Markdown Edit

Google Antigravity

Google Antigravity is an AI-first software development platform and agentic coding environment comprising a desktop application, IDE extensions, and the agy command-line interface.

Permissions & Security Architecture

Antigravity operates a unified, fine-grained permissions engine formatted as action(target) (such as read_url(*), command(git), or write_file(src/)). Operations are evaluated across three priority tiers: Deny > Ask > Allow.

Configuration Scopes

When managing permissions (via the /permissions interactive TUI in agy or the settings panel), permissions are split into three distinct scopes:

  1. Project Scope: Rules that apply exclusively when operating within a specific project/repository.
  2. Shared Scope: Rules shared across all Antigravity surfaces on the machine (IDE, Desktop App, and CLI).
  3. Global Scope: Rules applied across all sessions for the agy CLI.

Storage Locations on Disk

Scope Location on Disk Description
Project Permissions ~/.gemini/config/projects/<project-uuid>.json Project-scoped permission grants and trusted settings, keyed to the local repository directory path.
Global CLI Settings ~/.gemini/antigravity-cli/settings.json User-level global settings and global permission grants.
Shared Antigravity Config ~/.gemini/config/ / ~/.gemini/antigravity/ Cross-surface preferences and shared state.

Repository-Level vs. Local Security Isolation

Project permissions cannot be defined or committed directly within the Git repository folder itself (such as a checked-in .antigravity/permissions.json).

This design is a deliberate security boundary:

Antigravity Java SDK

The Antigravity Java SDK (io.github.glaforge.antigravity:antigravity-sdk-wrapper) provides a programmatic Java interface over the local Antigravity localharness binary via gRPC and Protocol Buffers.

API Key Resolution (GEMINI_API_KEY)

When instantiating io.github.glaforge.antigravity.Agent, Agent.resolveGeminiApiKey() resolves the Gemini API key used for both the localharness child process environment and the gRPC GeminiAPIEndpoint configuration in the following order:

  1. Java system property System.getProperty("GEMINI_API_KEY")
  2. Process environment variable System.getenv("GEMINI_API_KEY")
  3. A .local.env file in the current working directory (GEMINI_API_KEY=...)

Passing GEMINI_API_KEY only via AgentConfig.builder().environmentVariables(Map.of("GEMINI_API_KEY", ...)) is not sufficient on its own, because resolveGeminiApiKey() does not inspect config.getEnvironmentVariables() when configuring GeminiAPIEndpoint (falling back to "placeholder"). When bridging from another environment variable (such as TEST_GEMINI_API_KEY), set System.setProperty("GEMINI_API_KEY", apiKey) before constructing new Agent(config).

Workspace & Project Context

Storage Isolation vs. Jetski UI

Conversations executed through antigravity-java-sdk do not appear in the local Jetski / Antigravity IDE UI because:

  1. Separate Process: Agent spawns an isolated, headless localharness Go binary (~/.antigravity/bin/<slice>/localharness) over an ephemeral localhost WebSocket port rather than connecting to the running IDE daemon.
  2. Separate Storage Directory (saveDir): AgentConfig.Builder defaults saveDir to ${java.io.tmpdir}/antigravity-java (e.g. /tmp/antigravity-java/<cascadeId>.db) and appDataDir to "", whereas the Jetski UI stores its state under ~/.gemini/jetski.

Conversation History & Streaming

While localharness persists multi-turn state on disk in <saveDir>/<cascadeId>.db (resumable via .conversationId(id)), neither localharness.proto nor Agent exposes a read-back API to list historical messages from a .db file after the fact. Instead, conversation history can be captured in real time during each turn via:

Antigravity Managed Agent (Gemini Interactions API)

In addition to local execution via localharness, the Antigravity Managed Agent (antigravity-preview-09-2026) can be invoked remotely through the Gemini Interactions API (com.google.genai.gaos.models.interactions.CreateAgentInteraction in com.google.genai:google-genai).

Remote Sandbox Environments & Sources

Managed agent interactions execute inside isolated, Google-hosted Linux sandboxes (Google Cloud Gemini Agent Environments):