Antigravity CLI setup
Set up phone approvals for Antigravity CLI (agy) through its native hooks. Pushary becomes agy's only gate for shell commands, edits and MCP calls.
Antigravity CLI (agy) is the agent Google moved Google AI Pro, Ultra and free accounts to from Gemini CLI on 18 June 2026. Pushary gates it through agy's native hooks. Before agy runs a shell command, writes or edits a file, or calls an MCP tool, the call goes through your Pushary policy, and the risky ones wait for your answer on your phone.
Set it up
Install agy with Google's installer and start it once to sign in. Then run:
npx pushary@latest setupOn Windows PowerShell, run npx.cmd pushary@latest setup. The CLI needs Node.js 20.17+, 22.13+ or 23.5+.
Scan the QR code with your phone
Setup shows a QR code first. Scan it with your phone's camera or the Pushary app. Sign in or create an account, check that the code on your phone matches the one in your terminal, then tap Approve on Connect this computer? and allow notifications.
New accounts start a 3-day free trial, then pay $9.99 a month. A card is needed to start the trial. If this computer already has a Pushary key, setup reuses it and skips this step.
Pick Antigravity CLI
Setup asks Which agents do you use? with the agents it found already selected. Keep Antigravity CLI selected. To skip the question, run npx pushary@latest setup --agents antigravity_cli.
Answer the test question
Setup sends a test push, then a test question. Answer it on your phone. The terminal says You're set once your answer arrives.
Start a new agy session
agy loads hooks when a session starts. Run /hooks inside agy and check that pushary is listed.
On a Mac you can use Pushary Isle instead. Connecting your agents there wires agy the same way.
What setup changes on your computer
| File | What changes |
|---|---|
~/.gemini/config/hooks.json | Adds a hook named pushary for PreToolUse, PostToolUse and Stop. |
~/.gemini/config/mcp_config.json | Adds the Pushary MCP server (serverUrl, your key in an Authorization header). |
~/.gemini/antigravity-cli/settings.json | Sets "toolPermission": "always-proceed", only if you never chose a mode there. |
~/.pushary/setup/antigravity-tool-permission.json | A record of that change, so disconnecting can put your setting back. |
~/.pushary/config.json and your shell profile | Your API key, as PUSHARY_API_KEY. |
What each hook does
| Event | What happens |
|---|---|
PreToolUse | The approval gate. The kill switch and always-deny rules block here. Other gated calls go to your phone and run only if you approve. |
PostToolUse | Records tool_complete or tool_error for the session. |
Stop | Marks the session's turn finished in your session list. |
Pushary is agy's only gate
In its default mode, request-review, agy ignores a hook's allow and keeps its own review step, so an approval from your phone cannot let the call through. That is why connecting agy sets "toolPermission": "always-proceed". agy then asks nobody, and Pushary becomes the only gate. Plain agy works, with no flag.
Because agy has no prompt of its own in that mode, the CLI's hook asks your phone about every gated call, even while you sit at your computer. With the Mac app, the question can also show in the notch.
If you already chose a mode, such as strict, Pushary leaves it alone and tells you so. agy then still asks in its own prompt and ignores approvals from your phone. Set it to always-proceed, or start agy with --dangerously-skip-permissions, to hand the gate to Pushary.
| Your answer | What agy does |
|---|---|
| Approve | Runs the call. |
| Deny | Blocks the call. The model sees the reason. |
| No answer before your rule's wait ends | Blocks the call with a reason, unless your rule approves on timeout. |
Pushary answers agy only with allow or deny. In always-proceed mode agy runs a hook's "ask" without prompting, so a call that would go back to the terminal with another agent is blocked here instead. For the same reason, the pushary hook (1.9.14 or later) treats When I'm out like Every time for agy: your phone is asked about every gated call, even while you are at the keyboard, and it waits for your policy's timeout, not the short push window.
Check that it works
npx pushary@latest doctorDoctor checks your key and plan, then agy's hooks and MCP server. It sends a real test push. Add --roundtrip to send a test question too.
Then ask agy: Create a file called pushary-test.txt that says hello. Your phone buzzes with the write request. Tap Approve and the file appears.
What Pushary can and cannot enforce on agy
agy's tools have their own names, so Pushary maps them onto your existing rules:
| agy tool | Pushary rule |
|---|---|
run_command | Bash |
write_to_file | Write |
replace_file_content, multi_replace_file_content | Edit |
call_mcp_tool | mcp__<server>__<tool> |
A rule you set for Bash also gates run_command. Safe read-only commands such as ls run without a question.
- Blocks rather than guesses. A call Pushary cannot decide, because Pushary is offline, signed out or your subscription has ended, is blocked with a reason. While Pushary is offline, agy's shell commands, edits and MCP calls stop. Reading files still works.
- Leftover hook. If Pushary is removed without disconnecting agy first, its approval hook still runs and blocks each call with a message that says how to undo it.
- Not gated: file reads (
view_file) and web tools. - Kill switch: blocks every gated call, but cannot end the agy session itself.
- Shared file:
~/.gemini/config/hooks.jsonis shared with the Antigravity desktop app. Pushary is tested with the CLI.
Turn it off
npx pushary@latest disconnect antigravityThis removes the pushary hook and the Pushary MCP server, and puts toolPermission back if Pushary set it. Your other hooks, servers and settings stay as they are. Turning agy off in the Mac app does the same.
Troubleshooting
agy still asks in its own prompt
You chose a mode before Pushary connected, so Pushary left it alone. Change toolPermission to always-proceed with /config (or its alias /settings) inside agy, or start agy with --dangerously-skip-permissions. /permissions manages agy's allow, ask and deny rules, not this setting.
Every call is blocked
Pushary cannot decide the call. Run npx pushary@latest doctor to check your key and plan. If you removed Pushary, run npx pushary@latest disconnect antigravity to remove the leftover hook.
pushary is missing from /hooks
Start a new agy session. If it is still missing, run npx pushary@latest setup --agents antigravity_cli again.
Next steps
Set your approval rules
Choose which actions run on their own and which wait for you.
Antigravity CLI dangerously skip permissions
agy's flag, its toolPermission presets, and Gemini CLI's yolo mode.
Supported agents
Every agent Pushary gates, and how.