com.googleapis.sqladmin/mcp
REMOTE · SQLADMIN.GOOGLEAPIS.COM · SCANNED AUG 3
Create, manage, and query your Google Cloud SQL resources.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (execute_sql). See how to fix → View diagnostics → Fail
- HTTPS not yet verified: we couldn't determine whether a plaintext access path exists. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability50
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 7940 tokens (~529/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 98% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · sqladmin.googleapis.com
claude mcp add --transport http com-googleapis-sqladmin-mcp https://sqladmin.googleapis.com/mcp
[mcp_servers.com-googleapis-sqladmin-mcp] url = "https://sqladmin.googleapis.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-googleapis-sqladmin-mcp": {
"type": "remote",
"url": "https://sqladmin.googleapis.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-googleapis-sqladmin-mcp --url https://sqladmin.googleapis.com/mcp --transport streamable-http
mcp_servers:
com-googleapis-sqladmin-mcp:
url: "https://sqladmin.googleapis.com/mcp" {
"mcpServers": {
"com-googleapis-sqladmin-mcp": {
"type": "http",
"url": "https://sqladmin.googleapis.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 0
- “get_operation” dropped the optional parameter “location” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 2 Aug 26 +1
- “get_operation” added an optional parameter “location” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 53
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://sqladmin.googleapis.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=upload.video.google.com | CN=WR2,O=Google Trust Services,C=US | 29 Jun 2026 | 21 Sept 2026 | ECDSA 256 | SHA256-RSA | 4ebe71b8b548f0e910486393b0d74ba7 |
| SANs: upload.video.google.com, *.clients.google.com, *.docs.google.com, *.drive.google.com, *.gdata.youtube.com, *.googleapis.com, *.photos.google.com, *.youtube-3rd-party.com, upload.google.com, *.upload.google.com, upload.youtube.com, *.upload.youtube.com and 5 more | ||||||
| CN=WR2,O=Google Trust Services,C=US (CA) | CN=GTS Root R1,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | RSA 2048 | SHA256-RSA | 7ff005a07c4cded100ad9d66a5107b98 |
| CN=GTS Root R1,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 19 Jun 2020 | 28 Jan 2028 | RSA 4096 | SHA256-RSA | 77bd0d6cdb36f91aea210fc4f058d30d |
DNSSEC insecure
Validation of sqladmin.googleapis.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| googleapis.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://sqladmin.googleapis.com/mcp | Verified | 200 | |
| http (plaintext) | http://sqladmin.googleapis.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
clone_instance ~127
Create a Cloud SQL instance as a clone of a source instance. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * The clone operation can take several minutes. Use a command line tool to pause for 30 seconds before rechecking the status.
| Name | Type | Req | Description |
|---|---|---|---|
| body | — | yes | — |
| instance | string | yes | Required. The ID of the Cloud SQL instance to be cloned (source). This does not include the project ID. |
| project | string | yes | Required. Project ID of the source Cloud SQL instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
create_backup ~126
Takes a backup on a Cloud SQL instance. Always populate the project and instance fields on the request. The location (region) and description of the backup may also be optionally provided, in which case the corresponding request fields should also be populated.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | — | Optional. The description of this backup run. |
| instance | string | yes | Required. Cloud SQL instance ID. This does not include the project ID. |
| location | string | — | Optional. Location of the backup run. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
create_instance ~1,344
Initiates the creation of a Cloud SQL instance. * The tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * The instance creation operation can take several minutes. Use a command line tool to pause for 30 seconds before rechecking the status. * After you use the `create_instance` tool to create an instance, you can use the `create_user` tool to create an IAM user account for the user currently logged in to the project. * IMPORTANT: Set `ipv4_enabled` to 'false' if creating a Private Service Connect or a Private Service Access instance. * Set `free_trial` to 'true' to create a free trial instance. Free trial instances let you test majority of Cloud SQL features for up to 30 days without financial commitment. Subject to eligibility and availability. * The value of `data_api_access` is set to `ALLOW_DATA_API` by default. This setting lets you execute SQL statements using the `execute_sql` tool and the `executeSql` API. Unless otherwise specified, a newly created instance uses the default instance configuration of a development environment. The