To use Google Cloud database tools through the Model Context Protocol (MCP), choose the remote MCP server for your specific service, configure an MCP-compatible client to connect to that endpoint, and authenticate an identity with only the IAM permissions the agent needs. There is no single endpoint or shared toolset for every Google database. This guide walks through Cloud SQL for PostgreSQL and AlloyDB; use Google Cloud’s supported-products directory to find the current reference for other services.
Which Google database MCP server should I use?
Choose by the Google Cloud service that hosts the data, not just by the fact that the database uses SQL. Google documents separate remote MCP servers for supported products, and their endpoints, available tools, authentication, and limitations can differ. The endpoints below are those documented in the Google Cloud references accessed October 4, 2026; confirm the current service reference before deploying a client.
| Service | Endpoint and transport | Authentication and scope | Important qualification |
|---|---|---|---|
| Cloud SQL for PostgreSQL | https://sqladmin.googleapis.com/mcp; remote HTTP endpoint |
Cloud SQL API enablement and IAM authorization; specialized toolsets include a read-only endpoint | The endpoint’s toolset controls what tools are exposed, while IAM controls what the authenticated principal may do. |
| AlloyDB | https://alloydb.googleapis.com/mcp; Streamable HTTP |
OAuth 2.0 with IAM; API keys are not accepted | Google documents regional endpoints as Preview. Its documentation also notes response-size and PostgreSQL-version limitations described below. |
Google’s supported-products directory also lists BigQuery, Spanner, Firestore, Bigtable, and other services. Their presence in the directory does not mean they use either endpoint in this table; follow the product-specific endpoint and setup reference.
How does a remote database MCP server differ from a local one?
A Google remote MCP server runs on Google infrastructure and is reached over HTTP. A local MCP server typically runs on the same device as the client and communicates over standard input/output (stdio). These are different deployment patterns, not interchangeable endpoint values.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Google describes managed remote servers as providing fine-grained authorization, centralized audit logging, and optional prompt and response security with Model Armor. Its Cloud SQL documentation compares these controls with the local MCP Toolbox for Databases. These controls can improve governance, but they do not remove the need to scope IAM, review agent behavior, and protect data returned to the client.
How do I connect an MCP client to Cloud SQL for PostgreSQL?
The following is a service-specific setup path for Cloud SQL for PostgreSQL. The endpoint is not a generic Google database URL. Configure your chosen MCP-compatible application using its current instructions for remote HTTP servers; application configuration fields and authentication flows can vary.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
- Enable the Cloud SQL for PostgreSQL API. Google documents the remote MCP server as enabled when this API is enabled. Make sure the project and Cloud SQL instance you intend to use are the ones selected for setup.
- Choose the endpoint and toolset. Use
https://sqladmin.googleapis.com/mcpfor the general Cloud SQL endpoint. For the documented read-only set, usehttps://sqladmin.googleapis.com/mcp/readonly. - Authenticate the client. Sign in or configure the identity mechanism supported by your MCP client and Google Cloud environment. The client must make MCP calls as the principal whose IAM permissions you have reviewed.
- Grant the minimum required IAM permissions. Google identifies
roles/mcp.toolUserfor making MCP tool calls, with additional task-specific roles and permissions for operations such as SQL execution, instance management, secret access, and viewing resources. Select permissions for the intended actions rather than granting a broad administrative role for a read-only workflow. - Add the remote server to the client. Enter the Cloud SQL endpoint and complete the client’s authentication setup. Do not assume every client uses the same configuration format or supports identical remote-server features.
- Verify the exposed tools and allowed actions. Ask the client to list the server’s available tools, then test a low-risk operation appropriate to the granted permissions. Confirm that the client cannot perform actions outside the intended scope.
Cloud SQL read-only endpoint
Google documents these tools at https://sqladmin.googleapis.com/mcp/readonly:
get_instanceandlist_instancesfor instance details and discovery.list_usersfor user discovery.execute_sql_readonlyfor read-only SQL execution.get_operationfor operation status.postgres_upgrade_precheckfor a PostgreSQL upgrade precheck.
A read-only endpoint narrows the tools offered by that endpoint, but it is not a substitute for IAM. The authenticated principal still needs appropriate permissions, and IAM remains the authorization boundary for its actions.
Recommended Free Tools
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Client configuration: use the client’s supported remote-server fields
There is no single client configuration file format established for all MCP applications. In the client’s remote MCP server settings, select the transport and authentication method it supports, then enter the exact Cloud SQL endpoint above. Avoid copying a stdio configuration example into a remote HTTP setup: stdio expects a local process, while this Google server is remote. Google’s Cloud SQL guide names Gemini CLI, ChatGPT, Claude, and custom applications as client examples, but their interfaces and supported capabilities may change.
How is AlloyDB configured?
