Skip to main content

TokenPak — Local LLM proxy — guided setup

PyPI version Python 3.10+ License: Apache-2.0

The open logistics layer for AI context.

TokenPak is a local proxy for coding agents that records each request and shows how far the session can go: measured usage, estimated cost, burn and runway.

Know how far your agent can go. Today, the open-source core ships the session trip computer (on by default in the Claude Code footer, the Codex pane and tokenpak status; forecasts appear only where calibrated) and Spend Guard limits; calibrated forecasts for more model and effort combinations, and Pro reroute recommendations once calibration evidence exists, are planned.

Who it's for: Developers and tech leads running long coding-agent sessions in Claude Code or Codex who want to see what a session has used, what finishing will likely cost, and how far it can go.

The default proxy preserves conversation turns; a forwarded request can correctly report zero tokens saved. Explicit compression operations can reduce eligible content. Provider-bound requests still go to your chosen provider, with no TokenPak cloud relay.


First measured request receipt in three commands

Prerequisites: Python 3.10+ and an already authenticated supported client. The reference path below uses Codex and reuses its existing OAuth login and normal default model. An API key or explicit model override is optional, not required. Run it from a real project; provider usage may count against your subscription or incur provider charges.

python -m pip install tokenpak
tokenpak serve --profile aggressive --stats-footer  # terminal 1; leave running
tokenpak codex  # terminal 2; use your existing login and selected/default model

In Codex, make a normal context-bearing request. The proxy prints a measured receipt in terminal 1. In this unmodified reference setup, the built-in Pak builder leaves every system, user, and assistant conversation turn intact, so the receipt truthfully reports 0 tokens saved. This verifies routing and accounting without claiming savings that did not occur. The session-only --stats-footer receipt line is off by default and does not alter the provider response.

See the first receipt guide for prerequisites, the expected zero-savings output, the five-minute reference target, and the separate explicit compression surfaces.

Offline fixture demo

To inspect compression without credentials or provider spend:

tokenpak demo
┌──────────────────────────────────────────────────────┐
│  TokenPak — Offline Fixture Demo                     │
├──────────────────────────────────────────────────────┤
│  Scenario              DevOps agent (config + logs)  │
│  Data source                built-in sample fixture  │
│  Savings drivers                      dedup + alias  │
├──────────────────────────────────────────────────────┤
│  Original                                747 tokens  │
│  Compressed                              502 tokens  │
│  Fixture delta                  245 tokens  (32.8%)  │
│  Fixture cost delta            $0.00073 per fixture  │
│  Receipt status               not a savings receipt  │
├──────────────────────────────────────────────────────┤
│  Stages: dedup, alias, segmentize, directives        │
└──────────────────────────────────────────────────────┘

This is an illustrative fixture, not a measured first-request receipt. Token counts vary by route and workload. Measure your own with tokenpak savings; inspect provider-cache vs. TokenPak attribution with tokenpak status --tip-cache.


Works with

  • Tested SDK adapters: OpenAI SDK, Anthropic SDK and LiteLLM.
  • First-class integrations: Claude Code and Codex.
  • Compatibility targets, not yet independently verified: Cursor, Cline, Continue.dev and Aider.

Run tokenpak integrate to see the full client list with setup guides for each.


Install

uv tool install tokenpak      # or: pipx install tokenpak

Either one installs the tokenpak command into its own isolated environment. To use TokenPak as a library inside a project, pip install tokenpak into an activated virtual environment instead.

See docs/install-guide.md for per-installer detail, optional extras, and the externally-managed-environment (PEP 668) error. See docs/quickstart.md for per-client configuration.

Requirements: Python 3.10+.

Exposing the proxy beyond 127.0.0.1? Set TOKENPAK_PROXY_AUTH_TOKEN to a shared secret to require Authorization: Bearer <token> on remote requests (see docs/configuration/proxy-auth.md).


Runnable examples

The PyPI wheel keeps the install slim and does not bundle the repository's top-level examples. To run them after a normal package install, clone or download the source tree for the example files:

git clone https://github.com/tokenpak/tokenpak.git
cd tokenpak
python -m venv .venv
source .venv/bin/activate
python -m pip install -U tokenpak
python examples/basic_compression.py

examples/basic_compression.py is local-first and does not require provider credentials. See examples/README.md for the full examples index and developer editable-install path.


What's included (Free)

Dispatch (v0.1-alpha preview): a scoped, resumable, reviewable workflow-control surface. Released packages include the CLI and runtime modules; runtime commands require the optional [dispatch] dependencies. Live station execution and delivery receipts are not wired yet. See the Dispatch guide.

