Is orchestrating the official agy CLI (headless mode) from Paperclip allowed on a personal Google AI Pro account?

Hi Antigravity team,

I’d like an official answer from a Google/Antigravity team member before I set this up, because account suspension is a real concern.

Setup:

  • Paperclip (paperclip.ing) is an open-source (MIT), self-hosted agent orchestrator. It runs agents on schedules (“heartbeats”) and on task assignment.
  • A Paperclip adapter would launch the official, unmodified `agy` binary as a local child process, using the documented headless mode (`-p` / `–output-format stream-json`), one or more processes at a time.
  • Authentication is done once by the user through agy’s own interactive login. The adapter never reads, copies, stores or reuses OAuth tokens or cookies, never calls any Antigravity/Gemini backend endpoint directly, and does not modify or reimplement the client.
  • Single user, single machine, my own personal Google AI Pro account. No resale, no sharing of the account, no quota circumvention.
  • Runs may be unattended (scheduled), in isolated local workspaces.

What I read:

  • Clause 6 of the Antigravity Additional Terms says using third-party software, tools or services to access the Service (e.g. OpenClaw with Antigravity OAuth) is a breach.
  • The FAQ names Claude Code, OpenClaw and OpenCode with an Antigravity login as not allowed.
  • The headless mode docs describe scripting agy, CI integration and driving a session programmatically over stdin/stdout with cached credentials.
  • Some replies in other threads say launching the official CLI as a subprocess is fine, but I couldn’t confirm those come from Google staff, and none of them mention an orchestrator like this.

Questions:

  1. Does a local third-party orchestrator that only spawns the official `agy` binary in headless mode (no token access, no direct backend calls) count as “third-party software accessing the Service” under clause 6?
  2. Is scheduled/unattended use of headless agy, with several agy processes possibly running concurrently, within what a Google AI Pro subscription is meant to cover? Are there concurrency or automation limits that could trigger abuse detection even when usage stays inside the plan quota?
  3. Is there any difference in how this is treated depending on the tool that launches agy (a shell script or CI job vs. an agent orchestrator)?

A written confirmation from the team would really help me and other users who are trying to stay on the right side of the terms. Thanks!

Hi @H0PE,

Thank you for reaching out regarding the Antigravity Terms of Service and official CLI headless mode capabilities. Below is the official guidance regarding orchestrating the `agy` CLI:

  • Spawning the official, unmodified `agy` binary in headless mode (`-p` / `–output-format stream-json`) as a local child process does **not** violate Clause 6 of the Antigravity Additional Terms, provided that:

    • The orchestrator executes only the official, unmodified `agy` binary.
    • The adapter/tool never reads, extracts, stores, or reuses OAuth tokens, cookies, or session credentials.
    • The tool does not intercept, modify, or reimplement direct Antigravity backend API endpoints.
      Clause 6 specifically prohibits third-party clients, wrappers, or tools that extract OAuth credentials or bypass/reimplement official Antigravity interfaces (such as OpenClaw, OpenCode, or Claude Code with Antigravity credentials; see FAQ | Google Antigravity Docs ).
  • Personal Google AI Pro subscriptions are scoped to individual human-driven developer usage. While headless scripting is supported:

    • Running multiple concurrent or rapid unattended `agy` processes on a single personal account will quickly hit rolling Token-Per-Minute (TPM) and Request-Per-Minute (RPM) limits (resulting in HTTP 429 quota errors).
    • Continuous unattended execution or rapid process bursts may trigger automated abuse-detection algorithms if traffic patterns resemble automated scraping or credential sharing.
    • For high-volume automated pipelines, multi-agent orchestrators, or continuous background tasks, please use Google AI Studio API keys (https://aistudio.google.com/) or Vertex AI rather than personal Google AI Pro subscriptions.
  • From a policy standpoint, there is no difference between invoking `agy` from a shell script, CI pipeline, or a local agent orchestrator (such as Paperclip), provided the tool strictly delegates execution and authentication to the unmodified official `agy` binary.