<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Jayesh Kugsiya</title>
    <description>The latest articles on DEV Community by Jayesh Kugsiya (@jkugsiya).</description>
    <link>https://dev.to/jkugsiya</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4146807%2F173ecf25-3d2d-427c-80da-69870aff5d9a.jpg</url>
      <title>DEV Community: Jayesh Kugsiya</title>
      <link>https://dev.to/jkugsiya</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/jkugsiya"/>
    <language>en</language>
    <item>
      <title>DeviceGate: every machine gets its own key, limits and usage history on one Claude subscription</title>
      <dc:creator>Jayesh Kugsiya</dc:creator>
      <pubDate>Mon, 28 Sep 2026 09:47:12 +0000</pubDate>
      <link>https://dev.to/jkugsiya/devicegate-every-machine-gets-its-own-key-limits-and-usage-history-on-one-claude-subscription-2nn3</link>
      <guid>https://dev.to/jkugsiya/devicegate-every-machine-gets-its-own-key-limits-and-usage-history-on-one-claude-subscription-2nn3</guid>
      <description>&lt;p&gt;If you use Claude Code on more than one computer, you have probably run into this. The laptop, the desktop and that always-on box running agents all draw from the same 5-hour and weekly allowance. When you hit the limit, there's no way to tell which machine used it, and no way to stop the unattended one from quietly running everything on Opus.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;DeviceGate&lt;/strong&gt; is my answer to that. It's a small, self-hosted gateway you run on your own LAN. Your Claude login stays on one machine, and every other PC gets its own revocable key, its own model access, its own limits and its own usage history. It's free and open source (MIT): &lt;a href="https://github.com/jkugsiya/DeviceGate" rel="noopener noreferrer"&gt;github.com/jkugsiya/DeviceGate&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F66pz2rj3n80pe9fnppuw.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F66pz2rj3n80pe9fnppuw.gif" alt="DeviceGate demo" width="560" height="350"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;A quick tour: status page, adding a device, per-device limits and the usage explorer (sample data).&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;p&gt;DeviceGate sits in front of &lt;a href="https://github.com/KarpelesLab/teamclaude" rel="noopener noreferrer"&gt;TeamClaude&lt;/a&gt;, which signs in to your Claude account once, through Anthropic's own OAuth flow, and listens only on &lt;code&gt;127.0.0.1&lt;/code&gt;. DeviceGate runs next to it on the same machine and is the only thing the rest of your LAN talks to.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fboadbxh32sk3xd4w2roo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fboadbxh32sk3xd4w2roo.png" alt="DeviceGate architecture diagram" width="800" height="257"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;Each PC holds its own device token. Only the gateway machine holds the Claude login.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;For every request, DeviceGate checks the device token, applies that device's model allow-list and limits, forwards the request with the one credential it holds, and streams the response back unchanged. As the stream passes through, it reads the token counts out of it and records them. Prompts and responses are never stored.&lt;/p&gt;

&lt;p&gt;Claude Code itself needs no patches. The setup script only sets &lt;code&gt;ANTHROPIC_BASE_URL&lt;/code&gt; and &lt;code&gt;ANTHROPIC_AUTH_TOKEN&lt;/code&gt; in &lt;code&gt;~/.claude/settings.json&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;
  
  
  Adding a machine takes about two minutes
&lt;/h2&gt;

&lt;p&gt;In the admin, click &lt;strong&gt;Add device&lt;/strong&gt; and give it a name. You get a one-time setup code and the exact command to run on that PC, for macOS, Linux or Windows. Codes work once and expire after 15 minutes. After that, plain &lt;code&gt;claude&lt;/code&gt; just works on that machine.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnw8vp9aj5phnxuspbr3g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnw8vp9aj5phnxuspbr3g.png" alt="Add device setup instructions" width="800" height="845"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;The setup screen after adding a device.&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Different rules for different machines
&lt;/h2&gt;

