Everything on main since 0.1.18.
Added
- Grok and Cursor quotas.
caam limits,caam monitor,caam next --usage-awareand nowcaam run grok|cursor --precheckread Grok and Cursor quotas from the providers themselves. Quota data that is missing, malformed or contradictory is treated as unknown, and an account with unknown quota is never picked as if it had room (#79, PR #107). - Model-aware ranking.
caam limits --modelandcaam precheck --modelrank and gate accounts by the quota of the model the work will run on, so an account that is out of one model's allowance but fine on another is no longer treated as spent (#97). - Reset-aware seat choice. An opt-in drain policy spends the quota that resets soonest first instead of leaving it unused, and
--bestfor new work picks the seat with the earliest reset that still has headroom. The default ranking is unchanged (#81). - Clearer health signals.
caam lsreportsrefresh_due,launch_usableandlogin_requiredseparately, so a Codex account with a lapsed access token but a working refresh token reads as usable and due for refresh, not broken (#102). caam limitsnames which credential copy it read and can use an offline Claude cache (#100).caam shallow-spawnruns the profile's own provider CLI when no command is given.caam statusandcaam lsshow the Claude account email from the paired.claude.json.
Fixed
- A revoked credential no longer reads healthy. When a provider refuses a credential, caam records it and
caam ls/caam statusshow the account as needing a login, even if the file on disk still looks valid. A new login or a successful refresh clears it. Doctor andlimitschecks, which only use the access token, no longer clear a refused refresh token, and they no longer mark an account as rejected just because a stored access token has expired (#108). - On macOS,
caam backupandcaam activateread and write Claude Code's login from the macOS keychain, where Claude Code actually keeps it. Before, a Mac backup could save a profile with no token in it. - Cursor config and credential files are found where current cursor-agent puts them (
$CURSOR_CONFIG_DIR,$XDG_CONFIG_HOME/cursor), not only in~/.cursor. - Grok token expiry is read correctly, and a profile missing its provider home is repaired instead of failing (#101).
caam exec claudeshares user skills, plugins, commands and agents into the profile's Claude config dir (#90).- Shallow sessions clear every provider's home override, so a session started inside another provider's shallow session does not read the outer profile's state. Codex
config.tomlin shallow homes is kept in sync with the real one without overwriting profile settings (#103). A seeded.claude.jsonno longer carries the real account's identity. caam statusreports a rate-limit cap as rate-limited instead of "token expired", and no longer tells you to log in again.- Claude credentials that refresh themselves no longer trigger expiry warnings; a credential with nothing to renew from is never marked refresh-due.
- Subscription plan tiers (Pro, Max, Ultra) are scored the same way everywhere.
Security
golang.org/x/cryptoupdated to v0.56.0 (seven SSH advisories on the sync and deploy paths), plusx/net,x/textandgoldmarkupdates; builds use Go 1.26.8.