Sessions
A session is one run of a coding agent, identified by the session ID the agent reports. The Sessions tab lists them, and each session has a detail page with its cost, risk flags, external domains and a timeline of every tool call.
How sessions are built
- A session appears once at least one of its tool calls arrives. Tool calls carry the session ID, the actor and the agent.
- A session’s cost comes from the model calls that carry the same session ID. Claude Code reports model calls with token counts and cost. Codex CLI doesn’t, so Codex sessions show
—for cost. - A session’s duration is the wall-clock time from its first tool call to its last. It is elapsed time, not active time. An agent that resumes an earlier conversation reuses its session ID, so a session you return to over several days reports a duration of several days.
Sessions list
Open Sessions in the header. The subtitle reads “Per-session rollup — actor, agent, tools, errors, duration, cost.”
Filters
The filter bar has Window and Scope, which work as described in Dashboard basics. The list shows every session with at least one tool call in the window, from the selected scope.
Columns
| Column | Meaning |
|---|---|
| Session | A short label: the agent name and a shortened session ID (the first eight characters of a UUID), for example claude-code · 3f9c2a1b. Hover to see the full ID. Select it to open the session. |
| Actor | The display name of the actor that sent the session, with its role label underneath when it has one. If the actor isn’t known to the organization, its raw actor ID appears instead. |
| Agent | The name the agent reports for itself, such as claude-code, with its version underneath when reported. |
| Tools | Number of tool calls in the window. |
| Errors | Number of those tool calls that ran and failed. Highlighted when above zero. |
| Duration | Time between the first and last tool call in the window, shown as 45s, 12m, 3h 12m or 2d 4h. |
| Cost | The session’s total model spend across the whole session, not only the window. — means no model calls arrived for the session, so its cost is unknown. $0.00 means its model calls arrived without a price. |
| Started | Time of the session’s first tool call in the window, in UTC. |
Tools, Errors, Duration and Started count only the tool calls inside the window. For a session that began before the window, open the session to see its full figures.
Order and paging
Sessions are sorted by their most recent tool call, newest first. The list shows 25 sessions per page. Use Prev and Next below the table to move between pages; the label between them shows the page number and adds (last) on the final page. The page buttons are hidden when everything fits on one page.
Empty list
When no session matches, the table shows No sessions in this window. with Try 30 days and Back to Overview buttons. Widen the window or the scope, and check that an agent is configured to send data. See Agent setup.
Session detail
Select a session in any list to open its page. The heading shows the session label, and ← All sessions returns to the list.
The detail page always covers the whole session, regardless of the window you came from. A session ID that doesn’t exist in your organization returns a “404 page not found” page.
Overview card
| Field | Meaning |
|---|---|
| Session ID | The full session ID, selectable for copying. |
| Actor | The actor’s display name and role label. |
| Agent | The agent’s name and version. |
| Started | Time of the session’s first tool call. |
| Last seen | Time of the session’s most recent tool call. |
| Duration | Time from Started to Last seen. |
| Tool calls | Total tool calls, followed by the number of errors. When there are errors, the error count is a link that filters the timeline below to them. |
| Cost | Total model spend and the number of model calls, or — when no model calls arrived. |
Cost
The Cost card covers the whole session:
| Field | Meaning |
|---|---|
| Total cost | Sum of the cost of every model call. |
| Model calls | Number of model calls. |
| Fresh input tokens | Input tokens not served from the prompt cache. |
| Cache read tokens | Input tokens served from the prompt cache, followed by the share of all input read from cache. |
| Cache creation tokens | Tokens written to the prompt cache. |
| Output tokens | Tokens the model generated. |
When the session has no model calls, the card shows No model calls recorded. This is expected for agents that don’t report model calls, such as Codex CLI.
Spend by model
The Spend by model card lists each model the session used, most expensive first, with its Calls, Cost and a Share bar showing its portion of the session’s cost. A model call that didn’t name its model is listed as unattributed. When the session has no cost to divide, Share shows —. With no model calls the card shows Nothing to break down.
Risk flags
The Risk flags card lists what the Scout Trails detector found in the session’s tool calls, most severe first. Each row shows Severity, Flag and Evidence.
| Flag | Severity | Raised when |
|---|---|---|
credential_detected | high | A tool call’s arguments or result contain something shaped like a secret: an AWS access key, a GitHub token, an OpenAI-style sk- key, a JWT, a private key block, a Stripe live key, a Slack token or a Bearer authorization header. The evidence shows the kind and only the first few characters. |
destructive_operation | high | A shell (Bash) command runs something destructive: a recursive or forced rm, git push --force, git reset --hard, git clean -f, DROP TABLE, TRUNCATE TABLE, dd writing to a device, mkfs, shutdown or reboot, or chmod 777. |
sensitive_path | medium | Arguments or results mention a sensitive file, such as .env files, .ssh/ paths, credentials.json, .pem and .key files, .aws/credentials, SSH private keys like id_rsa, .kube/config, or keystores (.p12, .pfx, .keystore, .jks). |
Evidence is cut to 60 characters. When nothing was flagged the card shows No risk flags in this session.
External domains
The External domains card lists the internet hosts the session’s tool calls reached, with Hits counting the calls that touched each one, most-hit first. Scout Trails finds hosts in:
- URLs in shell commands that use
curlorwget. - The
urlargument ofWebFetchcalls. url,endpoint,uriorbase_urlarguments of MCP tool calls.
Only http and https URLs count, and localhost, 127.0.0.1, 0.0.0.0 and ::1 are left out. With none, the card shows No external domains reached.
Tool-call timeline
The Tool-call timeline lists the session’s tool calls, newest first.
| Column | Meaning |
|---|---|
| Tool | The tool’s name. Select it to open the tool call. |
| Type | The tool’s type, for example builtin or mcp. |
| Duration | How long the call took, such as 850ms, 1.2s, 3m05s or 1h02m. — for a denied call, which never ran. |
| Status | ok, error or denied. See Status. |
| Started | When the call happened, in UTC. |
When a call failed with an error message, its status is a toggle. Select it to show or hide an Error row with the message beneath the call.
The filter bar inside the card narrows the timeline only; the cards above always describe the whole session.
- Tool — one tool name used in this session, or Any.
- Tool type — one tool type, or Any.
- Status — ok, error, denied or Any.
Select Apply to filter. Reset appears once a filter is set and clears it. The timeline pages with Prev and Next, 25 calls per page, and keeps your filters as you page.
The timeline’s empty states:
- No tool calls match these filters. — the session has calls, but none match. Clear filters removes the filters.
- No tool calls on this page. — the page is past the end of the timeline. Previous page goes back.
Related pages
- Tool calls
- Trends — sessions with unusually many tool calls.
- Agent setup — what each agent sends.