What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google-managed MCP servers are remote HTTP endpoints that expose Google or Google Cloud tools to an MCP client. To use one, enable its API in a project, grant the required MCP and service-specific IAM permissions, add the endpoint to your client (such as Gemini CLI), authenticate with Google credentials or OAuth, discover only the tools you need, and keep confirmations and audit controls enabled. Use a separate least-privilege workload or agent identity for production rather than a personal account.

What a Google-managed MCP server is

Model Context Protocol (MCP) standardizes how an AI host discovers and invokes tools, prompts, and resources. A Google-managed server runs on Google or Google Cloud infrastructure and is reached over HTTP. A local MCP server normally runs on your computer and communicates over standard input/output (stdio).

The managed platform adds service discovery, toolsets, IAM administration, authorization, centralized governance, and (for supported services) Model Armor scanning. A toolset is a logical subset of a server’s tools, so an agent can load a focused surface instead of placing every available operation into its context.

Managed hosting removes local installation and patching of that server, but it does not make actions automatically safe. The MCP client still acts with the permissions of the identity you supply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Philips 24 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 241V8LB
  • CRISP CLARITY: This 23.8″ Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
  • WORK SEAMLESSLY: This sleek monitor is virtually bezel-free on three sides, so the screen looks even bigger for the viewer. This minimalistic design also allows for seamless multi-monitor setups that enhance your workflow and boost productivity
  • A BETTER READING EXPERIENCE: For busy office workers, EasyRead mode provides a more paper-like experience for when viewing lengthy documents

Set up a managed server: the complete workflow

1. Select the service and project

Identify the Google capability your workflow needs, then create or select a Google Cloud project. Enable the API for that service. Supported MCP endpoints become available after the corresponding service API is enabled. Record the project used for the service and, where applicable, the project used for execution; those can be different.

2. Grant the narrowest permissions

Ask an administrator for the predefined MCP Tool User role when the service requires it, then add only the service-specific IAM permissions needed by your workflow. Separate read and write permissions where practical. For production, create a dedicated workload or agent identity instead of using your personal identity; Google Cloud’s authentication guidance explicitly recommends this separation.

3. Add the remote endpoint to your client

Remote servers are configured with a URL (or httpUrl in Gemini CLI). Local servers generally use a command entry. Keep the endpoint, transport, and authentication settings in the client’s normal configuration file, and keep secrets out of that file by expanding environment variables at runtime.

4. Authenticate

Choose an identity and credential flow that matches the deployment:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Credential approach When it fits Important limitation
User credentials Interactive development on a developer workstation Actions are attributed to that user and inherit the user’s permissions.
Application Default Credentials (ADC) Code or a client already running in a Google-authenticated environment The ADC identity still needs the MCP and service IAM roles.
OAuth 2.0 client credentials Remote SSE or HTTP servers that publish OAuth metadata Scopes and refresh-token handling must be configured correctly.
Service-account impersonation IAP-protected services or controlled automation The caller must be allowed to impersonate the target service account.
Authorization header Clients that accept a bearer token or other documented header Do not place long-lived secrets in source control or shared settings.

IAM-backed Google services do not accept ordinary API keys. Google Maps is an example of a non-IAM service that can accept an API key, but that exception does not apply to IAM-protected MCP endpoints.

Rank #2
Philips 22 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 221V8LB
  • CRISP CLARITY: This 22 inch class (21.5″ viewable) Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • 100HZ FAST REFRESH RATE: 100Hz brings your favorite movies and video games to life. Stream, binge, and play effortlessly
  • SMOOTH ACTION WITH ADAPTIVE-SYNC: Adaptive-Sync technology ensures fluid action sequences and rapid response time. Every frame will be rendered smoothly with crystal clarity and without stutter
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors

5. Discover and narrow the tool surface

After the connection succeeds, use MCP discovery methods such as tools/list, prompts/list, and resources/list. Select a service toolset or define an allowlist rather than exposing every operation to the model. A smaller surface reduces accidental invocation and makes approvals easier to review.

6. Set execution controls

Leave client confirmation enabled for destructive, costly, externally visible, or irreversible actions. Use client allow and exclude policies to block operations that the workflow never needs. For supported endpoints, enable Model Armor to scan MCP requests and responses for prompt injection, sensitive-data disclosure, and tool-poisoning risks.

