spendguardco
v0.4.0
Published
SpendGuard CLI: route your AI API keys through SpendGuard in one command
Maintainers
Readme
spendguardco
Route your AI API calls through SpendGuard in one command. No code changes: the CLI only edits your .env.
Use Claude Code? claude
npx spendguardco claude- Reads your local Claude Code history and shows what the last 30 days cost: tokens at API list price per model, and every paid service you used via MCP (fal, Higgsfield, ElevenLabs, ...). Nothing is uploaded at this point.
- Asks for your email, sends a sign-in link, and continues by itself when you click it. No token to paste. New email = new workspace;
--join K7F2joins a colleague's. - Installs a PostToolUse hook (every tool call Claude makes is reported, priced) and a
spendguardMCP server so you can ask Claude "what did I spend on AI this week".
Only counts leave your machine: tool names, model names, token counts, number of images / seconds / characters. Never prompts or content.
Related: npx spendguardco sync pushes token usage from local transcripts; hook and mcp are what the installer wires up.
Team members: configure
Your admin gives you personal sg_ keys (one per provider). In your project:
npx spendguardco configure --openai sg_... --anthropic sg_... --google sg_...This rewrites your .env:
- Comments out the original real API keys (kept as backup)
- Inserts your
sg_proxy keys in the variables the official SDKs read (OPENAI_API_KEY,ANTHROPIC_API_KEY,GEMINI_API_KEY, ...) - Adds the matching base URL variables (
OPENAI_BASE_URL,ANTHROPIC_BASE_URL,GOOGLE_GEMINI_BASE_URL, ...) pointing at SpendGuard
Run it without flags and it asks for each key. Run it again later with new keys and it just updates, no duplicate lines.
Existing workspace: connect
cd your-project
npx spendguardco connectScans .env for real API keys, signs you in with a magic link (you paste the link from your email), registers each provider in your workspace, issues sg_ proxy keys and rewrites your .env. This is the "Developer? Run one command" route in onboarding step 3.
New workspace: init
cd your-project
npx spendguardco init- Scans
.envfor real API keys (OpenAI, Anthropic, Google, fal, ElevenLabs, and more) - Creates your SpendGuard workspace and emails you a sign-in link
- You paste the link back into the terminal
- Registers each provider (your real key is stored encrypted, never shown to your team)
- Issues
sg_proxy keys and rewrites your.envto use them
Flags
--backend URL SpendGuard backend (default: https://app.spendguard.co)
--env FILE init/connect: use this .env instead of searching the folder
--email, --org init/connect: skip the prompts
--openai sg_... configure: proxy key per provider
--anthropic sg_... (also: google, fal, elevenlabs, heygen, runway, replicate,
--google sg_... stability, higgsfield, adobe-firefly, mistral, groq,
... deepseek, xai, perplexity, together, openrouter)Guarantees
- Never sends your real API keys anywhere except, during
init, to your own SpendGuard workspace over HTTPS. - Never modifies code, only the first
.envit finds (.env,.env.local,.env.production,.env.development, thensrc/,config/,backend/). - Refuses to write a key that does not start with
sg_.
Notes
- Python:
load_dotenv(override=True)if your shell already exports API keys. - Google: the
google-genaiSDK readsGOOGLE_GEMINI_BASE_URLandGEMINI_API_KEY; both are written. - Set
SPENDGUARD_URLto point every command at a self-hosted backend.
