Google-hosted Model Context Protocol (MCP) servers let an MCP-compatible AI application call selected Google or Google Cloud services over a remote HTTP connection. To use one safely, choose the exact Google service and endpoint, enable any required API, authenticate with an identity that has the right permissions, and configure your host with the server’s transport and credentials. Google-managed remote servers are different from local MCP programs that run beside your AI app over stdio, and from a custom server you deploy to Cloud Run.
What a Google-hosted MCP server is
MCP is a protocol through which an AI host discovers tools, prompts, and resources and then invokes them. A Google-hosted server runs on Google infrastructure; your client connects to its remote HTTP endpoint. Claude, VS Code, Gemini CLI, and Cursor are examples of hosts identified in Google’s overview, but each host implements MCP and credential handling differently.
A remote server is not the same as installing a local package. Local servers commonly use stdio and run as a process on your computer. A Cloud Run deployment is a third option: you (or a vendor) operate a custom server, normally using Streamable HTTP. Cloud Run-hosted MCP servers do not support stdio transport.
Choose the right Google route first
Google-managed service endpoint
Google operates the endpoint and publishes the supported product, URL, tools, authentication methods, and permissions. The current supported-products catalog and the service’s own reference are authoritative; do not assume that one endpoint or one tool list applies to every Google service. Google’s March 27, 2026 blog names Google Maps, BigQuery, Google Kubernetes Engine, and Cloud Run as examples, not as a complete catalog.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
- Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
- CanaKit Turbine Black Case for the Raspberry Pi 5
- CanaKit Low Noise Bearing System Fan
- Mega Heat Sink - Black Anodized
Developer Knowledge MCP
For searching official developer documentation, the Developer Knowledge MCP reference lists https://developerknowledge.googleapis.com/mcp and a search_documents tool. Your host still needs to support remote MCP and the authentication method accepted by that endpoint.
Custom MCP server on Cloud Run
Use this when you need to develop or select a server that Google does not provide as a managed service. Google’s Cloud Run guide uses source deployment with gcloud run deploy --source .. Authentication depends on where the client runs, and the hosted server uses Streamable HTTP rather than stdio.
Remote Google Cloud CLI MCP server
Google documents a separate remote server for gcloud and bq commands in a sandbox. It is marked Preview and enabled through the Cloud CLI Execution API. Preview behavior and terms can change, so treat it as a test or controlled-use option and check the current documentation before relying on it.
Prerequisites and a safe setup sequence
- Pick the service and read its support page. Record the exact endpoint, supported transport, tools, required APIs, regions, and accepted credentials. Availability and capabilities are service-specific.
- Select a Google Cloud project where the service requires one. Enable the relevant product/API before configuring the client. Google’s Cloud Logging codelab, for example, has you select a project and enable
logging.googleapis.com. Billing is a prerequisite for that codelab and for some selected services, not a universal requirement for every MCP endpoint. - Decide which identity the client will use. Options can include your user account, an application or workload identity, or an agent identity. Calls made with your personal credentials are attributed to you and inherit your permissions. A dedicated application identity is usually easier to audit and limit for automation.
- Grant least-privilege access. For Google Cloud remote MCP calls, Google’s management guidance instructs administrators to grant
roles/mcp.toolUserplus the permissions required by the underlying resource. The authentication guide states that this predefined role containsmcp.tools.call. It does not replace service-specific roles such as permissions to read a log, query a dataset, or inspect a cluster. - Choose an authentication method accepted by both sides. Documented patterns include Application Default Credentials (ADC), an OAuth 2.0 client ID and secret, or an
Authorizationheader containing a bearer token. Some endpoints also accept an API key; IAM-protected services generally do not accept ordinary API-key authentication. Google Maps is an example of a service that may use API keys, while some endpoints require no authentication. - Configure the MCP host. Add the remote URL in the host’s MCP settings, select its HTTP or Streamable HTTP transport, and follow that host’s method for supplying OAuth, ADC, or headers. Never paste a long-lived secret into a prompt, repository, or shared configuration file.
- Discover capabilities before granting broad access. MCP defines discovery methods including
tools/list,prompts/list, andresources/list. A server may support only some of them. Where the server supports toolsets, select a narrow set so the model sees fewer unnecessary operations.
