The Core Update
Before, exposing enterprise REST APIs to AI agents meant building dedicated Model Context Protocol (MCP) servers. This duplicated authentication, routing, and quota logic from existing gateways. Google Cloud API Gateway now changes that directly. It can serve your existing REST operations as agent-ready MCP tools. This feature is currently in Public Preview. You no longer need separate MCP servers to build or maintain. Your APIs become discoverable by frameworks like the Agent Development Kit (ADK) and Gemini Enterprise, which natively understand MCP.Official Source: Google Announcement
Technical Impact & Mechanism
This update simplifies how AI agents interact with your services. API Gateway now accepts standard MCP JSON-RPC requests. It transcodes these requests into the correct REST calls. Your existing API policies remain active. JWT or API-key authentication, quota enforcement, and logging all work unchanged. Both MCP and REST traffic share the same policy path. A single quota allocation covers all invocation types.To enable this, you modify your OpenAPI specification. Add x-google-api-management: mcp: true at the root. Then, for specific operations, use x-google-mcp-tool to define the agent-facing tool. This includes a name and a critical description. The LLM uses this description to decide when to invoke your tool.
openapi: 3.0.4
info:
title: Order Service
version: 1.0.0
x-google-api-management:
mcp: true # Expose operations as MCP tools
backends:
orders-backend:
address: https://orders-a1b2c3-uc.a.run.app
paths:
/orders/{orderId}:
get:
operationId: getOrderStatus
description: Returns status, carrier, and ETA for an order.
x-google-backend: orders-backend
x-google-mcp-tool:
name: get_order_status
description: "Check delivery status and ETA for a customer order. Use this when a user asks about an order's location or arrival time."
parameters:
- name: orderId
in: path
required: true
schema:
type: string
Deploy this OpenAPI config to your API Gateway. It generates an MCP-aware setup automatically. MCP endpoints become active under the /mcp base path.
For production, secure your tool discovery. The tools/list endpoint exposes tool names and schemas. By default, it's unauthenticated. Require a JWT for discovery in production using x-google-api-management: mcp: tools-list: security:. Note: API keys do not secure discovery itself. tools/call always respects the underlying REST operation's authentication.
This solution is ideal for Cloud Run services needing quick agent exposure. For broader enterprise API management needs, Apigee remains the platform. If you manage outbound LLM calls, Agent Gateway is still the right tool.
Action Plan for Developers & Businesses
- Identify APIs: Pinpoint your existing REST APIs and specific operations agents could leverage. Focus on distinct business capabilities.
- Update OpenAPI Spec: Add
x-google-api-managementandx-google-mcp-toolannotations. Craft clear, concise tool descriptions for LLM selection logic. - Deploy to API Gateway: Update your API Gateway configuration. This publishes your MCP tools. Verify the
/mcpbase path. - Secure Discovery: Implement JWT authentication for the
tools/listendpoint in production environments. Default unauthenticated discovery is fine for dev.
Need help architecting your digital systems for AI integration? Or want to optimize your cloud spend? Let's talk strategy.
Explore Case Studies & Work Contact Waleed