Setup
Antigravity CLI (agy) on a server
Google's Antigravity CLI replaced Gemini CLI for personal accounts. It installs as a single binary and signs in fine over SSH. On a headless box, though, it behaves differently from a laptop. This guide covers what to expect.
Quick answer
Install with curl -fsSL https://antigravity.google/cli/install.sh | bash, which puts agy in ~/.local/bin. Over SSH, agy detects the remote session and prints a sign-in URL. Open it on any device and paste the code back. For headless or CI use, skip Google sign-in: set "modelProvider": "gemini" in ~/.gemini/antigravity-cli/settings.json and export GEMINI_API_KEY. Your GEMINI.md files keep working unchanged.
Since 18 June 2026, Gemini CLI no longer serves free, Google AI Pro or Ultra personal accounts. Google's announcement points those users to the Antigravity CLI, agy. On a server, the parts that need care are signing in without a browser, choosing between Google sign-in and an API key, and knowing how agy handles permissions when nobody's at the terminal. Here they are in order.
Install agy
On Linux or macOS, as your normal (non-root) user:
curl -fsSL https://antigravity.google/cli/install.sh | bash
export PATH="$HOME/.local/bin:$PATH" # if ~/.local/bin isn't on PATH yet
command -v agy
The official install page says the binary goes to ~/.local/bin/agy and lists macOS, Linux and Windows. The installer fetches a per-platform build, with Linux builds for both amd64 and arm64, so an ARM VPS is fine. Add the PATH line to ~/.bashrc or ~/.profile so new shells and tmux windows pick it up.
One server-specific habit: agy updates itself in the background. That's convenient on a laptop. On a box you leave running, it means the version can change under a long session. Maude pins the version it installs and turns this off with AGY_CLI_DISABLE_AUTO_UPDATE=1. If you want the same predictability, export that variable in the shell or unit that starts agy.
SSH sign-in flow
Start agy in an SSH session and pick Google sign-in. On a laptop it would open a browser. Over SSH it detects the remote session and prints an authorisation URL instead. Then:
- Copy the URL and open it on your phone or laptop.
- Sign in with the Google account you use for Antigravity.
- Copy the code the page gives you and paste it back into the terminal.
Credentials are stored in the OS keyring, which on Linux is the Secret Service. A bare VPS has no desktop session to unlock a keyring. A GitHub issue filed against agy 1.0.0 reports a sign-in loop on headless Linux caused by exactly that, plus a timezone bug in the file fallback. The reporter's workaround was GEMINI_FORCE_FILE_STORAGE=true TZ=UTC agy …. We haven't confirmed whether current versions still need it. If agy asks you to sign in again on every launch, that issue is the first place to look. Otherwise, use API-key mode.
To sign out and purge the stored profile, run /logout inside agy.
API-key mode for headless
For CI, a shared box, or any server where you'd rather not keep a Google session, run agy on a Gemini API key. The install docs give two steps. First, set the model provider in ~/.gemini/antigravity-cli/settings.json. Merge it into the file if one already exists:
{
"modelProvider": "gemini"
}
Then make the key available to the process:
export GEMINI_API_KEY="…" # e.g. in ~/.profile, or an EnvironmentFile for a systemd unit
This skips account sign-in entirely. Usage is billed per token under Gemini API pricing instead of counting against a Google AI plan. Keep the key out of shell history and out of the repository the agent works in.
Permissions when nobody is watching
This is the server behaviour that surprises people most. In our testing on agy 1.2.14, headless runs (agy -p …, or stream-json mode) can't stop and ask before a tool runs. A command or file write that needs permission is denied, and the turn's result lists it as denied. You have three ways to let work through:
- Allow rules.
agyreads them frompermissions.allowin~/.gemini/antigravity-cli/settings.json. Entries look like"command(npm test)","write_file(src/app.ts)"or"command(*)". They're read at startup. - Modes.
--mode accept-editsauto-approves file edits, though commands are still denied.--mode planplans without acting. - No checks at all.
--dangerously-skip-permissions, for a throwaway box. See running agents with full permissions, safely before you reach for it.
