how to

Set up slice, step by step.

Nine short steps, from install to uninstall. Every block below can be copied with the button in its top right corner.

Tested on Mac and Linux. The Windows lines are standard PowerShell. It all works the same in the terminal inside VS Code.

01Install

The slice CLI is a small package on PyPI. It needs Python 3.11 or newer.

Use pipx. It installs command line apps in their own space and puts slice on your PATH. On a new Mac, plain pip install is refused with the words externally managed environment. pipx is the fix, not a workaround.

  • Mac: macOS 13 Ventura and newer with Python from Homebrew, which is any Homebrew Python 3.11 or newer. The Python that ships with macOS is 3.9 and cannot run slice at all, so a Mac ends up on Homebrew and hits the refusal.
  • Linux: Debian 12 and newer, Ubuntu 23.04 and newer (so 24.04 LTS), Fedora 38 and newer, Arch since 2023. Older releases let plain pip through, pipx still works.
  • Windows: Windows 10 and 11 with Python 3.11 or newer from python.org. Windows never refuses pip, pipx just keeps the steps the same everywhere.
Terminal
$ brew install pipx
$ pipx ensurepath
$ pipx install slice-gateway
$ slice --version
Terminal after install
Terminal after pipx install slice-gateway, showing slice-gateway 0.2.2
Taken on my Mac. Your username and a few details will look different; the commands are the same.
No Homebrew? Install it first at brew.sh, one command. If slice --version says command not found after this, close the terminal and open a new one, then try again.

Expected output of the last line: slice-gateway 0.2.3 (or newer).

02Log in

Sign in with GitHub. slice login prints a link and a code, opens the link in your browser, and waits while you click Continue and then Authorize. The terminal then says Logged in as your username, prints your dashboard link, and opens that page too.

Terminal
$ slice login

What you should see

  To finish signing in, open:
    https://github.com/login/device
  and enter this code:
    WXYZ-1234

Waiting for you to authorize in the browser...
Logged in as your username

Your dashboard: https://sliceapp.dev/dashboard
Terminal after slice login
Terminal after slice login, showing the GitHub link and a code
GitHub: Device Activation, click Continue
GitHub Device Activation page with a Continue button
The GitHub pages look the same on every system.
GitHub: enter the code
GitHub page with eight boxes for the code and a Continue button
GitHub: Authorize slice
GitHub page asking to authorize slice
GitHub: done
GitHub page saying your device is now connected
Terminal: logged in, with your dashboard link
Terminal showing Logged in as jjk30 and the dashboard link

You will see your own GitHub username here.

Now open your dashboard

slice opened sliceapp.dev/dashboard for you, or open it yourself. Click Log in as your username, or Sign in with GitHub in a fresh browser: one click, no forms, because GitHub already trusts slice. The terminal login and the dashboard sign in are two separate doors, both through GitHub.

Dashboard: click Log in
Dashboard sign in page with a Log in as jjk30 button
Dashboard: signed in
Dashboard after signing in, showing spend tiles and the account budget

Your slice key

Login mints a slice key. It starts with slk_live_. The CLI saves it to ~/.slice/config.json, readable only by you, and does not print it. It is not shown again. The dashboard shows only its last four characters.

One key per device

The key is named after your machine, for example cli:Mac.home.local. Run slice login again on the same machine and slice revokes that machine's old key and saves a new one. Keys on your other machines are not touched.

Where to see it

Open the dashboard at sliceapp.dev/dashboard. The card called Your slice key shows your newest live key, masked, with its name and the day it was made.

To check the saved login from the terminal:

Terminal
$ slice init

What you should see

Gateway:  https://api.sliceapp.dev
Config:   /Users/you/.slice/config.json
Logged in as your username (account 1).

03Point your tools at slice

slice reads your slice key from the Authorization header. Your own Anthropic key goes in x-api-key, and slice forwards it to Anthropic. Each setup below sends both.

What slice sees, and what it keeps.

Your files never go to slice. Claude Code decides what to send to the model, and only that request passes through slice on its way to Anthropic. slice looks at it just long enough to pick a model and count the tokens, then sends it on.

What it keeps: which model, how many tokens, what it cost, and when. That is what the dashboard is built from.

What it does not keep: your prompt, the answer, your code, or your Anthropic key. The key rides through to Anthropic and is not saved.

Why you can trust that: the request table has those columns and nothing else, and the code is open on GitHub, so you can read it yourself.

Claude Code

Before you start. You need two things first: Claude Code on this machine, and an Anthropic API key. If you already have both, skip to the three lines below.

