Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Use a Google-managed MCP server by enabling the required Google API in a project, granting a least-privilege identity the MCP and service permissions it needs, adding the remote HTTP endpoint to your MCP client, and then narrowing and approving the tools the agent may call. Unlike a local MCP server that usually communicates over stdio on your computer, a managed server runs on Google infrastructure and is governed through IAM, centralized logging, and (for supported services) Model Armor.

What a Google-managed MCP server is

Model Context Protocol (MCP) standardizes how an AI host discovers and invokes tools, prompts, and resources. A Google-managed server exposes those MCP capabilities from a Google or Google Cloud endpoint over HTTP. Gemini CLI, Claude, VS Code and a custom MCP application can connect to that endpoint without installing the server implementation locally.

A local server normally starts as a process on your machine and speaks MCP over stdio. A managed server is hosted and patched by the service owner, so you trade local control for centralized identity, policy and operations. “Managed” does not mean the agent has unrestricted Google Cloud access: every call still runs with the permissions of the identity supplied by the client.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prerequisites and identity decisions

Choose a project and service

Decide which Google capability the workflow needs and select or create the Google Cloud project that will own the activity. Enable that service’s API first. Supported managed MCP endpoints become available only after the corresponding API is enabled.

#1 Best Overall
Sale
Philips 24 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 241V8LB
  • CRISP CLARITY: This 23.8″ Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
  • WORK SEAMLESSLY: This sleek monitor is virtually bezel-free on three sides, so the screen looks even bigger for the viewer. This minimalistic design also allows for seamless multi-monitor setups that enhance your workflow and boost productivity
  • A BETTER READING EXPERIENCE: For busy office workers, EasyRead mode provides a more paper-like experience for when viewing lengthy documents

Request the right IAM roles

Ask an administrator for the predefined MCP Tool User role when the service requires it, then add only the service-specific roles needed by your workflow. Read-only analysis, deployment, data export and destructive administration should not share one broad role.

Use a dedicated production identity

For production, create a separate workload or agent identity instead of using your personal identity. Google Cloud’s authentication guidance explicitly recommends a separate agent or workload identity for production workloads. This gives you cleaner audit attribution, safer rotation and a smaller blast radius. Service-account impersonation can provide short-lived credentials without distributing a key file.

End-to-end setup workflow

  1. Inventory the action. Write down the exact tools the agent must call, the project and regions involved, and whether each action is read-only or mutating.
  2. Enable the API. In the selected project, enable the Google service that publishes the MCP endpoint.
  3. Grant access. Assign the MCP Tool User role where required and the narrow service permissions for the planned operations.
  4. Prepare authentication. Choose user credentials for an interactive experiment, or ADC, workload identity, an agent identity or service-account impersonation for automation.
  5. Add the remote endpoint. Configure the URL in the MCP client. Remote servers use an HTTP or Streamable HTTP/SSE transport; a local server generally uses a command that starts a stdio process.
  6. Discover and restrict tools. Call MCP discovery methods, select a toolset or allowlist, and exclude everything the workflow does not need.
  7. Test with confirmation enabled. Run a harmless read operation first. Keep approval prompts on until the identity, project and arguments are verified.
  8. Operate and review. Inspect audit logs and IAM activity, refresh or rotate credentials, and re-check behavior after client or protocol updates.

Connect one from Gemini CLI

Gemini CLI stores MCP configuration in settings.json. The exact file can be user-level or project-level according to your CLI installation, but the structure is the same. A remote entry can use url or httpUrl; a local entry normally uses command.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
{
  "mcpServers": {
    "google-cloud-server": {
      "httpUrl": "https://example.googleapis.com/mcp",
      "authProviderType": "google_credentials",
      "oauth": {
        "scopes": ["https://www.googleapis.com/auth/cloud-platform"]
      }
    }
  }
}

Replace the example host with the endpoint for the Google service you enabled. Keep secrets out of this file. Gemini CLI can expand environment variables at runtime, discover OAuth metadata when the server publishes it, and store acquired tokens in ~/.gemini/mcp-oauth-tokens.json. When a refresh token is available, the CLI can refresh access automatically. It can also use Google Application Default Credentials (ADC) and impersonate a service account for an IAP-protected service.

