getunblocked.com/integrations/google-cloud-mcp

Connect Google Cloud with Unblocked to give AI agents live infrastructure context

Unblocked integrates with Google Cloud MCP so AI coding agents and developers can query Compute, Cloud Logging, and Cloud Monitoring in your projects — read-only, keyless, and reconciled with the code and pull requests behind what they find.

Google Cloud MCP integration details

Category
Incident & monitoring
Live-queried data
Compute, Cloud Logging, Cloud Monitoring
Supported products
Google Cloud
Works with
Claude Code, Cursor, Windsurf, GitHub Copilot, Codex, OpenCode, VS Code — via one MCP server connection
Content reviewed

What the Google Cloud MCP integration adds

Answering a question about a running system usually means leaving the editor for the Google Cloud Console. Unblocked connects to Google’s native MCP services so an agent can ask your project directly — what instances exist, what the logs say, what the metrics show — instead of reasoning from a stale screenshot pasted into the conversation.

This is live access, not an index: every request is made against your project at the moment the question is asked, through read-only tools only. Unblocked reconciles what comes back with your code, pull requests, tickets, and incidents, so an agent can move from a log line to the change that produced it.

Access is granted through Workload Identity Federation. Unblocked never holds a service-account key or any other long-lived Google credential, and you choose which of the Compute, Logging, and Monitoring services it may query.

Once connected, any MCP-compatible coding agent — Claude Code, Cursor, Windsurf, GitHub Copilot, Codex — can reach this context through a single Unblocked MCP server connection.

What you get

  • Live Compute, Logging, and Monitoring — Agents query your Google Cloud project as it is right now through Google’s native MCP services, rather than an index that was built hours ago.
  • Keyless access — Workload Identity Federation trusts one Unblocked AWS role to impersonate a service account you create, so no Google service-account key or other long-lived credential is ever shared.
  • Read-only, service-scoped — Only read-only tools are exposed, and only from the services you select — enable Compute, Logging, and Monitoring, or just the one you need.
  • Cross-source synthesis — Live cloud answers are combined with your code, pull requests, incidents, and Slack threads, so a symptom in production leads to the change behind it.

How to connect Google Cloud MCP to Unblocked

Need screenshots or troubleshooting?This is a concise connection summary. Follow the complete setup guide ↗

Prerequisites

  • An Unblocked account (free to start).
  • A Google Cloud project, and an administrator who can enable APIs, create a service account and Workload Identity Federation resources, and manage project IAM.
  • Terraform, the gcloud CLI, or access to the Google Cloud Console to complete the federation setup — all three paths are documented.
  • An MCP-compatible coding agent (Claude Code, Cursor, Windsurf, etc.) to use the context in your editor.

Step 1: Connect Google Cloud MCP to Unblocked

  1. In Google Cloud, create the service account and Workload Identity Federation resources Unblocked will use, with Terraform, the gcloud CLI, or the Google Cloud Console.
  2. Note the two values the setup produces: the service account email and the Workload Identity Provider resource name.
  3. In Unblocked, go to Settings → Data Sources → Connect another data source, and select Google Cloud MCP.
  4. Paste both values into the connection form and click Connect.
  5. Select the Google Cloud MCP services Unblocked can query — Compute, Logging, Monitoring — and click Save Settings.

The Unblocked AWS account and broker role in the setup are fixed values supplied by Unblocked; the Google-side service account, pool, and provider can be renamed to match your conventions.

Step 2: Install the Unblocked MCP server

On macOS or Linux, one command auto-detects and configures your supported agents (Claude Code, Cursor, Windsurf, GitHub Copilot, Codex, OpenCode, VS Code):

curl -fsSL https://getunblocked.com/install-mcp.sh | bash

On Windows, or when you prefer remote MCP, add the server manually using the configuration below, or follow the manual install guide ↗.

Claude Code

Add the remote server, then run /mcp in Claude Code, select unblocked, and log in via OAuth:

claude mcp add -s user --transport http unblocked https://getunblocked.com/api/mcpsse

Cursor

Open View: Open MCP Settings → Add Custom MCP, add the server, then click Connect to authenticate via OAuth:

{
  "mcpServers": {
    "unblocked": {
      "url": "https://getunblocked.com/api/mcpsse"
    }
  }
}

Other MCP clients

Any MCP-compatible client (Windsurf, Codex, VS Code, Claude Desktop, and others) can connect to the remote server with OAuth:

https://getunblocked.com/api/mcpsse

Connect Google Cloud MCP to Claude Code, Cursor, and other AI agents

To give Claude Code, Cursor, GitHub Copilot, Codex, or another MCP-compatible AI coding agent access to Google Cloud MCP context, connect Google Cloud MCP to Unblocked and add the single Unblocked MCP server to your agent.

Unblocked acts as the MCP context layer for your Google Cloud MCP data, searching Compute, Cloud Logging, Cloud Monitoring alongside your other connected sources and returning cited results through these tools:

  • gcp_mcpLists the read-only tools available from the Google Cloud MCP services you selected, then runs one against your project on request — returning live Compute, Logging, or Monitoring results to the agent.

Questions to ask an AI agent about Google Cloud MCP

Questions you (or your agent) can ask Unblocked about your Google Cloud MCP data:

  • Which Compute instances are running in this project, and how are they sized?
  • What errors did Cloud Logging record for the ingest service in the last hour?
  • Is CPU on the batch workers above its usual range this week?
  • Which recent pull request could explain the log errors on this service?

Google Cloud MCP integration FAQ

Does Unblocked need a Google service-account key?

No. Access runs through Workload Identity Federation: your project trusts a single Unblocked AWS role to impersonate a service account you create, so no service-account key or other long-lived Google credential is shared with Unblocked.

Which Google Cloud services can Unblocked query?

Compute, Cloud Logging, and Cloud Monitoring, through Google’s native MCP services. You select which of them Unblocked can query after connecting, and all read-only tools from the selected services are enabled automatically.

Can Unblocked change anything in my Google Cloud project?

No. Only read-only tools are exposed, and the service account is granted viewer-level roles, so agents can inspect resources, logs, and metrics but cannot modify them.

Is Google Cloud data indexed or queried live?

Queried live. Unlike document sources, Google Cloud MCP is not ingested into the index — each request runs against your project at the moment the question is asked and the result is cited back to the service it came from.

How do I set up Workload Identity Federation?

The documentation covers three interchangeable paths — a published Terraform module, a copy-paste gcloud CLI script, and step-by-step Google Cloud Console instructions. Each ends with the two values you enter in Unblocked.

Get started with Unblocked