1. Install Claude Code.

Terminal
$ curl -fsSL https://claude.ai/install.sh | bash
$ claude --version
Needs macOS 13, Windows 10 (1809) or Ubuntu 20.04 and newer. The last line prints a version number followed by (Claude Code). Full guide with Homebrew, WinGet and WSL options: code.claude.com/docs/en/quickstart

2. Get an Anthropic API key. Open console.anthropic.com, sign in, click API keys, then Create key. Copy it once; it starts with sk-ant-. This is the key that pays Anthropic for your requests. Signing in to Claude Code with a claude.ai subscription does not give you a key and does not work through slice; you need the console key.

Set three variables in the shell where you run Claude Code. slice use claude-code prints the same lines with your key filled in.

Terminal
export ANTHROPIC_BASE_URL=https://api.sliceapp.dev
export ANTHROPIC_API_KEY=(your own Anthropic key)
export ANTHROPIC_AUTH_TOKEN=(your slice key)
Fill in two things: (your own Anthropic key): the key you already use for Claude. If you have one, paste it here. If not, get one at console.anthropic.com under API keys. It starts with sk-ant-. (your slice key): your slice login key. Starts with slk_live_. Easiest: run slice use claude-code and it prints these three lines with your slice key already in. Or open ~/.slice/config.json and copy it from there. Delete the brackets when you paste. Paste the three lines only into your terminal, they hold your key. These three lines last only for the open terminal window. Close it and you set them again, or put them in your shell profile.
Terminal after slice use claude-code
Terminal after slice use claude-code, showing the three export lines with the keys shortened
Taken on my Mac. Your username and a few details will look different; the commands are the same.

ANTHROPIC_AUTH_TOKEN goes out as Authorization: Bearer, which is where slice reads its key. ANTHROPIC_API_KEY stays your own Anthropic key in x-api-key. Claude Code prints a notice that env auth takes precedence over your claude.ai login while these are set. That is expected. Unset the three variables to go back to normal.

Anthropic Python SDK

Give the client the slice address, your Anthropic key, and your slice key as the auth token. The SDK also reads the three variables above, so you can leave the keys out of the code.

Python
import anthropic

client = anthropic.Anthropic(
    base_url="https://api.sliceapp.dev",
    api_key="(your own Anthropic key)",
    auth_token="(your slice key)",
)
message = client.messages.create(
    model="claude-sonnet-5",
    max_tokens=64,
    messages=[{"role": "user", "content": "hi"}],
)
print(message.content[0].text)
Fill in two things: the same two keys as above. Delete the brackets and keep the quotes.

curl

The same two headers, by hand. This uses the variables from the Claude Code block.

Terminal
curl https://api.sliceapp.dev/v1/messages \
  -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \
  -H "content-type: application/json" \
  -d '{"model":"claude-sonnet-5","max_tokens":64,' \
     '"messages":[{"role":"user","content":"hi"}]}'
Terminal: the same curl run twice
The same curl run twice, first 200 in about 5 seconds, then 200 in under a tenth of a second from cache

Run it twice. The first call is billed. The second call, with the same body, is served from cache at $0. slice keeps an answer for one hour.

The answer may come from a cheaper model than the one you asked for, and the model field in the answer says which: that is slice saving you money.

Dashboard: Recent calls
Dashboard Recent calls panel showing a routed call with a cost and the repeat marked cached at $0.00

04Ask slice from Claude Code

Every step here works in the Mac Terminal, the Linux terminal, PowerShell on Windows, or the terminal inside VS Code. Same commands.

The pictures are from my Mac. Your username, folder names, times, and numbers will look different. That is fine.

1. Get the latest slice. Upgrade the package, then list what pipx put on your machine. You should see both slice and slice-mcp.

Terminal
$ pipx upgrade slice-gateway
$ pipx list
Terminal after pipx upgrade
Terminal after pipx upgrade slice-gateway, with pipx list showing slice and slice-mcp

slice-mcp with no key prints a short error. That is expected. It just proves the command is installed.

2. Set your three keys. These are the same three as the Claude Code section above. slice use claude-code prints them with your slice key filled in.

Terminal
export ANTHROPIC_BASE_URL=https://api.sliceapp.dev
export ANTHROPIC_API_KEY=(your own Anthropic key)
export ANTHROPIC_AUTH_TOKEN=(your slice key)
Do not mix the two keys up. The Anthropic key starts sk-ant-api and comes from console.anthropic.com. It is the one that pays Anthropic. The slice key starts slk_live_ and comes from sliceapp.dev/settings. It is your slice login key. These three lines last only for the open terminal window. Close it and you set them again, or put the three lines in your shell profile.

