Verified Google-managed MCP inventory

Google MCP Provider Warehouse

Aweb treats Google MCP as one governed provider family. The catalog is generated from official Google MCP supported-products documentation and the MCP Warehouse Google provider projections, with runtime access limited to reviewed read-only slices.

Executable runtime34L0/L1 governed read-only slices
Catalog only18Official but not callable yet
Observed catalog-only18Tool names sampled or reference-listed
Official-reference12Workspace tool lists from Google docs
Pending discovery0No reviewed live snapshot yet
Executable tools166No writes or destructive tools
Observed tools707All official entries combined

Official Source Boundary

The official count is not a marketing claim and is not inferred from community MCP projects. Aweb currently verifies 52 entries from Google Cloud MCP supported products.

Open Google source

Runtime Governance

1Prometheus mission
2Maestro plan
3MCP Warehouse capability routing
4Google MCP provider genome
5OS9 / Mission Contract policy gate
6Google-managed MCP invocation
7Receipt and Neon audit event
8Leonardo operator visibility

Maestro never receives direct unrestricted Google MCP access.

Generic invokeCapability fan-out has zero official Google MCP handlers.

Prometheus never calls Google MCP directly.

Aweb Code receives only L0/L1 read-only tools unless a Mission Contract approves more.

L2+ sensitive reads require a Mission Contract.

L4/L5 side-effect, destructive, IAM, billing, and production-deploy tools are disabled by default.

OAuth tokens, service account keys, and secrets are not published in docs or catalog JSON.

Risk Taxonomy

L0Safe metadata/read-only public docssafe metadata
L1Authenticated read-onlyauthenticated read
L2Sensitive readsensitive read
L3Non-destructive write candidatecandidate write
L4External side effectexternal side effect
L5Destructive, privileged, financial, or securitydestructive privileged

Inventory Summary

Groups

google cloud40

google7

google workspace5

Runtime state

registered executable34

catalog only18

Support state

read only candidate35

disabled by policy2

inventory only10

planned5

Governed Runtime Slices

These entries have registered MCP Warehouse genomes and adapters. They expose only reviewed L0/L1 tools; write, deploy, database-row, email-body, IAM, billing, and delete operations remain blocked unless later promoted through Mission Contract policy.

