Google reshuffled its terminal agents during 2026: Antigravity CLI took over on individual plans, while enterprise Code Assist runs on its own timeline. Treat exact dates and plan eligibility as vendor-announcement territory—third-party write-ups disagree with each other. What has not changed for restricted networks: the OAuth callback and a terminal that never used your proxy remain the top two failure modes.
Siblings: Gemini access, Claude Code proxy, Codex CLI proxy, Tun for AI tools.
Why migration breaks proxy setups
A generational change is exactly when proxy configs rot. The new CLI may carry a different binary name, a different config directory, and a different way extensions or MCP servers register—so the env vars or Tun rules you tuned for the old tool may not apply. Do not assume the old notes still match; verify the new tool's actual behaviour, following current official docs rather than screenshots from someone else's plan.
Check three things before migrating
- Account and plan. Individual account or enterprise Code Assist? Available tooling and quota differ; do not copy someone else's screenshots.
- Command name and config paths. A generational change can move the binary name, config directory, and how extensions or MCP servers register. Follow current official docs, not your old notes.
- Leftovers. Cached credentials and stale environment variables from the previous CLI can poison sign-in. When migration misbehaves, retry in a clean shell.
Two proxy styles—pick one, never both
| Style | Fits | Watch out |
|---|---|---|
| Tun mode | You hate per-shell variables; the tool ignores system proxy | Needs service mode/admin rights—see Tun start failures |
| Environment variables | Corporate machines that forbid virtual adapters | Applies to the current shell only; new windows need it again |
While debugging, keep exactly one active. Run both and a failure tells you nothing about which layer broke. Read the mixed port off the UI instead of copying numbers from articles (mixed port).
Sign-in: loopback must bypass
The usual flow is: CLI opens a browser, you authorize, the browser posts the result back to a temporary port on your machine. Export HTTP_PROXY/HTTPS_PROXY without NO_PROXY and that callback goes to the proxy instead—so the web page says success while the terminal waits forever.
Fix: add 127.0.0.1,localhost to NO_PROXY before signing in, or sign in under Tun. On headless machines, use the device-code / paste-the-code flow rather than waiting for a browser that will never appear.
Before trusting the sign-in, confirm egress independently. This should return a status line through the proxy—if it cannot, no login flow will either:
curl -sI -x http://127.0.0.1:7897 https://generativelanguage.googleapis.com | grep -iE "^HTTP|cf-ray"
Symptom routing
| Symptom | Check first | Next |
|---|---|---|
| Timeouts, no response | Outbound entries in the connections view | None means the terminal never used the proxy; enable Tun or set vars in a new shell |
| Browser succeeded, terminal frozen | Does NO_PROXY cover loopback? | Add it, or switch to device-code sign-in |
| Region/country unsupported | Exit node and account region | Pick a cleaner node via latency testing; stop retrying |
| 429 / quota | Plan and daily allowance | Account-side; unrelated to the proxy |
| Chat works, tool calls fail | How extensions or MCP connect | Remote MCP is network-bound—see MCP connection troubleshooting |
Day one after migrating
Do not open with a half-repo refactor. Run a read-only task from the repo root to confirm it actually sees your project, then a small verifiable change—edit one function, run a test you know. That rhythm keeps network, permission, and model problems separable, exactly as with Claude Code and Codex CLI.
Running several agents at once is now normal. Sharing one Clash Verge is fine, but verify separately: today you test Antigravity, so send only its minimal request. To manage several upstreams and quotas centrally, see 9Router.
Acceptance checklist
- Clash Verge on a working node; a foreign site opens.
- Fresh shell; exactly one proxy style enabled.
- Sign-in completes with loopback bypassed.
- A read-only task runs inside the repo.
- Outbound entries show up in the connections view—the only hard proof.
Client: download center. Variable details: PowerShell / Git / npm proxy. WSL2: WSL2 proxy.