7. Observe and maintain the integration

Review Cloud audit logs and IAM activity, rotate or refresh credentials, and verify the endpoint after client or server changes. Google’s current documentation references MCP protocol version 2026-07-28; treat that as a volatile implementation detail and check the version supported by your client before troubleshooting a handshake failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect Google-managed servers to Gemini CLI

Gemini CLI stores MCP definitions in its settings.json. A remote server entry can look like this (replace the example endpoint with the endpoint documented for your enabled service):

{
  "mcpServers": {
    "google-cloud-server": {
      "httpUrl": "https://example.googleapis.com/mcp",
      "authProviderType": "google_credentials",
      "oauth": {
        "scopes": ["https://www.googleapis.com/auth/cloud-platform"]
      }
    }
  }
}

Gemini CLI supports remote HTTP and SSE transports. When a server publishes OAuth metadata, the CLI can discover it, store tokens in ~/.gemini/mcp-oauth-tokens.json, and refresh them when refresh tokens are available. It can also use ADC and impersonate a service account for IAP-protected services. Use environment-variable expansion for any value that would otherwise expose a secret in settings.json.

Rank #3
Sale
Dell 24 Monitor - SE2426H - 23.8-inch FHD (1920x1080) 144Hz 1ms Display, in-Plane Switching (IPS) Technology, AMD FreeSync™, TÜV 3-Star 2X HDMI, Tilt
  • Clear visuals. Fluid motion: A 144Hz refresh rate and 1ms MPRT deliver smooth, tear‑free motion across work, gaming, and streaming for clearer, more fluid viewing.
  • Eye comfort: TÜV Rheinland 3‑star* certification reduces harmful blue light while preserving stunning color quality without compromise. *TÜV Rheinland 3-star eye comfort certification.
  • Wide viewing angle: Get consistent views across a wide 178° /178° viewing angle.
  • In-Plane Switching (IPS): See excellent color accuracy and consistency across wide viewing angles with In-plane Switching (IPS) technology.
  • Ultra-thin bezels: Maximize your viewing experience with thin bezels.
  1. Enable the service API and confirm that the endpoint is available in the selected project.
  2. Grant the MCP Tool User role and the service permissions required by the tools you intend to call.
  3. Add the remote URL to settings.json with the correct transport and credential provider.
  4. Start Gemini CLI and complete the OAuth flow, or make sure ADC is available to the process.
  5. List the server’s tools, then restrict the configuration to the required toolset or allowlist.
  6. Invoke a read-only tool first and verify the project, principal, and returned resource before enabling writes.

Run supported gcloud and bq operations through the Cloud CLI MCP server

Google’s Cloud CLI remote MCP server is a Preview feature under the Pre-GA terms. It is enabled through the Cloud CLI Execution API, uses OAuth 2.0 with IAM, and is exposed over Streamable HTTP at https://cloudcli.googleapis.com/mcp. It provides the run_gcloud_command and run_bq_command tools.

This server can execute supported gcloud and bq operations, but it is not an unrestricted shell. The supported-command list is limited and may change. Documented examples of unsupported commands include gcloud auth, gcloud config, gcloud iam service-accounts, and gcloud init.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pay attention to the request’s project parameter. It identifies the project used for Cloud CLI Execution; it is distinct from any --project flag inside the command string. Set both deliberately when your execution project and target resource project differ.

Security and governance practices

  • Use a dedicated identity: production agents should not run as a developer’s personal account.
  • Apply least privilege: grant only the MCP and service permissions needed for the selected tools.
  • Separate workflows: use different identities or policies for read-only investigation and mutation.
  • Require confirmation: pause before deletion, publication, billing changes, IAM changes, or other consequential calls.
  • Audit continuously: inspect IAM activity and audit logs so each action can be tied to the supplied identity.
  • Scan where supported: Model Armor can sanitize requests and responses. MCP Apps render server-published interactive resources in a sandboxed iframe, but content read through resource/read for rendering is not scanned by Model Armor; tool calls made through the app are scanned when Model Armor is enabled.

Managed versus local MCP servers

Decision area Google-managed remote server Local or third-party server
Hosting and transport Google or Google Cloud infrastructure over HTTP (including Streamable HTTP where documented) Usually a process on your machine over stdio
Installation and maintenance Little or no server installation; the provider operates the endpoint You install, patch, and operate the process
Identity lifecycle Google IAM, OAuth, ADC, and service-account impersonation options Depends on the implementation; credentials may be local and bespoke
Permission granularity IAM roles plus toolsets and client allowlists Defined by the server and client configuration
Auditability Centralized Google Cloud audit and IAM activity records Local logs or third-party logging, if implemented
Scanning and governance Model Armor and Google governance features for supported services Equivalent controls are your responsibility
Customization and offline use Less control over provider behavior; requires network access Can provide custom behavior and offline operation
Performance No general speed advantage is established; network distance, service load, and client behavior determine latency May avoid a network hop but still depends on the tools and local resources

Choose managed hosting when centralized IAM, auditability, and reduced operations matter. Choose local hosting when you need custom code, private offline execution, or control over the server lifecycle. You can also use both: keep sensitive bespoke tools local while connecting approved Google services remotely.