ServerGroupMax riskExecutable toolsMission contract
Design MCPgoogle.designGoogleL4 External side effectgenerate_color_scheme, search_icons, icons_instructions, search_fonts, describe_fontoptional public docs context
Developer Knowledge APIgoogle.developer.developer_knowledgeGoogleL0 Safe metadata/read-only public docssearch_documents, answer_query, get_documentsoptional public docs context
Maps Code Assistgoogle.maps.code_assistGoogleL3 Non-destructive write candidateretrieve-instructions, retrieve-google-maps-platform-docsoptional public docs context
Maps Grounding Litegoogle.maps.grounding_liteGoogleL2 Sensitive readsearch_places, lookup_weather, compute_routesoptional public docs context
Agent Registrygoogle.cloud.agent_registryGoogle CloudL5 Destructive, privileged, financial, or securitylist_agents, search_agents, list_mcp_servers, search_mcp_servers, list_services, get_operationread only integration scope
AlloyDB for PostgreSQLgoogle.databases.alloydbGoogle CloudL5 Destructive, privileged, financial, or securitylist_clusters, list_instances, get_operationread only integration scope
Apigee API hubgoogle.apigee.api_hubGoogle CloudL5 Destructive, privileged, financial, or securitysearch_resources, get_api, list_apis, get_version, list_versions, get_spec, list_specs, get_api_operation, list_api_operations, get_deployment, list_deployments, get_attribute, list_attributes, get_dependency, list_dependenciesread only integration scope
BigQuerygoogle.cloud.bigqueryGoogle CloudL5 Destructive, privileged, financial, or securitylist_dataset_ids, get_dataset_info, list_table_ids, get_table_inforead only integration scope
BigQuery Data Transfer Servicegoogle.cloud.bigquery_data_transferGoogle CloudL5 Destructive, privileged, financial, or securitylist_data_sources, get_data_sourceread only integration scope
Bigtablegoogle.databases.bigtableGoogle CloudL5 Destructive, privileged, financial, or securitylist_instances, get_instance, list_tables, get_tableread only integration scope
Cloud Asset Inventorygoogle.cloud.asset_inventoryGoogle CloudL5 Destructive, privileged, financial, or securitylist_assetsread only integration scope
Cloud Logginggoogle.cloud.loggingGoogle CloudL5 Destructive, privileged, financial, or securitylist_log_names, list_buckets, get_bucket, list_views, get_viewsensitive read contract
Cloud Monitoringgoogle.cloud.monitoringGoogle CloudL5 Destructive, privileged, financial, or securitylist_metric_descriptors, list_dashboards, get_dashboard, list_alert_policies, get_alert_policyread only integration scope
Cloud Product Registrygoogle.cloud.product_registryGoogle CloudL5 Destructive, privileged, financial, or securitylist_product_suites, get_product_suite, list_logical_products, get_logical_product, list_logical_product_variants, get_logical_product_variant, lookup_entity_by_nameread only integration scope
Cloud Rungoogle.cloud.runGoogle CloudL5 Destructive, privileged, financial, or securitylist_services, get_serviceread only integration scope
Cloud SQLgoogle.databases.cloud_sqlGoogle CloudL5 Destructive, privileged, financial, or securitylist_instances, get_operationread only integration scope
Cloud Storagegoogle.cloud.storageGoogle CloudL5 Destructive, privileged, financial, or securitylist_buckets, list_objects, get_object_metadataread only integration scope
Compute Enginegoogle.cloud.computeGoogle CloudL5 Destructive, privileged, financial, or securitylist_instances, get_instance_basic_info, list_instance_attached_disks, list_disks, get_disk_basic_info, get_disk_performance_config, list_machine_types, list_accelerator_types, list_images, get_zone_operationread only integration scope
Database Centergoogle.cloud.database_centerGoogle CloudL5 Destructive, privileged, financial, or securitylist_products, list_fleet_inventory, list_fleet_health_issues, list_fleet_issues, list_fleet_resource_groupsread only integration scope
Database Migration Servicegoogle.cloud.database_migration_serviceGoogle CloudL5 Destructive, privileged, financial, or securitylist_migration_jobs, list_static_ips, get_operationread only integration scope
Datastreamgoogle.cloud.datastreamGoogle CloudL5 Destructive, privileged, financial, or securitylist_streams, list_static_ips, get_operationread only integration scope
Firestoregoogle.databases.firestoreGoogle CloudL5 Destructive, privileged, financial, or securitylist_databases, get_database, list_indexes, get_indexread only integration scope
Gemini Enterprise Agent Platformgoogle.ai.gemini_enterprise_agent_platformGoogle CloudL5 Destructive, privileged, financial, or securityget_endpoint, list_endpoints, list_models, get_model, get_operationread only integration scope
GKEgoogle.cloud.gkeGoogle CloudL5 Destructive, privileged, financial, or securitylist_clusters, get_cluster, list_operations, get_operation, list_node_pools, get_node_poolread only integration scope
Knowledge Cataloggoogle.cloud.dataplex_knowledge_catalogGoogle CloudL5 Destructive, privileged, financial, or securitysearch_entries, list_data_products, get_data_product, list_data_assets, get_data_asset, lookup_context, lookup_entry, get_operationread only integration scope
Managed Service for Apache Airflowgoogle.cloud.composerGoogle CloudL5 Destructive, privileged, financial, or securitylist_environments, get_operationread only integration scope
Managed Service for Apache Kafkagoogle.cloud.managed_kafkaGoogle CloudL5 Destructive, privileged, financial, or securityget_cluster, list_clusters, get_operation, get_topic, list_topics, get_consumer_group, list_consumer_groups, get_connect_cluster, list_connect_clusters, get_connector, list_connectorsread only integration scope
Managed Service for Apache Sparkgoogle.cloud.dataprocGoogle CloudL5 Destructive, privileged, financial, or securitylist_clusters, get_cluster, get_operationread only integration scope
Memorystoregoogle.databases.memorystoreGoogle CloudL5 Destructive, privileged, financial, or securitylist_instances, get_instance, list_clusters, get_cluster, list_backup_collections, get_backup_collection, list_backups, get_backupread only integration scope
Network Intelligence Centergoogle.cloud.network_intelligence_centerGoogle CloudL5 Destructive, privileged, financial, or securitylist_connectivity_tests, get_connectivity_testread only integration scope
Oracle Database@Google Cloudgoogle.databases.oracle_databaseGoogle CloudL5 Destructive, privileged, financial, or securitylist_autonomous_databases, list_exadata_infrastructures, list_db_servers, list_cloud_vm_clusters, list_exascale_db_storage_vaults, list_exadb_vm_clusters, list_db_systems, list_odb_networks, list_odb_subnets, get_operationread only integration scope
Pub/Subgoogle.cloud.pubsubGoogle CloudL5 Destructive, privileged, financial, or securitylist_topics, get_topic, list_subscriptions, get_subscription, list_snapshots, get_snapshotread only integration scope
Resource Managergoogle.cloud.resource_managerGoogle CloudL5 Destructive, privileged, financial, or securitysearch_projectsread only integration scope
Spannergoogle.databases.spannerGoogle CloudL5 Destructive, privileged, financial, or securitylist_instances, get_instance, list_configs, get_config, list_databases, get_database_ddl, get_operationread only integration scope