For AlloyDB, configure an MCP client for Streamable HTTP at https://alloydb.googleapis.com/mcp, then authenticate with OAuth 2.0 and IAM. Google’s AlloyDB guide says API keys are not accepted. Google recommends a separate identity for agents so access can be controlled and monitored independently of a person’s everyday identity.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Grant that identity only the permissions required for the tools and data it needs. Do not copy Cloud SQL endpoint or tool assumptions into AlloyDB configuration: Google documents these as separate product servers. Regional AlloyDB endpoints are Preview, so check current availability and status before relying on one in production.
AlloyDB limitations to check
- Google’s AlloyDB MCP documentation says responses larger than 10 MB might be truncated. Avoid requesting unnecessarily large result sets, and use pagination or narrower queries where available.
execute_sql_read_onlyis documented as supported only for PostgreSQL 17 and later. Verify the database engine version and current service documentation before depending on this tool.
How should I scope access safely?
Treat tool exposure and IAM authorization as two separate controls. The server endpoint determines which tools the client can discover; IAM determines what the authenticated identity is allowed to do. A read-only endpoint is useful for reducing the available surface, but it does not make an overprivileged identity least-privileged.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
- Create or select a dedicated identity for an agent, particularly for AlloyDB, where Google recommends a separate identity.
- Start from the task: read instance metadata, run read-only queries, manage instances, or access secrets. Grant only the task-specific roles and permissions documented for those actions.
- Use Cloud SQL’s read-only toolset when write-capable tools are not required, and still review the identity’s IAM grants.
- Review audit records and outputs as part of operating the integration. Google documents centralized audit logging for managed remote MCP servers.
- Consider the documented optional Model Armor prompt and response security for managed remote servers where appropriate; it is an additional control, not a replacement for IAM or application-level review.
How do I verify the connection?
- Confirm the correct Google Cloud product and project are selected.
- Confirm the product API is enabled where required; for Cloud SQL, enable the Cloud SQL for PostgreSQL API.
- Check that the MCP client uses the exact product endpoint and a compatible remote transport.
- Authenticate as the intended identity, not an accidentally broader personal or administrative account.
- Check the identity’s IAM permissions against the operations the agent will perform.
- Inspect the tools returned by the server and compare them with the product reference; for Cloud SQL read-only access, confirm the documented read-only tool names are exposed.
- Test a permitted, low-risk operation, then verify that an unneeded action is unavailable or denied.
Common connection problems and fixes
| Symptom | Likely cause | What to check |
|---|---|---|
| Client cannot reach or initialize the server | Wrong service endpoint, incorrect transport, or client configured for local stdio instead of remote HTTP | Confirm the database product and exact endpoint; use the remote transport supported by that client. |
| Authentication fails for AlloyDB | API key used instead of OAuth 2.0 with IAM, or client identity is not authenticated | Use the documented OAuth 2.0/IAM flow; AlloyDB’s MCP server does not accept API keys. |
| Tool is missing | Selected endpoint exposes a narrower toolset, or the client did not refresh its server tools | Check the endpoint path and the product reference; Cloud SQL’s read-only endpoint intentionally offers a defined subset. |
| Tool is listed but action is denied | IAM permissions for the authenticated principal do not authorize the operation | Review the task-specific permissions and grant only what that operation requires; endpoint tool availability alone does not grant access. |
| AlloyDB read-only SQL tool is unavailable | The PostgreSQL version may be earlier than the documented minimum | Google documents execute_sql_read_only support for PostgreSQL 17 and later; verify current documentation and engine version. |
| AlloyDB response appears incomplete | Response may exceed the documented 10 MB truncation threshold | Reduce result size or split the request; confirm current service behavior in Google’s AlloyDB reference. |
ScreenshotNeo: a separate tool for website captures
ScreenshotNeo is a website screenshot API and MCP server, not a Google Cloud database MCP server; it does not connect an agent to Cloud SQL or AlloyDB. If your agent also needs website screenshots, it is an alternative to evaluate for that separate task. ScreenshotNeo removes cookie/consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are never billed; it has an MCP server for AI agents; and its free plan includes 1,000 screenshots a month with no card, with paid plans starting at $5 for 3,000.
Or skip the browser setup
For a website screenshot, one GET request can return an image or PDF. See the ScreenshotNeo API documentation for request options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo free.
FAQ
Can I use a Google database MCP server with any MCP client?
Only if the client supports the server’s remote transport and authentication flow. Client support and setup interfaces vary, so check the client’s current remote MCP instructions.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsDoes the Cloud SQL read-only endpoint make queries safe automatically?
No. It limits the documented tools exposed by that endpoint, but IAM still governs the authenticated identity, and query results can still disclose data the identity may read.
Can I use an AlloyDB API key instead of OAuth?
No. Google’s AlloyDB MCP documentation says API keys are not accepted.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

