Skip to main content
Every model call that goes through Nasiko is attributed before it is served. Unattributed usage is rejected, not billed later. That is what lets TokenOps join spend across vendors whose own invoices cannot be joined.

What is attributed

A cost row always has: Team and tenant dimensions exist when an organization is configured (Enterprise). On an open-source cluster, spend still resolves to a person and an agent. The routing engine’s agent-selection call is a separate line item. It is never folded into the agent it picked.

Strict attribution

Two identities ride on every model call and every MCP tools/call: Nasiko writes a flow record before the call is dispatched. The router looks up that flow. If the header is missing, malformed, names no live flow, or names a flow this agent is not part of, the call is rejected with 403. Embeddings (POST /v1/embeddings) use the same rule. Consequence: an agent cannot spend tokens outside a user flow, and cannot spend against another user’s flow. MCP tool calls are held to the same standard, because permissions and flow token limits key off that user identity. Coding-agent routed calls use the coding-agent identity created at registration. Reported sessions attach to the same identity, so harness spend and routed spend roll up together.

Cache-aware accounting

Provider cache hits (prompt cache reads and writes) are recorded as their own token counts, not billed as fresh input. TokenOps will not overcharge a cached prompt as if it were sent in full.

TokenOps API

The product name is TokenOps. The HTTP path is finops. All of these require a login. The dashboard Overview and TokenOps screens call the same routes. CLI: nasiko observe finops-dashboard and nasiko observe insights. There are no spend caps or alerts. Flow token limits (flow limits) and context budgets are the limits that ship.

TokenOps dashboard

The screens that plot these numbers.

Pricing

Where rates come from.