ACP and a one-shot CLI are compatible choices: acpx runs ACP agents headlessly, including one-prompt exec with JSON events. Native CLI paths are claude -p, gemini -p, codex exec, and opencode run. ACP adds sessions, progress, permissions, and cancellation; neither option wakes AX.
Ways to invoke an agent after wake-up
There are two decisions: how AX starts or resumes the sandbox, and how a process in that sandbox receives one prompt. ACP answers the second decision for coding agents; a native noninteractive CLI answers it for one agent. They can be combined.
| Invocation inside the sandbox | Ready implementation | Result and state |
|---|---|---|
| Native CLI | claude -p, gemini -p, codex exec, or opencode run |
Use each agent's JSON/JSONL mode, process exit, and its own resume/session options. Flags and event shapes differ. |
| ACP over local stdio | Start an ACP agent, negotiate initialize, create/load a session, send session/prompt, consume session/update and the final response, handle permissions and cancel. |
Common coding-agent interaction, but the client process and agent process must be started after wake-up. Loading a prior session is capability-dependent. |
| ACP through acpx | acpx --format json --cwd /workspace codex exec --file - (replace codex with another supported agent) |
A ready headless ACP client: temporary session, one prompt from stdin, raw ACP NDJSON stream. No custom ACP client is needed for this local invocation. |
Native examples: Claude Code headless, Gemini CLI headless, Codex exec, OpenCode CLI. In OpenCode, -p is a server password; its prompt command is opencode run.
The ACP v1 overview specifies prompt, updates, permissions, cancel, and optional session load. acpx CLI supports one-shot exec, named persisted sessions, JSON output, and permission policies. Pin versions: acpx is pre-1.0, and its Codex/Claude integrations launch separate ACP bridge packages. For a saved acpx session, both ~/.acpx state and the agent's own session files must survive AX suspend/resume; AX guarantees only its documented workspace snapshot. acpx may fall back to a new session when resume/load fails, so check continuity if the old context is essential.
The prompt should enter via stdin or a fetched payload identified by an invocation ID, rather than a full message in AX Task YAML or process arguments. This changes exposure of prompt content, not the agent's authority. Credentials supplied to the sandbox can still be read by the agent. Neither ACP authentication nor CLI invocation isolates such credentials. AX wake-up and release remain the outer controller's responsibility.