Tokaware

updated September 30, 2026

API

An organization on Business or Enterprise can read its numbers from its own tools: a data warehouse, a dashboard, a SIEM. Each request carries one of its API tokens, which its owners and admins make in Settings, API tokens, and which reads only what it was given.

Tokens and what they read

A token is shown once, when it is made; it can be revoked at any time. Making and revoking one go in the organization's audit log.

ScopeReads
membersThe organization's people, their roles and groups: /members
analyticsEach person's usage per day and tool: /usage
financeA month's spend, and the AI accounts: /spend, /accounts
auditThe audit log: /audit

Requests

Every endpoint answers GET under https://tokaware.com/api/v1 (on a self-hosted server, or a deployment in another region, under its own address), with the token as a bearer token, in JSON. Times are milliseconds since 1970 (UTC), days are YYYY-MM-DD in UTC, and money is in US dollars or cents as each field's name says.

curl -H "Authorization: Bearer aic_…" "https://tokaware.com/api/v1/usage?from=2026-09-01&to=2026-09-30"

Pages

Lists come a page at a time: "data", and "next", a cursor for the next page, or null after the last. Ask for the next page with ?cursor= and that value, keeping the other parameters. limit sets a page's size: 100 by default, 1000 at most (the audit log comes a hundred entries a page).

{
  "data": [ … ],
  "next": "WyIyMDI2LTA5LTAxIiwiYWJjIl0"
}

Limits and errors

A token makes up to 120 requests a minute; past that the answer is 429, with Retry-After in seconds. Errors come as { "error": "what went wrong" }.

StatusWhen
400A parameter that is not one: a day, a limit, a cursor this API did not give
401No token, or one that is wrong, revoked or out of date
402The organization's plan has no API
403The token may not read this, or usage further back than the plan keeps
429Too many requests from the token, or wrong tokens from the address

GET /members

The organization's people, as they joined: their id, email, role, when they joined, and their groups (with their role there, member or manager). Parameters: limit, cursor.

{ "data": [ { "id": "u1", "email": "ada@example.com", "role": "member", "joinedAt": 1790000000000,
    "groups": [ { "id": "g1", "name": "Platform", "role": "manager" } ] } ], "next": null }

GET /usage

Each person's day with a tool, as the Analytics tab counts it (the desktop app's numbers first, then OpenTelemetry's, then the providers' admin APIs'): tokens, the tokens read and read from cache, replies, the value at API list prices and the models without one, sessions, prompts, file changes, lines added and removed, commands and active hours.

Parameters: from and to (the last 7 days by default; up to 366 days at a time, within the history the plan keeps), tool (claude, codex, cursor, copilot, or all for every tool together, the default), person (an id), limit, cursor.

{ "data": [ { "day": "2026-09-01", "person": { "id": "u1", "email": "ada@example.com" }, "tool": "all",
    "tokens": 1830000, "tokensRead": 1790000, "cacheReads": 1650000, "replies": 412, "apiValueUsd": 3.42,
    "unpricedModels": [], "sessions": 6, "prompts": 38, "fileChanges": 61, "linesAdded": 820,
    "linesRemoved": 214, "commands": 97, "activeHours": 4.75 } ], "next": "…" }

GET /spend

A month of what AI coding cost, as Finance, Overview has it: seats and billed costs, what the month comes to by its end, its people's use at API prices and per dollar, and where it went by provider, category, group, person and project. Parameters: month (YYYY-MM, one of the last twelve; the current one by default).

GET /accounts

The AI accounts the organization's people use for work, by key: provider, email, plan, whether it is the company's, whose it is, what it costs a month at the organization's rates, its weekly peak over four weeks and the limits it hit. Parameters: limit, cursor.

GET /audit

The audit log, newest first: each entry's id, time, action and group, who did it and what to, the address it came from, the sentence the Audit tab shows, and its details. Parameters, as the Audit tab filters: group, actor (a person's id), from and to (the last 30 days by default), cursor.