Google Cloud MCP Server (gcloud-mcp)

Google's official, open-source MCP server for the Google Cloud Platform: control Google Cloud resources in natural language via the gcloud CLI, plus observability, storage, and backup/disaster recovery.

Description

The Google Cloud MCP Server, tracked in its official repository under the short name gcloud-mcp, is Google's open-source Model Context Protocol bridge to the Google Cloud Platform (GCP). The project is maintained by the googleapis organization on GitHub, backed according to the repository's publicly visible metadata by a dedicated internal Google Cloud SDK team. Instead of memorizing gcloud command syntax, flags, and arguments, users describe the outcome they want in natural language, and the agent translates the request into the appropriate gcloud calls. For software teams, DevOps engineers, and anyone who regularly works with Google Cloud resources, this lowers the barrier to entry and speeds up recurring tasks such as log analysis, storage management, or backup checks, without everyone needing to know the full gcloud reference by heart.

Unlike many single-product MCP servers, the Google Cloud MCP Server is a monorepo containing four separate sub-servers that can be set up individually or together. The core gcloud server executes arbitrary gcloud commands through natural language and deliberately blocks commands that make no sense for an agent to run, such as interactive sessions or open-ended arbitrary code execution. The observability sub-server connects to Google Cloud Observability and supports queries against log entries, metrics, traces, alert policies, and error groups, useful for investigating an incident directly inside a chat with the AI assistant. The storage sub-server manages Google Cloud Storage buckets and objects: listing, reading, writing, copying, moving, and deleting objects, plus IAM permission checks and insights queries at the bucket level. The backupdr sub-server controls Google Cloud Backup and Disaster Recovery, from an overview of backup vaults and plans through to restoring Compute Engine instances, disks, or Cloud SQL databases.

What the Google Cloud MCP Server is actually useful for

Anyone who regularly checks cloud resources, searches through logs, or monitors deployments benefits the most: instead of switching between a terminal, the Cloud Console, and documentation, an incident can be described directly inside the AI client ("show me the error logs from project X over the last hour"), and the agent calls the matching observability tools. Team members who rarely touch gcloud can carry out complex, multi-step operations (such as a backup restore) more safely, because the agent already knows the correct command sequence. The added value compared to plain gcloud CLI use comes from the interplay with the language model: results get interpreted, summarized, and turned into follow-up actions rather than just printed raw to a terminal.

Installation and supported clients

Requirements are Node.js version 20 or later plus an installed and authenticated gcloud CLI. For Gemini CLI and Gemini Code Assist, npx @google-cloud/gcloud-mcp init --agent=gemini-cli is enough, which registers the server as a Gemini CLI extension. For other MCP-capable clients such as Claude Desktop, Cline, Cursor, or Visual Studio Code, a standard JSON block referencing npx -y @google-cloud/gcloud-mcp (or @google-cloud/observability-mcp, @google-cloud/storage-mcp, @google-cloud/backupdr-mcp for the other sub-servers) is added to the respective configuration file. All four packages are published separately on npm and can be enabled independently — teams that only need storage tools do not have to set up the full gcloud core server.

Permissions, authentication, and security

The server's permissions mirror those of the currently active gcloud account exactly. For production use, Google's documentation recommends authenticating via a service account with a restricted role rather than a personal account with broad permissions (principle of least privilege). Several tools in the backupdr and storage sub-servers explicitly perform write or delete operations (for example delete_backup_vault, delete_bucket, restore_backup); teams running the server in production should deliberately decide which of these tools to expose rather than granting every agent unrestricted access. Because all content returned by the server (log excerpts, object contents, configuration data) is forwarded to the connected AI client and from there to the underlying model provider, sensitive or confidential data should not flow uncontrolled into the tool context. Log and object content from external or less trusted sources can also contain crafted instructions (prompt injection) that a language model might mistakenly interpret as a tool call.

Official status, license, and maturity

The repository explicitly notes that it provides a solution rather than an officially supported Google product; it is currently in preview, is not covered by the Google Cloud Terms of Service, and may still change. Even so, its origin is unambiguous: the project lives inside the googleapis GitHub organization, is maintained by a dedicated internal Google group, and its npm packages are published from Google's official publishing account. The source code is licensed under Apache 2.0, meaning it is freely viewable, modifiable, and usable commercially. This server should be distinguished from the separate, product-specific hosted remote MCP endpoints Google also operates for individual Google Cloud services (such as BigQuery or Cloud SQL), which are offered as separate, hosted servers through the official Google Cloud MCP documentation and are, in some cases, already listed as their own catalog entries.

Costs

The server and its source code are free. Costs only arise from the Google Cloud resources actually consumed through the tools (compute, storage, observability queries, backup storage) at standard, publicly listed Google Cloud pricing. The official Google Cloud pricing page is authoritative for exact figures.

Who should use it

The server is particularly well suited to teams already actively working on the Google Cloud Platform who want to weave AI agents into their development or operations workflows, for example for incident analysis through logs and traces, for managing storage buckets as part of data pipelines, or for monitoring backup plans. Anyone who only occasionally touches Google Cloud benefits from the natural-language access because they no longer need to memorize the gcloud command reference. For purely production-critical, highly sensitive environments, the preview status should be taken into account, and the feature set should be tested with restricted accounts before a broad rollout.

Requirements

Node.js 20 or later plus an installed and authenticated gcloud CLI. For Gemini CLI/Code Assist the server installs as an extension; other clients use standard MCP JSON configuration.

Installation instructions

npx -y @google-cloud/gcloud-mcp

Authentication

Uses the credentials of the active gcloud account. Google recommends a service account with a restricted role for production use rather than a personal account with broad permissions.

Required access permissions

Permissions match the signed-in gcloud account exactly. Several tools in the storage and backupdr sub-servers perform write or delete operations (e.g. delete_bucket, delete_backup_vault, restore_backup).

Transmitted or stored data

Not recorded yet.

Security risks

Write/delete tools for storage and backup/DR, full permissions of the account used, log/object content forwarded to the model provider, prompt-injection risk via untrusted log or object content, preview status per the provider (not an officially supported product, not covered by the Google Cloud Terms of Service SLA).

License and costs

License
Apache-2.0
Cost
free

The server itself is free and open source (Apache 2.0). Costs only arise from Google Cloud resources actually consumed (compute, storage, observability, backup) at standard Google Cloud pricing.

Alternatives

Not recorded yet.

At a glance

Provider
Google
Status
Official server
Deployment
Local
Current version
0.5.3
GitHub stars
910
Last reviewed
21.09.2026

Repository and documentation

Categories

Supported clients

Not recorded yet.