Skip to main content
Claude Code Governance for Engineering Teams

Control Claude costs before they become an invoice surprise.

Track every Claude Code session by developer and project, enforce budgets in real time, protect company data, and generate audit-ready reports — without changing your developers' workflow.

Quick workspace setup No application code changes Individual developer access Free plan available

What changes when TokenScope is running

Every request

Captured and attributed by developer and project automatically

Before the spend

Spending limits enforced — requests stop when a budget is reached

Eligible caching

Reduces token costs for repeated prompt context via Anthropic caching

One click

Generates an AI usage report for engineering leadership

Three outcomes every engineering leader needs.

TokenScope delivers visibility, control, and accountability — the three things missing from every team that adopts Claude without a governance layer.

Control the spend

Know exactly what Claude costs — and stop it before it goes over.

Set budgets by developer, project, team, department, or organisation. Requests stop automatically when a limit is reached — not after you reconcile the invoice.

  • Budget limits at five levels: org, cost centre, project, group, user
  • Real-time enforcement — spending stops before the request reaches Claude
  • Cost and token dashboard, updated on every request
  • Anomaly detection when usage deviates from project baselines
Protect company data

Replace shared API keys with individual governed access.

Developers never see or handle your real Anthropic API key. Each person connects through their own scoped access that you control and can revoke in seconds.

  • Individual access per developer — scoped to their role and project
  • Real API key is never stored or transmitted to developer machines
  • Revoke any person's access instantly without affecting others
  • Policy engine blocks off-scope, high-risk, or policy-violating requests
Measure usage

Attribute Claude usage to teams, projects, and cost centres.

Every request is attributed to a developer, project, and cost centre. Leadership gets clear data on what Claude is being used for — the foundation for any usage review or internal chargeback.

  • Usage attributed by developer, project, team, and department
  • One-click usage report for engineering and executive leadership
  • Audit trail: every prompt logged, searchable, and exportable
  • Relevance scoring flags usage that deviates from the stated project scope

You are in control by end of day. Your developers notice nothing changed.

Workspace setup takes minutes, not days. Developers connect with one command and every AI session is governed from that point forward — without changing how anyone works.

Configure your workspace

Create your workspace, add projects, and set budgets and policies. No technical knowledge required — everything is configured from a dashboard.

Free plan · No credit card

Developers connect quickly

Download the TokenScope launcher and type tokenscope in any terminal. Browser login, then Claude Code opens with governance active. Currently available on Windows — macOS and Linux are coming.

Works with Claude Code on Windows

Insights start immediately

Every Claude session is attributed, costed, and classified. Your dashboard shows what is happening across the whole team without any manual work.

Reporting available from the first request
Quick developer setup

Your developers need one command. Not a sprint.

Download the TokenScope launcher, run one install command, and type tokenscope to start any Claude session. Authentication, proxy routing, and session caching are handled automatically.

  • No application code changes for Claude Code users on Windows
  • Browser login: Google, Microsoft, or email/password
  • Session cached for 5 days for seamless daily use
  • Launcher distributed as a single .exe — no runtime required
View setup guide

# Step 1 — install once (Windows)

tokenscope.exe install

→ added to PATH automatically

# Step 2 — start any Claude session

tokenscope

→ browser opens for sign-in

→ Claude Code launches, governed

Session active · All requests governed

macOS / Linux launcher — coming soon

2-minute product walkthrough

See TokenScope in action

Watch a VP of Engineering get full visibility into team Claude usage, enforce budgets, and review an audit trail — in under 2 minutes.

No signup required to watch — or try the interactive live demo

Designed for engineering teams handling sensitive work

TokenScope sits in a sensitive path between your developers and Claude. We take that responsibility seriously. Your production API keys, developer sessions, and prompt metadata are protected by design — not as an afterthought.

  • Your real Anthropic API key is encrypted and never sent to developer machines
  • Each developer connects through individual scoped access you control
  • Prompt metadata logged; full prompt storage is configurable per plan
  • TLS in transit · AES-256 encrypted key storage at rest
  • Row-level tenant isolation — no cross-tenant data access
  • Immediate access revocation — no key rotation required
Read the full security overview

Data and privacy

Real key exposed to devsNever
Prompt metadata loggedYes
Full prompt storageConfigurable
Key encryptionAES-256
Tenant isolationRow-level
Data used for trainingNo
Policy enforcement

Four enforcement stages — not just block or allow.

