Hi Antigravity team,
I’d like an official answer from a Google/Antigravity team member before I set this up, because account suspension is a real concern.
Setup:
- Paperclip (paperclip.ing) is an open-source (MIT), self-hosted agent orchestrator. It runs agents on schedules (“heartbeats”) and on task assignment.
- A Paperclip adapter would launch the official, unmodified `agy` binary as a local child process, using the documented headless mode (`-p` / `–output-format stream-json`), one or more processes at a time.
- Authentication is done once by the user through agy’s own interactive login. The adapter never reads, copies, stores or reuses OAuth tokens or cookies, never calls any Antigravity/Gemini backend endpoint directly, and does not modify or reimplement the client.
- Single user, single machine, my own personal Google AI Pro account. No resale, no sharing of the account, no quota circumvention.
- Runs may be unattended (scheduled), in isolated local workspaces.
What I read:
- Clause 6 of the Antigravity Additional Terms says using third-party software, tools or services to access the Service (e.g. OpenClaw with Antigravity OAuth) is a breach.
- The FAQ names Claude Code, OpenClaw and OpenCode with an Antigravity login as not allowed.
- The headless mode docs describe scripting agy, CI integration and driving a session programmatically over stdin/stdout with cached credentials.
- Some replies in other threads say launching the official CLI as a subprocess is fine, but I couldn’t confirm those come from Google staff, and none of them mention an orchestrator like this.
Questions:
- Does a local third-party orchestrator that only spawns the official `agy` binary in headless mode (no token access, no direct backend calls) count as “third-party software accessing the Service” under clause 6?
- Is scheduled/unattended use of headless agy, with several agy processes possibly running concurrently, within what a Google AI Pro subscription is meant to cover? Are there concurrency or automation limits that could trigger abuse detection even when usage stays inside the plan quota?
- Is there any difference in how this is treated depending on the tool that launches agy (a shell script or CI job vs. an agent orchestrator)?
A written confirmation from the team would really help me and other users who are trying to stay on the right side of the terms. Thanks!