Native macOS menu-bar app

Switch Claude Code and Codex accounts without breaking your setup.

Most switchers move the credential and leave you to discover what else they changed. This one restores only the auth fields, verifies which account you actually landed on, and rolls back if it cannot finish. Your settings.json, MCP servers, and hooks are never touched.

  • Free and open source
  • Signed and notarized
  • macOS 14 Sonoma+
Limit Lifeboat menu-bar dashboard showing three Claude accounts and one Codex account with remaining usage meters.
Auth fields onlysettings.json untouched
Identity verifiedAfter every switch
Rolls backOr keeps recovery material
Zero telemetryOpen source on GitHub

Built for more than one login

Change the login, not your configuration.

A switch that goes wrong costs more than the switch saved. Every change is scoped to the credential, checked afterwards, and reversible.

Every account, one view

Never spend an afternoon on the wrong account.

The CLI shows one identity at a time, and a switch that moves the credential without moving the identity will happily bill the wrong employer. See every saved account, which one the CLI is really logged into, what each has left, and how old each reading is.

Transactional switching

A switch that assumes it will be interrupted.

It stages rollback material, restores only the auth fields, then verifies the account it landed on. If another process rewrites a credential mid-switch, that change wins and the switch aborts rather than overwriting it.

Useful, optional warnings

Hear about limits before they interrupt you.

Get a notification when an account is nearly depleted—or likely ready to use again. You choose which alerts are enabled.

Usage history

See the rhythm, not just the number.

Local history helps reveal how quickly a limit is moving and whether the current pace is sustainable.

Up and running in minutes

It works with the logins you already have.

There are no API keys to paste and no new account system to create. Limit Lifeboat works with the CLI logins you already use.

  1. 01

    Install the app

    Download the signed DMG or install the cask with Homebrew. Limit Lifeboat lives in the menu bar.

  2. 02

    Use your CLI logins

    Log in with claude or codex login. On refresh, the active account registers itself.

  3. 03

    Stay in command

    Watch usage, choose warnings, and switch a CLI only when you decide it is time.

Local-first by design

A narrow switch surface, and a way back.

Limit Lifeboat handles sensitive CLI authentication material with explicit boundaries, identity checks, and protected recovery.

  • Only provider authentication fields change

    Unrelated CLI settings, MCP servers, instructions, and local history stay in place.

  • The restored identity is verified

    A switch completes only after the selected account is confirmed; failed changes roll back safely.

  • Snapshots are protected by macOS Keychain

    Temporary rollback material is restricted and removed after a verified switch or recovery.

  • No App Sandbox, for a specific reason

    Switching must update provider-owned CLI files. The release entitlement is limited to optional Terminal automation.

Read the privacy details

The question everyone asks second

Is this allowed?

Short answer: holding more than one account is normal, and this app does not do the thing providers actually prohibit.

What providers prohibit

Sharing one account between people, and reselling or proxying subscription inference through third-party harnesses. Limit Lifeboat does neither. It never sends your credentials anywhere, never routes a model request, and never gives two people access to one subscription.

What this actually does

It moves your own logins between your own accounts on your own Mac, using the same credential store and the same official CLI you already use. Quotas are enforced by the provider, per account, exactly as before. Nothing is pooled, merged, or extended.

Why people need it

The common case is an employer-provisioned account plus a personal one. Both vendors have declined to build switching — the request has been open on Claude Code since January 2026 with several hundred upvotes — so people do it by hand with scripts that overwrite their config.

Where the line is

Use only accounts you are authorized to use, and follow whatever policy your employer sets for the account they gave you. That is your call to make, not this app's. It will not create accounts, and it will not touch a browser or desktop-app session.

Read the long answer, with what the terms actually say

Free, signed, and notarized

Install it and keep your config.

Free, open source, and made for Apple Silicon Macs.

Recommended

Signed DMG

Download the latest signed and notarized release, then drag Limit Lifeboat to Applications.

Download for Mac
For Homebrew users

Homebrew Cask

Install from the personal tap. The cask uses the same published DMG as the GitHub release.

brew install --cask Johannes-Berggren/tap/limit-lifeboat
Requires
macOS 14 Sonoma or newer
Hardware
Apple Silicon
Current version
1.1.10
Price
Free

Full install instructions, requirements, and update behaviour

Questions, answered

The practical details.

Still stuck? The support page has troubleshooting steps and the right place to report an issue.

Visit support
What exactly changes on disk when I switch?

Only the selected provider's authentication fields. settings.json, MCP server definitions, hooks, permissions, instructions, and local history are left byte-for-byte alone. The app captures the current login first, stages rollback material, then verifies the restored identity before it cleans up.

What happens if a switch fails halfway?

It rolls back. If another process rewrote a credential while the switch was running, that external change wins and the switch aborts rather than overwriting it. If a safe rollback is not possible, the app keeps a protected recovery directory and tells you, instead of guessing.

Can I keep work and personal accounts separate?

Yes. Each saved account has its own identity, usage reading, and Keychain-protected credential snapshot. Quotas stay separate and provider-enforced; nothing is pooled or merged. Use only accounts you are authorized to access and follow the provider and workplace policies that apply to them.

Which accounts does Limit Lifeboat support?

It supports Claude subscription accounts used by Claude Code and ChatGPT subscription accounts used by the Codex CLI. You can use either provider or both.

Does it switch accounts automatically?

Only if you turn that on, and it is off by default. When enabled, it moves off the active account at 5% session remaining or 1% weekly remaining, follows your saved priority order, and requires the target account to have at least 30% headroom and to be at least 20 points better than the one you are leaving.

Does it switch my browser or desktop app too?

No. Browser, Claude Desktop, ChatGPT Desktop, and CLI sessions are separate. Limit Lifeboat switches the corresponding command-line tool only.

Does the app update itself?

It checks the signed update feed once a day by default, but it never installs silently. Every update requires you to choose Install and Relaunch.

Where does my account data live?

Profiles and usage history stay in your user Library. App-managed credential snapshots are encrypted by macOS Keychain. There is no product analytics, advertising, or telemetry.

Can I use an Intel Mac?

Not in version 1.1.10. Limit Lifeboat requires an Apple Silicon Mac running macOS 14 Sonoma or newer.

Every account visible. Every switch reversible.

Change which account the CLI uses without changing anything else.

Download for Mac