Provenance  ·  Local-first  ·  Cross-tool

Your code says what changed.
Tokenome says why, for 38% fewer tokens.

The reasoning behind your code is trapped in chat history: siloed by tool, invisible to your team and your agents. Tokenome links every line to the conversation that produced it, on your machine, so nobody pays twice to work out what the team already knew. Measured: 38% less context, no measurable change in answer quality. See the evidence.

Nothing leaves your machine. No account. No cloud embeddings. The app checks the releases page for updates; what it sends.

Tokenome code context: line 31 of ledger.py blamed to the change called Go back to direct account lookups, with the conversations from just before that edit listed underneath.
Point at a line. Tokenome blames it, then brings back the conversations from exactly that change. The project and its conversations are sample data; the software is not.
Every linetraced to the conversation that produced it
0 bytesof your conversations ever leave the machine
Freeforever, for individual use on one machine

Signature feature

git blame for the "why"

Point at any line of code. Tokenome blames it to learn when it was last edited, then surfaces the conversations from exactly that change. Permanent, searchable, and yours.

  • Answer "why is this function written this way" in one click
  • Read the conversation behind a change under review
  • Recover the tradeoffs your commit message never kept
ledger.py
41def post_entry(tx, amount, key):
42 # idempotency lives here, not in retry
43 if ledger.seen(key):
44 return ledger.get(key)
45 entry = tx.write(amount, key)
46 metrics.emit("ledger.post", tenant=tx.tenant)
47 return entry

Hover a highlighted line

claude-code2026-06-14 · payments-api

Why is the retry wrapper double-posting on timeout?

Because the wrapper retries before the ledger write commits, so a slow commit looks like a failure and the second attempt writes again. Move the idempotency check into the ledger and let the client own backoff.

Edit tool call captured · ledger.py:42-44

See it work

From a line of code to the team's reasoning

A narrated tour in under three minutes: search, code context, the decision journal, the agent's view, and the team server. Short on time? Watch the 30-second cut.

Every screen is the real app. The project and its conversations are sample data; the software is not.

Your agent asks the same question, and gets receipts

Tokenome runs an MCP server on your machine. An agent calls why_was, gets the decision and the reversal that followed it, each with the conversation it came from, then opens the cited turn. No network calls leave the machine. See the agent's view in full.

In Claude Code the tools arrive as a plugin: claude plugin marketplace add tokenome/releases, then claude plugin install tokenome@tokenome. The app does both for you with tokenome claude install.

A coding agent calls the tokenome why_was tool and gets two records back, one decided and one reversed, each with the conversation it came from, then calls get_conversation to open the cited turn.
Both calls were made live against the sample stack at build time; nothing in the frame was typed in.

Why it exists

The reasoning behind your code is trapped in chat history

01

The problem

It all still exists, somewhere. It is just not where the work happens: not linked to the code, not visible to the team, not available to an agent.

Three moments where it costs hours
02

Capture to recall, on your machine

Five stages, all local: capture, segment, embed, index, serve. Claude Code, Claude Desktop, ChatGPT and Gemini today, served through a CLI, a web UI and MCP.

How it works
03

A day of decisions, with receipts

Once a day, Tokenome writes down what you decided and why. Every reason quotes the sentence it came from. If a claim cannot be quoted, it is not written down.

See a journal entry
04

Why we built it

The old tools for working together have mostly gone away. John O'Neil on what replaced them, and what Tokenome does about it.

Read the note
Tokenome's architecture in one drawing. A boundary marked Your machine encloses the AI coding tools, capture and segmentation, on-device embedding, the local Typesense index, code provenance, and every way you and your agent search it. One gate crosses the boundary, marked opted in and secrets redacted, and it leads to a team server you run.
Everything inside the line runs on your own machine and is free. The gate is the only way out, and only a project you opt in goes through it.
The same diagram in words

Your AI coding tools, Claude Code, Claude Desktop, ChatGPT and Gemini, write their transcripts to disk as you work. Tokenome reads them where they land.

On the same machine it splits the threads into turns, computes the embeddings on your own hardware, and indexes everything locally in Typesense. Code provenance links a line of code back to the conversation that produced it.

You reach the index through the app, the command line and a local web UI, and an agent reaches it over MCP. All of that is free, and none of it leaves the machine.

One gate crosses the boundary. When you opt a project in, its segments are redacted on the laptop and then mirrored to a team server your organization runs, where a teammate's search finds them with your name on them. Tokenome does not host that server.

