An agent control plane, not a replacement agent.
TokenSize helps agents coordinate the tools already on a developer's machine. The hosted API recommends and learns from verified outcomes; the local agent remains authoritative.
The boundary#
The client discovers installed harnesses, models, permissions and normalized allowance. Credentials and raw account output stay local.
The service receives task features, candidate metadata, policy and a request identifier. Prompt text is omitted unless you explicitly opt in.
The client validates the signed route receipt, enforces the permission ceiling and runs the selected local process with bounded depth.
Privacy model#
The default route is metadata-only. This is a product boundary, not a promise hidden in a marketing footnote.
Sent to the service
- Task features: role, complexity, risk and context size
- Candidate model metadata and capability flags
- Local policy, objective and content-free client version
- Opaque installation and request identifiers
Kept on the machine
- Credentials, provider keys and browser callback payloads
- Repository contents, source files and model output
- Raw allowance screens and local account identity
- Prompt text unless you explicitly enable sharing
Why allowance matters#
Quality comes first. Once the router establishes a quality-equivalent tier, normalized allowance helps distribute work across healthy subscriptions so one account does not become the bottleneck.
Router Brain: improve without collecting work#
Verified outcomes make the next decision more useful, while the data boundary stays the same. Learning is bounded, auditable, and reversible.
The public demo uses static catalog priors. Router Brain signals are available to authenticated agent and model routes after migration0005_router_learning.sql is applied.
Embedded Codex and OpenCode clients mark their root harness active. The router excludes that harness even at depth zero, and every child receives an incremented depth.