3. Register the MCP with Claude Code. One command adds it. -s user means it works from any folder, not just the one you are in.

Terminal
$ claude mcp add slice -s user -e SLICE_API_KEY=$ANTHROPIC_AUTH_TOKEN -- slice-mcp
Terminal after claude mcp add
Terminal after claude mcp add slice, confirming the slice MCP server was added

If you ever need to redo it, run claude mcp remove slice -s user first.

4. Start Claude Code. Run claude in your project folder. Two things you may see.

Terminal
$ claude
  • A yellow warning that both ANTHROPIC_AUTH_TOKEN and ANTHROPIC_API_KEY are set. Ignore it. slice needs both. One is your slice key, one is your Anthropic key.
  • The first time in a folder, it asks "Is this a project you trust?". Pick Yes, I trust this folder.
Claude Code: trust this folder
Claude Code asking Is this a project you trust, with Yes I trust this folder as the choice

5. Check it is connected. Type /mcp and press Enter. You should see slice, connected, 6 tools.

Claude Code: /mcp shows slice connected
Claude Code /mcp panel showing slice connected with 6 tools

Press Enter on slice to see the details. The command is slice-mcp.

Claude Code: the slice server details
Claude Code showing the slice server details, with the command slice-mcp

Press Enter on View tools to see the six tools. Press Esc three times to get back to the prompt.

Claude Code: the six slice tools
Claude Code listing the six slice tools

6. Ask it something. Type what is my slice spend this month. The first time, it asks Do you want to proceed?.

Claude Code: the permission prompt
Claude Code asking Do you want to proceed before running a slice tool

Pick 2, Yes, and don't ask again, so it stops asking for that tool. Pick 1 to be asked every time. Pick 3 to say no. It asks once per tool, so you will see it again for the next tool. Then the answer.

Claude Code: your spend this month
Claude Code showing this month's slice spend against the budget

7. Try another. Type what did my last 5 requests cost.

Claude Code: your last five requests
Claude Code showing the last five requests with model, cost, and routed from

Every request that says routed from opus-5 was answered by Haiku at a fraction of the cost. That is slice working.

The six tools

  • get_spend: this month's spend against your budget.
  • list_rules: your model-routing rules.
  • get_recent_requests: your last calls, with model, cost, and time.
  • get_eval_summary: the eval pass rate.
  • add_rule: add a routing rule.
  • delete_rule: remove a routing rule.

05Watch spend

The dashboard is at sliceapp.dev/dashboard. Sign in with GitHub. The first time, it asks for an email so slice can reach you.

The five tiles

spend this monthWhat your requests through slice have cost so far this month. Cache hits count as $0. If a model has no price in slice's table, the tile says how many requests were left out. This number is slice's estimate, worked out from token counts at list prices, and your Anthropic bill is the true figure.
AWS bill this monthYour AWS spend for the month so far, from Cost Explorer, with yesterday's total under it. It reads "not connected" until you connect AWS in step 05.
saved this monthFor each request slice routed to a cheaper model: what the model you asked for would have cost, minus what you paid. Only successful requests count.
requestsHow many calls went through slice this month, with how many were cache hits and how many were routed to a cheaper model.
eval pass rateslice scores a sample of the routed-down answers after the fact. This is the share that passed, and how many were scored.

The account cap

Every account starts on the default cap, $25 a month. Set your own under Monthly budget cap in Settings.

The Account budget panel shows what is used, the cap, and what is left.

  • Near the cap. When spend reaches 80% of the cap, slice sends one warning email for the month. Nothing is blocked yet.
  • At the cap. slice blocks requests. A blocked request gets a 429 with the message Monthly budget exceeded for this account. and costs nothing. A block email goes out.
  • New month. The counter resets on its own.

06Connect AWS

Optional. Connect a read-only role and the dashboard shows your AWS bill next to your AI spend. slice also scans the account once a day for risks and waste.

  1. In the dashboard, click Settings. Find Connect AWS (optional).
  2. Click Create the read-only role in AWS. It opens the CloudFormation quick-create page in your AWS account, with the template and your External ID already filled in. The stack is named slice-scanner-role.
  3. Read the template if you like. It is in the repo at infra/user-onboarding/slice-readonly-role.yaml. Tick the box that acknowledges the stack creates an IAM role, then click Create stack.
  4. When the stack shows CREATE_COMPLETE, open its Outputs tab and copy RoleArn.
  5. Back in Settings, paste it into the Role ARN box and click Connect. slice assumes the role once to check it. The status changes to connected.
Role ARN
arn:aws:iam::(your AWS account id):role/slice-scanner/(the name CloudFormation gave the role)
Fill in two things: (your AWS account id): the 12 digit number shown when you click your name at the top right of the AWS console. (the name CloudFormation gave the role): on the Outputs tab of the stack once it finishes. Easiest: copy the whole ARN line from Outputs. Delete the brackets when you paste.

