Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Use a Google-managed MCP server by enabling the required Google API in a project, granting a least-privilege identity the MCP and service permissions it needs, adding the remote HTTP endpoint to your MCP client, and then narrowing and approving the tools the agent may call. Unlike a local MCP server that usually communicates over stdio on your computer, a managed server runs on Google infrastructure and is governed through IAM, centralized logging, and (for supported services) Model Armor.
What a Google-managed MCP server is
Model Context Protocol (MCP) standardizes how an AI host discovers and invokes tools, prompts, and resources. A Google-managed server exposes those MCP capabilities from a Google or Google Cloud endpoint over HTTP. Gemini CLI, Claude, VS Code and a custom MCP application can connect to that endpoint without installing the server implementation locally.
A local server normally starts as a process on your machine and speaks MCP over stdio. A managed server is hosted and patched by the service owner, so you trade local control for centralized identity, policy and operations. “Managed” does not mean the agent has unrestricted Google Cloud access: every call still runs with the permissions of the identity supplied by the client.
Recommended Free Tools
Prerequisites and identity decisions
Choose a project and service
Decide which Google capability the workflow needs and select or create the Google Cloud project that will own the activity. Enable that service’s API first. Supported managed MCP endpoints become available only after the corresponding API is enabled.
#1 Best Overall
- CRISP CLARITY: This 23.8″ Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
- INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
- THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
- WORK SEAMLESSLY: This sleek monitor is virtually bezel-free on three sides, so the screen looks even bigger for the viewer. This minimalistic design also allows for seamless multi-monitor setups that enhance your workflow and boost productivity
- A BETTER READING EXPERIENCE: For busy office workers, EasyRead mode provides a more paper-like experience for when viewing lengthy documents
Request the right IAM roles
Ask an administrator for the predefined MCP Tool User role when the service requires it, then add only the service-specific roles needed by your workflow. Read-only analysis, deployment, data export and destructive administration should not share one broad role.
Use a dedicated production identity
For production, create a separate workload or agent identity instead of using your personal identity. Google Cloud’s authentication guidance explicitly recommends a separate agent or workload identity for production workloads. This gives you cleaner audit attribution, safer rotation and a smaller blast radius. Service-account impersonation can provide short-lived credentials without distributing a key file.
End-to-end setup workflow
- Inventory the action. Write down the exact tools the agent must call, the project and regions involved, and whether each action is read-only or mutating.
- Enable the API. In the selected project, enable the Google service that publishes the MCP endpoint.
- Grant access. Assign the MCP Tool User role where required and the narrow service permissions for the planned operations.
- Prepare authentication. Choose user credentials for an interactive experiment, or ADC, workload identity, an agent identity or service-account impersonation for automation.
- Add the remote endpoint. Configure the URL in the MCP client. Remote servers use an HTTP or Streamable HTTP/SSE transport; a local server generally uses a command that starts a stdio process.
- Discover and restrict tools. Call MCP discovery methods, select a toolset or allowlist, and exclude everything the workflow does not need.
- Test with confirmation enabled. Run a harmless read operation first. Keep approval prompts on until the identity, project and arguments are verified.
- Operate and review. Inspect audit logs and IAM activity, refresh or rotate credentials, and re-check behavior after client or protocol updates.
Connect one from Gemini CLI
Gemini CLI stores MCP configuration in settings.json. The exact file can be user-level or project-level according to your CLI installation, but the structure is the same. A remote entry can use url or httpUrl; a local entry normally uses command.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall{
"mcpServers": {
"google-cloud-server": {
"httpUrl": "https://example.googleapis.com/mcp",
"authProviderType": "google_credentials",
"oauth": {
"scopes": ["https://www.googleapis.com/auth/cloud-platform"]
}
}
}
}
Replace the example host with the endpoint for the Google service you enabled. Keep secrets out of this file. Gemini CLI can expand environment variables at runtime, discover OAuth metadata when the server publishes it, and store acquired tokens in ~/.gemini/mcp-oauth-tokens.json. When a refresh token is available, the CLI can refresh access automatically. It can also use Google Application Default Credentials (ADC) and impersonate a service account for an IAP-protected service.
