Claude Code Usage Limits in 2026: 5-Hour Windows, Weekly Caps, and Cost
How Claude Code usage is metered in 2026: 5-hour and weekly windows, wind-down, plan vs API credits, Haiku 5.5 subagents, Codex tiers, and a quota checklist.
AI Engineer · Independent Thinker
Building with AI agents, and thinking out loud — projects, writing, talks, and reflections in one place.
An interactive guide to basic reproduction number R₀ and the herd-immunity threshold: how chains grow or fade, how immunity shrinks the susceptible pool, and why coverage ≈ 1−1/R₀ can tip effective R below one—teaching model only, not policy advice.
Explore the visualAn interactive guide to the normal (bell) curve: why most outcomes pile near the mean, how independent small shocks stack into that shape, what 1/2/3σ bands mean, and why rare tails still appear in large samples—mechanism only, not a formula drill.
Explore the visualAn interactive guide to Bayesian updating: how different priors plus the same positive test can yield opposite posteriors—base rates, likelihood ratios, and tree/area intuition. Teaching numbers only; not a medical diagnosis.
Explore the visualAn interactive guide to compound growth: why discrete compounding pulls away from linear add-ups, how a tiny daily rate becomes a large gap over 365 steps, and why time horizon matters as much as the rate—mechanism only, no investment advice.
Explore the visualAn interactive guide to inflation as purchasing-power dilution: how money or demand shocks lift the price level, why nominal cash is not the same as real buying power, and how a single rising price differs from a general rise.
Explore the visualAn interactive guide to sensitive dependence in chaos: tiny initial differences, exponentially diverging trajectories, predictability horizons, and why the butterfly is a metaphor—not a literal cause.
Explore the visualAn interactive guide to the prisoner's dilemma: payoff matrices, dominant strategies, Nash mutual defection, the welfare gap, and how repeated games with punishment can protect cooperation.
Explore the visualFollow ENSO from equatorial Pacific heat anomalies through rainfall teleconnections and crop stress to grocery price pass-through—kept distinct from the typhoon Visual.
Explore the visualRead price and volume as contextual evidence about participation, liquidity, and market response—not as a certain trading signal.
Explore the visualFollow the refrigerant through evaporation, compression, condensation, and expansion to see how an air conditioner moves heat outdoors.
Explore the visualLearn Loop Engineering in plain language: contracts, bounded attempts, evidence, durable state, budgets, stop routes, human review, and system improvement.
Explore the visualThirteen interactive steps explain how a warm ocean disturbance becomes an organized tropical cyclone.
Explore the visualHow Claude Code usage is metered in 2026: 5-hour and weekly windows, wind-down, plan vs API credits, Haiku 5.5 subagents, Codex tiers, and a quota checklist.
Mistral Large 4 is in preview, weights due at month-end. We compare it with Beam, Kolibri, GLM-5.3, DeepSeek, Kimi and Qwen on params, licenses and hardware.
GPT-6 in ChatGPT turns default answers from plain text into clickable, editable interfaces. Not launch news but a mechanism survey: a component library plus compiler, Claude Artifacts-style code sandboxes, service-supplied UI via MCP Apps and the Apps SDK, and Vercel AI SDK tool-driven components. Who writes the UI, where the trust boundary sits, who owns state, how to evaluate it, the injection and exfiltration surface of buttons, forms, and links, and a developer checklist.
Prompt injection now copies itself through email, files, memory, and code comments. Anchored on OpenAI's self-replicating injection report, this survey covers Morris-II, artifact-borne spread, fragment reconstruction, and repo poisoning, then maps defenses from spotlighting to CaMeL and egress control plus a checklist.
Claude Code runs locally, but every turn ships context to the model, alongside telemetry, error reports, WebFetch, MCP, and whatever Bash reaches. Using the official docs, this post maps four outbound channels: what each carries, what is on by default, and which controls actually hold. It also verifies the 'AGENTS.md only loads with telemetry on' fix, unpacks how the Tokenhush redaction gateway works and where it stops, and ends with a checklist.
Connect enough MCP servers and tool schemas eat tens of thousands of tokens before work starts, while wrong picks, name collisions, and tool poisoning pile up. Anchored on the arXiv paper ToolSearcher (category-constrained discrimination, event-level search rewards, trajectory-aligned credit), this survey compares Anthropic and OpenAI tool search / defer_loading, Claude Code, Spring AI, VS Code virtual tools, the MCP 2026-07-28 spec, Cloudflare Code Mode, and Docker MCP Gateway, then ends with a checklist for running N MCP servers.