The first scan runs within about an hour. After that, once a day.

What the role can read

  • The list of your S3 buckets, and each bucket's ACL, policy, policy status, encryption, and public access settings.
  • Your account's public access block setting.
  • EC2 security groups, volumes, snapshots, instances, and Elastic IP addresses.
  • CloudWatch metric statistics.
  • IAM users, their access keys, when a key was last used, and the policies attached to a user.
  • Cost Explorer cost and usage.
  • Its own identity.

It cannot change anything. It cannot read a file in a bucket, a secret, or a password. Only slice's AWS account, 194133064379, can assume the role, and only with your External ID.

To disconnect, delete the slice-scanner-role stack in CloudFormation. slice's access ends the moment the role is gone.

07GitHub Actions

There is no slice action. A workflow step can call the gateway with curl. Store two repository secrets: SLICE_KEY and ANTHROPIC_API_KEY.

Paste the key on its own. When you paste a key into a GitHub secret, make sure nothing comes after it, no Enter and no space. A stray Enter breaks the request and slice answers 400 Request body is not valid JSON. On a Mac you can clean the clipboard first with pbpaste | tr -d '\r\n ' | pbcopy.

A key for CI. Make it in the dashboard: open Your slice key and click Create new key. Copy it once. This revokes every other live key on the account, including your laptop's, so run slice login again afterwards. A CLI login does not revoke a dashboard key.

.github/workflows/your-workflow.yml
- name: Ask Claude through slice
  env:
    ANTHROPIC_AUTH_TOKEN: ${{ secrets.SLICE_KEY }}
    ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
  run: |
    curl -sS https://api.sliceapp.dev/v1/messages \
      -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \
      -H "x-api-key: $ANTHROPIC_API_KEY" \
      -H "anthropic-version: 2023-06-01" \
      -H "content-type: application/json" \
      -d '{"model":"claude-sonnet-5","max_tokens":64,"messages":[{"role":"user","content":"hi"}]}'

Every call from CI shows up in the dashboard and counts against the same account cap.

08Alert emails

slice scans a connected AWS account once a day. When a scan finds new high-risk items, you get one email about them, at most one an hour. The budget warning and the block from step 04 arrive the same way.

Each finding is three short lines: what it is, why it matters, and the first thing to do. Then a Read more link to the AWS doc page for that check. Here is one:

Gmail: the alert email
A slice alert email in Gmail with two findings, each three lines and a Read more link, and the AI footer
Taken from my Gmail. Your findings and numbers will differ.

Every email ends with the same line: slice is an AI. Please double check before you change anything in AWS.

Some findings are on purpose, like a bucket that serves a public website. Open the AWS findings panel on the dashboard and turn on the expected switch for that finding. It stays in the list, muted, and leaves the emails until you turn the switch off.

Reply with a question

Reply to the email with a question about your own account. For example, how much you spent this month, or what a finding means. slice does not break costs down by week. Send it from the email you saved in Settings. slice answers from your own slice data, in plain words, under 150 words. It never sends commands or scripts to run. If it does not have the number, it says so.

Gmail: a question about your own account
A reply asking how much was spent this month, and slice's answer from the account's own data
Gmail: a general AWS question
A general AWS question about NAT gateway cost, and slice's answer marked as general advice

Anything off topic gets one line back: Sorry, I can't help with that here.

Gmail: blocked by NeMo Guardrails
An off topic question and slice's one line refusal

09Uninstall and revoke

Remove the CLI and its saved key, then revoke the key on the server.

Terminal
$ pipx uninstall slice-gateway
$ rm -rf ~/.slice
  1. Revoke the key. In the dashboard, open Your slice key and click Create new key. That revokes every live key on the account, including the one from your machine. The new key is shown once. Close it without saving it, and nothing can use it.
  2. Unset the variables. Remove ANTHROPIC_BASE_URL, ANTHROPIC_API_KEY, and ANTHROPIC_AUTH_TOKEN from your shell, so your tools talk to Anthropic directly again.
  3. Stop AWS access. If you connected AWS, delete the slice-scanner-role stack in CloudFormation.
  4. Sign out. Click Log out in the dashboard header.

That is the whole setup.

Free and open source. Read the code, or run it on your own box.

github.com/jjk30/slice