First connection checklist
- Authenticate with the same account or workload identity that received the IAM roles.
- Confirm that the endpoint’s audience, host and transport match what the service documents.
- Approve the OAuth scopes requested by the endpoint; do not grant unrelated scopes.
- Invoke a read-only tool and verify the returned project and region before attempting a write.
Authentication: which credential fits?
User credentials
User OAuth is convenient for an interactive developer session. It is also the easiest way to accidentally make production actions appear to come from one person. Use it for local exploration, not unattended jobs.
ADC and workload or agent identity
ADC lets Google client libraries and compatible MCP clients obtain credentials from the standard environment. In deployment, bind the workload or agent identity to the runtime and grant only the required IAM roles. This avoids embedding a long-lived personal token.
Rank #2
- CRISP CLARITY: This 22 inch class (21.5″ viewable) Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
- 100HZ FAST REFRESH RATE: 100Hz brings your favorite movies and video games to life. Stream, binge, and play effortlessly
- SMOOTH ACTION WITH ADAPTIVE-SYNC: Adaptive-Sync technology ensures fluid action sequences and rapid response time. Every frame will be rendered smoothly with crystal clarity and without stutter
- INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
- THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
Service-account impersonation
Impersonation lets a caller obtain temporary credentials for a narrowly permissioned service account. Grant the caller permission to impersonate that account, then audit both the initiating principal and the impersonated identity.
OAuth client IDs and authorization headers
Some clients use an OAuth client ID and negotiated authorization metadata; others accept an authorization header supplied by the host. Follow the endpoint’s documented flow rather than assuming that every MCP server accepts the same header or scope.
API keys are not a universal fallback
IAM-backed Google services do not accept standard API keys for MCP access. Google Maps is an example of a non-IAM service that can accept an API key, but that exception should not be generalized to Google Cloud MCP endpoints.
Use the Google Cloud CLI remote MCP server
The Cloud CLI remote MCP server is a Preview feature under the Pre-GA terms. It is exposed at https://cloudcli.googleapis.com/mcp over Streamable HTTP and authenticates with OAuth 2.0 and IAM. API-key authentication is rejected.
Configure that endpoint in an MCP client using the same remote-server pattern shown above, then authenticate with a Google identity that has Cloud CLI Execution API and command-specific permissions. The server publishes two principal tools:
Free tools Windows power users keep installed
One-click scans. No signup required.
run_gcloud_commandrun_bq_command
Only a documented subset of gcloud and bq operations is supported, and the list can change while the feature is in Preview. Commands such as gcloud auth, gcloud config, gcloud iam service-accounts and gcloud init are examples of unsupported operations. Ask the server to perform a supported read operation before building an automation around it.
Rank #3
- Clear visuals. Fluid motion: A 144Hz refresh rate and 1ms MPRT deliver smooth, tear‑free motion across work, gaming, and streaming for clearer, more fluid viewing.
- Eye comfort: TÜV Rheinland 3‑star* certification reduces harmful blue light while preserving stunning color quality without compromise. *TÜV Rheinland 3-star eye comfort certification.
- Wide viewing angle: Get consistent views across a wide 178° /178° viewing angle.
- In-Plane Switching (IPS): See excellent color accuracy and consistency across wide viewing angles with In-plane Switching (IPS) technology.
- Ultra-thin bezels: Maximize your viewing experience with thin bezels.
Do not confuse the two project parameters
The request’s project parameter selects the project used for Cloud CLI Execution. A project flag inside the command, such as a flag passed to gcloud or bq, can target a different resource project. Set and audit both deliberately; one does not override the other.
Discover tools, then reduce the surface
MCP discovery methods include tools/list, prompts/list and resources/list. Discovery tells you what the server currently publishes; it is not a security grant by itself. Use a toolset to load a smaller logical group of tools into the agent’s context instead of exposing an entire server. If your client supports allow and exclude policies, allow only the named tools required for the task.
