What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Google-managed MCP servers are remote HTTP endpoints that expose Google or Google Cloud tools to an MCP client. To use one, enable its API in a project, grant the required MCP and service-specific IAM permissions, add the endpoint to your client (such as Gemini CLI), authenticate with Google credentials or OAuth, discover only the tools you need, and keep confirmations and audit controls enabled. Use a separate least-privilege workload or agent identity for production rather than a personal account.
What a Google-managed MCP server is
Model Context Protocol (MCP) standardizes how an AI host discovers and invokes tools, prompts, and resources. A Google-managed server runs on Google or Google Cloud infrastructure and is reached over HTTP. A local MCP server normally runs on your computer and communicates over standard input/output (stdio).
The managed platform adds service discovery, toolsets, IAM administration, authorization, centralized governance, and (for supported services) Model Armor scanning. A toolset is a logical subset of a server’s tools, so an agent can load a focused surface instead of placing every available operation into its context.
Managed hosting removes local installation and patching of that server, but it does not make actions automatically safe. The MCP client still acts with the permissions of the identity you supply.
#1 Best Overall
- CRISP CLARITY: This 23.8″ Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
- INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
- THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
- WORK SEAMLESSLY: This sleek monitor is virtually bezel-free on three sides, so the screen looks even bigger for the viewer. This minimalistic design also allows for seamless multi-monitor setups that enhance your workflow and boost productivity
- A BETTER READING EXPERIENCE: For busy office workers, EasyRead mode provides a more paper-like experience for when viewing lengthy documents
Set up a managed server: the complete workflow
1. Select the service and project
Identify the Google capability your workflow needs, then create or select a Google Cloud project. Enable the API for that service. Supported MCP endpoints become available after the corresponding service API is enabled. Record the project used for the service and, where applicable, the project used for execution; those can be different.
2. Grant the narrowest permissions
Ask an administrator for the predefined MCP Tool User role when the service requires it, then add only the service-specific IAM permissions needed by your workflow. Separate read and write permissions where practical. For production, create a dedicated workload or agent identity instead of using your personal identity; Google Cloud’s authentication guidance explicitly recommends this separation.
3. Add the remote endpoint to your client
Remote servers are configured with a URL (or httpUrl in Gemini CLI). Local servers generally use a command entry. Keep the endpoint, transport, and authentication settings in the client’s normal configuration file, and keep secrets out of that file by expanding environment variables at runtime.
4. Authenticate
Choose an identity and credential flow that matches the deployment:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match| Credential approach | When it fits | Important limitation |
|---|---|---|
| User credentials | Interactive development on a developer workstation | Actions are attributed to that user and inherit the user’s permissions. |
| Application Default Credentials (ADC) | Code or a client already running in a Google-authenticated environment | The ADC identity still needs the MCP and service IAM roles. |
| OAuth 2.0 client credentials | Remote SSE or HTTP servers that publish OAuth metadata | Scopes and refresh-token handling must be configured correctly. |
| Service-account impersonation | IAP-protected services or controlled automation | The caller must be allowed to impersonate the target service account. |
| Authorization header | Clients that accept a bearer token or other documented header | Do not place long-lived secrets in source control or shared settings. |
IAM-backed Google services do not accept ordinary API keys. Google Maps is an example of a non-IAM service that can accept an API key, but that exception does not apply to IAM-protected MCP endpoints.
Rank #2
- CRISP CLARITY: This 22 inch class (21.5″ viewable) Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
- 100HZ FAST REFRESH RATE: 100Hz brings your favorite movies and video games to life. Stream, binge, and play effortlessly
- SMOOTH ACTION WITH ADAPTIVE-SYNC: Adaptive-Sync technology ensures fluid action sequences and rapid response time. Every frame will be rendered smoothly with crystal clarity and without stutter
- INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
- THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
5. Discover and narrow the tool surface
After the connection succeeds, use MCP discovery methods such as tools/list, prompts/list, and resources/list. Select a service toolset or define an allowlist rather than exposing every operation to the model. A smaller surface reduces accidental invocation and makes approvals easier to review.
6. Set execution controls
Leave client confirmation enabled for destructive, costly, externally visible, or irreversible actions. Use client allow and exclude policies to block operations that the workflow never needs. For supported endpoints, enable Model Armor to scan MCP requests and responses for prompt injection, sensitive-data disclosure, and tool-poisoning risks.
7. Observe and maintain the integration
Review Cloud audit logs and IAM activity, rotate or refresh credentials, and verify the endpoint after client or server changes. Google’s current documentation references MCP protocol version 2026-07-28; treat that as a volatile implementation detail and check the version supported by your client before troubleshooting a handshake failure.