following is the default configuration for an instance in a development environment: ``` { "tier": "db-perf-optimized-N-2", "data_disk_size_gb": 100, "region": "us-central1", "database_version": "POSTGRES_18", "edition": "ENTERPRISE_PLUS", "availability_type": "ZONAL", "tags": [{"environment": "dev"}] } ``` The following configuration is recommended for an instance in a production environment: ``` { "tier": "db-perf-optimized-N-8", "data_disk_size_gb": 250, "region": "us-central1", "database_version": "POSTGRES_18", "edition": "ENTERPRISE_PLUS", "availability_type": "REGIONAL", "tags": [{"environment": "prod"}] } ``` The following instance configuration is recommended for SQL Server: ``` { "tier": "db-perf-optimized-N-8", "data_disk_size_gb": 250, "region": "us-central1", "database_version": "SQ…
| Name | Type | Req | Description |
|---|---|---|---|
| availabilityType | string | — | Optional. Availability type. Potential values: * `ZONAL`: The instance serves data from only one zone. Outages in that zone affect data accessibility. This is the default value. * `REGIONAL`: The ins… |
| dataCacheEnabled | boolean | — | Optional. Whether data cache is enabled for the instance. |
| dataDiskSizeGb | string | — | Optional. Data disk size in GB. Default value is 100. |
| databaseVersion | string | — | Optional. The database engine type and version. The default value is `POSTGRES_18`. For Mysql, it can be `MYSQL_8_4`, `MYSQL_8_0`, `MYSQL_5_7`, etc. For Postgres, it can be `POSTGRES_18`, `POSTGRES_1… |
| edition | string | — | Optional. The edition of the instance, can be ENTERPRISE or ENTERPRISE_PLUS. If not specified: - For Postgres and Mysql, the default value is ENTERPRISE_PLUS. - For SQL Server, the default value is E… |
| enableGoogleMlIntegration | boolean | — | Optional. When this parameter is set to true, Cloud SQL instances can connect to Vertex AI to pass requests for real-time predictions and insights to the AI. The default value is false. This applies… |
| freeTrial | boolean | — | Optional. Whether the instance is a free trial instance. If true, the instance will be created with a free trial configuration. |
| ipv4Enabled | boolean | — | Optional. Whether to enable public IP for the instance. Enabling this flag makes the resource accessible from the public internet, which is a security risk if not properly managed. It is recommended… |
| name | string | yes | Required. Name of the Cloud SQL instance. This does not include the project ID. |
| project | string | yes | Required. Project ID of the project to which the newly created Cloud SQL instances should belong. |
| psaMcpConfig | — | — | Optional. Use this to connect to the Cloud SQL instance using Private Service Access. |
| pscMcpConfig | — | — | Optional. Configuration for Private Service Connect (PSC) instance creation. |
| region | string | — | Optional. The geographical region of the Cloud SQL instance. For example, `us-central1`, `europe-west1`, and `asia-east1`. If not specified, the default value is `us-central1`. |
| tags | object | — | Optional. Input only. Tag keys and tag values that are bound to this instance. You must represent each item in the map as: `"" : ""`. For example, a single resource can have the following tags: ``` "… |
| tier | string | — | Optional. The tier (or machine type) for this instance. If not specified: - For `ENTERPRISE_PLUS` edition, the default tier is `db-perf-optimized-N-2`, which gives you 2 vCPUs and 16 GB of RAM. - For… |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
create_user ~1,031
Create a database user for a Cloud SQL instance. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * When you use the `create_user` tool, specify the type of user: `CLOUD_IAM_USER`, `CLOUD_IAM_SERVICE_ACCOUNT`, or `BUILT_IN`. * By default the newly created user is assigned the `cloudsqlsuperuser` role, unless you specify other database roles explicitly in the request. * You can use a newly created user with the `execute_sql` tool if the user is a currently logged in IAM user. The `execute_sql` tool executes the SQL statements using the privileges of the database user logged in using IAM database authentication. The `create_user` tool has the following limitations: * To create a built-in user with password, use the `password_secret_version` field to provide password using the Google Cloud Secret Manager. The value of `password_secret_version` should be the resource name of the secret version, like `projects/12345/locations/us-central1/secrets/my-password-secret/versions/1` or `projects/12345/locations/us-central1/secrets/my-password-secret/versions/latest`. The caller needs to have `secretmanager.secretVersions.access` permission on the secret version. * The `create_user` tool doesn't support creating a user for SQL Server. To create an IAM user in PostgreSQL: * The database username must be the IAM user's email address and all lowercase. For example, to create user for PostgreSQL IAM user `[email protected]`, you can use the following request: ``` { "name": "[email protected]", "type": "CLOUD_IAM_USER", "instance":"test-instance", "project": "test-project" } ``` The created database username for the IAM user is `[email protected]`. To create an IAM service account in PostgreSQL: * The database username must be created without the `.gserviceaccount.com` suffix even though the full email address for the account is`service-account-n…