Troubleshooting common failures

Endpoint is not found or returns a 404

Confirm that the service API is enabled in the intended project and that you copied the service’s documented MCP endpoint exactly. A normal API URL is not necessarily its MCP URL.

Rank #4
Samsung 27" Essential S3 (S36GD) Series FHD 1800R Curved Computer Monitor
  • CURVED FOR ENHANCED ENGAGEMENT: An immersive viewing experience with a curved monitor that wraps more closely around your field of vision; It creates a wider view, enhancing depth perception and minimizing peripheral distraction
  • SMOOTH PERFORMANCE FOR SEAMLESS CONTENT: Stay in the action when playing games, watching videos, or working on creative projects; The 100Hz refresh rate reduces lag and motion blur so you don't miss a thing in fast-paced moments¹
  • MORE GAMING POWER: Gain the edge with optimizable game settings; Color and image contrast can be adjusted to see scenes more vividly and spot enemies hiding in the dark; Game Mode adjusts any game to fill the screen so you can view every detail²
  • KEEP IT EASY ON THE EYES: Care for your eyes and stay comfortable, even during long sessions; Advanced eye comfort technology certified by TÜV reduces eye strain by minimizing blue light and reducing irritating screen flicker²
  • INCREASED VERSATILITY: Connect to more; Plug devices straight into your monitor for increased flexibility, making your computing environment even more convenient

Permission denied or unauthenticated

Check which principal the client actually used, then verify the MCP Tool User role and every service-specific permission required by the selected tool. Refresh OAuth credentials or ADC if they are expired. For impersonation, verify that the caller has permission to impersonate the target service account.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

API key rejected

Remove the API key for IAM-backed services and use OAuth, ADC, or an authorized identity header. API-key authentication is an exception for some non-IAM services such as Google Maps, not a general MCP method.

Gemini CLI cannot complete the handshake

Verify whether the endpoint expects HTTP, SSE, or Streamable HTTP, and whether your CLI version supports that transport. Recheck the endpoint’s advertised protocol version; Google’s documentation currently references 2026-07-28, which can change.

A tool is missing or the model sees too many tools

Run tools/list and inspect the selected toolset. Remove an overbroad toolset and apply an allowlist. Restart the client after changing settings.json so it reloads the definition.

Cloud CLI command fails even though gcloud works locally

The remote server supports only a documented subset of commands. Check the supported-command list, avoid unsupported commands such as authentication and configuration commands, and distinguish the request’s execution project from a project flag embedded in the command.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sceptre New 22-Inch Gaming Monitor, FHD 1080p, Up to 144Hz, HDMI, DisplayPort, Built-in Speakers, Machine Black (E225W-FW144 Series, 2026)
  • 【INTEGRATED SPEAKERS】Whether you're at work or in the midst of an intense gaming session, our built-in speakers provide rich and seamless audio, all while keeping your desk clutter-free.
  • 【EASY ON THE EYES】 Protect your eyes and enhance your comfort with Blue-Light Shift technology. This feature reduces harmful blue light emissions from your screen, helping to alleviate eye strain during long hours of use and promoting healthier viewing habits.
  • 【WIDEN YOUR PERSPECTIVE】Our sleek minimal bezel design ensures undivided attention. The nearly bezel-free display seamlessly connects in a dual monitor arrangement, delivering an unobstructed view that lets you focus on more at once, completely distraction-free.

An MCP App displays unexpected content

Remember that resource/read content used to render an app is not scanned by Model Armor. Treat rendered content as untrusted, keep confirmation on for resulting tool calls, and limit the app’s available tools.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your agent workflow also needs a clean image of a webpage, ScreenshotNeo provides a website screenshot API and MCP server at https://screenshotneo.com. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and each response reports the result with X-Page-Verdict and X-Billed headers.

One request is enough:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for all options. The same call from Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Or from Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. It supports full-page and element captures, device and retina settings, custom CSS and JavaScript, waits, request blocking, headers, cookies, geolocation, PDF output, caching, signed links, asynchronous jobs, bulk capture, and a usage API. The Free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 shots, and every feature is available on every plan. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can one Gemini CLI configuration include both remote and local MCP servers?

Yes. Define remote entries with a URL or httpUrl and local entries with their command; apply separate allowlists and confirmation policies to each.

Does the Cloud CLI MCP server provide a general remote terminal?

No. It exposes run_gcloud_command and run_bq_command for a limited, changeable set of supported operations, and rejects commands such as gcloud auth, gcloud config, gcloud iam service-accounts, and gcloud init.

Who is accountable for an action made through a managed server?

The action is attributed to the identity supplied by the MCP client. Using a personal identity attributes it to that user; a dedicated agent or workload identity provides separate production accountability.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.