Developer Tools
12 MIN READ
2024-09-20

Antigravity Auth Vault (ag-auth): Multi-Account Switcher & Zero-Knowledge Vault for Google Antigravity

Stop hitting Claude Sonnet and Gemini Pro rate limits. Antigravity Auth Vault (ag-auth) solves AI quota exhaustion with instant 1-key account switching (<200ms), zero-knowledge AES-256-CBC token encryption, pooled team PostgreSQL sync, and pure Node.js 1-line execution.

AS
Sulaiman Hossain Sefat (Axo Solaman)Security Researcher • Software Engineer
Antigravity Auth Vault (ag-auth): Multi-Account Switcher & Zero-Knowledge Vault for Google Antigravity

The Dilemma: AI Quota Exhaustion & Account Juggling

Google Antigravity is one of the most capable agentic coding systems available today, offering native access to top-tier reasoning engines like Claude 3.5 Sonnet and Gemini Pro. However, any developer or engineering team pushing serious code quickly encounters two painful bottlenecks:

  1. Strict Rolling Quotas: Heavy coding sessions deplete weekly caps and 5-hour rolling limits within hours.
  2. The Friction of Multi-Account Management: Many developers, students, and teams maintain multiple accounts—such as GitHub Student Developer Packs, personal accounts, client profiles, and dedicated organizational seats. But toggling between them requires logging out of the browser, clearing session cookies, copying OAuth tokens manually, and re-linking IDE databases.

To eliminate this friction permanently, I architected and released Antigravity Auth Vault (ag-auth)—a high-performance, cross-platform session vault, instant account switcher, and encrypted team database synchronizer.


Key Architectural Highlights

1. Instant 1-Key Profile Switching (<200ms)

By executing the 1-character alias @, developers launch an interactive, arrow-navigable terminal UI that lists all stored accounts, active surface bindings, and real-time AI quota bars. Switching active profiles takes under 200 milliseconds without ever touching a browser.

$ @
Select Universal Antigravity Account (↑/↓ arrow keys, Enter to switch, 1-9 direct, q to cancel):
  ▶ [1] student-pack@university.edu  [Gem: 94.2% | Cld: 100.0%] [CURRENT ACTIVE] (CLI, IDE, App)
    [2] work-lead@company.com        [Gem: 88.5% | Cld: 100.0%]  (CLI, IDE, App)
    [3] team-ai-pool@gmail.com       [Gem: 76.1% | Cld:  63.4%]  (CLI)
    [4] sandbox-dev@gmail.com        [Gem: 99.0% | Cld: 100.0%]  (CLI)

2. Multi-Surface Atomic Synchronization

Unlike basic token scripts that only update CLI configuration, ag-auth atomically updates the state across all three Antigravity surfaces simultaneously:

  • Antigravity CLI (agy): Updates ~/.gemini/antigravity-cli/antigravity-oauth-token and system credentials.
  • Antigravity IDE: Atomically patches the SQLite ItemTable in Antigravity IDE/User/globalStorage/state.vscdb.
  • Antigravity 2.0 Desktop: Synchronizes session state in Antigravity/User/globalStorage/state.vscdb.

3. Zero-Knowledge AES-256-CBC Encryption

Security is paramount when handling authentication tokens:

  • All sensitive tokens and credentials are encrypted on the client side using AES-256-CBC with key derivation via PBKDF2 (100,000 iterations) and cryptographic salts.
  • Native integration with operating system keyrings: Apple Keychain (macOS), Secret Service / libsecret (Linux), and Windows Credential Manager (Windows).
  • Local vault files are locked down with strict 0600 file permissions.

4. Pooled Team Quotas & Cloud Sync

Engineering teams and student study groups can combine their accounts into a unified, encrypted quota pool. With a single command, connect ag-auth to any serverless PostgreSQL provider (Neon, Supabase, or private PostgreSQL):

ag-auth sync postgres://user:password@ep-cool-pool.neon.tech/neondb?sslmode=require

Every account is encrypted with a team passphrase before hitting the wire, ensuring that even the cloud database provider has zero visibility into plaintext tokens.


Instant 1-Line Execution

No manual NPM publishing or complex setup required. Run directly in any terminal:

npx github:axosecurity/antigravity-auth-vault

What This Does Automatically:

  1. Provisions the secure vault directory at ~/.antigravity-auth-vault.
  2. Links the ag-auth executable and the instant @ switcher to your user $PATH.
  3. Enables shell tab autocompletion across zsh, bash, fish, and PowerShell.
  4. Captures your current session and presents real-time capacity meters.

Command Cheat Sheet

Command Action
@ Launch interactive account picker with live quota meters
ag-auth switch <profile> Instantly switch active account across CLI, IDE, and 2.0 Desktop
ag-auth quota Query Google Cloud Code APIs for weekly & 5-hour quota percentages
ag-auth save <name> Save the current active session into the vault
ag-auth sync <url> Synchronize encrypted tokens with remote team PostgreSQL / Neon
ag-auth list List all configured profiles with storage metadata
ag-auth export / import Export or import encrypted backup bundles across machines

Open Source & Community

Antigravity Auth Vault is 100% open-source under the MIT license and built in pure modern Node.js (>= 14) with zero heavy binary dependencies. Check out the source code, contribute, or star the repository on GitHub:

👉 github.com/axosecurity/antigravity-auth-vault

#Antigravity#AIQuotas#AES256#ZeroKnowledge#PostgreSQL#CloudCode#MultiAccount#NodeJS