| Name | Type | Req | Description |
|---|---|---|---|
| databaseRoles | array | — | Optional. Role memberships of the user. Default value is [cloudsqlsuperuser]. |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| name | string | yes | Required. The name of the user in the Cloud SQL instance. |
| passwordSecretVersion | string | — | Optional. Input only. The resource name of the Secret Manager secret holding the password for the user, only needed if `type` is `BUILT_IN`. The expected format is `projects/{project}/secrets/{secret… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| type | string | yes | Required. The user type. It determines the method to authenticate the user during login. Use type CLOUD_IAM_USER when authenticating with a Cloud IAM user. Use type CLOUD_IAM_SERVICE_ACCOUNT when aut… |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
execute_sql ~1,098
Execute any valid SQL statement, including data definition language (DDL), data control language (DCL), data query language (DQL), or data manipulation language (DML) statements, on a Cloud SQL instance. To support the `execute_sql` tool, a Cloud SQL instance must meet the following requirements: * The value of `data_api_access` must be set to `ALLOW_DATA_API`. * For built_in users password_secret_version must be set. * Otherwise, for IAM users, for a MySQL instance, the database flag `cloudsql_iam_authentication` must be set to `on`. For a PostgreSQL instance, the database flag `cloudsql.iam_authentication` must be set to `on`. * After you use the `create_instance` tool to create an instance, you can use the `create_user` tool to create an IAM user account for the user currently logged in to the project. The `execute_sql` tool has the following limitations: * If a SQL statement returns a response larger than 10 MB, then the response will be truncated. * The `execute_sql` tool has a default timeout of 30 seconds. If a query runs longer than 30 seconds, then the tool returns a `DEADLINE_EXCEEDED` error. * The `execute_sql` tool isn't supported for SQL Server. If you receive errors similar to "IAM authentication is not enabled for the instance", then you can use the `get_instance` tool to check the value of the IAM database authentication flag for the instance. If you receive errors like "The instance doesn't allow using executeSql to access this instance", then you can use `get_instance` tool to check the `data_api_access` setting. When you receive authentication errors: 1. Check if the currently logged-in user account exists as an IAM user on the instance using the `list_users` tool. 2. If the IAM user account doesn't exist, then use the `create_user` tool to create the IAM user account for the logged-in user. 3. If the currently logged in user doesn't have the proper database user roles, then you can use `update_u…
| Name | Type | Req | Description |
|---|---|---|---|
| database | string | — | Optional. Name of the database on which the statement will be executed. For Postgres it's required, for MySQL it's optional. For Postgres, if your query is not scoped to an existings database, like l… |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| passwordSecretVersion | string | — | Optional. The resource name of the Secret Manager secret holding the password for the user to log into the database. The secret should be created using the regional endpoint (for API) or from the Reg… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| sqlCommenterEnabled | boolean | — | Optional. If set to true, enables sqlcommenter-style tagging. Automatically collects and populates mcp.server, mcp.tool, mcp.client, and user.identity. See https://google.github.io/sqlcommenter/ for… |
| sqlStatement | string | yes | Required. SQL statements to run on the database. It can be a single statement or a sequence of statements separated by semicolons. |
| user | string | — | Optional. The name of an existing database user to connect to the database. This field is used together with the `password_secret_version` field. When not both are set, the API caller's identity is u… |
| Name | Type | Req | Description |
|---|---|---|---|
| messages | array | — | A list of notices and warnings generated during query execution. For PostgreSQL, this includes all notices and warnings. For MySQL, this includes warnings generated by the last executed statement. To… |
| metadata | — | — | The additional metadata information regarding the execution of the SQL statements. |
| results | array | — | The list of results after executing all the SQL statements. |
| status | — | — | Contains the error from the database if the SQL execution failed. |
No examples provided.
