MCP Reference: auditmanager.googleapis.com

Cloud Audit Manager API for MCP (Prod)

A Model Context Protocol (MCP) server acts as a proxy between an external service that provides context, data, or capabilities to a Large Language Model (LLM) or AI application. MCP servers connect AI applications to external systems such as databases and web services, translating their responses into a format that the AI application can understand.

Server Setup

You must enable MCP servers and set up authentication before use. For more information about using Google and Google Cloud remote MCP servers, see Google Cloud MCP servers overview.

Server Endpoints

An MCP service endpoint is the network address and communication interface (usually a URL) of the MCP server that an AI application (the Host for the MCP client) uses to establish a secure, standardized connection. It is the point of contact for the LLM to request context, call a tool, or access a resource. Google MCP endpoints can be global or regional.

The Audit Manager API MCP server has the following global MCP endpoints:

  • https://auditmanager.us-central1.rep.googleapis.com/mcp
  • https://auditmanager.europe-west1.rep.googleapis.com/mcp

MCP Tools

An MCP tool is a function or executable capability that an MCP server exposes to a LLM or AI application to perform an action in the real world.

Tools

The auditmanager.googleapis.com MCP server has the following tools:

MCP Tools
enroll_resource Enrolls a project in Audit Manager. This enables auditing capabilities and allows specifying eligible Cloud Storage buckets (eg. gs://...) where generated reports can be uploaded. Format: 'projects/{project}/locations/{location}'. CRITICAL: For {location}, use the location specified by the user. If no location is specified, prompt the user to provide one. Do not use 'global'. The location must match the chosen Regional Endpoint (REP) region (e.g., us-central1).
get_resource_enrollment_status Fetches the enrollment status for a project in Audit Manager. Format: 'projects/{project}/locations/{location}/resourceEnrollmentStatuses/-'. CRITICAL: For {location}, use the location specified by the user. If no location is specified, prompt the user to provide one. Do not use 'global'. The location must match the chosen Regional Endpoint (REP) region (e.g., us-central1).
generate_audit_report Registers a report generation request for a compliance framework. Returns a long-running operation ID. Scope format: 'projects/{project}/locations/{location}'. CRITICAL: For {location}, use the location specified by the user. If no location is specified, prompt the user to provide one. Do not use 'global'. The location must match the chosen Regional Endpoint (REP) region (e.g., us-central1). Framework format: 'organizations/{org}/locations/{location}/frameworks/{id}' or 'projects/{project}/locations/{location}/frameworks/{id}'. Example IDs: 'builtin-aipp', 'builtin-security-essentials'. If 'complianceFramework' is unknown, prompt the user for it. Suggest they list frameworks via: 'gcloud compliance-manager frameworks list --project={project} --location=global' or 'gcloud compliance-manager frameworks list --organization={organization_id} --location=global'
get_audit_report Gets the full metadata of an audit report and its control level summary. Format: 'projects/{project}/locations/{location}/auditReports/{auditReportId}'. CRITICAL: For {location}, use the location specified by the user. If no location is specified, prompt the user to provide one. Do not use 'global'. The location must match the chosen Regional Endpoint (REP) region (e.g., us-central1).
list_audit_reports Lists the audit reports for the specified parent scope. Format: 'projects/{project}/locations/{location}'. CRITICAL: For {location}, use the location specified by the user. If no location is specified, prompt the user to provide one. Do not use 'global'. The location must match the chosen Regional Endpoint (REP) region (e.g., us-central1). * Filter or review the returned list of audit reports as needed based on the user's request.
generate_audit_scope_report Generates an audit scope report for the given compliance framework. Based on assets present in the selected scope and predefined compliance checks for given compliance controls, this generates an audit task breakdown against required compliance controls. Scope format: 'projects/{project}/locations/{location}'. CRITICAL: For {location}, use the location specified by the user. If no location is specified, prompt the user to provide one. Do not use 'global'. The location must match the chosen Regional Endpoint (REP) region (e.g., us-central1). Framework format: 'organizations/{org}/locations/{location}/frameworks/{id}' or 'projects/{project}/locations/{location}/frameworks/{id}'. Example IDs: 'builtin-aipp', 'builtin-security-essentials'. If 'complianceFramework' is unknown, prompt the user for it. Suggest they list frameworks via: 'gcloud compliance-manager frameworks list --project={project} --location=global' or 'gcloud compliance-manager frameworks list --organization={organization_id} --location=global'
get_operation Gets the latest state of a long-running operation (e.g., returned by 'generate_audit_report'). Use this to poll the operation returned by generate_audit_report. Format: 'projects/{project}/locations/{location}/operationIds/{operation_id}'. CRITICAL: For {location}, use the location specified by the user. If no location is specified, prompt the user to provide one. Do not use 'global'. The location must match the chosen Regional Endpoint (REP) region (e.g., us-central1). CRITICAL: The generate_audit_report tool returns operations with /operations/ in the response. Ensure to replace /operations/ with /operationIds/ before calling this tool.

Get MCP tool specifications

To get the MCP tool specifications for all tools in an MCP server, use the tools/list method. The following example demonstrates how to use curl to list all tools and their specifications currently available within the MCP server.

Curl Request
curl --location 'https://auditmanager.us-central1.rep.googleapis.com/mcp' \
--header 'content-type: application/json' \
--header 'accept: application/json, text/event-stream' \
--data '{
    "method": "tools/list",
    "jsonrpc": "2.0",
    "id": 1
}'