Who is tokenmaxxing? Find your heaviest AI token users
No spike needed: rank who uses the most tokens in a period, and see how concentrated usage is.
To see who caused a jump between two periods, see Which user is driving my token spike?
Rank one synthetic week
python3 -m venv .venv
.venv/bin/python -m pip install --no-cache-dir llm-sketchkit==0.2.2
.venv/bin/python - <<'PY'
import random
import secrets
from llm_sketchkit import USER_V1, canonicalize_text_v1, frequentitems, hash64
from llm_sketchkit.hash import Secret
secret = Secret(secrets.token_bytes(32)) # use your protected key in practice
ranking = frequentitems.Sketch("small", USER_V1)
total = 0
# One synthetic week: 60 people with heavy-tailed session sizes.
rng = random.Random(2026)
for n in range(60):
digest = hash64(secret, USER_V1, canonicalize_text_v1(f"person-{n:02d}@example.com"))
for _ in range(rng.randint(3, 25)):
tokens = int(20_000 * rng.paretovariate(1.2))
ranking.add_hash(digest, tokens)
total += tokens
items = ranking.frequent_items(frequentitems.NO_FALSE_NEGATIVES)
assert ranking.max_error() == 0 # This 60-user example fits in the 512-entry ranking.
people = len(items)
top = sorted(items, key=lambda i: i.lower_bound, reverse=True)[:5]
print(f"People using AI this week: {people}")
print(f"Total reported tokens: {total:,}")
print("Heaviest users (keyed; only the key holder can look them up):")
for rank, item in enumerate(top, 1):
exact = item.lower_bound == item.upper_bound
amount = f"{item.lower_bound:,}" if exact else f"{item.lower_bound:,} to {item.upper_bound:,}"
print(f" #{rank}: {amount} tokens")
low = sum(i.lower_bound for i in top) / total
high = min(1.0, sum(i.upper_bound for i in top) / total)
share = f"{low:.0%}" if f"{low:.0%}" == f"{high:.0%}" else f"{low:.0%} to {high:.0%}"
print(f"The top 5 of {people} people account for {share} of all tokens.")
PY
People using AI this week: 60
Total reported tokens: 78,126,732
Heaviest users (keyed; only the key holder can look them up):
#1: 17,034,328 tokens
#2: 8,652,754 tokens
#3: 3,136,006 tokens
#4: 2,615,589 tokens
#5: 2,273,034 tokens
The top 5 of 60 people account for 43% of all tokens.
In this synthetic week, 5 of 60 people account for 43% of reported tokens. The ranking holds keyed values, not names, so it can be shared with a manager or a finance team as it is. Whoever holds the key can look up a person by hashing a known ID.
Teams and budgets
Teams are few, so count them exactly; a few dozen budget lines don't need a sketch. Use the keyed ranking for people, where the list is long and names are sensitive.
From your gateway or collector
If your usage flows through an OpenTelemetry Collector, the released connector keeps the same keyed, token-weighted ranking continuously, in snapshot logs and summary files, without user labels on your metrics. See per-user metrics and the ranking configuration.
Reported tokens measure usage, not productivity or useful work. Rankings from keyed IDs are pseudonymous: whoever holds the key can identify people.
Measurement notes