execute_sql_readonly ~1,108
Execute any valid read only SQL statement on a Cloud SQL instance. To support the `execute_sql_readonly` tool, a Cloud SQL instance must meet the following requirements: * The value of `data_api_access` must be set to `ALLOW_DATA_API`. * For a MySQL instance, the database flag `cloudsql_iam_authentication` must be set to `on`. For a PostgreSQL instance, the database flag `cloudsql.iam_authentication` must be set to `on`. * An IAM user account or IAM service account (`CLOUD_IAM_USER` or `CLOUD_IAM_SERVICE_ACCOUNT`) is required to call the `execute_sql_readonly` tool. The tool executes the SQL statements using the privileges of the database user logged with IAM database authentication. After you use the `create_instance` tool to create an instance, you can use the `create_user` tool to create an IAM user account for the user currently logged in to the project. The `execute_sql_readonly` tool has the following limitations: * If a SQL statement returns a response larger than 10 MB, then the response will be truncated. * The tool has a default timeout of 30 seconds. If a query runs longer than 30 seconds, then the tool returns a `DEADLINE_EXCEEDED` error. * The tool isn't supported for SQL Server. If you receive errors similar to "IAM authentication is not enabled for the instance", then you can use the `get_instance` tool to check the value of the IAM database authentication flag for the instance. If you receive errors like "The instance doesn't allow using executeSql to access this instance", then you can use `get_instance` tool to check the `data_api_access` setting. When you receive authentication errors: 1. Check if the currently logged-in user account exists as an IAM user on the instance using the `list_users` tool. 2. If the IAM user account doesn't exist, then use the `create_user` tool to create the IAM user account for the logged-in user. 3. If the currently logged in user doesn't have the proper database…
| Name | Type | Req | Description |
|---|---|---|---|
| database | string | — | Optional. Name of the database on which the statement will be executed. For Postgres it's required, for MySQL it's optional. For Postgres, if your query is not scoped to an existings database, like l… |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| passwordSecretVersion | string | — | Optional. The resource name of the Secret Manager secret holding the password for the user to log into the database. The secret should be created using the regional endpoint (for API) or from the Reg… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| sqlCommenterEnabled | boolean | — | Optional. If set to true, enables sqlcommenter-style tagging. Automatically collects and populates mcp.server, mcp.tool, mcp.client, and user.identity. See https://google.github.io/sqlcommenter/ for… |
| sqlStatement | string | yes | Required. SQL statements to run on the database. It can be a single statement or a sequence of statements separated by semicolons. |
| user | string | — | Optional. The name of an existing database user to connect to the database. This field is used together with the `password_secret_version` field. When not both are set, the API caller's identity is u… |
| Name | Type | Req | Description |
|---|---|---|---|
| messages | array | — | A list of notices and warnings generated during query execution. For PostgreSQL, this includes all notices and warnings. For MySQL, this includes warnings generated by the last executed statement. To… |
| metadata | — | — | The additional metadata information regarding the execution of the SQL statements. |
| results | array | — | The list of results after executing all the SQL statements. |
| status | — | — | Contains the error from the database if the SQL execution failed. |
No examples provided.
get_instance ~55
Get the details of a Cloud SQL instance.
