ScreenshotNeo

BlogAI agents

How to Use Google Cloud Managed MCP Servers

Connect AI agents to Google Cloud managed MCP servers: discover endpoints, enable APIs, configure OAuth and IAM, test tools, and troubleshoot failures.

By the ScreenshotNeo team1 October 202611 min read

Google Cloud managed MCP servers are remote HTTP endpoints hosted on Google infrastructure. An AI application connects through an MCP client, while you still choose the Google Cloud project, authenticate an identity, enable the relevant API and grant permissions for both MCP and the underlying operation.

This guide shows how to connect an AI agent to Google Cloud using MCP, using BigQuery as the worked example. Product availability, endpoint names, release status and client setup are service-specific, so always check the supported products directory and the service’s MCP reference before deploying.

What a Google Cloud managed MCP server is

MCP standardizes how an AI host discovers and calls tools, prompts and resources. The host is the main application, such as Claude, VS Code, Gemini CLI or Cursor. Its MCP client communicates with a server.

  • Local MCP server: usually runs on your machine and commonly communicates over stdio.
  • Google Cloud managed remote MCP server: runs on Google infrastructure and exposes an HTTP endpoint for a supported Google Cloud service.

The managed option removes the need to run that service’s MCP process yourself. It does not remove project selection, identity management, IAM, API enablement or client configuration. Google documents the current protocol version as 2026-07-28, backward compatible with 2025-11-25; treat protocol behavior and client instructions as version-specific.

Google’s overview describes the model this way: “Only agents, MCP clients, and end-users with established identities can authenticate and use MCP tools, prompts, and resources.” Read the Google Cloud MCP servers overview for the current architecture and security model.

Find the right endpoint

Start with the maintained Supported products directory. For each service, check:

Check Why it matters
HTTP endpoint The URL is different for each service; some products also have regional endpoints.
MCP reference and setup guide Tool names, client instructions and permissions are product-specific.
Release status A service can be Preview even when Google’s managed MCP offering is generally available.
Required API For supported products, enabling the product API enables its corresponding managed server. Rollout has been gradual across regions.
Toolsets Some servers expose separate toolset endpoints so an agent can load only the tools it needs.
Regional scope Official built-in servers are registered in the global location, so their IAM bindings use global scope.

The directory currently includes examples such as BigQuery (https://bigquery.googleapis.com/mcp), Cloud Run (https://run.googleapis.com/mcp), Cloud Storage (https://storage.googleapis.com/storage/mcp) and Cloud SQL (https://sqladmin.googleapis.com/mcp). Do not copy this list into automation as a permanent inventory; use the live directory.

Set up the BigQuery MCP server

1. Select or create a project

Select a project that the agent can access. Selecting an existing accessible project needs no special role. Creating a project requires the Project Creator role. Record the project ID because you will use it when enabling APIs and assigning IAM.

2. Enable BigQuery

The documented BigQuery endpoint is https://bigquery.googleapis.com/mcp. The remote server is enabled when the BigQuery API is enabled. New projects automatically enable the API; verify it anyway before troubleshooting authentication.

gcloud services enable bigquery.googleapis.com --project=PROJECT_ID

Google’s release notes say separate MCP-server enablement is no longer required for supported products as the change rolls out. The product API remains the relevant prerequisite. See Use the BigQuery MCP server for the service-specific procedure.

3. Create a dedicated agent identity

Use a separate identity for an agent that calls MCP tools. This makes access easier to limit, audit and revoke. Authenticate with OAuth 2.0 and Google Cloud IAM using a supported user or service identity according to your client and organization policy.

4. Grant MCP and BigQuery permissions

Authentication proves who is calling. It does not grant permission to perform an operation. The caller needs the MCP permission and the permission for the underlying resource.

For the BigQuery query workflow documented by Google, grant:

  • roles/mcp.toolUser, which includes mcp.tools.call.
  • roles/bigquery.jobUser, which includes bigquery.jobs.create.
  • roles/bigquery.dataViewer, which includes bigquery.tables.getData.
gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="serviceAccount:AGENT_SERVICE_ACCOUNT" \
  --role="roles/mcp.toolUser" \
  --condition=None \
  --project=PROJECT_ID

gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="serviceAccount:AGENT_SERVICE_ACCOUNT" \
  --role="roles/bigquery.jobUser" \
  --condition=None \
  --project=PROJECT_ID

gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="serviceAccount:AGENT_SERVICE_ACCOUNT" \
  --role="roles/bigquery.dataViewer" \
  --condition=None \
  --project=PROJECT_ID

Use the narrowest resource scope that supports your workflow. Other BigQuery operations can require additional permissions. Do not apply these exact roles to another Google Cloud service; consult that service’s MCP guide and the MCP roles and permissions reference.

5. Add the remote server to your AI client

In your AI application, choose the option for adding a remote MCP server, enter the service endpoint and complete the client’s OAuth flow. Gemini CLI, ChatGPT, Claude and custom applications are covered by Google’s BigQuery guide, but configuration formats change. Follow the current instructions for your client instead of assuming that a local stdio configuration works for a remote HTTP endpoint.

