Use cases · Teams that keep data in-house

Run Token Controller on your own servers.

The same Docker image as the hosted Team plan, with every Team plan feature, on your own Postgres in your own region. Free under the AGPL.

What your security team will ask.

  • Where does our cost data live?
  • What leaves a person's laptop?
  • What do we have to run and keep up to date?

One container, one database.

The service is one program, written in Rust, in one Docker image. All data lives in one Postgres database.

  1. 1

    Start Postgres and the service

    With Docker Compose, behind your own reverse proxy with TLS.

  2. 2

    Set your public URL and email

    Any SMTP server sends the magic links and reminders for late token sheets.

  3. 3

    Point the local tools at it

    Run tc connect with your URL, and send telemetry to your own ingest endpoint.

Your network, your regionLaptopsClaude Code mod, CLICIGitHub ActionTelemetryClaude Code, Codex, …Token Controllerone containerone PostgresFinancecost sheet, CSVPeople managersreportsbills by API
Everything runs inside your network. Only the bills come in from your providers.
# compose.yaml, trimmed services: tokencontroller: image: ghcr.io/tokencontroller/tokencontroller:1.0 environment: DATABASE_URL: postgres://tc:secret@db/tc TC_PUBLIC_URL: https://tc.example.com db: image: postgres:17 # then point the local tools at it tc connect https://tc.example.com

What stays where.

Transcripts stay on the machine

Prompts, tool output and file contents never leave a laptop. The summary and the tag values are the only text in a token entry.

Open source

The service is AGPL-3.0. Issues on GitHub are open, and community support happens there.

Support when you need it

With a support contract, a self-hosted instance becomes an Enterprise plan instance with OIDC, SCIM and an audit log. If the contract ends, your data and reports stay.

In the docs

Start alone in a few minutes. Add your team when the first month closes.

No card for the free plan. Fourteen days to try the Team plan.