| Name | Type | Req | Description |
|---|---|---|---|
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| availableMaintenanceVersions | array | — | Output only. List all maintenance versions applicable on the instance |
| backendType | string | — | The backend type. `SECOND_GEN`: Cloud SQL database instance. `EXTERNAL`: A database server that is not managed by Google. This property is read-only; use the `tier` property in the `settings` object… |
| connectionName | string | — | Connection name of the Cloud SQL instance used in connection strings. |
| createTime | string | — | Output only. The time when the instance was created in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| currentDiskSize | string | — | The current disk usage of the instance in bytes. This property has been deprecated. Use the "cloudsql.googleapis.com/database/disk/bytes_used" metric in Cloud Monitoring API instead. Please see [this… |
| databaseInstalledVersion | string | — | Output only. Stores the current database version running on the instance including minor version such as `MYSQL_8_0_18`. |
| databaseVersion | string | — | The database engine type and version. The `databaseVersion` field cannot be changed after instance creation. |
| diskEncryptionConfiguration | — | — | Disk encryption configuration specific to an instance. |
| diskEncryptionStatus | — | — | Disk encryption status specific to an instance. |
| dnsName | string | — | Output only. The dns name of the instance. |
| dnsNames | array | — | Output only. The list of DNS names used by this instance. |
| etag | string | — | This field is deprecated and will be removed from a future version of the API. Use the `settings.settingsVersion` field instead. |
| failoverReplica | — | — | The name and status of the failover replica. |
| gceZone | string | — | The Compute Engine zone that the instance is currently serving from. This value could be different from the zone that was specified when the instance was created if the instance has failed over to it… |
| geminiConfig | — | — | Gemini instance configuration. |
| includeReplicasForMajorVersionUpgrade | boolean | — | Input only. Determines whether an in-place major version upgrade of replicas happens when an in-place major version upgrade of a primary instance is initiated. |
| instanceType | string | — | The instance type. |
| ipAddresses | array | — | The assigned IP addresses for the instance. |
| ipv6Address | string | — | The IPv6 address assigned to the instance. (Deprecated) This property was applicable only to First Generation instances. |
| kind | string | — | This is always `sql#instance`. |
| maintenanceVersion | string | — | The current software version on the instance. |
| masterInstanceName | string | — | The name of the instance which will act as primary in the replication setup. |
| maxDiskSize | string | — | The maximum disk size of the instance in bytes. |
| name | string | — | Name of the Cloud SQL instance. This does not include the project ID. |
| nodeCount | integer | — | The number of read pool nodes in a read pool. |
| nodes | array | — | Output only. Entries containing information about each read pool node of the read pool. |
| onPremisesConfiguration | — | — | Configuration specific to on-premises instances. |
| outOfDiskReport | — | — | This field represents the report generated by the proactive database wellness job for OutOfDisk issues. * Writers: * the proactive database wellness job for OOD. * Readers: * the proactive database w… |
| primaryDnsName | string | — | Output only. DEPRECATED: please use write_endpoint instead. |
| project | string | — | The project ID of the project containing the Cloud SQL instance. The Google apps domain is prefixed if applicable. |
| pscServiceAttachmentLink | string | — | Output only. The link to service attachment of PSC instance. |
| region | string | — | The geographical region of the Cloud SQL instance. It can be one of the [regions](https://cloud.google.com/sql/docs/mysql/locations#location-r) where Cloud SQL operates: For example, `asia-east1`, `e… |
| replicaConfiguration | — | — | Configuration specific to failover replicas and read replicas. |
| replicaNames | array | — | The replicas of the instance. |
| replicationCluster | — | — | Optional. A primary instance and disaster recovery (DR) replica pair. A DR replica is a cross-region replica that you designate for failover in the event that the primary instance experiences regiona… |
| rootPassword | string | — | Initial root password. Use only on creation. You must set root passwords before you can connect to PostgreSQL instances. |
| satisfiesPzi | boolean | — | Output only. This status indicates whether the instance satisfies PZI. The status is reserved for future use. |
| satisfiesPzs | boolean | — | This status indicates whether the instance satisfies PZS. The status is reserved for future use. |
| scheduledMaintenance | — | — | The start time of any upcoming scheduled maintenance for this instance. |
| secondaryGceZone | string | — | The Compute Engine zone that the failover instance is currently serving from for a regional instance. This value could be different from the zone that was specified when the instance was created if t… |
| selfLink | string | — | The URI of this resource. |
| serverCaCert | — | — | SSL configuration. |
| serviceAccountEmailAddress | string | — | The service account email address assigned to the instance.\This property is read-only. |
| settings | — | — | The user settings. |
| sqlNetworkArchitecture | string | — | — |
| state | string | — | The current serving state of the Cloud SQL instance. |
| suspensionReason | array | — | If the instance state is SUSPENDED, the reason for the suspension. |
| switchTransactionLogsToCloudStorageEnabled | boolean | — | Input only. Whether Cloud SQL is enabled to switch storing point-in-time recovery log files from a data disk to Cloud Storage. |
| tags | object | — | Optional. Input only. Immutable. Tag keys and tag values that are bound to this instance. You must represent each item in the map as: `"" : ""`. For example, a single resource can have the following… |
| upgradableDatabaseVersions | array | — | Output only. All database versions that are available for upgrade. |
| writeEndpoint | string | — | Output only. The dns name of the primary instance in a replication group. |
No examples provided.