For a custom client, keep these values in configuration:

{
  "name": "google-bigquery",
  "url": "https://bigquery.googleapis.com/mcp",
  "project": "PROJECT_ID",
  "auth": "OAuth 2.0 / Google Cloud identity"
}

The JSON above is a planning shape, not a universal client schema. Your MCP host may call the URL field serverUrl, require a separate OAuth registration, or provide a graphical setup flow. Use the host’s current documentation.

Discover and call tools over HTTP

After authentication, an MCP client normally initializes a session and discovers tools with JSON-RPC methods such as initialize and tools/list. The exact headers and session handling depend on the protocol version and server. The following examples show the request shape for a custom HTTP client; obtain an OAuth access token with your approved Google identity before running them.

cURL

export ACCESS_TOKEN="ya29..."
export MCP_URL="https://bigquery.googleapis.com/mcp"

curl -sS "$MCP_URL" \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  --data-raw '{
    "jsonrpc":"2.0",
    "id":1,
    "method":"initialize",
    "params":{
      "protocolVersion":"2026-07-28",
      "capabilities":{},
      "clientInfo":{"name":"my-agent","version":"1.0.0"}
    }
  }'

curl -sS "$MCP_URL" \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  --data-raw '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'

Python

import os
import requests

url = "https://bigquery.googleapis.com/mcp"
headers = {
    "Authorization": f"Bearer {os.environ['ACCESS_TOKEN']}",
    "Content-Type": "application/json",
    "Accept": "application/json, text/event-stream",
}

initialize = {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "initialize",
    "params": {
        "protocolVersion": "2026-07-28",
        "capabilities": {},
        "clientInfo": {"name": "my-agent", "version": "1.0.0"},
    },
}

r = requests.post(url, headers=headers, json=initialize, timeout=90)
r.raise_for_status()
print(r.text)

r = requests.post(
    url,
    headers=headers,
    json={"jsonrpc": "2.0", "id": 2, "method": "tools/list", "params": {}},
    timeout=90,
)
r.raise_for_status()
print(r.text)

Node.js

const token = process.env.ACCESS_TOKEN;
const url = 'https://bigquery.googleapis.com/mcp';
const headers = {
  Authorization: `Bearer ${token}`,
  'Content-Type': 'application/json',
  Accept: 'application/json, text/event-stream'
};

const initialize = await fetch(url, {
  method: 'POST',
  headers,
  body: JSON.stringify({
    jsonrpc: '2.0',
    id: 1,
    method: 'initialize',
    params: {
      protocolVersion: '2026-07-28',
      capabilities: {},
      clientInfo: { name: 'my-agent', version: '1.0.0' }
    }
  })
});
if (!initialize.ok) throw new Error(`${initialize.status} ${await initialize.text()}`);
console.log(await initialize.text());

const tools = await fetch(url, {
  method: 'POST',
  headers,
  body: JSON.stringify({ jsonrpc: '2.0', id: 2, method: 'tools/list', params: {} })
});
if (!tools.ok) throw new Error(`${tools.status} ${await tools.text()}`);
console.log(await tools.text());

Some servers return a session identifier or stream response that your client must reuse on subsequent requests. Preserve response headers and follow the service’s current MCP reference when implementing a production client.

How to connect an AI agent to Google Cloud using MCP

  1. Choose the Google Cloud product and open its entry in the supported-products directory.
  2. Copy the documented endpoint and note whether it is global, regional, Preview or GA.
  3. Select the project that owns the data or workload.
  4. Enable the product API.
  5. Create or select a dedicated agent identity.
  6. Grant mcp.tools.call through the documented MCP role.
  7. Grant the underlying resource permissions for each operation the agent may perform.
  8. Configure OAuth and the remote endpoint in your MCP host.
  9. Run discovery and remove tools your agent does not need from its allowed set.
  10. Apply IAM conditions, logging and tracing, then test with a least-privilege identity.

Govern access with IAM

Google Cloud IAM policies can govern MCP calls by service and tool attributes. Allow and deny policies have different supported attributes. Deny policies can additionally use the OAuth client ID and whether a tool is read-only.

  • These MCP attributes are enforced for mcp.tools.call.
  • The OAuth client ID attribute is deny-only.
  • Service and tool-name conditions must be managed with the Google Cloud CLI.
  • MCP attributes cannot control access to the Resource Manager MCP server.
  • Built-in Google and Google Cloud servers are registered globally; use --region=global for their registry IAM bindings.

For syntax and current limitations, see Control MCP use with IAM and Register MCP servers.

Discovery, toolsets and context size

Use tools/list to discover what a server exposes. Some services publish toolsets as separate endpoints so an agent does not load every tool into its context. Select the smallest toolset that supports the task and expose read-only tools where possible.

When a supported Google Cloud API is enabled, its corresponding official server and tools are registered for discovery automatically. No manual upload of tool specifications is required for these built-in servers.