-38%context tokens, routed by question type
46/50facts recalled, within noise of the grep baseline
40controlled agent sessions, ten questions asked four ways
136 vs 241operations: fewer lookups, not smaller answers

A 38% cut in context, with no measurable change in answer quality. The quality differences between configurations sit inside the measurement noise; the token savings do not. The evidence in brief  ·  the full evaluation, including what we cannot claim.

Team  ·  in beta

One search across everyone, with who said it

Team is real and running. A member searches their own history and everyone's shared projects in the same query, and every team hit carries the name of the person it came from. You pick which projects to share. Secrets are redacted on the laptop before anything leaves it, and the server is yours: Docker or Railway, on your own infrastructure. Team is free while it is in beta.

The server is one container image, ghcr.io/tokenome/tokenome-server, built and smoke-tested on x86_64 and aarch64 with every release. The compose bundle on the releases page pins the version and brings up the index, the server and automatic TLS; on Railway it is the same image as one service with a volume. The image is published with the launch release, so if a pull is refused, write to hello@tokenome.ai and we will get you access.

One search for how refunds stay idempotent, returning the member's own hits and team hits attributed to priya and dana.
One query, Mine and Team, with attribution on every team hit.
A backfill reporting eight segments shipped and one held back for review, the held card naming the exclude pattern that caught it, and a shared table showing a redacted customer name.
The share gate holds back what it cannot make safe, and redacts the rest before it leaves the laptop.

In the beta now

  • Team-wide search with attribution
  • Per-project opt-in sharing
  • Secrets redacted on the laptop, before anything leaves it
  • Backfill of history you already have; retract and purge
  • Device-key enrollment; admin enroll and revoke
  • The admin console, below

Coming, not available yet

  • Pull request provenance bot
  • Team FAQ from everyone's journals
  • Flags where two people disagree
  • Provenance API
  • SSO and SCIM

Admin console  ·  in the beta now

The answers an admin has to give, on one screen

Who has access, on which devices, what is being shared, what is kept and for how long, and who looked at what. It runs on your server, next to the index, and every member can see their own footprint without asking anyone.

The admin console People and devices page: a member roster with roles, groups, device counts, last seen and shared project counts, plus tabs for groups, invites and stale devices.
People and devices: the roster, the groups, the roles, and how to recover when a laptop is lost.
The append-only audit log with action and actor filters and an export to CSV.
An append-only audit log, filterable by action and actor, exportable as CSV. Search queries are never stored as text.
Retention set to 180 days with per-project windows and overrides, and two legal holds listed below.
Retention windows per project, and legal holds that pin content against the sweeper until they are lifted.
A sharing coverage matrix showing which members share which projects, with per-member counts.
Sharing coverage: who shares which project, and who is sharing nothing at all.
The My footprint page a member sees: what they share, their devices, who viewed their data, and the organization settings in plain words.
My footprint, for every member: what you share, your devices, who looked, and the org settings in plain words.
The License and seats page: a free beta banner saying no licence is required, fourteen seats of unlimited with one idle seat and one pending invite, and an installed-key card saying no key is needed in beta.
License and seats. Team is in free beta: nothing is enforced, there is no seat limit and there is no key to install. No price is shown anywhere on the page, because the server does not know one.
The admin console People and devices page at phone width, with the roster stacked and no sideways scroll.
The console at 390px.
  • Lost-laptop recovery: revoke the device, mint a recovery code, keep the data
  • Seats: who counts as a seat, who has gone idle, who has an invite outstanding
  • Groups and roles: admin, lead, member, viewer
  • Stale devices surfaced before anyone has to go looking

Pricing

Free on your machine.
Paid when the answer has to leave it.

Embeddings run on your own hardware, so there is no usage meter and no bill that grows with how much you search.

Individual

Available today
Free forever, on one machine

Not a trial. Not a freemium clock.

  • Full local capture, every AI you use
  • Hybrid search: CLI, web UI, MCP
  • Code provenance included
  • Daily journal and running FAQ
  • Tool actions captured, not just chat
  • Nothing leaves your machine. No account. No cloud embeddings.
Install now

Team

Beta
$24 per seat, per month

Free while Team is in beta. $240 a seat a year on the annual plan, self-hosted and paid up front, which is two months free. 3 seats minimum, because a team-wide search does nothing for one person.

In the beta now, on top of Individual

  • One search across the team, with who said it
  • Opt-in sharing per project; secrets redacted on the laptop
  • Backfill of existing history; retract and purge
  • Device-key enrollment; admin enroll and revoke
  • Admin console: people and devices, lost-laptop recovery, audit log, retention and legal holds, sharing coverage, seats, My footprint
  • Server on your infrastructure: Docker or Railway

Coming

  • Pull request provenance bot
  • Team FAQ from everyone's journals
  • Flags where two people disagree
  • Provenance API, SSO, SCIM
Join the preview

Enterprise

Planned
Talk to us quoted to your deployment

Annual contract, invoiced. Nothing on this card ships today, and we are not naming a date for it.