get_operation ~91
Get the status of a long-running operation. A long-running operation can take several minutes to complete. If an operation takes an extended amount of time, then use a command line tool to pause for 30 seconds before rechecking the status of the operation.
| Name | Type | Req | Description |
|---|---|---|---|
| operation | string | yes | Required. Instance operation ID. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
import_data ~610
Import data into a Cloud SQL instance. If the file doesn't start with `gs://`, then the assumption is that the file is stored locally. If the file is local, then the file must be uploaded to Cloud Storage before you can make the actual `import_data` call. To upload the file to Cloud Storage, you can use the `gcloud` or `gsutil` commands. Before you upload the file to Cloud Storage, consider whether you want to use an existing bucket or create a new bucket in the provided project. After the file is uploaded to Cloud Storage, the instance service account must have sufficient permissions to read the uploaded file from the Cloud Storage bucket. This can be accomplished as follows: 1. Use the `get_instance` tool to get the email address of the instance service account. From the output of the tool, get the value of the `serviceAccountEmailAddress` field. 2. Grant the instance service account the `storage.objectAdmin` role on the provided Cloud Storage bucket. Use a command like `gcloud storage buckets add-iam-policy-binding` or a request to the Cloud Storage API. It can take from two to up to seven minutes or more for the role to be granted and the permissions to be propagated to the service account in Cloud Storage. If you encounter a permissions error after updatingthe IAM policy, then wait a few minutes and try again. After permissions are granted, you can import the data. We recommend that you leave optional parameters empty and use the system defaults. The file type can typically be determined by the file extension. For example, if the file is a SQL file, `.sql` or `.csv` for CSV file. The following is a sample SQL `importContext` for MySQL. ``` { "uri": "gs://sample-gcs-bucket/sample-file.sql", "kind": "sql#importContext", "fileType": "SQL" } ``` There is no `database` parameter present for MySQL since the database name is expected to be present in the SQL file. Specify only one URI. No other fields are required outside of `importCo…
| Name | Type | Req | Description |
|---|---|---|---|
| body | — | — | — |
| instance | string | — | Cloud SQL instance ID. This does not include the project ID. |
| project | string | — | Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
list_instances ~220
List all Cloud SQL instances in the project.
| Name | Type | Req | Description |
|---|---|---|---|
| filter | string | — | A filter expression that filters resources listed in the response. The expression is in the form of field:value. For example, 'instanceType:CLOUD_SQL_INSTANCE'. Fields can be nested as needed as per… |
| maxResults | integer | — | The maximum number of instances to return. The service may return fewer than this value. If unspecified, at most 500 instances are returned. The maximum value is 1000; values above 1000 are coerced t… |
| pageToken | string | — | A previously-returned page token representing part of the larger set of results to view. |
| project | string | — | Project ID of the project for which to list Cloud SQL instances. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | — | List of mcp instance resources. |
| kind | string | — | This is always sql#instancesList. |
| nextPageToken | string | — | The continuation token, used to page through large result sets. Provide this value in a subsequent request to return the next page of results. |
| warnings | array | — | List of warnings that occurred while handling the request. |
No examples provided.