Most governance tools give you one dial: allow or deny. TokenScope offers four progressive enforcement modes so you can roll out governance at the pace that suits your team.

01
Observe

All requests pass through. Usage is captured, attributed, and classified — no action taken on the request itself.

Ideal for: initial rollout, baseline measurement, trust-building.

02
Alert

Requests pass through, but admins receive notifications when off-scope or high-cost activity is detected.

Ideal for: pilot programmes, developer onboarding.

03
Warn

Developers see a policy warning inline in their Claude session. They can acknowledge and continue, creating a clear audit record.

Ideal for: policy education, progressive enforcement.

04
Enforce

Requests that violate policy or exceed budget are blocked before reaching Claude. The developer receives a clear explanation.

Ideal for: production teams, regulated environments.

Each workspace sets its own enforcement mode. You can start on Observe and move to Enforce as your team becomes comfortable with the policy. See all governance features

Data and privacy

Choose how much prompt detail you store.

Two storage modes give engineering leaders control over the privacy and auditability trade-off. Privacy Mode is designed for teams handling commercially sensitive or personal data in their prompts.

Full contentAll plans

Prompt and response text is stored for search, audit, and classification. Visible to admins with appropriate permissions.

Metadata only (Privacy Mode)Team plan+

Only request metadata is stored — model, token count, project, timestamp, and a content hash. Prompt text is never written to disk.

Who can see what

RoleOwnOthersAgg.
Developer
Project manager
Dept. admin
Org admin

Agg. = aggregated usage data only

Platform support

Currently for Windows. macOS and Linux coming.

The TokenScope launcher runs on developer workstations. Windows is fully supported today — other platforms are in progress.

WindowsSupported

Launcher .exe — single file, no runtime required.

macOSPlanned

Native launcher in development. ETA on roadmap.

LinuxPlanned

CLI launcher planned. ETA on roadmap.

View full compatibility matrix
How TokenScope is different

TokenScope governs Claude Code. That's all it does.

Generic API gateways, general-purpose AI usage platforms, and internal tooling all exist — but none are purpose-built for Claude Code governance at the team level.

Built for Claude Code specifically

TokenScope intercepts and governs Claude Code sessions. It is not an attempt to be an all-purpose AI gateway — it is purpose-built for the way Claude Code actually runs.

Developer experience is the constraint

Generic API gateways make developers change code. TokenScope's launcher means developers connect without touching application code on Windows.

Governance at the workspace level

Budget enforcement, policy evaluation, prompt classification, audit logging, and access control work together from a single admin interface — not five separate tools.

Staged enforcement, not binary control

Move from Observe to Enforce at your own pace. No sudden policy changes, no developer backlash, no blocked productivity on day one.

Trust Centre

Security posture, sub-processor list, data retention policies, and answers to security-review requests — all in one place.

Open Trust Centre

Free to start, scales with your team

All paid plans include a 14-day free trial. No credit card required to start the free plan.

Free

$0

1 project · 3 developers

Startup

$79/mo

5 projects · 15 developers

Popular

Team

$299/mo

20 projects · 75 developers

Business

$799/mo

Unlimited projects · 300 devs

Claude governance readiness

Three questions you should be able to answer today.

  • Can you see which developer spent the most on Claude this week?
  • Do you know what percentage of your team's prompts are off-topic or personal?
  • If a developer left today, would their Claude access stop automatically?

If any of these are hard to answer, your team is running Claude without the oversight it needs.

Common questions

From engineering leaders, developers, and finance teams.

More questions? See the full FAQ on the pricing page or contact us.

Your team uses Claude.
TokenScope governs it.

Free plan available. Insights appear after the first governed request. No credit card required. No application code changes for Windows users.

Free plan, no time limit No application code changes (Windows) Cancel paid plans any time 14-day trial on paid plans

Questions about implementation or security? Talk to us · We respond within one business day.