Authentication details that matter
Application Default Credentials
ADC is useful when the client runs in an environment already configured for Google credentials, such as Cloud Shell, a workstation authenticated with the Google Cloud CLI, or a Google-managed runtime. Confirm which account or service identity ADC resolves to before testing; otherwise a successful connection may still operate under the wrong permissions.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
- Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM)
- Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
- CanaKit Premium High-Gloss Raspberry Pi 4 Case with Integrated Fan Mount, CanaKit Low Noise Bearing System Fan
- CanaKit 3.5A USB-C Raspberry Pi 4 Power Supply (US Plug) with Noise Filter, Set of Heat Sinks, Display Cable - 6 foot (Supports up to 4K60p)
- CanaKit USB-C PiSwitch (On/Off Power Switch for Raspberry Pi 4)
OAuth 2.0
OAuth is appropriate when a user must consent and actions should be attributable to that user. Use the scopes and redirect flow required by the target service and host. Store client secrets in the host’s secret store or an operating-system credential manager.
Bearer tokens and API keys
A bearer token is sent in an Authorization: Bearer … header when the endpoint documents that method. API keys are not interchangeable with IAM credentials. An endpoint that requires IAM will reject an API key even if the key belongs to the same project. Treat keys as secrets, restrict them by API and application where possible, and rotate them.
Discovering a server over HTTP
The exact request envelope depends on the server’s MCP transport version. Use the service reference for headers, session handling, and initialization. A generic discovery request looks like this:
curl -X POST "https://developerknowledge.googleapis.com/mcp"
-H "Content-Type: application/json"
-H "Authorization: Bearer $GOOGLE_ACCESS_TOKEN"
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
If the endpoint uses OAuth or a different initialization sequence, follow its documented handshake rather than copying this request unchanged. Inspect the response for the available tool names and schemas, then configure the host to expose only the capabilities your workflow needs.
Rank #3
- Not including the Raspberry Pi 5 (8GB), the Crowpi advanced version comes with the Raspberry Pi 5
- ELECROW Black Case for the Raspberry Pi 5, CrowPi is equipped with a 9-inch HD touchscreen along with a camera; All the regular components used in DIY electronics are packed into the CrowPi development board, such as LCD, LED matrix, buzzer, light sensor, PIR sensor, ultrasonic sensor, IR sensor, etc
- Raspberry Pi Sensors: The Crowpi raspberry pi 5 programming kit is jam-packed with lots of buttons such as 19 different sensors in a tidy easy to use package; You don't have to wait and wire things
- Build Quality: Solid ABS shell and well made components in one place make it strong and convenient to travel
- Programming Lessons: This raspberry pi 5 learning kit ships with step by step instructions and provides 21 lessons to take you through identifying components reading code and running it in the terminal
Google-hosted versus local and Cloud Run servers
| Route | Who operates it | Transport | Identity and permissions | Setup burden | Launch stage |
|---|---|---|---|---|---|
| Google-managed MCP | Remote HTTP or Streamable HTTP, service-specific | Google identity, OAuth, ADC, bearer token, or documented key; underlying resource permissions still apply | Enable service, grant access, configure host | Follow the service’s current documentation | |
| Local MCP server | You or a local vendor package | Usually stdio | Local process credentials and whatever API permissions it uses | Install, update, sandbox, and maintain the process | Depends on the package |
| Custom Cloud Run MCP | You or your chosen operator | Streamable HTTP; not stdio | Determined by deployment, ingress, and the client’s identity | Build, deploy, secure, monitor, and update | Depends on your deployment |
| Google Cloud CLI remote MCP | Remote sandbox for gcloud and bq |
Cloud CLI Execution API and configured Google access | Enable the feature and control command permissions | Preview |
Security and governance checks
- Use a separate service or workload identity when automation should not act as an individual.
- Grant
roles/mcp.toolUserand only the underlying resource roles required for the selected tools. - Review tool schemas before enabling write or destructive operations.
- Restrict which host applications can reach the endpoint and keep credentials outside prompts and source control.
- Google describes optional Model Armor protection. Its behavior and availability are configuration-specific; in unsupported jurisdictions, routing can affect data-residency compliance. If Model Armor logging is enabled, logs may include the full payload.
Troubleshooting common failures
401 or 403 responses
A 401 usually means the token is missing, expired, or issued for the wrong audience. A 403 commonly means the identity lacks mcp.tools.call or an underlying service permission. Verify the active account, project, role bindings, and token scopes.
The host cannot add the remote server
Check whether your MCP client supports remote HTTP or Streamable HTTP. Some clients support only local stdio servers or require a particular configuration key. Use the host’s current MCP documentation and the server’s initialization requirements.
