Field guide
What's actually in your Claude Code usage logs
Claude Code already writes everything you need to work out what it costs you. Here is where it lives, what the fields mean, and the one mistake that made our own first estimate wrong by a factor of 633.
Where the logs are
Every session is appended to a JSON Lines file under your home directory:
~/.claude/projects/<encoded-project-path>/<session-id>.jsonl
One JSON object per line. The directory name is derived from the project path you were working in, which is what makes per-project attribution possible without any extra configuration on your side.
The fields that matter
Assistant messages carry a usage object. The parts relevant to cost are:
{
"timestamp": "2026-08-22T04:53:13.857Z",
"cwd": "/Users/you/code/some-project",
"message": {
"model": "claude-sonnet-5",
"usage": {
"input_tokens": 2,
"output_tokens": 878,
"cache_read_input_tokens": 409004,
"cache_creation_input_tokens": 1993
}
}
}That is the whole surface you need: four token counts, a model name, a timestamp, and the working directory. Nothing about cost requires reading the prompt text or the file contents that make up the rest of the line.
The mistake: input + output is not your usage
The obvious way to price a session is to sum input_tokens and output_tokens. That is wrong, and not by a little. Here is the real breakdown across 17,202 usage-bearing events from 35 session files on one working machine:
| Field | Tokens | Share |
|---|---|---|
| cache_read_input_tokens | 6,545,108,694 | 97.46% |
| cache_creation_input_tokens | 159,983,196 | 2.38% |
| output_tokens | 10,549,546 | 0.16% |
| input_tokens | 59,353 | 0.00% |
Cache reads are 97.46% of all tokens. Input and output together came to 10.6 million out of 6.72 billion — so pricing on those two fields alone undercounts by roughly 633×.
This is not an anomaly, it is how an agentic coding tool works. Claude Code re-reads a large cached context on nearly every turn, so cached input dwarfs the handful of new tokens you actually type. Cached reads are billed at a lower rate than fresh input, which is exactly why they are worth having — but a lower rate is not a zero rate, and at this volume the difference decides your bill.
Other things worth knowing
- The logs are mostly not usage data. On the same machine, 402 MB of raw
.jsonlcontained about 9 MB of usage metadata. The rest is prompt and file content. - Spend per project is lumpy. A couple of repositories accounted for most of the total, and they were not the ones we would have guessed before measuring.
- Models are mixed within a session. Entries carry their own model name, so you cannot price a whole session at one rate.
- Some entries are synthetic. You will see a
<synthetic>model on a small number of lines; they are not billable turns.
Reading it yourself
You do not need us for any of this. Our collector is open source and dependency-free, and it will do the arithmetic above against your own logs — no key, no account, nothing uploaded:
npx github:THEMANJH/agentspend-upload --report
If you would rather see the raw payload a team sync would send instead of a summary, --dry-run prints exactly that and uploads nothing.
It reads only the four token counts, the model name, the project folder name and the timestamp — never prompt text or file contents. You can confirm that in about two minutes by reading the source, which is one file.
Related: What actually drives your Claude Code bill — the same dataset broken down by model and project, including why Opus turns cost 4.5x more than Sonnet turns while using fewer tokens.
If you need this for a whole team
The CLI shows one machine. AgentSpend is the hosted version: everyone's spend in one dashboard split by person and project, with an email alert before you cross a budget. Flat $19/mo for up to 10 people, never metered on the spend you track.
Figures measured 22 August 2026 on a single heavily-used machine: 35 session files, 17,202 usage-bearing events, 6,715,700,789 tokens total. Your mix will differ; the method is what transfers.