&lt;p&gt;Each device gets its own model allow-list and its own limits: daily and weekly token and request quotas, requests per minute, and concurrent requests. Models match by family prefix, so a new Opus or Sonnet version is covered without any changes. When a device hits a limit, Claude Code shows a readable error with the reset time instead of failing in some confusing way.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsmmw7nej8gv8z3l2gxbb.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsmmw7nej8gv8z3l2gxbb.png" alt="Per-device access and limits" width="800" height="602"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;The always-on agent box: Haiku and Sonnet only, 800 requests a day, 20 a minute, 2 at a time.&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Seeing where the capacity went
&lt;/h2&gt;

&lt;p&gt;The usage explorer records input, output and cache tokens for every request, plus what those tokens would have cost at Anthropic's API rates. Your subscription already covers the traffic, so nothing is billed. The number is there to compare devices and spot the one burning through your quota.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2pu3qok91ch6y8ai8bsw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2pu3qok91ch6y8ai8bsw.png" alt="Usage explorer" width="799" height="562"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;Usage by day, with filters for device, model and outcome. Every filter lives in the URL, so any view is a link you can bookmark.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzmhed81e94nkaikcqbev.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzmhed81e94nkaikcqbev.png" alt="Usage by model and device" width="800" height="488"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;Breakdown by model and by device.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The overview puts the numbers that matter on one screen, including your remaining 5-hour and weekly capacity, read straight from Anthropic's own response headers.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fooje0m61q1wrws6npkli.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fooje0m61q1wrws6npkli.png" alt="Admin overview" width="799" height="562"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;The admin overview.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;There's also a public status page at &lt;code&gt;/&lt;/code&gt; that needs no login. It's handy to keep open on a spare screen, and it only shows device names and totals.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq8vgxxdtkj1ctogw17fv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq8vgxxdtkj1ctogw17fv.png" alt="Public status page" width="800" height="1087"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;The status page: capacity left, totals, and usage over time.&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Small on purpose
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;One Next.js process and one SQLite file. No Redis, no Postgres.&lt;/li&gt;
&lt;li&gt;Docker Compose if you prefer containers.&lt;/li&gt;
&lt;li&gt;An audit log of every admin action and sign-in attempt, with before/after diffs.&lt;/li&gt;
&lt;li&gt;Device tokens and setup codes are stored only as hashes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;
  
  
  For your own machines only
&lt;/h2&gt;

&lt;p&gt;DeviceGate is built for one person and their own devices. Anthropic's Consumer Terms don't allow routing other people's requests through your Pro or Max credentials, so please don't hand a device token to anyone else. If several people need Claude Code, each should use their own subscription, or a Team/Enterprise plan or API keys. DeviceGate is an independent project and isn't affiliated with or endorsed by Anthropic.&lt;/p&gt;
&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;You need an always-on Linux or macOS machine on your LAN, Node.js 20.9+, &lt;a href="https://bun.sh" rel="noopener noreferrer"&gt;Bun&lt;/a&gt; and a Pro or Max plan. The README walks through the whole setup. The short version, with Docker:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# on the gateway machine, with TeamClaude signed in and running&lt;/span&gt;
git clone https://github.com/jkugsiya/DeviceGate.git &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;DeviceGate
bun run init-env
docker compose up &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="nt"&gt;--build&lt;/span&gt;
docker compose &lt;span class="nb"&gt;exec&lt;/span&gt; &lt;span class="nt"&gt;-it&lt;/span&gt; devicegate bun run admin create you@example.com &lt;span class="s2"&gt;"Your Name"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then open &lt;code&gt;http://&amp;lt;gateway-ip&amp;gt;:3000/admin&lt;/code&gt;, add your first device, and run the command it gives you on that PC.&lt;/p&gt;

&lt;p&gt;The code is on GitHub: &lt;a href="https://github.com/jkugsiya/DeviceGate" rel="noopener noreferrer"&gt;github.com/jkugsiya/DeviceGate&lt;/a&gt;. Issues and pull requests are welcome. There are a few good first issues open, from a Docker health check to a dark mode. If you try it, I'd love to hear how it goes.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://jayesh125047.substack.com/p/devicegate-every-machine-gets-its" rel="noopener noreferrer"&gt;my Substack&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>opensource</category>
      <category>selfhosted</category>
      <category>productivity</category>
    </item>
  </channel>
</rss>
