A connected governance system for teams using Claude Code
TokenScope is not a collection of independent features — it is a governance layer that connects cost visibility, access control, policy enforcement, and reporting into one coherent system.
Cost visibility and attribution
Every Claude request is attributed to a developer, project, cost centre, and department. Costs update in real time — you never wait for an invoice to understand what was spent.
Available on all plans- Live cost dashboard by developer, project, team, and org
- Token breakdown: input, output, and cached tokens per request
- Cost by model — Haiku, Sonnet, Opus usage tracked separately
- Trend charts by day, week, or month
- CSV export for finance and chargeback allocation
- Forecasting based on current run rate
Budget enforcement
Spending limits are enforced at the proxy level — before a request reaches Claude. When a limit is reached, the request is blocked, not flagged after the fact.
Available on Startup plan and above- Five enforcement levels: organisation, cost centre, group, project, user
- Monthly and daily limits, both configurable
- Requests blocked when a limit is reached — zero overage possible
- Enforcement mode: hard block or soft warning per policy
- Override process for temporary exceptions (admin-controlled)
- Usage counter visible in real time
Individual developer access
Developers never see or handle the real Anthropic API key. Each person connects through a scoped session that you control and can revoke in seconds.
Available on all plans- Scoped proxy tokens per developer — not shared
- Real API key encrypted at rest, never transmitted to developers
- Instant revocation: remove any person's access without key rotation
- Scope types: project, group, department, user, or organisation
- Session duration configurable (default: 5 days)
- Browser SSO login: Google, Microsoft, or email/password
Policy enforcement
Apply governance rules to every Claude request, automatically. Policies are evaluated at the proxy before the request is forwarded to Claude.
Policy engine on Startup+; PII detection on Team+- Allowed model list per project (block Opus if only Haiku is approved)
- Relevance threshold: block off-topic or personal requests
- Risk threshold: block high-risk content automatically
- PII detection: flag or block prompts with sensitive data
- Enforcement mode per policy: block, warn, or allow
- Classifier fallback: allow or block when classifier is unavailable
Anomaly detection and alerts
TokenScope surfaces unusual usage patterns — spikes in cost, off-topic requests, blocked prompts — without you having to watch a dashboard all day.
Alerts on Startup+; custom rules on all plans- Configurable alert rules: off-topic rate, high-risk count, blocked requests
- Severity levels: Info, Warning, Critical
- Alert cooldown periods to reduce noise
- Email notification per alert (per-user preference configurable)
- Bell icon with unread badge in the dashboard
- Live mode: 15-second polling when you need real-time awareness
Audit trail and reporting
Every Claude request is logged with metadata, classification results, and policy decisions. Reports are generated automatically — no analyst or spreadsheet preparation required.
30-day audit log on Free; reports on Team+- Full audit log: every request, logged with attribution and outcomes
- Searchable and filterable by developer, project, date, model, and outcome
- One-click usage report for engineering and leadership
- FinOps report: cost breakdown by cost centre with GL codes
- Compliance report: policy violations and blocked requests
- Exportable to CSV and PDF
Claude Code launcher
A single .exe that developers download once. It handles authentication, proxy routing, and session management automatically — zero config for developers.
Available on all plans- Windows: tokenscope.exe — runs as a standard executable
- Authenticates via browser (Google, Microsoft, or email)
- Sets proxy environment variables automatically for Claude Code
- Session cached for 5 days — one login per working week
- Pre-approves token in Claude Code to prevent prompts
- Self-updating: downloads new version automatically on launch
AI-powered insights
Connect your own Claude API key to ask questions about your team's usage in plain English. The insights feature uses your own key — no additional cost on TokenScope's side.
Available on Team plan and above- Natural language Q&A over your own usage data
- Ask: "Which project is over budget?" or "Who used the most tokens this week?"
- AI generates suggested insights from recent patterns
- Insight history saved per user and accessible from the sidebar
- Uses your own configured Claude key — no additional billing
Team management and roles
Six distinct roles give engineering leaders precise control over who can do what. Cost centre managers, team leads, finance, and compliance all have the access they need — no more.
Role management on Startup+- Six roles: Super Admin, Tenant Admin, Team Lead, Cost Centre Manager, Finance, Developer
- Role-scoped dashboards: each role sees what they need
- Invitation system: email invitations with configurable access
- Cost centre assignment for chargeback and reporting
- Department hierarchy for reporting and policy scoping
- Group-level API keys for team or project scope
Work hours enforcement
Restrict Claude access to business hours by timezone. Applies at organisation, cost centre, project, or individual level — with clear, actionable block messages.
Available on Team plan and above- Per-level schedules: organisation, cost centre, project, or user
- Timezone-aware: each schedule uses an IANA timezone
- Day-level and hour-level configuration
- Block messages explain what schedule applied and when access resumes
- Override model: lower levels can restrict but not expand hours
What is coming next
The following capabilities are on our active roadmap. Dates are directional and subject to change. Enterprise customers can contact us to discuss priority and custom implementation timelines.
Questions about a specific capability? Contact us
See it working on your team
The free plan gives you cost visibility, audit logging, and the proxy connection — without a credit card.