---
title: "Antigravity MCP setup: add an MCP server"
description: "Add an MCP server to Google Antigravity: mcp_config.json with serverUrl, agy mcp add, why the token must be literal, and how to see it loaded."
canonical: "https://scalebrowser.net/docs/agents/mcp-clients/antigravity"
last_modified: "2026-09-22T18:16:38.000Z"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://scalebrowser.net/llms.txt
> Use this file to discover all available pages before exploring further.

# Antigravity MCP setup: add an MCP server

> Add an MCP server to Google Antigravity: mcp_config.json with serverUrl, agy mcp add, why the token must be literal, and how to see it loaded.

Antigravity keeps one MCP configuration for the IDE, the app and the CLI together. Its remote-server entry uses `serverUrl` rather than the `url` most other clients expect.

The worked example is Scalebrowser's own server, which gives the agent a real browser on your machine. Any other HTTP MCP server takes the same entry with its own address.

## Before you start

Everything below assumes a daemon that is already running and a token to reach it with.

<CardGroup columns={2}>
  <Card title="Windows desktop app">
    The app starts the daemon for you. The token is the contents of
    `%LOCALAPPDATA%\Scalebrowser\token`, and the address it is listening on is the
    `native_addr` field of `%LOCALAPPDATA%\Scalebrowser\runtime.json`. That is usually
    `127.0.0.1:8787`, but the app moves up a port when something else already holds it.
  </Card>
  <Card title="Self-hosted daemon">
    `scalebrowser-daemon --generate-token` prints a token and stores it under
    `<data_dir>/token`. The address is whatever `bind_addr` says, which is `127.0.0.1:8787`
    unless you changed it. See [Install & run](/docs/install#the-api-token).
  </Card>
</CardGroup>

<Warning>

**The token is a full-power credential.** It reaches every profile, every stored session
and the whole management API. Treat it like a password and keep it out of a repository.
Antigravity has no way to read it from the environment, so the file that holds it is the one
thing to protect.

</Warning>

## Add the server

`~/.gemini/config/mcp_config.json` is the file the IDE, the Antigravity app and the `agy` CLI all read.
A workspace can carry its own `.agents/mcp_config.json`, but the CLI has been reported to ignore it
(an open issue in September 2026), so the global file is the one that works everywhere.

```json ~/.gemini/config/mcp_config.json
{
  "mcpServers": {
    "scalebrowser": {
      "serverUrl": "http://127.0.0.1:8787/v1/mcp",
      "headers": {
        "Authorization": "Bearer <token>"
      }
    }
  }
}
```

<Warning>

**The token has to be written into the file.** Antigravity does not expand environment variables
in `mcp_config.json`: a header of `Bearer ${SCALEBROWSER_TOKEN}` is sent as exactly that text, and the
daemon answers `Unauthorized`. Keep this file out of any repository, and never put a token into the
workspace copy.

</Warning>

The CLI writes the same entry. Flags go before the name:

```bash
agy mcp add --header "Authorization: Bearer <token>" scalebrowser http://127.0.0.1:8787/v1/mcp
```

In the IDE you can reach the same file without leaving the editor: **…** at the top of the
agent panel → **MCP Servers** → **Manage MCP Servers** → **View raw config**. The MCP Store opens
from the same **MCP Servers** menu; a server you run yourself is added here, not there.

<Note>

**Write `serverUrl`.** Current builds also accept `url`, older ones read an entry with `url` as a
different shape and never load it. `serverUrl` works on every version, and it is what `agy mcp add`
writes.

</Note>

## Check that it loaded

- **CLI:** `agy mcp list` prints each server with its type and status. Inside a session, `/mcp` opens the manager with a status per server, a reload and the logs.
- **Antigravity app:** **Settings** → **Customizations** → **Installed MCP Servers**, with a toggle and a refresh per server.
- **IDE:** **MCP Servers** → **Manage MCP Servers** lists what loaded.

New MCP tools start on **Ask**, so the first call of each asks for permission. Antigravity speaks
stdio, Streamable HTTP and SSE.

## When it does not load

| Antigravity says | What to do |
| --- | --- |
| `Unauthorized` | The header did not carry the real token, most often because it was written as a variable. Put the token in literally. |
| `must have either command or serverUrl` | The entry uses a key this build does not know, such as `httpUrl`. Rename it to `serverUrl`. |
| `cannot have both command and serverUrl` | One entry mixes a local command with a remote address. Keep `serverUrl` only. |
| The server is missing from the list | It sits in the workspace file. Move it to `~/.gemini/config/mcp_config.json`. |

## What the agent can do now

Ask it to open a page and it will lease a profile, bind a tab and start reading. The tool
set, the page map and the failure shapes are on [MCP server](/docs/agents/mcp-server); what the
agent is **allowed** to do is decided by the daemon, not by the client, so see
[tool profiles](/docs/agents/mcp-server#the-tool-set).