The tool is not listed
The server may not implement tools/list, the selected toolset may be too narrow, or your identity may not be authorized for that capability. Confirm the service catalog and inspect the discovery response.
API enabled but calls still fail
Enabling an API only activates the product. It does not grant access to datasets, logs, clusters, or other resources. Add the required resource-level role and verify you are operating in the intended project.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Rank #4
- Fully assembled for plug-and-play operation
- Includes Raspberry Pi 5 with 8GB RAM
- 256 GB PCIe Pi NVMe SSD (Pre-loaded with Pi 64-Bit OS)
- M.2 HAT+
- CanaKit Turbine Black Case for the Pi 5
Cloud Run deployment works locally but not remotely
Confirm that the service accepts Streamable HTTP, configure ingress and authentication for the client’s identity, and do not attempt to connect with stdio. Review Cloud Run logs for rejected requests and missing environment variables.
Performance, reliability, and cost considerations
There is no single latency, uptime, or price figure for “Google MCP.” Those properties belong to the specific Google service, region, quota, model host, and underlying API. Keep discovery narrow, avoid exposing every tool to every agent, and design retries only for operations documented as safe to repeat. Cache read-only results in your application when freshness allows, and monitor the underlying API’s quotas and billing rather than assuming MCP changes them.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
If your workflow also needs a clean screenshot of a page while an AI agent works, ScreenshotNeo provides a website screenshot API and MCP server. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the page verdict and billing status in X-Page-Verdict and X-Billed headers. Its MCP tools include take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.
One request is enough:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for options such as full-page and element capture, device and retina settings, PDF output, custom CSS or JavaScript, waits, headers, cookies, geolocation, blocking rules, caching, signed links, async webhooks, bulk capture, and usage reporting. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
FAQ
Do all Google MCP servers require authentication?
No. Google states that most Google and Google Cloud MCP servers require authentication, but individual endpoints can document no-auth access or a different method.
Best Value
- 【What you Get】You will get 1*Pi 5 8GB Single Board,1*RasTech Case,1*Active Cooler,1*Screwdriver,1*Installation instructions,12-month free warranty, lifetime service, 24-hour prompt and friendly response.
- 【More Connectors】There are two USB 3.0 ports(5Gbps simultaneously) and two USB 2.0 ports, which triple total bandwidth ,support any combination of up to two cameras or displays. Peak SD card performance is doubled through support for the SDR104 high-speed mode. It provides a smooth desktop experience for you. Offer Gigabit Ethernet and a PCIe interface, along with dual-band Wi-Fi and Bluetooth 5.0/BLE wireless capability. The RasTech Pi 5 Kit use the new 27W 5.1V 5A USB-C power connector.
- 【 Support Dual 4Kp60 Display 】Each of the two microHDMI sockets can control a 4K display at 60 Hertz, now support HDR, offering super HD video for media streaming projects. RPi 5 is the first RPi model that comes with a PCI Express port (PCIe 2.0 x1 with 500 MB/s) to attach SSDs (requires separate M.2 HAT).
- 【 Excellent Chips And Applications】Pi 5 is a full-size Pi computer using silicon built in-house at Pi. The RP1 “southbridge” provides the bulk of the I/O capabilities for Pi 5. Pi 5 is more friendly and convenient in the development of Internet of Things, Web development, machine identification, automatic control and other electronic equipment applications and network.
- 【 Faster CPU, Better GPU 】 Pi 5 features a Broadcom BCM2712 64-bit quad-core Arm Cortex-A76 processor running at 2.4GHz, it delivers a 2–3× increase in CPU performance relative to RaspberryPi 4. The 800MHz VideoCore VII GPU is compatible to OpenGL ES 3.1 and Vulkan 1.2, substantial uplift in graphics performance. Pi 5 Offers lightning-fast CPU speed, a PCI Express interface, a Real Time Clock (RTC) and a power button and runs significantly cooler than Pi 4.
Can I use a Google MCP server from any AI app?
Only if the app includes an MCP client and supports the server’s remote transport and credential method. Host support is not universal.
Is Cloud Run required for Google-hosted servers?
No. Google-managed endpoints are already hosted. Cloud Run is for a custom server you deploy or operate.
Frequently Asked Questions
Do all Google MCP servers require authentication?
No. Google says most do, but the exact endpoint determines whether authentication is required and which method is accepted.
Can I use a Google MCP server from any AI app?
Only when the app supports MCP, the server’s remote transport, and its authentication method.
Is Cloud Run required for Google-hosted servers?
No. Cloud Run is a separate route for deploying a custom MCP server.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

