Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To connect an AI agent to a Google Cloud service with MCP, enable the service’s API, grant the agent identity both MCP-call permission and the permissions for the underlying task, then configure an MCP client with that service’s remote endpoint. Google hosts the server, but you still choose the project, identity, tools, and access controls. For BigQuery, the endpoint is https://bigquery.googleapis.com/mcp.

There is no single endpoint or universal setup for every Google Cloud product. Use Google’s supported products directory for the current endpoint, service-specific guide, and availability status.

What Google Cloud managed MCP servers do

Model Context Protocol (MCP) is an open protocol that lets AI applications connect to external tools and services. In this setup, the AI application is the host; an MCP client inside it communicates with a remote MCP server. Google Cloud managed remote MCP servers run on Google infrastructure and expose service-specific HTTP endpoints. That means you do not deploy the Google service’s MCP server on your own machine, but you remain responsible for client configuration, identity, project selection, and permissions. Google describes the arrangement as providing enterprise-ready governance, security, and access control through remote MCP servers in its MCP servers overview.

A local MCP server commonly runs on a user-controlled machine and communicates through stdio. A Google-managed server is remote and uses HTTP. Neither approach removes the need to evaluate what the AI host can access. Managed hosting shifts server operation to Google; it does not make tool calls anonymous or automatically authorize the agent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The overview lists Claude, VS Code, Gemini CLI, and Cursor as examples of AI hosts. The BigQuery guide also documents client options including Gemini CLI, ChatGPT, Claude, and custom applications. Client configuration formats change, so use the current instructions for both the selected client and service rather than copying a configuration intended for a different client.

How to find the right endpoint and check availability

Open the supported products directory and locate the Google Cloud service you intend to use. Each entry can point to its endpoint, MCP reference, setup guide, and release status. Some products have global and regional endpoints; some servers are Preview while others are generally available. Check the individual entry before configuring a client, especially if your workload has a regional or production requirement.

Examples in the directory include BigQuery at https://bigquery.googleapis.com/mcp, Cloud Run at https://run.googleapis.com/mcp, Cloud Storage at https://storage.googleapis.com/storage/mcp, and Cloud SQL at https://sqladmin.googleapis.com/mcp. These examples are not a substitute for checking the current directory and the product-specific reference.

Google’s release notes say Google and Google Cloud remote MCP servers reached general availability on May 1, 2026, while individual servers may still have their own Preview or GA status. The supported protocol version was updated to 2026-07-28 on September 14, 2026, and is backward compatible with 2025-11-25. These protocol and availability details are time-sensitive; consult the release notes and product directory for the latest position.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to set up the BigQuery MCP server

The BigQuery guide is a concrete example of the setup pattern. Use a dedicated agent identity where practical so its access can be separately controlled and monitored. The exact roles below apply to the documented BigQuery query workflow, not to every Google Cloud MCP server.

  1. Select a project. Choose an existing Google Cloud project the agent can access, or create one. The BigQuery guide says selecting an accessible existing project requires no special role; creating a project requires Project Creator.
  2. Enable BigQuery. Enable the BigQuery API for the project if it is not already enabled. The remote BigQuery MCP server is enabled when that API is enabled; new projects automatically enable the API according to the guide. Google’s release notes state that, beginning March 17, 2026, separate MCP-server enablement was no longer needed for supported products as the change rolled out across regions.
  3. Grant the agent identity the required roles. For the guide’s query example, grant roles/mcp.toolUser, roles/bigquery.jobUser, and roles/bigquery.dataViewer. The corresponding permissions called out include mcp.tools.call, bigquery.jobs.create, and bigquery.tables.getData. Other BigQuery tasks may require additional permissions. For details, see the BigQuery MCP guide and MCP roles and permissions.
  4. Authenticate. Configure the client to authenticate to Google Cloud with OAuth 2.0 and IAM using a supported Google Cloud identity. Authentication establishes who is calling; it does not grant that identity access to every tool or dataset.
  5. Add the remote server to the AI host. In the host’s MCP settings, add the BigQuery endpoint https://bigquery.googleapis.com/mcp and follow that client’s current BigQuery-specific instructions. The guide includes instructions for supported clients and custom applications; do not assume one client’s JSON or UI configuration applies to another.
  6. Discover and select tools. Use the client’s discovery flow (MCP includes methods such as tools/list) to see the tools this endpoint offers. Enable only the tools the agent needs. Some servers expose separate toolset endpoints so a client can avoid loading unnecessary tools into the agent’s context.
  7. Test the intended task. Run a limited query or other low-risk operation first. Confirm that the selected identity can call the tool and access the specific BigQuery resources involved before giving the agent broader work.

What permissions does a Google Cloud MCP server need?

The caller needs permission to invoke MCP tools and permission for the underlying Google Cloud operation. These are separate checks. Google’s IAM guide gives the example that an identity with mcp.tools.call but without bigquery.datasets.get cannot retrieve dataset metadata; conversely, data access without MCP-call permission is not enough to invoke the tool.

Do not copy the BigQuery roles to a different service without checking that service’s guide. Identify the tool’s actual operation, grant the least access needed for it, and test with the same identity the client will use. The managed endpoint does not bypass the service’s ordinary resource permissions.