Security and response inspection

Some Google Cloud MCP servers support Model Armor scanning of calls and responses, but support varies by endpoint. Model Armor does not scan resource/read calls used to render MCP Apps; tool calls made through an MCP App can still be scanned when Model Armor is enabled. Confirm support for the service you are deploying.

Give the agent only the roles and tools it needs. A caller with mcp.tools.call but without the required BigQuery data permission cannot read that data. The reverse also fails: a data permission without the MCP call permission cannot invoke the managed tool.

Monitor calls with Cloud Trace

Cloud Trace can help show which servers and tools a project invokes, whether the agent selected the wrong tool, and whether latency came from the client, network or server.

  • Only tools/call operations generate MCP spans.
  • Requests rejected during authentication, authorization, API enablement or other policy checks may not produce eligible spans.
  • Use W3C trace headers. X-Cloud-Trace-Context and other non-W3C headers are not supported for this MCP tracing path.

Performance, reliability and cost considerations

  • Latency: a remote HTTP call adds client, network, authorization and service execution time. Trace supported calls to identify which segment is slow.
  • Retries: retry only operations that are safe to repeat. A read can usually be retried more safely than a mutating operation; follow the service’s guidance and preserve request identity where supported.
  • Timeouts: set a client timeout appropriate to the underlying operation and surface the server’s error instead of silently retrying forever.
  • Availability: check the product’s Preview or GA status and regional endpoint requirements. Google-managed MCP availability does not make every individual server GA.
  • Context efficiency: discover tools once per session where possible and select a narrow toolset.
  • Cost: the research sources do not provide a neutral MCP cost benchmark. Google Cloud service usage and any agent infrastructure remain subject to the applicable product pricing and quotas.

Troubleshooting

Symptom Likely cause Fix
404 or endpoint not found Copied an old URL, wrong product endpoint or wrong regional host. Open the live supported-products directory and copy the endpoint from the service entry.
401 Unauthorized Missing, expired or incorrectly scoped OAuth token. Re-authenticate the configured identity and send Authorization: Bearer TOKEN.
403 Permission denied The identity lacks mcp.tools.call or the underlying resource permission. Grant the service-documented MCP role and operation-specific role; verify the project and resource scope.
API not enabled The product API is disabled or enablement has not propagated. Run gcloud services enable for the product API, then retry after propagation.
Tools list is empty or incomplete Wrong toolset, client filtering or service-specific discovery behavior. Check the MCP reference, call tools/list, and select the documented toolset endpoint.
Protocol version error Client and server negotiated incompatible MCP versions. Use a client supporting 2026-07-28 or its backward-compatible 2025-11-25 behavior, following the server guide.
Works in one client but not another Remote MCP and OAuth configuration formats differ by host. Use that host’s current remote-server instructions; do not reuse a local stdio configuration unchanged.
No Cloud Trace span Request failed before an eligible tool call or used unsupported trace headers. Verify the call reached tools/call and propagate W3C trace headers.
Global IAM binding has no effect Binding was applied to a regional location. Use global scope for official built-in servers, as documented by Agent Registry.

Google-managed remote MCP versus a local server

Decision area Managed remote server Local server
Infrastructure Hosted on Google infrastructure. Operated by your team or developer environment.
Transport Remote HTTP endpoint. Typically local stdio.
Deployment No service-specific MCP process to deploy. You install, update and run the server.
Identity and policy Uses Google Cloud identity and IAM integration. You design the credential and policy path.
Setup work Still requires endpoint, API, OAuth, project and permissions. Requires local process configuration plus credentials and permissions.

Or skip the browser setup

If your agent also needs website screenshots, ScreenshotNeo provides a single HTTP endpoint instead of requiring you to run browser automation. Cookie and consent banners, newsletter popups and chat widgets are removed before capture. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. ScreenshotNeo also provides an MCP server with take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' }); const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo API documentation for the full option set. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

FAQ

Do I need to host a Google MCP server?

No. A managed server is hosted by Google, but you still configure the MCP client, identity, project, API and IAM.

Is enabling an API enough to authorize an agent?

No. API enablement makes the supported server available. The caller still needs mcp.tools.call and the permissions for the requested Google Cloud operation.

Are all Google Cloud MCP servers configured the same way?

No. Endpoints, toolsets, permissions, regional availability, release status and client instructions vary by product.

Where should I look for new services?

Use the live Supported products directory; it is maintained separately from this article.

Can IAM restrict individual MCP tools?

IAM conditions can target documented service and tool attributes with limitations. Review the current IAM control guide before writing a policy.

Deployment checklist

  • Endpoint copied from the current supported-products directory.
  • Product API enabled in the intended project.
  • Dedicated agent identity selected.
  • OAuth flow completed by the MCP client.
  • MCP call permission granted.
  • Underlying data or resource permissions granted at the narrowest useful scope.
  • Only required tools or toolsets exposed to the agent.
  • Preview and regional constraints documented.
  • Trace and IAM policies tested with a least-privilege identity.
  • Client errors and server responses retained for diagnosis.

Google’s documentation changes as services and protocol versions evolve. Recheck the product reference, supported-products directory and release notes immediately before production rollout.