list_users ~52
List all database users for a Cloud SQL instance.
| Name | Type | Req | Description |
|---|---|---|---|
| instance | string | — | Database instance ID. This does not include the project ID. |
| project | string | — | Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | — | List of user resources in the instance. |
| kind | string | — | This is always `sql#usersList`. |
| nextPageToken | string | — | Unused. |
No examples provided.
postgres_upgrade_precheck ~400
Checks if a Cloud SQL for PostgreSQL instance is ready for a major version upgrade to the specified target version. The `target_database_version` MUST be provided in the request (e.g., `POSTGRES_15`). This tool helps identify potential issues *before* attempting the actual upgrade, reducing the risk of failure or downtime. This tool is only supported for PostgreSQL primary instances and does not run on read replicas. The precheck typically evaluates: - Database schema compatibility with the target version. - Cloud SQL limitations and unsupported features. - Instance resource constraints (e.g., number of relations). - Compatibility of current database settings and extensions. - Overall instance health and readiness. This tool returns a long-running operation. Use the `get_operation` tool with the operation name returned by this call to poll its status. IMPORTANT: Once the operation status is DONE, the detailed precheck results are available within the `Operation` resource. You will need to inspect the response from `get_operation`. The findings are located in the `pre_check_major_version_upgrade_context.pre_check_response` field. The findings are structured, indicating: - INFO: General information. - WARNING: Potential issues that don't block the upgrade but should be reviewed. - ERROR: Critical issues that MUST be resolved before attempting the upgrade. Each finding should include a message and any required actions. Addressing any reported issues is crucial before proceeding with the major version upgrade. If `pre_check_response` is empty or missing, it indicates that no issues were identified during the precheck. Running this precheck does not impact the instance's availability.
| Name | Type | Req | Description |
|---|---|---|---|
| body | — | yes | Required. The context for request to perform the pre-check major version upgrade operation. |
| instance | string | yes | Required. Cloud SQL instance ID. This does not include the project ID. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
restore_backup ~451
Restores a backup to a Cloud SQL instance. The target_instance and target_project must be provided and populated in the request. The backup identifier can be provided in several ways: 1. A backup_run_id (which is an integer). 2. A backup URI of the format `projects/{project-id}/backups/{backup-uid}`. 3. A backup URI of the format `projects/{project-id}/locations/{location}/backupVaults/{backupvault}/dataSources/{datasource}/backups/{backup-uid}`. Use the identifier to populate the `backup_id` field in the request. The source_project must be populated in the request. If the identifier is a backup_run_id, the source_project will be provided. If the identifier is a backup URI, the source_project may need to be extracted from the URI. Do not confuse the extracted source_project with the target_project, which will be provided in other ways. In addition, if the identifier is a backup_run_id, the source_instance must be provided and populated in the request. Do not try to create the instance before the restore, the restore itself will create the instance if needed. Confirm the parameters with the user before executing the restore.
| Name | Type | Req | Description |
|---|---|---|---|
| backupId | string | yes | Required. The identifier of the backup to restore. This will be one of the following: 1. An int64 containing a backup_run_id. 2. A backup name of the format 'projects/{project}/backups/{backup-uid}'.… |
| sourceInstance | string | — | Optional. The Cloud SQL instance ID of the source instance containing the backup. Only necessary if the backup_id is a backup_run_id. |
| sourceProject | string | yes | Required. The project ID of the source instance containing the backup. |
| targetInstance | string | yes | Required. Cloud SQL instance ID of the target. This does not include the project ID. |
| targetProject | string | yes | Required. Project ID of the target project. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
update_instance ~415
Partially updates the configuration settings of a Cloud SQL instance. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * Some update operations, such as changing the edition upgrade or instance tier, etc might cause the instance to restart, resulting in downtime. Before you proceed with such operations, get confirmation from the user.