Interactive agy in a terminal, and Remote Control (below), can pause and ask. So this limitation applies to scripted, headless use specifically.
Bringing your Gemini CLI config
The migration guide covers this. The short version for a server that already had Gemini CLI on it:
- First launch offers to migrate. If
agyfinds existing Gemini CLI configuration, it shows a checklist of extensions and global settings to convert. - Extensions become plugins. Run
agy plugin import geminiat any time to convert Gemini extensions to Antigravity plugins. - Context files work as they are.
GEMINI.md(workspace and~/.gemini/GEMINI.md) andAGENTS.mdare read with no changes. - MCP servers need a small edit. Global servers live in
~/.gemini/config/mcp_config.json, workspace ones in.agents/mcp_config.json. Rename the legacyurl/httpUrlkeys toserverUrl. - Skills move. Workspace skills go from
.gemini/skills/to.agents/skills/, and global ones to~/.gemini/antigravity-cli/skills/. You have to move these yourself.
Google says there isn't full feature parity yet, and the migration guide notes that some custom themes and visual tweaks don't carry over. If a workflow depends on a specific extension, test it after import before you delete the old setup.
Remote Control daemon vs Maude
Google ships an official way to reach agy from another device. According to the Remote Control docs, you can start it three ways:
/remote-controlinside a running session. The tunnel ends when that CLI session exits.agy --remote-controlwhen you launch a session. This tunnel also ends when the session exits.- The headless daemon:
agy remote-control start --name my-vps, withagy remote-control statusandagy remote-control stop. It registers an OS service that keeps running in the background.
You control it from a web dashboard in any browser, signed in with the same Google account. The docs say you can install the dashboard to your phone's home screen to get push notifications, and that you can answer permission prompts from either the terminal or the remote UI. They also say an account or organisation feature flag can block it.
| agy Remote Control | Maude | |
|---|---|---|
| Cost | Free with your Antigravity access | Paid app ($2.99/week (3-day trial) or $59.99/year (7-day trial)) |
| Client | Browser dashboard, installable as a web app | Native iOS, iPadOS and Android app |
| Agents | Antigravity only | Antigravity, Claude Code, Codex, OpenCode, Grok Build |
| Setup on the server | You install and sign in to agy, then start the daemon | The app deploys its daemon and a pinned agy over SSH |
| Permission prompts | Answered live, from terminal or dashboard | Shown after a denial: you approve and the action is retried |
| Sign-in | Your Google account | Google sign-in with a pasted code, or a Gemini API key, from the phone |
If Antigravity is the only agent you use and the feature flag is on for your account, the official daemon is the obvious first choice. It's free, and it can ask before acting.
Run it from your phone
If you want agy on a server alongside other agents and driven from a native app, Maude is one option. Add the server, and the app installs agy at a tested version and signs you in from the phone. You can use Google sign-in with a pasted code or a Gemini API key. To be upfront about Antigravity in Maude: because Maude drives headless agy, it can't stop and ask before a tool runs. Maude shows you the denied action, and if you approve, it adds an allow rule and retries. The Antigravity agent page has the details. The Gemini CLI change itself, and what other options people moved to, is covered in our Gemini CLI shutdown post.
Frequently asked questions
How do I log in to agy over SSH?
agy and choose Google sign-in. It detects the SSH session and prints an authorisation URL instead of opening a browser. Open the URL on any device, sign in, and paste the code it gives you back into the terminal.Does my GEMINI.md still work?
GEMINI.md (in the workspace and in ~/.gemini/) and AGENTS.md without changes. MCP server configs and skills do need moving; see the migration section above.Can I still use Gemini CLI with an API key?
What happened on June 18, 2026?
Why does headless agy deny commands instead of asking?
~/.gemini/antigravity-cli/settings.json, use --mode accept-edits for file edits, or run agy interactively or through Remote Control when you want it to ask.What changed
- — First published. Install, auth, migration and Remote Control details checked against antigravity.google docs; headless permission behaviour from our own testing on agy 1.2.14.