What is attributed
A cost row always has:
Team and tenant dimensions exist when an organization is configured (Enterprise). On an open-source cluster, spend still resolves to a person and an agent.
The routing engine’s agent-selection call is a separate line item. It is never folded into the agent it picked.
Strict attribution
Two identities ride on every model call and every MCPtools/call:
Nasiko writes a flow record before the call is dispatched. The router looks up that flow. If the header is missing, malformed, names no live flow, or names a flow this agent is not part of, the call is rejected with 403. Embeddings (
POST /v1/embeddings) use the same rule.
Consequence: an agent cannot spend tokens outside a user flow, and cannot spend against another user’s flow. MCP tool calls are held to the same standard, because permissions and flow token limits key off that user identity.
Coding-agent routed calls use the coding-agent identity created at registration. Reported sessions attach to the same identity, so harness spend and routed spend roll up together.
Cache-aware accounting
Provider cache hits (prompt cache reads and writes) are recorded as their own token counts, not billed as fresh input. TokenOps will not overcharge a cached prompt as if it were sent in full.TokenOps API
The product name is TokenOps. The HTTP path isfinops.
All of these require a login. The dashboard Overview and TokenOps screens call the same routes. CLI:
nasiko observe finops-dashboard and nasiko observe insights.
There are no spend caps or alerts. Flow token limits (flow limits) and context budgets are the limits that ship.
Related
TokenOps dashboard
The screens that plot these numbers.
Pricing
Where rates come from.
