Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a Google Cloud managed remote MCP server by enabling the product API, granting the agent both MCP and product-specific IAM permissions, then adding that product’s HTTPS endpoint to an MCP client. For BigQuery, for example, the endpoint is https://bigquery.googleapis.com/mcp. Google hosts the server; you still own the project, identity, client configuration, authorization, and governance.

This guide shows the complete setup with BigQuery, explains how to find endpoints for other services, and covers permissions, protocol versions, observability, security controls, and common failures.

What a Google Cloud managed MCP server is

Model Context Protocol (MCP) standardizes how an AI application discovers and invokes external tools, prompts, and resources. The host is the main AI application, such as Claude, VS Code, Gemini CLI, or Cursor. An MCP client inside that host communicates with an MCP server.

A Google Cloud managed remote MCP server runs on Google infrastructure and exposes an HTTP endpoint for a supported Google Cloud service. You do not deploy or patch that service’s MCP server locally, but you must still configure the client, choose a project, authenticate an identity, and grant the permissions required by each tool.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is different from a local MCP server, which you typically run yourself and connect over stdio. Google Cloud’s overview describes the current protocol as version 2026-07-28; it is backward compatible with 2025-11-25. The core protocol is stateless in the 2026-07-28 version, so treat protocol behavior and client support as version-specific.

Google’s documentation summarizes the authorization model this way: “Only agents, MCP clients, and end-users with established identities can authenticate and use MCP tools, prompts, and resources.” See the Google Cloud MCP servers overview for the current architecture and supported concepts.

Find the right server and endpoint

Do not guess an endpoint or assume every product has identical tools. Use the maintained Supported products directory. Each entry links to its HTTP endpoint, MCP reference, setup instructions, and release status. Some products have global and regional endpoints; some are Preview.

Examples currently listed include:

Product Example endpoint What to verify
BigQuery https://bigquery.googleapis.com/mcp BigQuery API enabled; BigQuery-specific IAM roles and client instructions
Cloud Run https://run.googleapis.com/mcp Current server status, supported tools, and resource permissions
Cloud Storage https://storage.googleapis.com/storage/mcp Bucket permissions, endpoint scope, and available toolset
Cloud SQL https://sqladmin.googleapis.com/mcp Instance permissions, region requirements, and client compatibility

Google and Google Cloud remote MCP servers are automatically registered in the Agent Registry. When a supported product API is enabled, its corresponding server and tools are registered for discovery without a manual tool-spec upload. Built-in servers are registered in the global location, so IAM bindings for them must use --region=global; regional bindings are not supported for these global servers. See Register MCP servers.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up the BigQuery MCP server

1. Select or create a project

Choose the project whose BigQuery resources the agent will access. Selecting a project you can already access requires no additional role. Creating one requires the Project Creator role. Keep the agent’s resources and permissions in a deliberately chosen project rather than relying on an unrelated personal project.

2. Enable BigQuery

Enable the BigQuery API in that project. The remote BigQuery MCP server is enabled when the BigQuery API is enabled, and newly created projects automatically enable the API. Since March 17, 2026, supported remote MCP endpoints no longer require a separate MCP-server enablement step; rollout was gradual across regions, so check the current release notes if a newly enabled service is not visible.

In the Google Cloud console, open APIs & Services → Library, search for BigQuery API, open it, and select Enable. You can also enable it with the Cloud SDK:

gcloud services enable bigquery.googleapis.com --project=PROJECT_ID

3. Create a dedicated agent identity

Use a separate user or service identity for an agent that calls MCP tools. A dedicated identity makes access easier to limit, audit, rotate, and revoke than a developer’s broad personal account. Authenticate the MCP client with OAuth 2.0 and Google Cloud IAM using a supported identity; follow the BigQuery guide’s current client-specific instructions for the credential flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Grant MCP and BigQuery permissions

Authentication proves who is calling; it does not grant access to data. For the documented BigQuery query workflow, grant these roles to the agent identity:

Role Relevant permission Purpose in the example
roles/mcp.toolUser mcp.tools.call Allows the principal to invoke MCP tools
roles/bigquery.jobUser bigquery.jobs.create Allows query jobs to be created
roles/bigquery.dataViewer bigquery.tables.getData Allows reading table data

Grant the roles at the narrowest practical project, dataset, or resource scope. Other operations need additional permissions. For example, an identity with mcp.tools.call but without bigquery.datasets.get cannot retrieve dataset metadata; the reverse is also true. The complete role definitions are in Google Cloud MCP servers roles and permissions and the workflow is documented in Use the BigQuery MCP server.

