mcp-gcloud-adc-proxy
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-gcloud-adc-proxylist all Cloud Run services"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-gcloud-adc-proxy
An auth proxy for accessing remote MCP servers using Google Cloud Application Default Credentials (ADC)
Overview
This tool runs as a stdio MCP server and forwards all requests to a remote MCP server, automatically attaching an Authorization header with a Google Cloud Application Default Credentials (ADC) token.
It allows you to connect to remote MCP servers hosted on IAM-protected services such as Cloud Run.
Related MCP server: Unified Auth0 MCP Server
Usage
Prerequisites
You need to configure Google Cloud authentication. Choose one of the following methods:
# Method 1: User authentication using gcloud CLI
gcloud auth application-default login
# Method 2: Using service account key
export GOOGLE_APPLICATION_CREDENTIALS="path/to/service-account.json"See the Google Cloud documentation for more details.
Basic Usage
# Start MCP proxy
npx mcp-gcloud-adc-proxy --url https://your-cloud-run-service.run.app
# With service account impersonation
npx mcp-gcloud-adc-proxy --url https://your-cloud-run-service.run.app --impersonate-service-account sa@project.iam.gserviceaccount.com
# With custom audience
npx mcp-gcloud-adc-proxy --url https://your-cloud-run-service.run.app --audiences https://example.comService Account Impersonation
You can use service account impersonation to generate ID tokens for a specific service account instead of using the default ADC credentials:
npx mcp-gcloud-adc-proxy \
--url https://your-cloud-run-service.run.app \
--impersonate-service-account your-sa@your-project.iam.gserviceaccount.comRequirements:
The ADC principal must have the
roles/iam.serviceAccountTokenCreatorrole on the target service accountThe target service account must have the necessary permissions to access the remote MCP server
Forwarding the original user's identity
When impersonation is enabled and --forward-impersonator-token is passed,
the proxy also attaches an X-Impersonator-Id-Token header containing an ID token
of the original ADC user (the human who ran the proxy), in addition to the
impersonated service account token in Authorization.
npx mcp-gcloud-adc-proxy \
--url https://your-cloud-run-service.run.app \
--impersonate-service-account your-sa@your-project.iam.gserviceaccount.com \
--forward-impersonator-tokenThis lets a remote MCP server that authenticates via the service account still
learn who the real caller is (e.g. to scope per-user permissions). It is off by
default; without the flag, only the service account token is sent. The header is
attached only when the ADC is a user credential (gcloud auth application-default login); it is omitted for service-account keys and other non-user credentials.
If the original user's token cannot be obtained, the request still proceeds
without the header.
Custom Audience
By default, the target URL is used as the audience for the ID token. You can override this with the --audiences option:
npx mcp-gcloud-adc-proxy \
--url https://your-cloud-run-service.run.app \
--audiences https://custom-audience.example.comSetup to Claude Code
# Add to user scope (available across all projects)
claude mcp add foobar -s user -- npx -y mcp-gcloud-adc-proxy -u https://foobar.run.app
# Or add to project scope to share with your team
claude mcp add foobar -s project -- npx -y mcp-gcloud-adc-proxy -u https://foobar.run.app
# With service account impersonation
claude mcp add foobar -s user -- npx -y mcp-gcloud-adc-proxy -u https://foobar.run.app --impersonate-service-account sa@project.iam.gserviceaccount.comLicense
Apache 2.0 License
This server cannot be deployed
Maintenance
Related MCP Connectors
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
- ArcjetOAuthcom.arcjet
An MCP server for Arcjet - the runtime security platform that ships with your AI code.
The Remote MCP server acts as a standardized bridge between LLM applications (like Claude, ChatGPT, and Cursor) and external services, enabling AI agents to access external tools and resources. Its primary capability is providing a centralized search tool to discover other MCP servers and their respective tools. Unlike local implementations, it runs remotely with OAuth authentication and permission controls for security.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceA MCP server that requires user authentication via Auth0, allowing it to call protected APIs on behalf of authenticated users.-
- -licenseNot gradedqualityNot gradedmaintenanceAn MCP server that enables Claude Code to access Auth0-protected APIs by handling OAuth authentication flows and securely proxying API requests with user credentials.-
- FlicenseNot gradedqualityCmaintenanceA secure MCP server example that demonstrates how to deploy to Google Cloud Run with authentication and identity token protection. Serves as a tutorial template for building production-ready MCP servers in the cloud.-
- AlicenseNot gradedqualityDmaintenanceA transparent proxy server that simplifies authentication by chaining its own OAuth layer with an upstream MCP server's credentials. It manages dual token sets behind a single interface, enabling secure and streamlined access to protected MCP resources.MIT