Updated 07:17
Agents as code, and the file that remembers which ones are yours
The interesting part is not the YAML but the lockfile, and the three ways the command refuses to run.
Anthropic's Claude Platform release notes for September 3 carry one entry, and it is a shape developers will recognize from Terraform: "Version 1.30.0 of the ant CLI adds ant apply, which creates and updates agents, environments, skills, memory stores, and deployments from files in your repository. Describe each resource in a file, run ant apply, and approve the plan it prints. Commit the claude-lock.json lockfile it writes so that later runs, on your machine or in CI, update the same resources instead of creating new ones."
The documentation page is where the behavior lives, and it is more specific than the announcement.
The plan is the product
A resource is a file whose contents are "the request body you would send to that kind's create endpoint." Agents and deployments are Markdown with YAML frontmatter, where "the frontmatter holds the agent's configuration ... and the body is its system prompt." Environments and memory stores are YAML. A skill is a directory with a SKILL.md at its root, uploaded as one bundle.
Files point at each other by relative path rather than ID: "Wherever the API expects another resource's ID, write the relative path to that resource's file instead." The command "creates them in dependency order and fills in the real IDs," and pins agent and skill references "to the version it just applied," so editing a reviewer agent updates the coordinator that lists it in the same run.
In a terminal the command prints a plan and waits. Answer d for a field-by-field diff; --dry-run prints the same and exits without touching anything.
What the lockfile records
The first run writes claude-lock.json in the current directory. Per resource it stores the kind, the ID, the version, and two hashes:
"./agents/summarizer.md": {
"kind": "agent",
"id": "agent_011CYm1BLqPXpQRk5khsSXrs",
"version": "1",
"hash": "d23251c8d99b3613a64f3f8d87f5fad4",
"remote_hash": "1b771bee5bdbf600a5ad972fdac32d94"
}
"The two hashes fingerprint what was last sent and what the API returned. That's how a later run notices an edited file, or a resource changed outside these files." The lockfile also records the organization and workspace, and that is enforced, not advisory: "ant apply refuses credentials that resolve to any other organization or workspace."
Three refusals
The documentation is unusually clear about failure modes, which is what makes the tool worth trusting.
- Drift. If a resource "was edited, archived, or deleted outside these files (in the Claude Console, for example), the plan ends with
This plan cannot be applied:and the reason. The command then exits withrefusing to apply." Only--forceoverrides it. - No adoption. "
ant applycan't adopt a resource you created in the Console or withant beta:agents create. Only what's in the lockfile is managed, and applying a file that describes an existing agent creates a second one." The escape hatch is the Console's Export as code, whose download "includes its ownclaude-lock.json." - No terminal. Without one, the command "prints the plan and stops with
cannot ask for confirmation without a terminal; re-run with --yes to apply, or --dry-run to see the plan only."
Deleting a file does not delete the resource; it "leaves its resource in place with a warning, and --prune removes it." Renaming a file "therefore declares a new resource and leaves the old one in place until you prune."
The CI trap in Anthropic's own example
The page's CI guidance says to name the directory: "Run ant apply --yes . on your default branch after merge, naming the project directory. A bare ant apply --yes reconciles only files the lockfile already tracks and skips a newly added one." It also says to commit the lockfile "even when the apply step failed partway, because a partial apply still records what it created," and to "Run one apply at a time, because nothing locks the lockfile."
The GitHub Actions workflow in the CLI README, which the docs page links as the complete example, runs the bare form:
- name: Apply
run: ant apply --yes
Read together with the docs, that workflow will apply edits to agents it already knows and silently skip a new file added in the same merge. The README's comment on its concurrency: ant-apply line does match the docs: "apply does not guard against concurrent runs itself." The README also authenticates with an OIDC token minted from GitHub rather than a stored key, which is the docs' recommendation as well.
Primary sources: Claude Platform release notes, September 3, 2026, Manage resources as code with ant apply, anthropic-cli README, read 2026-09-08.