First connection checklist

  • Authenticate with the same account or workload identity that received the IAM roles.
  • Confirm that the endpoint’s audience, host and transport match what the service documents.
  • Approve the OAuth scopes requested by the endpoint; do not grant unrelated scopes.
  • Invoke a read-only tool and verify the returned project and region before attempting a write.

Authentication: which credential fits?

User credentials

User OAuth is convenient for an interactive developer session. It is also the easiest way to accidentally make production actions appear to come from one person. Use it for local exploration, not unattended jobs.

ADC and workload or agent identity

ADC lets Google client libraries and compatible MCP clients obtain credentials from the standard environment. In deployment, bind the workload or agent identity to the runtime and grant only the required IAM roles. This avoids embedding a long-lived personal token.

Rank #2
Philips 22 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 221V8LB
  • CRISP CLARITY: This 22 inch class (21.5″ viewable) Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • 100HZ FAST REFRESH RATE: 100Hz brings your favorite movies and video games to life. Stream, binge, and play effortlessly
  • SMOOTH ACTION WITH ADAPTIVE-SYNC: Adaptive-Sync technology ensures fluid action sequences and rapid response time. Every frame will be rendered smoothly with crystal clarity and without stutter
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors

Service-account impersonation

Impersonation lets a caller obtain temporary credentials for a narrowly permissioned service account. Grant the caller permission to impersonate that account, then audit both the initiating principal and the impersonated identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OAuth client IDs and authorization headers

Some clients use an OAuth client ID and negotiated authorization metadata; others accept an authorization header supplied by the host. Follow the endpoint’s documented flow rather than assuming that every MCP server accepts the same header or scope.

API keys are not a universal fallback

IAM-backed Google services do not accept standard API keys for MCP access. Google Maps is an example of a non-IAM service that can accept an API key, but that exception should not be generalized to Google Cloud MCP endpoints.

Use the Google Cloud CLI remote MCP server

The Cloud CLI remote MCP server is a Preview feature under the Pre-GA terms. It is exposed at https://cloudcli.googleapis.com/mcp over Streamable HTTP and authenticates with OAuth 2.0 and IAM. API-key authentication is rejected.

Configure that endpoint in an MCP client using the same remote-server pattern shown above, then authenticate with a Google identity that has Cloud CLI Execution API and command-specific permissions. The server publishes two principal tools:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • run_gcloud_command
  • run_bq_command

Only a documented subset of gcloud and bq operations is supported, and the list can change while the feature is in Preview. Commands such as gcloud auth, gcloud config, gcloud iam service-accounts and gcloud init are examples of unsupported operations. Ask the server to perform a supported read operation before building an automation around it.

Rank #3
Sale
Dell 24 Monitor - SE2426H - 23.8-inch FHD (1920x1080) 144Hz 1ms Display, in-Plane Switching (IPS) Technology, AMD FreeSync™, TÜV 3-Star 2X HDMI, Tilt
  • Clear visuals. Fluid motion: A 144Hz refresh rate and 1ms MPRT deliver smooth, tear‑free motion across work, gaming, and streaming for clearer, more fluid viewing.
  • Eye comfort: TÜV Rheinland 3‑star* certification reduces harmful blue light while preserving stunning color quality without compromise. *TÜV Rheinland 3-star eye comfort certification.
  • Wide viewing angle: Get consistent views across a wide 178° /178° viewing angle.
  • In-Plane Switching (IPS): See excellent color accuracy and consistency across wide viewing angles with In-plane Switching (IPS) technology.
  • Ultra-thin bezels: Maximize your viewing experience with thin bezels.

Do not confuse the two project parameters

The request’s project parameter selects the project used for Cloud CLI Execution. A project flag inside the command, such as a flag passed to gcloud or bq, can target a different resource project. Set and audit both deliberately; one does not override the other.

Discover tools, then reduce the surface

MCP discovery methods include tools/list, prompts/list and resources/list. Discovery tells you what the server currently publishes; it is not a security grant by itself. Use a toolset to load a smaller logical group of tools into the agent’s context instead of exposing an entire server. If your client supports allow and exclude policies, allow only the named tools required for the task.