Connect Google-managed servers to Gemini CLI
Gemini CLI stores MCP definitions in its settings.json. A remote server entry can look like this (replace the example endpoint with the endpoint documented for your enabled service):
{
"mcpServers": {
"google-cloud-server": {
"httpUrl": "https://example.googleapis.com/mcp",
"authProviderType": "google_credentials",
"oauth": {
"scopes": ["https://www.googleapis.com/auth/cloud-platform"]
}
}
}
}
Gemini CLI supports remote HTTP and SSE transports. When a server publishes OAuth metadata, the CLI can discover it, store tokens in ~/.gemini/mcp-oauth-tokens.json, and refresh them when refresh tokens are available. It can also use ADC and impersonate a service account for IAP-protected services. Use environment-variable expansion for any value that would otherwise expose a secret in settings.json.
Rank #3
- Clear visuals. Fluid motion: A 144Hz refresh rate and 1ms MPRT deliver smooth, tear‑free motion across work, gaming, and streaming for clearer, more fluid viewing.
- Eye comfort: TÜV Rheinland 3‑star* certification reduces harmful blue light while preserving stunning color quality without compromise. *TÜV Rheinland 3-star eye comfort certification.
- Wide viewing angle: Get consistent views across a wide 178° /178° viewing angle.
- In-Plane Switching (IPS): See excellent color accuracy and consistency across wide viewing angles with In-plane Switching (IPS) technology.
- Ultra-thin bezels: Maximize your viewing experience with thin bezels.
- Enable the service API and confirm that the endpoint is available in the selected project.
- Grant the MCP Tool User role and the service permissions required by the tools you intend to call.
- Add the remote URL to
settings.jsonwith the correct transport and credential provider. - Start Gemini CLI and complete the OAuth flow, or make sure ADC is available to the process.
- List the server’s tools, then restrict the configuration to the required toolset or allowlist.
- Invoke a read-only tool first and verify the project, principal, and returned resource before enabling writes.
Run supported gcloud and bq operations through the Cloud CLI MCP server
Google’s Cloud CLI remote MCP server is a Preview feature under the Pre-GA terms. It is enabled through the Cloud CLI Execution API, uses OAuth 2.0 with IAM, and is exposed over Streamable HTTP at https://cloudcli.googleapis.com/mcp. It provides the run_gcloud_command and run_bq_command tools.
This server can execute supported gcloud and bq operations, but it is not an unrestricted shell. The supported-command list is limited and may change. Documented examples of unsupported commands include gcloud auth, gcloud config, gcloud iam service-accounts, and gcloud init.
Pay attention to the request’s project parameter. It identifies the project used for Cloud CLI Execution; it is distinct from any --project flag inside the command string. Set both deliberately when your execution project and target resource project differ.
Security and governance practices
- Use a dedicated identity: production agents should not run as a developer’s personal account.
- Apply least privilege: grant only the MCP and service permissions needed for the selected tools.
- Separate workflows: use different identities or policies for read-only investigation and mutation.
- Require confirmation: pause before deletion, publication, billing changes, IAM changes, or other consequential calls.
- Audit continuously: inspect IAM activity and audit logs so each action can be tied to the supplied identity.
- Scan where supported: Model Armor can sanitize requests and responses. MCP Apps render server-published interactive resources in a sandboxed iframe, but content read through
resource/readfor rendering is not scanned by Model Armor; tool calls made through the app are scanned when Model Armor is enabled.
Managed versus local MCP servers
| Decision area | Google-managed remote server | Local or third-party server |
|---|---|---|
| Hosting and transport | Google or Google Cloud infrastructure over HTTP (including Streamable HTTP where documented) | Usually a process on your machine over stdio |
| Installation and maintenance | Little or no server installation; the provider operates the endpoint | You install, patch, and operate the process |
| Identity lifecycle | Google IAM, OAuth, ADC, and service-account impersonation options | Depends on the implementation; credentials may be local and bespoke |
| Permission granularity | IAM roles plus toolsets and client allowlists | Defined by the server and client configuration |
| Auditability | Centralized Google Cloud audit and IAM activity records | Local logs or third-party logging, if implemented |
| Scanning and governance | Model Armor and Google governance features for supported services | Equivalent controls are your responsibility |
| Customization and offline use | Less control over provider behavior; requires network access | Can provide custom behavior and offline operation |
| Performance | No general speed advantage is established; network distance, service load, and client behavior determine latency | May avoid a network hop but still depends on the tools and local resources |
Choose managed hosting when centralized IAM, auditability, and reduced operations matter. Choose local hosting when you need custom code, private offline execution, or control over the server lifecycle. You can also use both: keep sensitive bespoke tools local while connecting approved Google services remotely.
