact version and artifact distribution.
Compare the published SHA-256 with the downloaded bytes.
Use Gatekeeper, Authenticode, a package signature, or the relevant store to verify the platform subject.
For source/build evidence, follow the release-specific commands in the canonical guide.
Read the full verification guide on GitHub
for exact commands, release-manifest fields, direct-download versus
Store distribution, and authoritative platform documentation.
TiboTattle supports macOS 14 or later on Apple silicon and Intel.
If you use Homebrew,
the same command installs the signed release for your Mac:
brew install --cask adamallcock/tap/tibotattle
Or choose the matching Apple silicon or Intel download on the
public home page or
GitHub Releases,
open the DMG, and drag TiboTattle to Applications. The app includes
its runtime; installing it does not require Node.js, pnpm, or Xcode.
On first launch, read the complete
local-source disclosure, choose whether TiboTattle starts at login,
and select Get Started. The app hosts its private
dashboard in its own window; this public website never scans local
files or accepts contributions.
What Refresh reads
Refresh processes usage metadata from the selected Codex
sessions and archived_sessions folders. It
also reads state_5.sqlite for rollout lineage,
config.toml for service-tier settings, the installed
Codex app-server account/read,
account/rateLimits/read, and
account/usage/read methods. Processing and derived
personal results stay on this Mac.
Read your Codex week
Estimated API-equivalent value of the observed seven-day allowance.
Seven-day history across quota-reset observations.
Allowance metadata and uncertainty when the evidence supports it.
Version 0.1.24 includes GPT-6 Sol and GPT-6 Luna in API-equivalent
estimates using OpenAI’s published pricing.
Rates depend on the recorded service tier, context length and cache
usage. These estimates describe API-equivalent value, not charges
to your ChatGPT subscription; missing pricing evidence stays unknown.
Gaps are not zero
Unknown, unavailable,
stale, partial, and
unattributed are different evidence states. A
retained last-good value keeps its timestamp and source. TiboTattle
does not smooth missing history or turn absent coverage into zero.
Refresh and recovery
The first deep pass is bounded, cancellable, and resumable. Closing
the window keeps the app and companion running; quitting stops the
pass and preserves completed checkpoints. If indexing reports an
incompatible schema or integrity problem, preserve the original
state and seek support—do not delete the only index or change its
SQLite version.
Local state and uninstall
Personal indexes, settings, cached calculations, and prepared
contributions live in the owner-only
~/Library/Application Support/Usage Monitor state root.
Ordinary uninstall preserves that state. Homebrew
--zap removes the app's local state and preferences but
deliberately leaves Codex data and TiboTattle Keychain identities
alone; identity reset and hosted deletion are separate actions.
Optional contribution
Local use needs no account. Fresh Electron installations enable
content-free sharing automatically, with no social sign-in. Turn it
off in Settings or Community to save a persistent choice. Existing
choices are preserved; undecided existing installations receive
three visible notices before delayed activation. Choosing now
cancels the remaining reminders. Older native Mac releases retain
their review-and-approve flow.
An installation credential identifies a contribution source, not a
unique person or provider account. Sharing off and device disconnect
do not erase accepted hosted history or local analysis. Hosted
erasure is handled by the service owner. See the
privacy overview for the
notice schedule, shared fields, retention, and identity limits.
Community evidence
The public site is read-only and does not enroll contributors.
Switch the allowance chart between Aggregate, By plan, and By model.
All three compare a full Pro 20x-equivalent weekly allowance at API
prices, not each plan's actual allowance or money paid. Model
estimates appear only when the evidence identifies a model's rate;
missing or unstable history remains a gap. Sample counts can be as
small as one account; see the
publication disclosure.
Activity totals alone are never presented as an allowance.
Updates and channels
Signed releases use the Sparkle feed at
updates.tibotattle.com. Manual checks are always under
Settings → About; automatic downloads can also be
changed there. Development builds have no updater and preview
builds use manual checks only. A source build, preview, installed
release, and published update are separate evidence gates.
Get support safely
Use GitHub Issues
for ordinary bugs and the repository's private Security Advisory
form for vulnerabilities. Include the app version, install channel,
evidence state, and fixed diagnostic code. Never paste prompts,
responses, credentials, account identifiers, or real session paths.
Platform support
The published product currently supports macOS 14 or later on Apple
silicon and Intel. Windows and Linux source, contract, container, or native
experiments are preparation evidence only; neither platform is a
supported install until a release lists and qualifies its own final
artifact.