| Name | Type | Req | Description |
|---|---|---|---|
| dataApiAccess | string | — | Optional. The settings for controlling data API access to an instance. |
| dataCacheConfig | — | — | Optional. Configuration for the data cache. A data cache can improve performance for read-heavy workloads by caching frequently accessed data in-memory. |
| dataDiskSizeGb | string | — | Optional. Data disk size in GB. |
| databaseFlags | array | — | Optional. The database flags. |
| edition | string | — | Optional. The edition of the instance, can be ENTERPRISE or ENTERPRISE_PLUS. |
| googleMlIntegrationEnabled | boolean | — | Optional. Enables Cloud SQL instances to connect to Vertex AI to pass requests for real-time predictions and insights to the AI. The default value is false. This applies only to Cloud SQL for MySQL a… |
| instance | string | yes | Required. Cloud SQL instance ID. This does not include the project ID. |
| ipv4Enabled | boolean | — | Optional. Whether to enable public IP for the instance. Enabling this flag makes the resource accessible from the public internet, which is a security risk if not properly managed. It is recommended… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| psaMcpConfig | — | — | Optional. Configuration for Private Service Access (PSA) instance update. |
| pscMcpConfig | — | — | Optional. Configuration for Private Service Connect (PSC) instance update. |
| tier | string | — | Optional. The tier (or machine type) for this instance. format: db-custom-{CPUs}-{Memory}. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.
update_user ~812
Update a database user for a Cloud SQL instance. A common use case for the `update_user` is to grant a user the `cloudsqlsuperuser` role, which can provide a user with many required permissions. This tool only supports updating users to assign database roles. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * Before calling the `update_user` tool, always check the existing configuration of the user such as the user type with `list_users` tool. * As a special case for MySQL, if the `list_users` tool returns a full email address for the `iamEmail` field, for example `{name=test-account, [email protected]}`, then in your `update_user` request, use the full email address in the `iamEmail` field in the `name` field of your toolrequest. For example, `[email protected]`. Key parameters for updating user roles: * `database_roles`: A list of database roles to be assigned to the user. * `revokeExistingRoles`: A boolean field (default: false) that controls how existing roles are handled. How role updates work: 1. **If `revokeExistingRoles` is true:** * Any existing roles granted to the user but NOT in the provided `database_roles` list will be REVOKED. * Revoking only applies to non-system roles. System roles like `cloudsqliamuser` etc won't be revoked. * Any roles in the `database_roles` list that the user does NOT already have will be GRANTED. * If `database_roles` is empty, then ALL existing non-system roles are revoked. 2. **If `revokeExistingRoles` is false (default):** * Any roles in the `database_roles` list that the user does NOT already have will be GRANTED. * Existing roles NOT in the `database_roles` list are KEPT. * If `database_roles` is empty, then there is no change to the user's roles. Examples: * Existing Roles: `[roleA, roleB]` * Re…
| Name | Type | Req | Description |
|---|---|---|---|
| databaseRoles | array | — | Optional. List of database roles to grant to the user. body.database_roles will be ignored for update request. |
| host | string | — | Optional. Host of the user in the instance. |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| name | string | yes | Required. Name of the user in the instance. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| revokeExistingRoles | boolean | — | Optional. revoke the existing roles granted to the user. |
| type | string | yes | Required. The user type. It determines the method to authenticate the user during login. The default is the database's built-in user type. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | — | — | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | — | — | An Admin API warning message. |
| backupContext | — | — | The context for backup operation, if applicable. |
| endTime | string | — | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | — | — | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | — | — | The context for export operation, if applicable. |
| importContext | — | — | The context for import operation, if applicable. |
| insertTime | string | — | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | — | This is always `sql#operation`. |
| name | string | — | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | — | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | — | — | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | — | The URI of this resource. |
| startTime | string | — | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| status | string | — | The status of an operation. |
| subOperationType | — | — | Optional. The sub operation based on the operation type. |
| targetId | string | — | Name of the resource on which this operation runs. |
| targetLink | string | — | — |
| targetProject | string | — | The project ID of the target instance related to this operation. |
| user | string | — | The email address of the user who initiated this operation. |
No examples provided.