Troubleshooting common failures
Endpoint is not found or returns a 404
Confirm that the service API is enabled in the intended project and that you copied the service’s documented MCP endpoint exactly. A normal API URL is not necessarily its MCP URL.
Rank #4
- CURVED FOR ENHANCED ENGAGEMENT: An immersive viewing experience with a curved monitor that wraps more closely around your field of vision; It creates a wider view, enhancing depth perception and minimizing peripheral distraction
- SMOOTH PERFORMANCE FOR SEAMLESS CONTENT: Stay in the action when playing games, watching videos, or working on creative projects; The 100Hz refresh rate reduces lag and motion blur so you don't miss a thing in fast-paced moments¹
- MORE GAMING POWER: Gain the edge with optimizable game settings; Color and image contrast can be adjusted to see scenes more vividly and spot enemies hiding in the dark; Game Mode adjusts any game to fill the screen so you can view every detail²
- KEEP IT EASY ON THE EYES: Care for your eyes and stay comfortable, even during long sessions; Advanced eye comfort technology certified by TÜV reduces eye strain by minimizing blue light and reducing irritating screen flicker²
- INCREASED VERSATILITY: Connect to more; Plug devices straight into your monitor for increased flexibility, making your computing environment even more convenient
Permission denied or unauthenticated
Check which principal the client actually used, then verify the MCP Tool User role and every service-specific permission required by the selected tool. Refresh OAuth credentials or ADC if they are expired. For impersonation, verify that the caller has permission to impersonate the target service account.
Free tools Windows power users keep installed
One-click scans. No signup required.
API key rejected
Remove the API key for IAM-backed services and use OAuth, ADC, or an authorized identity header. API-key authentication is an exception for some non-IAM services such as Google Maps, not a general MCP method.
Gemini CLI cannot complete the handshake
Verify whether the endpoint expects HTTP, SSE, or Streamable HTTP, and whether your CLI version supports that transport. Recheck the endpoint’s advertised protocol version; Google’s documentation currently references 2026-07-28, which can change.
A tool is missing or the model sees too many tools
Run tools/list and inspect the selected toolset. Remove an overbroad toolset and apply an allowlist. Restart the client after changing settings.json so it reloads the definition.
Cloud CLI command fails even though gcloud works locally
The remote server supports only a documented subset of commands. Check the supported-command list, avoid unsupported commands such as authentication and configuration commands, and distinguish the request’s execution project from a project flag embedded in the command.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsBest Value
- 【INTEGRATED SPEAKERS】Whether you're at work or in the midst of an intense gaming session, our built-in speakers provide rich and seamless audio, all while keeping your desk clutter-free.
- 【EASY ON THE EYES】 Protect your eyes and enhance your comfort with Blue-Light Shift technology. This feature reduces harmful blue light emissions from your screen, helping to alleviate eye strain during long hours of use and promoting healthier viewing habits.
- 【WIDEN YOUR PERSPECTIVE】Our sleek minimal bezel design ensures undivided attention. The nearly bezel-free display seamlessly connects in a dual monitor arrangement, delivering an unobstructed view that lets you focus on more at once, completely distraction-free.
An MCP App displays unexpected content
Remember that resource/read content used to render an app is not scanned by Model Armor. Treat rendered content as untrusted, keep confirmation on for resulting tool calls, and limit the app’s available tools.
Or skip the browser setup
If your agent workflow also needs a clean image of a webpage, ScreenshotNeo provides a website screenshot API and MCP server at https://screenshotneo.com. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and each response reports the result with X-Page-Verdict and X-Billed headers.
One request is enough:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for all options. The same call from Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Or from Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. It supports full-page and element captures, device and retina settings, custom CSS and JavaScript, waits, request blocking, headers, cookies, geolocation, PDF output, caching, signed links, asynchronous jobs, bulk capture, and a usage API. The Free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 shots, and every feature is available on every plan. Create a free ScreenshotNeo account.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Frequently Asked Questions
Can one Gemini CLI configuration include both remote and local MCP servers?
Yes. Define remote entries with a URL or httpUrl and local entries with their command; apply separate allowlists and confirmation policies to each.
Does the Cloud CLI MCP server provide a general remote terminal?
No. It exposes run_gcloud_command and run_bq_command for a limited, changeable set of supported operations, and rejects commands such as gcloud auth, gcloud config, gcloud iam service-accounts, and gcloud init.
Who is accountable for an action made through a managed server?
The action is attributed to the identity supplied by the MCP client. Using a personal identity attributes it to that user; a dedicated agent or workload identity provides separate production accountability.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

