New · 0.2 Actualis 0.2 reads GitHub Copilot CLI, and --card turns your own numbers into a postable image. Release notes →
Actualis

Reference

Limits

A measurement tool that overstates its reach is worse than none. These are the boundaries.

It only sees what the agent already logged

If a session was never written to disk, or the transcript was deleted or rotated away, there is nothing to read. Actualis reconstructs history from records that already exist; it does not create new ones.

Secret detection is pattern-based

A bespoke internal token with no distinguishing shape can pass unnoticed. A clean report means nothing matched, not nothing is there.

Subagent shell activity is partly invisible

Commands run inside subagents are not recorded in the parent transcript. The report states what share of shell activity that accounts for rather than quietly under-counting — that is finding AF011.

Cost depends on published rates

Spend is computed from recorded token counts against published per-model rates. A model with no published rate is priced at the top of the known range for its provider, so that portion is an upper bound rather than a measurement. It is included in the total but reported as its own number (cost_usd_from_unpriced_models), so you can subtract it and see the floor instead of having to trust the estimate. Rates sourced from a third party rather than the vendor are flagged separately.

Some cache pricing is inferred

Anthropic prices a cache write by its TTL: 2.00× at one hour, 1.25× at five minutes. Older transcript records carry only a flat total with no split, so the multiplier has to be assumed.

Measured across 71,903 records that do carry the split, the real mix is 95.2% 1h and 4.8% 5m. Assuming 5m — which this tool did until 0.1.4 — under-priced that component by 57%. It now assumes 1h, the more expensive reading, on the same principle as unknown model rates: a bill that surprises you downward is a better failure than one that surprises you upward.

The assumed volume is reported separately as cache_w_assumed, so you can see how much of a total rests on it. On current transcripts it is zero.

Windows are whole calendar days

--days N covers the last N calendar days including today, in UTC. It used to cut at a rolling timestamp, which landed mid-day and let a seven-day window report eight active days — a rate whose denominator exceeded its own window. If your day boundaries matter and you are far from UTC, that is the assumption to know about.

Deduplication depends on message ids

One billable message can appear many times in a transcript while a response streams. Repeats are collapsed by message.id, so a record carrying no id cannot be keyed and is always counted. If a transcript format stopped emitting ids, over-counting would return silently — a repeat count of zero on a large scan is the signal that this has happened.

The three agents are supported unevenly, and here is how

All three are read, but their transcripts do not contain the same things. A section fed by a field one vendor does not write is single-vendor — and comparing two projects on different agents compares different measurements.

CapabilityClaude CodeCodexCopilot CLIRests on
Cost and token usageyesyesyesmessage.usage / token_count / session.shutdown modelMetrics
Per-message dedupyespartialpartialmessage.id
Shell command textyesyesyestool_use Bash / function_call shell_command / tool.execution_start bash
Project attributionyesyesyescwd / gitRoot
Git branchyesnoyesgitBranch / session context branch
Tool refusalsyesnoyestoolDenialKind / permission.completed, joined by call id
Permission modeyesyesyespermissionMode / approval_policy / permission.requested
Sandbox policynoyesnosandbox_policy
Subagent activitypartialnopartialtoolUseResult.toolStats / subagent.completed
Subagent costnononoonly each run's final message survives, so a floor is reported and excluded from the total
Cache TTL splitpartialnonocache_creation ephemeral_1h/5m
Reasoning effortyesnonoeffort

The clearest case is refusals: Claude Code and Copilot CLI record every refused tool call and Codex records none, so Codex sessions are absent from that section. Run actualis --explain vendors for the same table with its reasoning.

Three agents are supported

Claude Code, Codex and GitHub Copilot CLI are the transcript formats implemented. Other tools are not partially supported without saying so — they are simply not read. Cursor and Windsurf keep their content server-side, so there is nothing local to read; verified on a machine with both installed.

It will not rotate, revoke or block anything

Actualis tells you a credential was exposed. Rotating it is your job, and deliberately so — a read-only tool cannot break your workflow, and that guarantee is worth more than the convenience of acting for you.