mcp-gcloud-adc-proxy
An auth proxy that forwards requests to remote MCP servers, attaching Google Cloud ADC tokens for authentication. It enables secure access to IAM-protected services like Cloud Run.
README
mcp-gcloud-adc-proxy
An auth proxy for accessing remote MCP servers using Google Cloud Application Default Credentials (ADC)
Overview
This tool runs as a stdio MCP server and forwards all requests to a remote MCP server, automatically attaching an Authorization header with a Google Cloud Application Default Credentials (ADC) token.
It allows you to connect to remote MCP servers hosted on IAM-protected services such as Cloud Run.
Usage
Prerequisites
You need to configure Google Cloud authentication. Choose one of the following methods:
# Method 1: User authentication using gcloud CLI
gcloud auth application-default login
# Method 2: Using service account key
export GOOGLE_APPLICATION_CREDENTIALS="path/to/service-account.json"
See the Google Cloud documentation for more details.
Basic Usage
# Start MCP proxy
npx mcp-gcloud-adc-proxy --url https://your-cloud-run-service.run.app
# With service account impersonation
npx mcp-gcloud-adc-proxy --url https://your-cloud-run-service.run.app --impersonate-service-account sa@project.iam.gserviceaccount.com
# With custom audience
npx mcp-gcloud-adc-proxy --url https://your-cloud-run-service.run.app --audiences https://example.com
Service Account Impersonation
You can use service account impersonation to generate ID tokens for a specific service account instead of using the default ADC credentials:
npx mcp-gcloud-adc-proxy \
--url https://your-cloud-run-service.run.app \
--impersonate-service-account your-sa@your-project.iam.gserviceaccount.com
Requirements:
- The ADC principal must have the
roles/iam.serviceAccountTokenCreatorrole on the target service account - The target service account must have the necessary permissions to access the remote MCP server
Forwarding the original user's identity
When impersonation is enabled and --forward-impersonator-token is passed,
the proxy also attaches an X-Impersonator-Id-Token header containing an ID token
of the original ADC user (the human who ran the proxy), in addition to the
impersonated service account token in Authorization.
npx mcp-gcloud-adc-proxy \
--url https://your-cloud-run-service.run.app \
--impersonate-service-account your-sa@your-project.iam.gserviceaccount.com \
--forward-impersonator-token
This lets a remote MCP server that authenticates via the service account still
learn who the real caller is (e.g. to scope per-user permissions). It is off by
default; without the flag, only the service account token is sent. The header is
attached only when the ADC is a user credential (gcloud auth application-default login); it is omitted for service-account keys and other non-user credentials.
If the original user's token cannot be obtained, the request still proceeds
without the header.
Custom Audience
By default, the target URL is used as the audience for the ID token. You can override this with the --audiences option:
npx mcp-gcloud-adc-proxy \
--url https://your-cloud-run-service.run.app \
--audiences https://custom-audience.example.com
Setup to Claude Code
# Add to user scope (available across all projects)
claude mcp add foobar -s user -- npx -y mcp-gcloud-adc-proxy -u https://foobar.run.app
# Or add to project scope to share with your team
claude mcp add foobar -s project -- npx -y mcp-gcloud-adc-proxy -u https://foobar.run.app
# With service account impersonation
claude mcp add foobar -s user -- npx -y mcp-gcloud-adc-proxy -u https://foobar.run.app --impersonate-service-account sa@project.iam.gserviceaccount.com
License
Apache 2.0 License
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.