The main Codex limit stays clear
Usage Overlay deliberately selects the main Codex limit and keeps Spark or other model-specific buckets out of the interface.
Usage Overlay keeps the main Codex usage limit beside the desktop app. It shows primary and secondary main-limit details when returned, hides model-specific rows, and leaves credentials and conversations outside its boundary.
Version 0.3.1 · Windows 10/11 x64 · Installer + portable ZIP · MIT licence · Unsigned release
Focused on the main limit
The rail keeps the main Codex limit in view. The detail card adds returned primary and secondary windows, reset timing, and connection status.
Usage Overlay deliberately selects the main Codex limit and keeps Spark or other model-specific buckets out of the interface.
The detail card shows primary and secondary windows as separate labelled rows when App Server provides both.
Signing out or switching Codex accounts clears the previous reading and refreshes usage for the active account.
Windows alerts can fire once when a returned limit crosses the configured amber or red threshold. They are off by default.
Check for updates makes one user-triggered request to the public GitHub release endpoint and never installs anything automatically.
Disconnect releases only the App Server child process started by Usage Overlay. The rail also stays hidden on Codex-owned file picker, Open, and Save dialogs.
Platform support
The published v0.3.1 build is a Windows x64 companion for Codex. We are evaluating Cursor support separately; it is not available in this download.
A narrow connection
Codex CLI keeps account ownership and network access. Usage Overlay requests rate-limit metadata through the documented App Server surface and renders it in a separate WPF process.
After you sign into another account in Codex, the overlay reloads usage automatically, normally within about seven seconds plus the request time when the login is saved to disk. Credential-manager changes can take about a minute. An expired login still needs you to sign in again; fresh usage requires a working connection.
Read App Server documentationUsage Overlay launches codex app-server --stdio as a child process.
It checks saved login-file timestamps and size every two seconds. A change clears the previous account’s usage and reconnects the overlay automatically, without reading credential contents.
It requests account/rateLimits/read, exposes the main bucket’s primary and secondary windows, and hides model-specific buckets.
Routine polls no longer force token refreshes. Stalled requests reconnect after 30 seconds, and late replies cannot restore usage from a previous account.
Privacy by scope
The product boundary is narrow in code and visible in the public repository. Account ownership stays with Codex CLI; Usage Overlay keeps only local settings and redacted diagnostics.
Codex owns authentication and account-data network access. Usage Overlay checks login-file metadata to detect changes, but never reads or writes credential contents. It does not request prompts, responses, history, repository files, API keys, passwords, or cookies.
Preferences and diagnostic logs remain under the current Windows user profile. Sensitive-looking values are redacted before diagnostic messages are written.
Installation reporting is optional and off by default: a random installation ID and app version are sent to Haroone at most once per UTC day while running. No account, conversation, quota or log data is sent. Daily activity expires after 90 days; summaries expire after 90 inactive days. Disable reporting in Settings to stop future reports. There is no analytics SDK or advertising.

Native settings
General, Visibility, Position, Appearance, and Connection & diagnostics controls stay together. Save and Cancel are explicit, theme choices preview safely, and validation keeps impossible thresholds or paths from being written.
Installation and trust
Download app opens the public 0.3.1 installer. A portable ZIP and SHA256SUMS file are available in the same GitHub Release for users who prefer a manual install or want to verify the package before launch.
The installer, portable ZIP, manifest, and checksum file are published on GitHub.
The installer adds a normal Installed apps entry and uninstaller.
Compare the download with the published SHA256SUMS value.
Version 0.3.1 fixes automatic detection of Codex logout, login, and account switching. It passed a zero-warning Release build, all 18 specifications, simulated account-switch regression checks, live usage and reconnect checks, and package validation.
The published SHA-256 values match GitHub’s asset digests for both downloads. The installer is unsigned, so Windows SmartScreen may warn on first launch.
Go deeper
The case study covers the product tradeoffs, App Server connection, privacy boundary, testing, and open-source preparation.