5. Add the remote server to your MCP client

In your AI application, choose its option to add a remote MCP server, enter https://bigquery.googleapis.com/mcp, and select the Google OAuth/IAM identity you prepared. Client labels and configuration formats change, so use the current BigQuery instructions for Gemini CLI, ChatGPT, Claude, or your custom application rather than copying an old client file.

For a custom application, implement an MCP HTTP client that performs the server’s initialization and capability negotiation, supplies an OAuth access token, and then calls discovery and tool methods. Do not put a long-lived service-account key in a client configuration file; use the credential mechanism recommended for your runtime and protect refresh tokens and logs.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Discover tools before allowing autonomous use

After connection, call MCP discovery (commonly tools/list) and inspect names, descriptions, input schemas, and annotations. Enable only the tools your agent needs. Some Google servers expose toolsets as separate endpoints so an agent can load a focused set instead of every available tool into its context. Require explicit confirmation for destructive or costly operations.

How do I connect an AI agent to Google Cloud using MCP?

  1. Pick the service: find its current endpoint and release status in the Supported products directory.
  2. Choose the project: identify the project containing the resources and billing context the agent should use.
  3. Enable the product API: the managed MCP endpoint becomes available with the supported product API.
  4. Create or select an identity: prefer a dedicated, monitored agent identity.
  5. Grant two layers of access: mcp.tools.call plus every underlying permission required by the selected operation.
  6. Configure the client: add the HTTPS endpoint, OAuth/IAM credentials, and any service-specific settings.
  7. Discover and test: run tools/list, invoke a harmless read-only tool, and verify the returned resource is the expected project and region.
  8. Govern production use: apply IAM conditions, logging, tracing, approval gates, and rate or budget controls appropriate to the service.

What permissions does a Google Cloud MCP server need?

The caller needs permission to invoke MCP and permission to perform the underlying Google Cloud action. There is no universal role that authorizes every managed server. BigQuery’s three roles above are specific to its documented query example; Cloud Run, Storage, SQL, and other products require their own resource permissions.

IAM policies can restrict MCP calls by service and tool name. Deny policies can additionally use the OAuth client ID and whether a tool is read-only. These attributes are enforced only for mcp.tools.call; the OAuth client ID attribute is deny-only. Service and tool-name conditions must be managed with the Google Cloud CLI, and MCP attributes cannot control access to the Resource Manager MCP server. For global built-in servers, use global IAM scope.

Some endpoints support Model Armor scanning of calls and responses, but support is not universal. The overview notes that Model Armor does not scan resource/read calls used to render MCP Apps; tool calls made through an MCP App remain scanned when Model Armor is enabled. Verify support for the specific server before treating scanning as a control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Managed remote server or local MCP server?

Decision point Google-managed remote server Locally hosted server
Infrastructure Google hosts the service endpoint You deploy and operate the server
Transport HTTPS remote endpoint Typically local stdio
Scaling and patching Managed by Google for that service Your team owns capacity, upgrades, and uptime
Identity and policy Integrates with Google OAuth and IAM controls You design credential handling and policy integration
Setup work Product endpoint, API enablement, client, and IAM Runtime, package, process supervision, networking, and credentials

A managed endpoint reduces hosting work, not authorization work. Choose local hosting when you need a custom proxy, private tool implementation, or a service that is not in Google’s directory.