Keep the initial context small for two reasons: the model has fewer opportunities to choose an irrelevant or dangerous tool, and the request carries less schema overhead. Re-run discovery after a service update because a managed endpoint can add, remove or change tools independently of your client release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Execution controls and security

Require confirmation for consequential calls

Leave client confirmation enabled for deletion, IAM changes, externally visible messages, deployments and data export. A useful pattern is automatic approval for idempotent reads and explicit approval for every mutating operation.

Apply least privilege twice

IAM limits what the identity can do on Google Cloud. The MCP client’s allowlist limits what the model can ask for. Use both controls; an allowlist is not a substitute for IAM, and IAM alone still leaves the model a large tool surface.

Use Model Armor where supported

Model Armor can scan MCP requests and responses to help mitigate prompt injection, sensitive-data disclosure and tool-poisoning risks. Support is service-dependent. For MCP Apps, server-published interactive resources render in a sandboxed iframe, but resource/read content used to render an app is not scanned by Model Armor; tool calls made through the app are scanned when Model Armor is enabled.

Rank #4
Samsung 27" Essential S3 (S36GD) Series FHD 1800R Curved Computer Monitor
  • CURVED FOR ENHANCED ENGAGEMENT: An immersive viewing experience with a curved monitor that wraps more closely around your field of vision; It creates a wider view, enhancing depth perception and minimizing peripheral distraction
  • SMOOTH PERFORMANCE FOR SEAMLESS CONTENT: Stay in the action when playing games, watching videos, or working on creative projects; The 100Hz refresh rate reduces lag and motion blur so you don't miss a thing in fast-paced moments¹
  • MORE GAMING POWER: Gain the edge with optimizable game settings; Color and image contrast can be adjusted to see scenes more vividly and spot enemies hiding in the dark; Game Mode adjusts any game to fill the screen so you can view every detail²
  • KEEP IT EASY ON THE EYES: Care for your eyes and stay comfortable, even during long sessions; Advanced eye comfort technology certified by TÜV reduces eye strain by minimizing blue light and reducing irritating screen flicker²
  • INCREASED VERSATILITY: Connect to more; Plug devices straight into your monitor for increased flexibility, making your computing environment even more convenient

Audit and rotate

Review Cloud audit logs and IAM activity for the agent identity, watch for unexpected projects or methods, and rotate or refresh credentials on a schedule. Never place a service-account key or refresh token in source control, a shared settings file or an MCP prompt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Managed versus local MCP servers

Concern Google-managed server Local or third-party server
Hosting and transport Runs on Google infrastructure and is reached remotely over HTTP, SSE or Streamable HTTP as supported. Usually runs on your machine over stdio; a third party may host it over its own transport.
Identity Google user, workload or agent identity, ADC, OAuth or impersonation, with IAM enforcement. Whatever credential and authorization model the server implements.
Tool governance Toolsets, discovery, client allowlists and Google administrative controls. Depends on the server and client; governance is often your responsibility.
Scanning Model Armor is available for supported services. No equivalent is established here; you must evaluate the provider’s controls.
Auditability Central Google audit and IAM activity records. Local logs or provider-specific telemetry.
Operations Less local installation and patching; endpoint behavior can change with the managed service. More customization and offline control; you own updates, availability and dependency maintenance.
Performance No general performance advantage is established; network latency and service load still matter. Local calls may avoid a network hop, but remote dependencies can still be involved.

Reliability, cost and lifecycle notes

A remote MCP call depends on DNS, TLS, OAuth, IAM, the MCP endpoint and the underlying Google service. Add timeouts, retries with exponential backoff for transient failures, and idempotency checks before retrying a mutating operation. Cache safe discovery results briefly, but do not assume that a tool schema or permission remains unchanged.

