Policy Troubleshooter MCP Server provides tools to troubleshoot Google Cloud IAM access issues.
A Model Context Protocol (MCP) server acts as a proxy between an external service that provides context, data, or capabilities to a Large Language Model (LLM) or AI application. MCP servers connect AI applications to external systems such as databases and web services, translating their responses into a format that the AI application can understand.
Server Setup
You must enable MCP servers and set up authentication before use. For more information about using Google and Google Cloud remote MCP servers, see Google Cloud MCP servers overview.
Server Endpoints
An MCP service endpoint is the network address and communication interface (usually a URL) of the MCP server that an AI application (the Host for the MCP client) uses to establish a secure, standardized connection. It is the point of contact for the LLM to request context, call a tool, or access a resource. Google MCP endpoints can be global or regional.
The Policy Troubleshooter API MCP server has the following global MCP endpoint:
- https://policytroubleshooter.googleapis.com/mcp
MCP Tools
An MCP tool is a function or executable capability that an MCP server exposes to a LLM or AI application to perform an action in the real world.
Tools
The policytroubleshooter.googleapis.com MCP server has the following tools:
| MCP Tools | |
|---|---|
troubleshoot_access |
Analyzes Google Cloud IAM policies to diagnose why a principal has or does not have a specific permission on a resource. This tool examines allow policies, deny policies, and principal access boundary (PAB) policies that impact the principal's access. Use this tool when a user or service account is unexpectedly denied access to a Google Cloud resource, or to verify that a principal has been granted a specific permission. Do not use this tool for troubleshooting Cloud Storage Access Control Lists (ACLs). For diagnosing VPC Service Controls violations, use the VPC Service Controls violation analyzer (https://docs.cloud.google.com/vpc-service-controls/docs/violation-analyzer) instead. This tool requires the following parameters:
The tool returns an explanation of how the applicable IAM policies affect the final access state. |
troubleshoot_iam_error_id |
Checks the access request associated with the error identifier and explains why the access is blocked by IAM policies. If the error ID is not found by the backend, retry using an exponential backoff strategy. Start with an initial delay of If you are an agent that does not have the capability to wait or understand time, do not retry. Instead, return an error stating that waiting is required to retry finding the error ID, but your environment does not support waiting or tracking time. |
Get MCP tool specifications
To get the MCP tool specifications for all tools in an MCP server, use the tools/list method. The following example demonstrates how to use curl to list all tools and their specifications currently available within the MCP server.
| Curl Request |
|---|
curl --location 'https://policytroubleshooter.googleapis.com/mcp' \ --header 'content-type: application/json' \ --header 'accept: application/json, text/event-stream' \ --data '{ "method": "tools/list", "jsonrpc": "2.0", "id": 1 }' |