Availability, versions, and regional details

Google announced more than 50 Google-managed MCP servers generally available or in preview on April 28, 2026; that inventory can change, so use the live directory rather than treating the figure as a current count. Google and Google Cloud remote MCP servers reached general availability on May 1, 2026, while individual servers may still be Preview or GA.

The release notes record these milestones: separate MCP enablement was removed beginning March 17, 2026; IAM policy conditions gained tool.name control on July 2, 2026; and supported protocol version 2026-07-28 was announced on September 14, 2026. Check Google Cloud MCP servers release notes before production rollout because endpoint status, regional availability, and client support can change.

Monitoring and troubleshooting

Endpoint or server not found

  • Cause: the product is not supported in your region, the endpoint was mistyped, or the API rollout is incomplete.
  • Fix: copy the endpoint from the live Supported products directory, confirm the API is enabled, and check the product’s MCP reference and release status.

Unauthenticated or invalid-credential error

  • Cause: the client has no valid OAuth token, the token belongs to a different identity, or the client’s protocol flow is stale.
  • Fix: reauthenticate with the intended Google identity, refresh the client, and use its current remote-MCP configuration instructions.

Permission denied on a tool call

  • Cause: the principal lacks mcp.tools.call or the underlying product permission.
  • Fix: inspect the tool’s operation, grant the least-privilege product role required, and verify the binding applies to the correct project, dataset, resource, and global scope where applicable.

Tools list is empty or unexpectedly large

  • Cause: discovery failed, the client filtered tools, or the server exposes multiple toolsets.
  • Fix: inspect the raw discovery response, confirm the negotiated MCP version, and select the documented toolset endpoint when the product provides one.

Calls time out or appear slow

  • Cause: latency may come from the client, network, server, or the underlying Google Cloud operation.
  • Fix: test a small read-only call, reduce unnecessary tool discovery, and trace eligible calls. Cloud Trace supports W3C trace headers; X-Cloud-Trace-Context and other non-W3C headers are not supported. Only tools/call operations generate spans, and requests rejected during authentication, authorization, API enablement, or policy checks may produce no eligible span. See Use Cloud Trace to monitor MCP tool use.

Wrong project, dataset, or region

  • Cause: the client or identity is using a default project different from the one you intended.
  • Fix: set the project explicitly where the client supports it, verify the resource name in the tool input, and run a read-only check before enabling writes.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If you need a clean image or PDF of an MCP guide, endpoint reference, or cloud-console page for documentation, ScreenshotNeo is a website screenshot API and MCP server. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server lets Claude, Cursor, and other MCP clients call take_screenshot, get_page_info, and capture_pdf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

One request is enough:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://docs.cloud.google.com/mcp/overview -o shot.webp

See the ScreenshotNeo API and MCP documentation for options such as full-page capture, CSS selectors, device presets, custom headers, cookies, JavaScript, PDF output, caching, and async jobs. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Sign up for free.

Operational checklist

  • Endpoint copied from the current Supported products directory
  • Product API enabled in the intended project
  • Dedicated agent identity selected and monitored
  • mcp.tools.call and underlying resource permissions granted at least privilege
  • Current client instructions and protocol version verified
  • Tools discovered and unnecessary tools disabled
  • IAM conditions, approval gates, and Model Armor support reviewed
  • Read-only test completed in the correct project and region
  • Cloud Trace and audit diagnostics tested for eligible calls

Frequently Asked Questions

Does enabling a Google Cloud API automatically deploy an MCP server in my project?

No. Google hosts the managed endpoint. Enabling a supported product API makes its corresponding server available and registered for discovery; you do not deploy server code into your project.

Can one MCP client connect to several Google Cloud services?

Yes, when the client supports multiple remote servers. Add each service’s documented endpoint separately and authorize the identity for each service’s MCP and underlying resource permissions.

Are all Google Cloud MCP tools read-only?

No. Tool capabilities vary by product and endpoint. Inspect the discovered schemas and use IAM conditions or approval workflows to restrict write or destructive operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where should I check whether a server is Preview or GA?

Use the live Supported products directory and the individual product MCP reference; release status is product-specific and can change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.