  • Session trip computer — measured usage, estimated cost, burn and runway for each session, on by default in the Claude Code footer and the Codex pane; forecasts appear only where calibrated.
  • Context tools and truthful receipts — explicit compression operations can reduce eligible content. The built-in Pak builder preserves role-bearing conversation turns; byte-preserved routes report zero product-attributed reduction. Inspect recorded usage with tokenpak savings and cache attribution with tokenpak status --tip-cache. make benchmark-headline exercises a fixed fixture; its result is not a default-proxy savings receipt.
  • Client integration — setup guides and helpers for the compatibility tiers above
  • Routing policy — configuration and observe-mode records; automatic model changes and fallback enforcement are not active by default
  • Cost tracking — per model, per session, per agent; local SQLite, adds no cloud service
  • TIP Spend Guard — pre-send circuit breaker; blocks runaway requests before provider call. Yes/No release or [TIP: allow=once max=$X] directive. Catches both single-request spikes and the death-by-1000-cuts pattern via session-cumulative tracking. See docs/spend-guard.md.
  • Vault indexing + semantic search — index your codebase; search without an LLM call
  • MultiPak Pro Phase 1 OSS surface — read-only Vault Pak adapter, companion journal promotion-candidate marking, tokenpak pak CLI, /pak/v1/* proxy stubs. Full MultiPak (capture pipeline, recall ranking, Handoff Paks, anchor hydration) requires tokenpak-paid (Pro). See docs/multipak.md.
  • CLI + proxy server — tokenpak serve, tokenpak cost, tokenpak savings
  • Value proof — tokenpak prove run benchmarks direct API vs. TokenPak on your own prompt workload and prints a side-by-side cost/token report. See the value proof guide.
  • A/B testing and replay/debug — compare compression configs, replay past requests
  • 50 built-in compression recipes — YAML, customizable

Provider cache reuse is distinct from TokenPak context reduction. A provider cache hit does not mean the proxy omitted that context from the request. See docs/quickstart.md and docs/api-tpk-v1.md to get started.


Open source & editions

TokenPak's core is Apache-2.0 open source. TokenPak Pro is the proprietary tokenpak-paid package, distributed separately with license requirements. Hosted services remain deferred.


Support


License

The TokenPak open-source core is licensed under the Apache License 2.0 — see LICENSE. TokenPak Pro is proprietary; hosted services remain deferred.

Trademark

"TokenPak", the TokenPak name, logo, and brand assets are trademarks of TokenPak and are not licensed under Apache-2.0 (Apache-2.0 §6 grants no trademark rights). Nominative and reference use — for example "works with TokenPak" or "a plugin for TokenPak" — is fine. Using the name or logo in a way that implies endorsement, sponsorship, or affiliation, or naming a fork, product, or service "TokenPak" (or something confusingly similar), is not.

Metadata

Release files for tokenpak 1.30.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tokenpak 1.30.1
File Size Uploaded
tokenpak-1.30.1.tar.gz 2.6 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for tokenpak 1.30.1
File Interpreter ABI Platform
tokenpak-1.30.1-py3-none-any.whl Python 3 none any Details

Total release size: 5.8 MB

Release files / tokenpak-1.30.1.tar.gz

Download URL tokenpak-1.30.1.tar.gz
Size 2.6 MB
Tags Source
SHA-256 checksum
How to use checksums
3659aa8b8640be1e7c7fc96911d02f65d454d3fc9d4cd066f6f0b27bf4a9d3f0
BLAKE2b-256 checksum
How to use checksums
0b32f7d2890714e7e14b57edc5739e57e8f9648e45d5be2f3993082d39600fb5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / tokenpak-1.30.1-py3-none-any.whl

Download URL tokenpak-1.30.1-py3-none-any.whl
Size 3.2 MB
Tags Python 3
SHA-256 checksum
How to use checksums
e42b3bde50f9966ceb07a707dc6165d511e7ca3e18fad3a97901bc9de26d9ae9
BLAKE2b-256 checksum
How to use checksums
95fcc768b56bd247c71ff5b13e62eeb1a113948d24f6c22f178c7406fd6f3d01
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.30.1 This release

2 release files

1.30.0

2 release files

1.29.0

2 release files

1.28.0

2 release files

1.22.0

2 release files

1.21.0

2 release files

1.20.0

2 release files

1.19.3

2 release files

1.19.1

2 release files

1.19.0

2 release files

1.16.0

2 release files

1.15.0

2 release files

1.14.0

2 release files

1.13.0

2 release files

1.12.0

2 release files

1.10.0

2 release files

1.9.3

2 release files

1.9.2

2 release files

1.9.1

2 release files

1.9.0

2 release files

1.8.0

2 release files

1.7.1

2 release files

1.7.0

2 release files

1.6.1

2 release files

1.5.6

2 release files

1.5.5

2 release files

1.5.4

2 release files

1.5.2

2 release files

1.5.1

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.22

2 release files

1.3.20

2 release files

1.3.18

2 release files

1.3.17

2 release files

1.3.16

2 release files

1.3.15

2 release files

1.3.14

2 release files

1.3.13

2 release files

1.3.12

2 release files

1.3.11

2 release files

1.3.10

2 release files

1.3.9

2 release files

1.3.8

2 release files

1.3.7

2 release files

1.3.6

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.93

2 release files

1.2.92

2 release files

1.2.91

2 release files

1.2.9

2 release files

1.2.8

2 release files

1.2.7

2 release files

1.2.6

2 release files

1.2.5

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.0

1 release file

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page