Google’s managed-MCP material does not establish a universal latency, uptime or price benchmark. Budget for the underlying Google service and any Cloud CLI Execution charges that apply to your project, then verify current service terms before committing to a workload. Preview behavior and supported commands can change without the stability guarantees you might expect from a generally available API.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common failures

Symptom Likely cause Fix
Endpoint is unreachable Wrong host, transport, firewall or disabled API. Confirm the exact endpoint, use the transport it advertises, enable the service API and test connectivity from the machine running the client.
401 or OAuth loop Expired token, missing refresh token, wrong OAuth scope or clock problem. Sign in again, remove the stale token from ~/.gemini/mcp-oauth-tokens.json, request the documented scope and retry.
403 permission denied MCP Tool User role or service-specific IAM permission is missing, or the request targets another project. Check the principal actually used by the client, grant the narrow missing role and verify both the execution project and resource project.
API key rejected The endpoint is IAM-backed. Use OAuth, ADC, workload identity or impersonation. Do not replace IAM credentials with an API key.
Tool does not appear The API is disabled, the tool is outside the selected toolset, or the server changed its schema. Run tools/list, enable the API, select the correct toolset and refresh the client configuration.
Cloud CLI command rejected The command is outside the Preview server’s supported allowlist. Check the current supported-command list and rewrite the task using a supported gcloud or bq operation. Authentication, configuration and initialization commands are not accepted.
Unexpected destructive action Broad IAM permissions or an unrestricted client policy. Separate read and write identities, tighten the allowlist, and require interactive confirmation for mutating tools.

FAQ

Can a Google-managed MCP server run arbitrary shell commands?

No. An MCP server exposes the tools its service publishes. The Cloud CLI server, for example, accepts only a changing subset of supported gcloud and bq operations rather than an unrestricted shell.

Does remote hosting make an MCP server automatically safer?

No. Managed hosting supplies IAM, centralized governance and optional Model Armor, but the client still inherits the supplied identity’s permissions. Safety depends on least privilege, tool restrictions and confirmation policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I use the same configuration for every MCP client?

The MCP concepts are portable, but configuration keys, OAuth handling and policy controls differ by client. Verify whether your host expects url, httpUrl, SSE or Streamable HTTP and how it loads credentials.

Best Value
Sale
Sceptre New 22-Inch Gaming Monitor, FHD 1080p, Up to 144Hz, HDMI, DisplayPort, Built-in Speakers, Machine Black (E225W-FW144 Series, 2026)
  • 【INTEGRATED SPEAKERS】Whether you're at work or in the midst of an intense gaming session, our built-in speakers provide rich and seamless audio, all while keeping your desk clutter-free.
  • 【EASY ON THE EYES】 Protect your eyes and enhance your comfort with Blue-Light Shift technology. This feature reduces harmful blue light emissions from your screen, helping to alleviate eye strain during long hours of use and promoting healthier viewing habits.
  • 【WIDEN YOUR PERSPECTIVE】Our sleek minimal bezel design ensures undivided attention. The nearly bezel-free display seamlessly connects in a dual monitor arrangement, delivering an unobstructed view that lets you focus on more at once, completely distraction-free.

Or skip the browser setup

If your workflow also needs reliable website screenshots for documentation, tests or agent context, ScreenshotNeo is a direct HTTP alternative to maintaining a headless-browser capture service. It accepts consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture; each cleanup step can be disabled.

Only clean shots are billed. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and response headers report the page verdict and whether the request was billed. ScreenshotNeo also provides an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

One request is enough:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for all 63 options, including full-page lazy-image loading, CSS-selector element capture, dark mode, device presets, retina scale, PDF paper and page-range controls, custom JavaScript and CSS, click and wait conditions, request blocking, headers and cookies, timezone and geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture and usage reporting. The API accepts the parameter names used by other screenshot services, which can simplify migration.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ScreenshotNeo’s Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan. Create a free ScreenshotNeo account and try the endpoint without adding a card.

Frequently Asked Questions

What should I log for each MCP tool call?

Record the initiating principal, impersonated identity when applicable, project, tool name, approval decision and result status so an incident reviewer can reconstruct the action.

How should I handle a managed endpoint schema change?

Pin client versions where practical, run discovery in a staging project, compare tool schemas and permissions, then re-approve your allowlist before production rollout.

Is the Cloud CLI MCP server suitable for production automation today?

It is documented as a Preview feature under Pre-GA terms, with a limited command set that may change; evaluate that status and the current supported-command list before relying on it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.