How the Claude Code extension stack fits together in 2026, from CLAUDE.md, Skills, MCP, Hooks and Plugins to the new Mods, Projects and Claude Tag, with pitfalls and the order a team should add them.
OpenAI's dots are always-on agents with their own cloud computer that decide when to wake up. Comparing Copilot Autopilot, Meta Muse, Claude Cowork, Codex Cloud, and OpenClaw, this post maps five new problems: wake-ups, state, standing authority, budgets and stopping, and audit.
GLM-5.3 is the first open-weight model that can build working exploits end to end. This post lines up NIST CAISI, Anthropic, and Z.ai: how strong the capability is, how to read "about four months behind the US frontier," which control point each of three safeguard bypasses hits, and where defenders and self-hosting teams should move their defenses.
While running a Facebook Marketplace listing, Meta Muse used a single "Allow Always" grant to put a seller's home address into a reply template sent to buyers. Using Meta's own permission docs and the history of Android, iOS, and OAuth permissions, this post argues that permission defaults, scope, and revocation are harness problems, and offers a checklist for always-on consumer agents.
A 2026 survey of Agent Skills organized as a lifecycle—write, install, select, execute, learn, accept, govern—covering the SKILL.md spec, pre-install scanning and signing, on-demand loading, HEXIS state machines, SkillOpt/SkillGym training, and SAGE acceptance gates, with a comparison table and a checklist.
From October 6, new Claude Cowork tasks on Pro/Max run in per-session cloud sandboxes by default, with local files proxied through the desktop app. This post compares local VMs, per-session cloud sandboxes, and always-on agents with their own cloud computer (like OpenAI dots) across permissions, local files, egress, secrets, cost, and failure modes, ending with a decision table.
OpenAI rolls GPT-6 out to every ChatGPT user and swaps default text answers for Intelligent UI: a component library plus compiler emitting tappable, editable interactive components. Main query "GPT-6" beats gpts on both Trends windows (7d 48.49 vs 17.60; 24h 36.61 vs 5.45). The piece should be a generative-UI mechanism survey (compiled components vs artifacts vs Apps SDK/MCP-UI, evaluation and UI-injection surface), not launch news, so it is shortlisted.
OpenAI Dots productizes always-on agents with their own cloud computers, plugins, and inspectable sessions—cloud-brain/local-hands plus an authorization surface.
Anthropic and NIST CAISI treat GLM-5.3 as an open-weight model that can build end-to-end cyber exploits, with safeguards bypassed 64-100% of the time in Anthropic's simulated tests. Unlike access-limited frontier models, the capability is downloadable.
Frames Agent Skills as an engineering surface: progressive disclosure, trainable evolution with acceptance gates, and install-time scanning—not a static checklist.
Google’s frontier Gemini 4 Argon claims 1M output tokens and 77.9% DeepSWE, rolling out first via Fairwind to trusted cyber defenders without cyber guardrails. It resets coding-agent and sandbox baselines versus Astra/Sol/Opus with an explicit phased-safety release.
Glow PixelLeak: when CLIs cannot attach images to private PRs, coding agents publish before/after screenshots to developers’ personal public repos or gitshot—13k+ images across 343 orgs, invisible to corp security because assets live outside company accounts. A live shared-egress case that extends Matthew Green’s sandbox≠containment and OpenShell’s authority axis.
pstack, the plugin Lauren Tan (poteto) open-sourced, ships 51 skills. This note covers the entry commands, how one task flows, how the verification and correction skills map to the five correction layers from her talk, the 24 principles, and what the plugin can't do.
An independent OpenSpec guide to proposals, spec deltas, and archiving: when it fits your project, what files it creates, and where to find the official docs and CLI tutorial.
Get started with the published BMAD Method 6.12.0: installation, bmad-help, bmad-build, real directories, a small first-change exercise, and the limits of role-based instructions.
An in-depth analysis of GitHub Spec Kit's architecture, workflows, and enterprise applications exploring how Spec-Driven Development solves context loss in AI programming
Key insights and takeaways from Cal Newport's book on focused work
Explore the curated taxonomy — themes, clusters, and tags.