Lifestyle
Google Cloud Previews a Remote MCP Server That Lets AI Agents Run gcloud and bq Commands for You
Google Cloud has opened a public preview of its Google Cloud CLI remote MCP server. It lets AI agents run Google Cloud's gcloud and bq command-line tools in isolated cloud sandboxes, with nothing to install locally. This article explains how it works, the safeguards Google describes, the pricing, and what it means for businesses, developers and everyday readers.
About 6 min read

What happened
Google Cloud announced on its official blog that the Google Cloud CLI remote MCP server is now available in public preview. A CLI (command-line interface) is a tool you operate by typing text commands instead of clicking through menus. MCP (Model Context Protocol) is a standard protocol that lets AI agents connect to external tools. Google Cloud says the server is built on two of its command-line tools, gcloud and bq (for BigQuery, its data warehouse service). It brings hundreds of commands into a single MCP server that AI agents can use to manage Google Cloud infrastructure and handle BigQuery workflows.
According to Google Cloud, the server provides two tools: run_gcloud_command and run_bq_command. The first covers gcloud operations, and Google gives observability and incident diagnosis as examples. The second extends what agents can do in BigQuery: scheduling queries, viewing query execution details, managing reservations, and viewing and updating table permissions. Google Cloud notes that its existing BigQuery MCP server focuses on data analysis and exploration.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
Why move the command line to a remote server
Google Cloud's argument is that, until now, letting an AI agent manage the cloud meant installing and maintaining the Google Cloud CLI inside the agent's runtime environment. That adds version-management overhead across development, testing and production. The remote MCP server instead runs commands in isolated sandboxes on Google Cloud infrastructure. A sandbox is a sealed-off space where commands run separately from everything else, so there is nothing to install locally. Google Cloud also says web-hosted agent platforms such as Gemini Enterprise can now use CLI operations through the remote approach, because users of those platforms cannot install local packages in the first place.
As for why it chose the command line, Google Cloud argues that a single CLI command can wrap multi-step workflows and validation checks. It adds that large language models have been heavily pre-trained on public command-line documentation and examples, which makes them more likely to call commands correctly. This is Google's argument; how well it works in practice remains for users to test during the preview.
| Item | Traditional approach (as described by Google Cloud) | CLI remote MCP server (as described by Google Cloud) |
|---|---|---|
| Where the CLI is installed | Installed inside the agent runtime environment | Runs in isolated sandboxes on Google Cloud |
| Versions and dependencies | Must be maintained in each environment | No local installation or runtime maintenance |
| Web-based agent platforms | Cannot install local packages | Can use it via remote MCP |
| Authentication | — | Agent Identity, OAuth 2.0, IAM |
| Extra cost | — | No charge for the server itself; pay only for resources and data transfer |
The security and governance mechanisms Google describes
- No ambient credentials: According to Google Cloud, commands run inside a network-restricted proxy boundary with no ambient credentials, meaning no stored login keys are left lying around in the environment. Authentication and authorization are handled through Agent Identity, OAuth 2.0 and IAM (Identity and Access Management, Google Cloud's system for deciding who may do what).
- Runs with caller permissions: Google Cloud says every command runs with the permissions of the authenticated caller's identity, and that IAM permissions and organization policy constraints are enforced.
- Model Armor integration: Google Cloud says its Model Armor service can screen LLM prompts and responses to guard against prompt injection (hidden instructions meant to trick an AI) and malicious input.
- Audit logs: Google Cloud says the server can be configured to log each tool call. The logs show the caller's identity, OAuth client and IAM authorization decisions without exposing sensitive command content or personally identifiable information.
Practical impact for everyday readers and businesses
For everyday consumers, this update will not directly change the services they use. It does reflect a trend: AI agents are moving from "answering questions" to "operating systems directly". For businesses and development teams on Google Cloud, if Google's description holds, teams could ask agents in natural language to help investigate issues, schedule queries or check permissions, without packaging the CLI themselves.
According to Google Cloud, getting started takes three steps. First, enable the Cloud CLI Execution API (cloudcli.googleapis.com) in a project. Next, grant the agent or user the MCP Tool User (roles/mcp.toolUser) IAM role. Finally, connect an MCP client to cloudcli.googleapis.com/mcp. Google Cloud says platforms hosted on Google Cloud can use keyless Agent Identity, while external runtime environments use OAuth 2.0. Because the server is still in preview, features and terms may change.
Frequently asked questions
What is MCP?
MCP stands for Model Context Protocol, a standard protocol that lets AI agents connect to external tools. Google Cloud says this server implements standard MCP, so any MCP-compatible agent platform can connect using a standard configuration.
Does this service cost money?
Google Cloud says there is no extra charge for using the MCP server itself. Users pay only for the GCP resources they create and any applicable data transfer fees.
How is it different from the existing BigQuery MCP server?
According to Google Cloud, the existing BigQuery MCP server focuses on data analysis and exploration. The new run_bq_command tool extends to more advanced tasks such as scheduled queries, query execution details, reservation management and table permissions.
Could an AI agent exceed its permissions?
Google Cloud says every command runs with the permissions of the authenticated caller's identity, enforces IAM and organization policy constraints, and can be paired with Model Armor and audit logs. However, these are Google's claims, and the actual risk still depends on how businesses configure permissions.
Can it be used in production now?
Google Cloud says the server is currently in public preview. Features may change during the preview, so businesses are advised to evaluate it first and trial it in test environments.
Browse the latest news in this topic
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Lifestyle
Google unveils Gemini 4 Argon: cyber defenders get it first, everyone else still has to wait
On September 30, 2026, Google announced Gemini 4 Argon, which it calls its new frontier (most advanced) AI model. For now it is available only to trusted cyber defenders through the Fairwind Program. Here is what Google says the model can do, what it will cost developers, how Google says it is managing the risks, and what it means for everyday users. All figures come from Google itself.
Lifestyle
NVIDIA: CoreWeave Begins Offering Vera Rubin NVL72, With Cognition as First Production Customer
According to the NVIDIA blog, AI cloud provider CoreWeave now offers NVIDIA's next-generation Vera Rubin NVL72 systems, plans to offer the Vera CPU and launched CoreWeave Forge. This matters mainly to companies building AI agents, and could eventually mean faster AI tools for everyday users.
Lifestyle
Google Cloud makes Spanner Omni generally available: its Spanner database can now run in companies' own data centers and on other clouds
Google Cloud says Spanner Omni, a version of its Spanner database that businesses run themselves, is now ready for real-world use in their own data centers, on other clouds or on a laptop. This matters to organizations that want Spanner outside Google Cloud, but they take on the running of it. Here are the features, licences and trade-offs Google Cloud describes.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family