diff --git a/reference/mcp-server/clients/antigravity.mdx b/reference/mcp-server/clients/antigravity.mdx index 5bf0a94..e534e77 100644 --- a/reference/mcp-server/clients/antigravity.mdx +++ b/reference/mcp-server/clients/antigravity.mdx @@ -3,11 +3,9 @@ title: "Google Antigravity" description: "Connect Google Antigravity to the Kernel MCP server" --- - -Antigravity can complete the OAuth flow and still send `initialize` without the bearer token attached, which comes back as `401 Unauthorized` ([antigravity-cli#25](https://github.com/google-antigravity/antigravity-cli/issues/25)). - -If you hit that, [connect with an API key](#connect-with-an-api-key-workaround) instead of OAuth. - + +Kernel connects to Antigravity over stdio through `mcp-remote` rather than as a remote `serverUrl` server. Antigravity's remote-server client can complete the OAuth flow and still send `initialize` without the bearer token attached, which comes back as `401 Unauthorized` ([antigravity-cli#25](https://github.com/google-antigravity/antigravity-cli/issues/25)). `mcp-remote` runs the OAuth flow itself, so the token does not depend on that client. + ## Install with the Kernel CLI @@ -25,35 +23,60 @@ Alternatively, open the agent side panel, click the ellipsis (**…**) menu, and { "mcpServers": { "kernel": { - "serverUrl": "https://mcp.onkernel.com/mcp" + "command": "npx", + "args": [ + "-y", + "mcp-remote", + "https://mcp.onkernel.com/mcp", + "--static-oauth-client-metadata", + "{\"client_name\":\"Antigravity\"}" + ] } } } ``` -Antigravity uses `serverUrl` for remote servers; `url` and `httpUrl` are ignored. Reload the window to pick up the change. +If the entry previously used `serverUrl`, remove that key. Reload the window to pick up the change. + +`--static-oauth-client-metadata` names the OAuth client. Without it, `mcp-remote` registers as **MCP CLI Proxy** and the Kernel consent screen asks you to trust that name instead of Antigravity. ## Connect -Press **⌘/Ctrl ,** to open agent settings, go to the **Customizations** tab, and click **Authenticate** next to **kernel**. +Go to **Settings → Customizations**, scroll to **Installed MCP Servers**, and click the reload button. + +`mcp-remote` opens a browser window for you to authorize access. Once it completes, Kernel shows as connected in the **Installed MCP Servers** list. Tokens are cached under `~/.mcp-auth` and refreshed for you. + +## Connect with an API key -Authorize access in the browser window that opens, then copy the authorization code, paste it back into the settings panel, and click **Submit**. Antigravity stores the tokens in `~/.gemini/antigravity/mcp_oauth_tokens.json` and refreshes them for you. +For headless or scripted use, where no browser is available to complete the OAuth flow, authenticate with a project-scoped Kernel API key from the [Kernel Dashboard](https://dashboard.onkernel.com/api-keys) instead. `kernel mcp install --target antigravity` always writes the OAuth config, so wire this up by hand. -## Connect with an API key (workaround) +Put the key in a header file that only you can read: -Get a project-scoped Kernel API key from the [Kernel Dashboard](https://dashboard.onkernel.com/api-keys) and pass it as a header instead of authenticating. `kernel mcp install --target antigravity` always writes the OAuth config, so add the `headers` block by hand: +```bash +mkdir -p ~/.kernel +install -m 600 /dev/null ~/.kernel/mcp-headers.txt +echo "Authorization: Bearer YOUR_KERNEL_API_KEY" > ~/.kernel/mcp-headers.txt +``` + +Then point `mcp-remote` at it: ```json { "mcpServers": { "kernel": { - "serverUrl": "https://mcp.onkernel.com/mcp", - "headers": { - "Authorization": "Bearer YOUR_KERNEL_API_KEY" - } + "command": "npx", + "args": [ + "-y", + "mcp-remote", + "https://mcp.onkernel.com/mcp", + "--header-file", + "/Users/you/.kernel/mcp-headers.txt" + ] } } } ``` -Leave the **Authenticate** button alone when using this — Antigravity sends the header on every request, including `initialize`. +Use an absolute path. `mcp-remote` opens the file directly, so a leading `~` isn't expanded and a relative path resolves against whatever directory Antigravity launched it from. + +`--header Authorization:...` takes the value inline instead, but the key then sits in the process arguments, where any other account on the machine can read it from the process list.