Catalog-Only Official Entries

These servers are official Google-managed MCP entries but are not callable in Aweb yet. Tool names may be visible where safe discovery sampled them; full schema capture, risk mapping, fixtures, and policy tests are required before runtime registration.

ServerGroupStatusObserved toolsSupport state
Android Management APIgoogle.android.managementGoogleofficial supported-products row, no explicit lifecycle badge9Disabled by policy
Google Pay and Walletgoogle.payments_wallet.pay_walletGooglePreview10Disabled by policy
Stitchgoogle.stitchGoogleBeta14Inventory only
Agent Searchgoogle.ai.agent_searchGoogle Cloudofficial supported-products row, no explicit lifecycle badge2Inventory only
App Lifecycle Managergoogle.cloud.app_lifecycle_managerGoogle CloudPreview40Read-only candidate
BigQuery Migration Servicegoogle.cloud.bigquery_migrationGoogle Cloudofficial supported-products row, no explicit lifecycle badge5Inventory only
Cloud Tracegoogle.cloud.traceGoogle Cloudofficial supported-products row, no explicit lifecycle badge2Inventory only
Customer Experience Agent Studiogoogle.cloud.customer_experience_agent_studioGoogle Cloudofficial supported-products row, no explicit lifecycle badge60Inventory only
Database Insightsgoogle.cloud.database_insightsGoogle Cloudofficial supported-products row, no explicit lifecycle badge2Inventory only
Error Reportinggoogle.cloud.error_reportingGoogle Cloudofficial supported-products row, no explicit lifecycle badge1Inventory only
Filestoregoogle.cloud.filestoreGoogle Cloudofficial supported-products row, no explicit lifecycle badge8Inventory only
Gemini Cloud Assistgoogle.ai.gemini_cloud_assistGoogle CloudPreview5Inventory only
Google Security Operationsgoogle.cloud.security_operationsGoogle Cloudofficial supported-products row, no explicit lifecycle badge68Inventory only
Calendargoogle.workspace.calendarGoogle WorkspaceDeveloper Preview8Planned
Chatgoogle.workspace.chatGoogle WorkspaceDeveloper Preview4Planned
Drivegoogle.workspace.driveGoogle WorkspaceDeveloper Preview8Planned
Gmailgoogle.workspace.gmailGoogle WorkspaceDeveloper Preview12Planned
People APIgoogle.workspace.peopleGoogle WorkspaceDeveloper Preview3Planned

Workspace OAuth Boundary

Gmail, Drive, Calendar, Chat, and People are official Workspace MCP servers, but Aweb keeps them catalog-only until OS9-bound user OAuth subject binding, revocation, credential-boundary receipts, adapters, schema fixtures, and sanitizer tests are in place.

Runtime

Statusrequired not implemented

Evidence lanesevidence lanes ready runtime blocked

Runtime-enabled Workspace providers0

Runtime promotion allowedNo

Tool classes

L1 metadata candidates5

L2+ blocked tools30

Official setup

Workspace MCP providers5

Open Workspace MCP configuration

Subject binding

Runtime enabledNo

Revocation receiptsRequired

Runtime-review readinessRequired

Prior revoked bindingRequired

Submitted booleans trustedNo

Implemented evidence lanes6

Disabled runtime lanes7

ServerPlanning-only L1 candidates
Drivegoogle.workspace.driveget_file_metadata, list_recent_files, search_files
Gmailgoogle.workspace.gmaillist_labels
Calendargoogle.workspace.calendarlist_calendars
Chatgoogle.workspace.chatNone yet
People APIgoogle.workspace.peopleNone yet