Keep the initial context small for two reasons: the model has fewer opportunities to choose an irrelevant or dangerous tool, and the request carries less schema overhead. Re-run discovery after a service update because a managed endpoint can add, remove or change tools independently of your client release.
Execution controls and security
Require confirmation for consequential calls
Leave client confirmation enabled for deletion, IAM changes, externally visible messages, deployments and data export. A useful pattern is automatic approval for idempotent reads and explicit approval for every mutating operation.
Apply least privilege twice
IAM limits what the identity can do on Google Cloud. The MCP client’s allowlist limits what the model can ask for. Use both controls; an allowlist is not a substitute for IAM, and IAM alone still leaves the model a large tool surface.
Use Model Armor where supported
Model Armor can scan MCP requests and responses to help mitigate prompt injection, sensitive-data disclosure and tool-poisoning risks. Support is service-dependent. For MCP Apps, server-published interactive resources render in a sandboxed iframe, but resource/read content used to render an app is not scanned by Model Armor; tool calls made through the app are scanned when Model Armor is enabled.
Rank #4
- CURVED FOR ENHANCED ENGAGEMENT: An immersive viewing experience with a curved monitor that wraps more closely around your field of vision; It creates a wider view, enhancing depth perception and minimizing peripheral distraction
- SMOOTH PERFORMANCE FOR SEAMLESS CONTENT: Stay in the action when playing games, watching videos, or working on creative projects; The 100Hz refresh rate reduces lag and motion blur so you don't miss a thing in fast-paced moments¹
- MORE GAMING POWER: Gain the edge with optimizable game settings; Color and image contrast can be adjusted to see scenes more vividly and spot enemies hiding in the dark; Game Mode adjusts any game to fill the screen so you can view every detail²
- KEEP IT EASY ON THE EYES: Care for your eyes and stay comfortable, even during long sessions; Advanced eye comfort technology certified by TÜV reduces eye strain by minimizing blue light and reducing irritating screen flicker²
- INCREASED VERSATILITY: Connect to more; Plug devices straight into your monitor for increased flexibility, making your computing environment even more convenient
Audit and rotate
Review Cloud audit logs and IAM activity for the agent identity, watch for unexpected projects or methods, and rotate or refresh credentials on a schedule. Never place a service-account key or refresh token in source control, a shared settings file or an MCP prompt.
Managed versus local MCP servers
| Concern | Google-managed server | Local or third-party server |
|---|---|---|
| Hosting and transport | Runs on Google infrastructure and is reached remotely over HTTP, SSE or Streamable HTTP as supported. | Usually runs on your machine over stdio; a third party may host it over its own transport. |
| Identity | Google user, workload or agent identity, ADC, OAuth or impersonation, with IAM enforcement. | Whatever credential and authorization model the server implements. |
| Tool governance | Toolsets, discovery, client allowlists and Google administrative controls. | Depends on the server and client; governance is often your responsibility. |
| Scanning | Model Armor is available for supported services. | No equivalent is established here; you must evaluate the provider’s controls. |
| Auditability | Central Google audit and IAM activity records. | Local logs or provider-specific telemetry. |
| Operations | Less local installation and patching; endpoint behavior can change with the managed service. | More customization and offline control; you own updates, availability and dependency maintenance. |
| Performance | No general performance advantage is established; network latency and service load still matter. | Local calls may avoid a network hop, but remote dependencies can still be involved. |
Reliability, cost and lifecycle notes
A remote MCP call depends on DNS, TLS, OAuth, IAM, the MCP endpoint and the underlying Google service. Add timeouts, retries with exponential backoff for transient failures, and idempotency checks before retrying a mutating operation. Cache safe discovery results briefly, but do not assume that a tool schema or permission remains unchanged.