Use IAM policies to limit calls

IAM allow and deny policies can control MCP use through documented service and tool attributes. Deny policies additionally support the OAuth client ID and whether a tool is read-only. There are important boundaries: these MCP attributes are enforced only for mcp.tools.call; OAuth client ID is deny-only; service and tool-name conditions must be managed with Google Cloud CLI; and MCP attributes cannot control access to the Resource Manager MCP server. The IAM control guide documents the supported conditions and limits. The release notes record that tool.name policy conditions were added July 2, 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Account for global server registration

Google’s Agent Registry documentation says official Google and Google Cloud remote MCP servers are automatically registered and ingested. When a supported product API is enabled, its corresponding server and tools are registered for discovery without manual tool-spec upload. These built-in servers are registered in the global location, so IAM bindings for them must use global scope (--region=global); regional bindings are unsupported for these global servers. See Register MCP servers before building registry or IAM automation around this behavior.

Security, governance, and diagnostics

Protect the tool boundary

Only agents, MCP clients, and end users with established identities can authenticate and use MCP tools, prompts, and resources, according to Google’s overview. Still, a valid identity can be over-privileged. Use a distinct agent identity where appropriate, narrow its IAM grants, and make tool availability match the task rather than granting broad access for convenience.

Some Google Cloud MCP servers support Model Armor scanning of calls and responses, but support is not universal. Check the endpoint’s documentation and configure the control where available instead of assuming scanning is automatically enabled. Google notes that Model Armor does not scan resource/read calls used to render MCP Apps; tool calls made through an MCP App are scanned if Model Armor is enabled.

Use Cloud Trace for eligible calls

Cloud Trace can help identify which servers and tools a project invokes, whether an agent selected an inappropriate tool or a tool failed, and whether latency arose in the client, network, or server. Support has limits: only tools/call operations generate spans, and calls rejected for authentication, authorization, API enablement, or other policy checks may not be eligible. Trace context must use W3C trace headers; X-Cloud-Trace-Context and other non-W3C headers are not supported. Confirm service eligibility and setup in Cloud Trace monitoring for MCP tool use.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to use a managed endpoint or run a server yourself

Consideration Google Cloud managed remote server Locally hosted MCP server
Infrastructure Hosted on Google infrastructure Hosted and operated by you
Connection pattern Remote HTTP endpoint Typically local stdio communication
Operations Google operates the managed service endpoint; you configure its client, identity, project, and permissions You operate deployment and scaling
Access controls Integrates with Google identity and IAM controls; exact capabilities vary by service Depends on the server and the controls you implement
Setup Requires the service-specific endpoint and client instructions Requires installing and configuring the server and its local client connection

Google’s documentation establishes these architectural differences, not a neutral latency or cost comparison. Choose based on operational ownership, deployment constraints, required controls, and whether the desired Google service has a supported endpoint in the maintained directory.

Troubleshooting common setup failures

  • The client cannot connect to the endpoint. Recheck the exact service endpoint in the live directory, client-specific remote-server instructions, and whether the product API is enabled in the intended project. Do not substitute a similarly named endpoint or assume a different region’s endpoint is interchangeable.
  • The server appears unavailable or a tool is missing. Check that the product is listed and review its Preview or GA status and service guide. Confirm that the relevant API is enabled, then refresh tool discovery. Server and tool availability can differ by product.
  • Authentication succeeds but an operation is denied. Verify both mcp.tools.call and the underlying resource permissions for the exact operation. For BigQuery queries, compare the identity’s roles with the documented query workflow; metadata access or other tasks can need different permissions.
  • An IAM condition appears ineffective. Check that the policy is controlling mcp.tools.call, that the attribute is supported for allow or deny policies as applicable, and that service/tool-name conditions were managed using Google Cloud CLI. Resource Manager MCP is excluded from MCP-attribute access control. For built-in registry servers, use global scope rather than a regional binding.
  • Trace shows no MCP span. Verify that the operation is tools/call, that the request includes a valid W3C trace header, and that it was not rejected before reaching an eligible call. Other operations and non-W3C trace headers do not generate the described MCP spans.
  • The agent invokes an unintended tool. Review the discovered tool list and expose only what the task requires. Where a server offers toolsets as separate endpoints, use the narrower toolset to reduce irrelevant choices.

Or skip the browser setup

If your task is capturing website screenshots rather than connecting an agent to Google Cloud services, ScreenshotNeo is a separate screenshot API and MCP server from Yorker Media. A single GET request returns an image or PDF; this cURL example saves a WebP screenshot of Stripe. See the ScreenshotNeo API documentation for request options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie and consent banners and removes 60+ known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses report page verdict and billing headers. Its MCP server gives AI agents tools including take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does Google Cloud MCP replace the Google Cloud APIs?

No. The managed MCP endpoint exposes tools for an AI client; the underlying Google Cloud service and its permissions still determine what operations and resources the identity can access.

Can I use one MCP endpoint for all Google Cloud services?

No. Each supported product has its own endpoint and service-specific setup. Use the maintained supported-products directory to find the correct one.

Do I need to run a local MCP server to use a Google-managed endpoint?

No. The managed server is remote and Google-hosted. You still need an MCP-capable host/client and a configured identity with appropriate access.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.