All Official Google MCP Servers

Design MCPGoogleGoverned read-only runtime / L4 External side effectDeveloper Knowledge APIGoogleGoverned read-only runtime / L0 Safe metadata/read-only public docsMaps Code AssistGoogleGoverned read-only runtime / L3 Non-destructive write candidateMaps Grounding LiteGoogleGoverned read-only runtime / L2 Sensitive readAgent RegistryGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityAlloyDB for PostgreSQLGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityApigee API hubGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityBigQueryGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityBigQuery Data Transfer ServiceGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityBigtableGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCloud Asset InventoryGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCloud LoggingGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCloud MonitoringGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCloud Product RegistryGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCloud RunGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCloud SQLGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCloud StorageGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityCompute EngineGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityDatabase CenterGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityDatabase Migration ServiceGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityDatastreamGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityFirestoreGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityGemini Enterprise Agent PlatformGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityGKEGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityKnowledge CatalogGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityManaged Service for Apache AirflowGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityManaged Service for Apache KafkaGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityManaged Service for Apache SparkGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityMemorystoreGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityNetwork Intelligence CenterGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityOracle Database@Google CloudGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityPub/SubGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityResource ManagerGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securitySpannerGoogle CloudGoverned read-only runtime / L5 Destructive, privileged, financial, or securityAndroid Management APIGoogleCatalog only / L5 Destructive, privileged, financial, or securityGoogle Pay and WalletGoogleCatalog only / L5 Destructive, privileged, financial, or securityStitchGoogleCatalog only / L4 External side effectAgent SearchGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityApp Lifecycle ManagerGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityBigQuery Migration ServiceGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityCloud TraceGoogle CloudCatalog only / L2 Sensitive readCustomer Experience Agent StudioGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityDatabase InsightsGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityError ReportingGoogle CloudCatalog only / L4 External side effectFilestoreGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityGemini Cloud AssistGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityGoogle Security OperationsGoogle CloudCatalog only / L5 Destructive, privileged, financial, or securityCalendarGoogle WorkspaceCatalog only / L5 Destructive, privileged, financial, or securityChatGoogle WorkspaceCatalog only / L5 Destructive, privileged, financial, or securityDriveGoogle WorkspaceCatalog only / L5 Destructive, privileged, financial, or securityGmailGoogle WorkspaceCatalog only / L5 Destructive, privileged, financial, or securityPeople APIGoogle WorkspaceCatalog only / L5 Destructive, privileged, financial, or security

Explicit Non-Official Findings

Cloud Build

Not present in the verified Google-managed MCP supported-products list; do not expose as an official Google MCP server until Google lists it.

Artifact Registry

Not present in the verified Google-managed MCP supported-products list; do not expose as an official Google MCP server until Google lists it.

Aweb Gmail REST adapter

The local `gmail` provider is not the Google-managed Gmail MCP endpoint. The official Gmail MCP entry is `google.workspace.gmail` and remains catalog-only until user OAuth and Mission Contract controls are complete.

Aweb Drive REST adapter

The local `google_drive` provider is not the Google-managed Drive MCP endpoint. The official Drive MCP entry is `google.workspace.drive` and remains catalog-only until user OAuth and Mission Contract controls are complete.

Aweb GCP Inventory wrapper

The local `gcp_inventory` provider is a Warehouse-native Google Cloud inventory wrapper, not a Google-managed remote MCP server and not part of the 51-entry official Google MCP count.

Request Access

Google MCP access starts as an OS9 access request, not an OAuth launch. Operators choose the required risk tier, review scopes or IAM roles, bind the request to a Mission Contract, and only then issue eligible approvals for runtime use. Side-effect approvals are source-run-bound from a live blocked Maestro run, and destructive Google MCP approvals are not issued by the standard OS9 route. The access-plan API prepares the approval shape without issuing authority or executing Google tools.

Select Google MCP family and provider scope.Choose read-only, sensitive read, candidate write, or side-effect tier.Review Google APIs, OAuth scopes, or IAM roles.Create exact OS9 evidence; use run-bound approval only for side effects.

Catalog Integration

The same projection is available at /api/v2/integrations/google-mcp and is also embedded in /api/v2/integrations/catalog under googleMcp. Access requests are planned at /api/v2/integrations/google-mcp/access-request before any OS9 approval token, OAuth credential, or Google MCP runtime is used. General provider cards route Google MCP entries here so the public catalog cannot imply unrestricted Gmail, Drive, Cloud, database, IAM, billing, or deploy access.