Wednesday, September 30, 2026 Newsletter Advertise
Breaking
Products

Google Cloud launches CLI remote MCP server in public preview

The managed server lets AI agents run gcloud and bq commands in an isolated cloud sandbox without installing CLI binaries, Google Cloud said.

Google Cloud launches CLI remote MCP server in public preview. Source: Google Cloud

Google Cloud said on September 30, 2026 that it has introduced the Google Cloud CLI remote MCP server in preview, a managed service that gives AI agents access to gcloud and BigQuery (bq) command-line operations. The company said the server is available today in public preview with no additional charge for the MCP server itself.

What Google Cloud announced

In a post by Prosper Nwankpa, senior engineering manager, and Adam Hwang, software engineering manager, Google Cloud said the new server expands its ecosystem of managed remote MCP servers and is "Powered by the popular gcloud and bq (BigQuery) command-line tools."

According to the company, the server packages hundreds of gcloud and bq commands into a single MCP server, which it said gives agents higher-level abstractions instead of multi-step API orchestration. Google Cloud also argued that large language models are heavily pre-trained on public command-line documentation, making CLI invocation "intuitive and highly accurate for models."

The company said the server exposes two tools, run_gcloud_command and run_bq_command. It described use cases including observability and incident diagnostics, automating scheduled queries via BigQuery Data Transfer Service configurations, job and resource management covering processed data volume, slot usage, execution plans and reservations, and inspecting and updating table permissions.

Why run the CLI remotely

Google Cloud said managing cloud infrastructure with AI agents traditionally requires installing and maintaining Google Cloud CLI binaries inside agent execution environments. The remote server instead provides what the company called an isolated execution sandbox on Google Cloud infrastructure, removing local installations and runtime maintenance.

The company said this also opens access for web-hosted agent platforms and interfaces, such as Gemini Enterprise and other hosted enterprise agent platforms, where users cannot control or install local packages.

Security and governance claims

Google Cloud said the server isolates execution in a network-restricted proxy boundary with no ambient credentials, and that authentication and authorization are handled through Agent Identity, OAuth 2.0 and Identity and Access Management.

Every command runs with the permissions of the authenticated caller identity, with IAM permissions and organization policy service constraints enforced against downstream target resources, according to the company. Google Cloud said the server integrates with Model Armor so customers can screen LLM prompts and responses against risks such as prompt injection and malicious inputs.

The company added that tool invocations can be logged to Audit Logs as Data Access logs under cloudcli.googleapis.com/mcp, giving security teams visibility into caller identities, OAuth clients and IAM authorization decisions "without exposing sensitive command payloads or personally identifiable information (PII)."

Availability and connection

Because the server implements the standard Model Context Protocol, Google Cloud said any MCP-compatible agent platform or orchestration runtime can connect via standard configuration pointing to the URI https://cloudcli.googleapis.com/mcp.

Authentication is handled via keyless Agent Identity for hosted Google Cloud platforms, or standard OAuth 2.0 for external runtimes, the company said. It said customers pay only for the Google Cloud resources they create and any applicable data transfer costs.

What to do

  • Enable the Cloud CLI Execution API (cloudcli.googleapis.com) in your Google Cloud project, as Google Cloud instructs.
  • Grant the MCP Tool User role (roles/mcp.toolUser) to the agent or user identity that will call the server.
  • Configure your MCP client to connect to cloudcli.googleapis.com/mcp, using keyless Agent Identity on hosted Google Cloud platforms or OAuth 2.0 for external runtimes.
  • Consult Google Cloud's MCP Authentication Guide and the Google Cloud CLI Remote MCP Server Guide for authentication and setup options.
  • If you need audit visibility, configure logging of tool invocations to Audit Logs as Data Access logs under cloudcli.googleapis.com/mcp.
Key facts and where they come from
  • Google Cloud introduced the Google Cloud CLI remote MCP server in preview.
    Today, we’re expanding our ecosystem of managed remote MCP servers by introducing the Google Cloud CLI remote MCP server in preview.
  • The server exposes two tools: run_gcloud_command and run_bq_command.
    The Cloud CLI remote MCP server exposes two powerful tools, run_gcloud_command and run_bq_command
  • There is no additional charge for the MCP server itself, Google Cloud said.
    The Google Cloud CLI MCP server is available today in public preview. There is no additional charge to use the MCP server itself.
  • Execution is isolated with no ambient credentials, using Agent Identity, OAuth 2.0 and IAM.
    The server isolates execution in a network-restricted proxy boundary with no ambient credentials. Authentication and authorization are handled through Agent Identity, OAuth 2.0, and Identity and Access Management (IAM).
  • The server integrates with Model Armor to screen prompts and responses.
    the Cloud CLI remote MCP server integrates with Model Armor. You can proactively screen LLM prompts and responses to protect against risks like prompt injection and malicious inputs.
  • Tool invocations can be logged to Audit Logs under cloudcli.googleapis.com/mcp.
    can be configured to log every tool invocation to Audit Logs (Data Access logs under cloudcli.googleapis.com/mcp)

Read the original from Google Cloud →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Products