Everything in Team, plus

  • Air-gapped install
  • SSO and SCIM
  • Provenance and audit reporting
  • SOC 2
  • Support SLA
Contact sales
You run it: your own laptop, or a server you operate No usage meter, no per-token billing Provenance is in the free tier, permanently

Founding customers

Team is free for now. When billing starts, the first ten teams to move from the beta onto a paid plan pay half price for their first paid year: $120 a seat a year on the annual plan, or $12 a seat a month. The renewal price is the list price, and it is written into your order before you sign anything. Asking for a slot holds the discount for when billing starts; it charges nothing now.

Now, the arithmetic: put your own numbers in

Put your own numbers in

These are your inputs, not our claims. The arithmetic is on the page.

$37,050 a year, lost to reconstructing context
$2,880 a year for Tokenome Team at $24 per seat
$15,645 difference, if it recovers even half those minutes

Put another way: at $24 per seat per month, Tokenome pays for itself if it saves each engineer 3.5 minutes a week. One found conversation covers a month.

Join the preview

Nothing here is measured from your systems and none of it is a promise. It is your own arithmetic, shown openly, so you can decide whether the problem is worth solving before you install anything.

Team beta

Team is in beta. Join the preview.

A real team runs on it today: each member searches everyone's shared projects and sees who said what. You choose which projects to share, secrets are redacted on the laptop before anything leaves it, and the server runs on your own infrastructure. Team is free for the whole beta. Tell us roughly how many engineers, and we will help you stand up a server and enroll your team. Enterprise is not open yet; say so here and we will come back to you.

Which are you interested in?

One address, used once, to set up your team on the beta or to tell you when Enterprise ships. No list, no newsletter, no sharing. The free tier needs none of this: install it and it works today.

Who builds it

The people behind it

John O'Neil

Founder

Sid Probstein

Engineering

Erik Spears

Engineering

Install it today, free

One machine, no account, nothing to sign up for. Pick the AIs you use, and start searching.

macOS  ·  Apple Silicon

Download the app

A signed and notarized DMG from the public releases page. Open it, drag Tokenome to Applications, and launch it. The app updates itself from then on.

Download for macOS

On the tokenome/releases page on GitHub, as tokenome_<version>_aarch64.dmg.

Linux  ·  x86_64 and aarch64

AppImage or deb

Take the AppImage, make it executable and run it, or install the deb. The AppImage is the one that updates itself.

Download for Linux

On the same page, as tokenome_<version>_amd64.AppImage, tokenome_<version>_aarch64.AppImage and the matching .deb files. Every download carries a .sha256 next to it.

Everything is in the download

The Python runtime, the search engine and the embedding model are inside the bundle. There is nothing else to fetch, no runtime to install first, and no model download on first run.

Want it on the command line? The app installs that for you: open Settings, choose Install command-line tool, and tokenome lands at ~/.local/bin/tokenome, running the runtime the app already has. Then tokenome app opens the web UI at localhost:8741.

Only want the command line? It is published as tokenome-ai, and uv fetches the Python it needs with it:

uv tool install tokenome-ai

That puts three commands on your PATH: tokenome for the CLI, tokenome-mcp for the server your agent talks to, and tokenome-web for the web UI. No app, no account, same local index.

Give Claude Code the tools

The plugin is how an agent gets why_was and the rest. Two lines, and Claude Code can ask your history itself:

claude plugin marketplace add tokenome/releases
claude plugin install tokenome@tokenome

From the app, tokenome claude install does both for you and registers the MCP server with the token for this machine.

On Windows? There is no Windows build yet. Ask us for one.

The Tokenome dashboard: segment and conversation counts, journaled decisions, index health, and a panel showing the context tokens saved across agent calls.
The dashboard, counting what the index saved your agents.
A search for why the ledger checks the idempotency key, returning six hits across claude-code, chatgpt and gemini with the matching terms highlighted.
One search across Claude Code, ChatGPT and Gemini at once.

It works on a phone

The Tokenome dashboard at phone width, with the metric cards stacked and the menu collapsed.
The dashboard at 390px.
Code context at phone width: the blame header for line 31 and the first conversation from before that edit.
Code context at 390px, no sideways scroll.

Local-first  ·  Cross-tool  ·  Searchable  ·  Yours