CodexQuota does not accept, read, copy, or log browser cookies, passwords,
session tokens, API keys, or Codex credential files. The appserver provider
starts the official local Codex app-server and requests only derived rate-limit
information through account/rateLimits/read. Authentication remains owned by
Codex.
Runtime quota state and local JSON input are intentionally ignored by Git because even derived percentages and reset times can be private. Never attach credentials or authentication files to a bug report.
Until a repository security contact is configured, do not publish an unpatched credential exposure or code-execution issue in a public issue. Use the repository host's private vulnerability-reporting feature. Ordinary bugs that contain no private data may be reported publicly.