Google Cloud MCP servers roles and permissions

This page lists the IAM roles and permissions for Google Cloud MCP servers. To search through all roles and permissions, see the role and permission index.

Google Cloud MCP servers roles

Role Permissions

(roles/mcp.toolUser)

Gives permission to call tools on any MCP server enabled by the parent project.

mcp.tools.call

resourcemanager.projects.get

resourcemanager.projects.list

Google Cloud MCP servers permissions

Permission Included in roles

Owner (roles/owner)

Editor (roles/editor)

Gemini Cloud Assist User (roles/geminicloudassist.user)

MCP Tool User (roles/mcp.toolUser)

Service agent roles