| Version | Supported |
|---|---|
| 1.x | ✓ |
ccs-stats reads your Claude Code OAuth token from (in priority order):
CLAUDE_CODE_OAUTH_TOKENenvironment variable~/.claude/.credentials.jsonfile- macOS Keychain via the
securitycommand
The token is used solely to fetch usage data from https://api.anthropic.com/api/oauth/usage. It is never logged, transmitted elsewhere, or stored beyond a 5-minute cache in your system's temp directory (<tmpdir>/claude_usage_cache_<session_id>.json). Cache files are created with 0600 permissions (owner read/write only) and pruned after 24 hours.
ccs-stats also writes to ~/.claude/settings.json (install/uninstall only) and creates a timestamped backup before any modification.
For sensitive disclosures, please use GitHub's private vulnerability reporting. This keeps the report private until a fix is ready.
For non-sensitive issues, open a GitHub issue with the title prefix [SECURITY].