Google’s managed-MCP material does not establish a universal latency, uptime or price benchmark. Budget for the underlying Google service and any Cloud CLI Execution charges that apply to your project, then verify current service terms before committing to a workload. Preview behavior and supported commands can change without the stability guarantees you might expect from a generally available API.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting common failures
| Symptom | Likely cause | Fix |
|---|---|---|
| Endpoint is unreachable | Wrong host, transport, firewall or disabled API. | Confirm the exact endpoint, use the transport it advertises, enable the service API and test connectivity from the machine running the client. |
| 401 or OAuth loop | Expired token, missing refresh token, wrong OAuth scope or clock problem. | Sign in again, remove the stale token from ~/.gemini/mcp-oauth-tokens.json, request the documented scope and retry. |
| 403 permission denied | MCP Tool User role or service-specific IAM permission is missing, or the request targets another project. | Check the principal actually used by the client, grant the narrow missing role and verify both the execution project and resource project. |
| API key rejected | The endpoint is IAM-backed. | Use OAuth, ADC, workload identity or impersonation. Do not replace IAM credentials with an API key. |
| Tool does not appear | The API is disabled, the tool is outside the selected toolset, or the server changed its schema. | Run tools/list, enable the API, select the correct toolset and refresh the client configuration. |
| Cloud CLI command rejected | The command is outside the Preview server’s supported allowlist. | Check the current supported-command list and rewrite the task using a supported gcloud or bq operation. Authentication, configuration and initialization commands are not accepted. |
| Unexpected destructive action | Broad IAM permissions or an unrestricted client policy. | Separate read and write identities, tighten the allowlist, and require interactive confirmation for mutating tools. |
FAQ
Can a Google-managed MCP server run arbitrary shell commands?
No. An MCP server exposes the tools its service publishes. The Cloud CLI server, for example, accepts only a changing subset of supported gcloud and bq operations rather than an unrestricted shell.
Does remote hosting make an MCP server automatically safer?
No. Managed hosting supplies IAM, centralized governance and optional Model Armor, but the client still inherits the supplied identity’s permissions. Safety depends on least privilege, tool restrictions and confirmation policy.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Can I use the same configuration for every MCP client?
The MCP concepts are portable, but configuration keys, OAuth handling and policy controls differ by client. Verify whether your host expects url, httpUrl, SSE or Streamable HTTP and how it loads credentials.
Best Value
- 【INTEGRATED SPEAKERS】Whether you're at work or in the midst of an intense gaming session, our built-in speakers provide rich and seamless audio, all while keeping your desk clutter-free.
- 【EASY ON THE EYES】 Protect your eyes and enhance your comfort with Blue-Light Shift technology. This feature reduces harmful blue light emissions from your screen, helping to alleviate eye strain during long hours of use and promoting healthier viewing habits.
- 【WIDEN YOUR PERSPECTIVE】Our sleek minimal bezel design ensures undivided attention. The nearly bezel-free display seamlessly connects in a dual monitor arrangement, delivering an unobstructed view that lets you focus on more at once, completely distraction-free.
Or skip the browser setup
If your workflow also needs reliable website screenshots for documentation, tests or agent context, ScreenshotNeo is a direct HTTP alternative to maintaining a headless-browser capture service. It accepts consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture; each cleanup step can be disabled.
Only clean shots are billed. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and response headers report the page verdict and whether the request was billed. ScreenshotNeo also provides an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.
One request is enough:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for all 63 options, including full-page lazy-image loading, CSS-selector element capture, dark mode, device presets, retina scale, PDF paper and page-range controls, custom JavaScript and CSS, click and wait conditions, request blocking, headers and cookies, timezone and geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture and usage reporting. The API accepts the parameter names used by other screenshot services, which can simplify migration.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
ScreenshotNeo’s Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan. Create a free ScreenshotNeo account and try the endpoint without adding a card.
Frequently Asked Questions
What should I log for each MCP tool call?
Record the initiating principal, impersonated identity when applicable, project, tool name, approval decision and result status so an incident reviewer can reconstruct the action.
How should I handle a managed endpoint schema change?
Pin client versions where practical, run discovery in a staging project, compare tool schemas and permissions, then re-approve your allowlist before production rollout.
Is the Cloud CLI MCP server suitable for production automation today?
It is documented as a Preview feature under Pre-GA terms, with a limited command set that may change; evaluate that status and the current supported-command list before relying on it.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

