Google Cloud API Gateway MCP (24 Sep 2026): Buyer Checklist for Turning REST APIs into Agent Tools
Verdict: Google’s 24 Sep 2026 announcement that Google Cloud API Gateway can act as a remote MCP server in Public Preview matters if you already front Cloud Run (or similar) REST APIs with API Gateway — and you want agents to call those operations without standing up a separate MCP host. Treat it as a buyer checklist for platform and security teams on Google Cloud, not a reason to rewrite every API overnight. For full API lifecycle/monetization, Google still points heavier needs to Apigee; for outbound agent egress control, see Agent Gateway.
Best for: Teams with OpenAPI 3.x APIs on API Gateway who want MCP tools/list and tools/call on the same policy path as REST.
Not for: Orgs still on OpenAPI 2.0 specs (unsupported for MCP) or those expecting MCP resources/prompts/streaming on day one of Preview.
News summary based on the Google Developers Blog post dated 24 Sep 2026 and related API Gateway docs — Preview limits and metering can change. Confirm live in Google Cloud documentation and your billing account. Do not invent dollar add-ons.
What was announced
On 24 September 2026, Google engineers announced that API Gateway can expose REST operations as MCP tools by annotating an OpenAPI 3.0.x/3.1.x spec (x-google-api-management.mcp, per-operation x-google-mcp-tool), deploying as usual, and serving MCP under a /mcp base path. JSON-RPC tools/call is transcoded into the existing REST request so JWT/API-key auth, quotas, and logging stay shared. Discovery (tools/list) defaults to open for convenience — production should require JWT (API keys cannot secure discovery). Clients such as ADK can point an MCP toolset at the gateway URL.
Buyer checklist
- Contract / SKU fit: Confirm MCP Preview is available on your API Gateway usage and region — do not invent a separate public MCP surcharge; validate any bill impact in Cloud Billing against existing Gateway meters.
- Spec readiness: Migrate OpenAPI 2.0 → 3.x first; ensure each exposed operation has a backend and a non-empty, LLM-friendly description.
- Identity & least privilege: Lock down
tools/listwith JWT; keeptools/callon the same auth as REST; separate sandbox vs production gateways. - Quota & abuse: Remember MCP and REST share one quota allocation per operation — model agent fan-out so humans are not starved.
- Write actions: Allowlist which tools may mutate state; require human approval for irreversible deletes/refunds.
- Platform choice: API Gateway for lightweight on-ramps; Apigee for full lifecycle; Agent Gateway for outbound agent control.
- Preview limits: No resources/prompts/streaming yet; 204s skipped; tool caps and no MCP+model-routing combo in one config — read current docs.
- Success metric: Pilot one read-only tool for two weeks before enabling writes.
Pricing note
The announcement does not publish a new standalone dollar price for “MCP on API Gateway.” Budget from your existing API Gateway (and related Google Cloud) consumption, agent runtime tokens, and engineering time to annotate specs. Do not invent an MCP add-on line item — confirm live packaging and Preview terms with Google Cloud docs/sales.
Who should act this week
Platform owners on API Gateway should prototype in non-prod. Security must review discovery auth before public egress. Procurement should confirm Preview coverage under current agreements without assuming net-new SKUs.
Bottom line
Best for Google Cloud teams who want REST→MCP without operating a side server. Not for teams on OpenAPI 2.0 or those needing full MCP resources/streaming today. Read the 24 Sep 2026 announcement, run the checklist above, and confirm live Preview limits before enabling write tools in production.
