Where the ledger lives

One append-only file for the whole machine. What is written to it, when, and what happens if it is lost or damaged.

One file for the machine #

The ledger is quota.jsonl, in ~/.autodev/. There is one for the machine and not one for each project, because a subscription spans every project on it. It is JSON Lines, and AutoDev only appends to it.

It is not one of the indexes AutoDev can rebuild, and it never rotates. It is the only copy of the measurement data. The event log rotates when it grows, and applying that to the ledger would delete the history the panel is drawn from.

What a line looks like #

One line is one record. The three kinds are in What is measured, and this is their shape:

quota.jsonl
{"type":"call","ts":"<time>","provider":"<provider>","root":"<project path>","ms":<n>,"ok":true,"model":"<model>","usd":null,"usdDelta":null,"tokens":null,"usage":null,"quota":[],"compactions":[],"inferences":null,"contextWindow":null,"context":null}
{"type":"limit","ts":"<time>","provider":"<provider>","root":"<project path>","retryAt":"<time>","source":"text","kind":null}
{"type":"work","ts":"<time>","provider":"<provider>","root":"<project path>","commit":"<sha>","mode":"thread","taskId":null}

Every record carries root, the absolute path of the project. A call also carries the model. If you share the file, share it knowing that.

How it is written #

Every provider is built through one function, so every call is recorded: each turn of each participant, and the calls that check the run, such as the completion audit. The call record is written when the call ends, and a limit record follows it when the call reported a limit. A work record is written when AutoDev credits a commit.

Writing is best effort. If the ledger cannot be written, the call still succeeds and a quota.record_failed warning goes to the log, because instrumentation must not be able to break what it measures. Concurrent projects append to the same file, which is why it is JSON Lines and not one JSON array.

Reading it yourself #

Every figure in the panel is computed from this file, by code that reads it and nothing else. You can read the same records:

powershell
autodev quota --json

autodev report --json prints the report's model in the same way. Each line of quota.jsonl is plain JSON, so any tool that reads JSON Lines reads it.

If it is damaged or lost #

A line that cannot be read is counted and shown in the Integrity section of autodev quota, and it is skipped. A partly written last line is healed on the next append. A file that is deleted is gone: nothing rebuilds it, and the panel starts again from an empty history.

AutoDev does not send the ledger anywhere. The server that remote access starts can serve the derived quota view to a token holder or a paired browser, under the rules of its telemetry tier. What you can do from the phone lists them.

Where state lives lists the other files in ~/.autodev/, and Reading the quota panel covers what the panel does with this one.