Summary
On Windows, the Antigravity CLI collector fails with:
level=ERROR msg="Failed to fetch Antigravity quotas" source=cli error="antigravity cli: quota service did not become ready"
Cause
In internal/api/antigravity_cli.go:
- Line 264 notes
// No CSRF token is required for the CLI's server.
- On Windows,
agy.exe enforces CSRF validation on its Connect-RPC endpoint. Without a token, requests return HTTP 401:
{"code":"unauthenticated","message":"missing CSRF token"}
launch() does not supply --csrf_token <token> to agy.exe, and post() does not send the X-Codeium-Csrf-Token header, causing awaitReady() to time out after 90 seconds.
Proposed Fix
- In
launch(), generate a session token (e.g., uuid.New().String()) and pass --csrf_token <token> to agy.
- In
post(), add header req.Header.Set("X-Codeium-Csrf-Token", r.sess.csrfToken).
Validation
Tested against agy.exe on Windows 11. Supplying --csrf_token and the X-Codeium-Csrf-Token header returns HTTP 200 with all 4 quota pools and model limits. Omitting it reproduces the 401 unauthenticated response immediately.
Note
Drafted with AI assistance during homelab deployment troubleshooting and verified on a live Windows 11 environment.
Summary
On Windows, the Antigravity CLI collector fails with:
level=ERROR msg="Failed to fetch Antigravity quotas" source=cli error="antigravity cli: quota service did not become ready"Cause
In
internal/api/antigravity_cli.go:// No CSRF token is required for the CLI's server.agy.exeenforces CSRF validation on its Connect-RPC endpoint. Without a token, requests return HTTP 401:{"code":"unauthenticated","message":"missing CSRF token"}launch()does not supply--csrf_token <token>toagy.exe, andpost()does not send theX-Codeium-Csrf-Tokenheader, causingawaitReady()to time out after 90 seconds.Proposed Fix
launch(), generate a session token (e.g.,uuid.New().String()) and pass--csrf_token <token>toagy.post(), add headerreq.Header.Set("X-Codeium-Csrf-Token", r.sess.csrfToken).Validation
Tested against
agy.exeon Windows 11. Supplying--csrf_tokenand theX-Codeium-Csrf-Tokenheader returns HTTP 200 with all 4 quota pools and model limits. Omitting it reproduces the 401 unauthenticated response immediately.Note
Drafted with AI assistance during homelab deployment troubleshooting and verified on a live Windows 11 environment.