Integrate IaC Code via ACP
The Agent Client Protocol (ACP) is suitable for IDEs, editors, and custom agent clients. It provides structured sessions, streaming text, and tool events, and allows clients to respond to permission requests initiated by IaC Code. This document covers transport selection, minimal clients, and session lifecycle.
Prerequisites
IaC Code is installed and configured. For more information, see Install and configure IaC Code.
Determine the absolute project path that the client allows IaC Code to operate on.
If you use HTTP + SSE, prepare service authentication and network access control.
Choose a transport
Transport | Startup command | Scenarios |
Stdio, default |
| Local IDE integration, in which the client starts and manages the IaC Code child process on the local machine. |
HTTP+SSE |
| Standalone deployment, multiple clients, or network connectivity. |
ULocal IDE integrations should prefer Stdio to avoid exposing extra ports. ACP-compatible clients can use the following process configuration:
{
"agent_servers": {
"iac-code": {
"type": "custom",
"command": "iac-code",
"args": ["acp"]
}
}
}Minimal Stdio client
The base package already includes the ACP runtime dependencies. The following Python example completes protocol initialization, creates a session, sends a prompt, receives streaming text, and closes the session:
import asyncio
from pathlib import Path
from typing import Any
import acp
import acp.schema
class IaCCodeClient(acp.Client):
async def session_update(
self, session_id: str, update: Any, **kwargs: Any
) -> None:
if isinstance(update, acp.schema.AgentMessageChunk):
print(update.content.text, end="", flush=True)
async def request_permission(
self, options: Any, session_id: str, tool_call: Any, **kwargs: Any
) -> acp.RequestPermissionResponse:
# This minimal example denies by default. A production client must show the
# operation and let the user decide.
return acp.RequestPermissionResponse(
outcome=acp.schema.DeniedOutcome(outcome="cancelled")
)
async def main() -> None:
async with acp.spawn_agent_process(
IaCCodeClient(), "iac-code", "acp"
) as (connection, _):
initialized = await connection.initialize(
protocol_version=1,
client_info=acp.schema.Implementation(
name="iac-code-demo", version="1.0"
),
)
print(f"ACP version: {initialized.protocol_version}")
session = await connection.new_session(cwd=str(Path.cwd()))
result = await connection.prompt(
session_id=session.session_id,
prompt=[
acp.schema.TextContentBlock(
type="text",
text="Check the ROS templates in the current directory. Return suggestions only and do not modify files.",
)
],
)
print(f"\nstop_reason={result.stop_reason}")
await connection.close_session(session_id=session.session_id)
asyncio.run(main())Expected output: The client first prints the protocol version, then prints the reply incrementally, and finally prints the stop reason. Beyond text, session_update can also handle events such as thoughts, tool calling, and tool progress.
Handle permissions and sessions
new_session(cwd=...)binds the session to a project directory. Use an absolute path and limit the root directories that the client can select.The client should show the user the tools, parameters, and impact in the permission request, then return one of the following: allow once, allow always, or deny.
Do not default-approve all file access, commands, and cloud write operations in examples or production clients.
After a prompt finishes,
prompt()returns a stop reason. Streaming content arrives throughsession_update.Call
close_sessionas soon as a session is no longer used, and close the Stdio child process or the HTTP connection when the client exits.
Use HTTP+SSE
Start the service:
iac-code acp --transport http --host 127.0.0.1 --port 8765Check the health status:
curl http://127.0.0.1:8765/healthFor cross-host access, set IACCODE_ACP_HTTP_TOKEN using a Secret in the deployment environment. The client should send a matching Authorization: Bearer <token> header with each request. For the full flow of connection IDs, JSON-RPC requests, and SSE events, see the ACP HTTP+SSE transport documentation.
FAQ
Stdio disconnects immediately after connecting
Run iac-code acp directly to check for startup errors, and then verify the client command, environment variables, and working directory. The standard output of Stdio carries protocol frames, so neither the client nor the startup script can write regular logs to it.
Tool operations are not run
Confirm that the client implements request_permission and returns the protocol-supported allow or deny result. IaC Code will not bypass tool permissions just because ACP is being used.
HTTP requests return 401
Make sure that the server sets the expected IACCODE_ACP_HTTP_TOKEN, that the client uses the same Secret, and that no proxy removes the Authorization request header.