Google Cloud remote MCP servers let you use Identity and Access Management (IAM) to enforce fine-grained authorization across your resource hierarchy. You can configure access at the project or individual resource level to control tool use based on resource tags and read-only or read-write permissions.
You can't use IAM to control access to non-Google Cloud MCP servers.
For detailed information about IAM and its features, see IAM overview.
Grant access
Grant a principal the Tool User role on a project.
In the Google Cloud console, go to the IAM page.
Select your project.
Click Grant access.
Enter an identifier for the principal. For example,
my-app@example.com.From the Select a role drop-down menu, search for Tool User, and then click Tool User.
Click Save.
Verify that the principal and the corresponding role are listed in the IAM page.
You have successfully granted an IAM role to a principal.
To learn more about other management access tasks, such as revoking IAM roles or granting multiple IAM roles, see Manage access to projects, folders, and organizations in the IAM documentation.
Identity and Access Management conditions
Google Cloud remote MCP servers support IAM Conditions. Identity and Access Management conditions let you define and enforce conditional, attribute-based access control. This means you can grant access to principals only if specified conditions are met, such as the time of the request, the resource name, the resource type, or the tags attached to the resource.
You can use IAM Conditions in the following places:
- Allow policy role bindings, including role bindings managed by Privileged Access Manager entitlements
- Deny policy rules
- Policy bindings for principal access boundary policies
For more information, see the Attribute reference for Identity and Access Management Conditions.
Google Cloud MCP servers roles and permissions
The following sections describe the IAM roles required for interacting with and controlling the use of Google Cloud MCP servers.
Roles
In order to use MCP tools, the tool caller must be granted the Tool User
(roles/mcp.toolUser) role on the Google Cloud project, as well as the required
roles for any Google Cloud products or services that you access.
Permissions
The following permissions are required to access Google Cloud services through MCP:
mcp.tools.call