An agent control plane, not a replacement agent.
TokenSize helps agents coordinate the tools already on a developer's machine. The hosted API recommends; the local agent remains authoritative.
The boundary#
The client discovers installed harnesses, models, permissions and normalized allowance. Credentials and raw account output stay local.
The service receives task features, candidate metadata, policy and a request identifier. Prompt text is omitted unless you explicitly opt in.
The client validates the signed route receipt, enforces the permission ceiling and runs the selected local process with bounded depth.
Privacy model#
The default route is metadata-only. This is a product boundary, not a promise hidden in a marketing footnote.
Sent to the service
- Task features: role, complexity, risk and context size
- Candidate model metadata and capability flags
- Local policy, objective and content-free client version
- Opaque installation and request identifiers
Kept on the machine
- Credentials, provider keys and browser callback payloads
- Repository contents, source files and model output
- Raw allowance screens and local account identity
- Prompt text unless you explicitly enable sharing
Why allowance matters#
Quality comes first. Once the router establishes a quality-equivalent tier, normalized allowance helps distribute work across healthy subscriptions so one account does not become the bottleneck.
Embedded Codex and OpenCode clients mark their root harness active. The router excludes that harness even at depth zero, and every child receives an incremented depth.