com.googleapis.sqladmin/mcp
REMOTE · SQLADMIN.GOOGLEAPIS.COM · SCANNED SEP 20
Create, manage, and query your Google Cloud SQL resources.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (execute_sql). See how to fix → View diagnostics → Fail
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability57
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 8023 tokens (~534/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 98% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety88
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 1 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "execute_sql_readonly" implies "execute" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the com.googleapis.sqladmin/mcp server?
com.googleapis.sqladmin/mcp is a hosted endpoint at https://sqladmin.googleapis.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · sqladmin.googleapis.com
claude mcp add --transport http com-googleapis-sqladmin-mcp 'https://sqladmin.googleapis.com/mcp'
{
"mcpServers": {
"com-googleapis-sqladmin-mcp": {
"url": "https://sqladmin.googleapis.com/mcp"
}
}
} {
"servers": {
"com-googleapis-sqladmin-mcp": {
"type": "http",
"url": "https://sqladmin.googleapis.com/mcp"
}
}
} [mcp_servers.com-googleapis-sqladmin-mcp] url = "https://sqladmin.googleapis.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-googleapis-sqladmin-mcp": {
"type": "remote",
"url": "https://sqladmin.googleapis.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-googleapis-sqladmin-mcp --url 'https://sqladmin.googleapis.com/mcp' --transport streamable-http
mcp_servers:
com-googleapis-sqladmin-mcp:
url: "https://sqladmin.googleapis.com/mcp" {
"McpServers": {
"com-googleapis-sqladmin-mcp": {
"Transport": "http",
"Url": "https://sqladmin.googleapis.com/mcp"
}
}
} assistant mcp add com-googleapis-sqladmin-mcp -t streamable-http -u 'https://sqladmin.googleapis.com/mcp'
{
"mcpServers": {
"com-googleapis-sqladmin-mcp": {
"type": "http",
"url": "https://sqladmin.googleapis.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Aug 26 0
- Tool “execute_sql” rewrote its description, which is the text the model reads security
- Tool “execute_sql_readonly” rewrote its description, which is the text the model reads security
- “clone_instance” added an optional parameter “location” cosmetic
- “get_instance” added an optional parameter “location” cosmetic
- “import_data” added an optional parameter “location” cosmetic
- “list_instances” added an optional parameter “location” cosmetic
- “list_users” added an optional parameter “location” cosmetic
- “postgres_upgrade_precheck” added an optional parameter “location” cosmetic
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 23 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 5 Aug 26 0
- “get_operation” added an optional parameter “location” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 3 Aug 26 0
- “get_operation” dropped the optional parameter “location” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 2 Aug 26 0
- “get_operation” added an optional parameter “location” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://sqladmin.googleapis.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=upload.video.google.com | CN=WR2,O=Google Trust Services,C=US | 4 Sept 2026 | 27 Nov 2026 | ECDSA 256 | SHA256-RSA | 26b7552c6ebf922f0aa0ebf2fb6115e4 |
| SANs: upload.video.google.com, *.clients.google.com, *.docs.google.com, *.drive.google.com, *.gdata.youtube.com, *.googleapis.com, *.photos.google.com, *.youtube-3rd-party.com, upload.google.com, *.upload.google.com, upload.youtube.com, *.upload.youtube.com and 5 more | ||||||
| CN=WR2,O=Google Trust Services,C=US (CA) | CN=GTS Root R1,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | RSA 2048 | SHA256-RSA | 7ff005a07c4cded100ad9d66a5107b98 |
| CN=GTS Root R1,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 19 Jun 2020 | 28 Jan 2028 | RSA 4096 | SHA256-RSA | 77bd0d6cdb36f91aea210fc4f058d30d |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of sqladmin.googleapis.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| googleapis.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://sqladmin.googleapis.com/mcp | Verified | 200 | |
| http (plaintext) | http://sqladmin.googleapis.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
clone_instance ~142
Create a Cloud SQL instance as a clone of a source instance. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * The clone operation can take several minutes. Use a command line tool to pause for 30 seconds before rechecking the status.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | – |
| instance | string | yes | Required. The ID of the Cloud SQL instance to be cloned (source). This does not include the project ID. |
| location | string | – | Optional. Region of the Cloud SQL instance. |
| project | string | yes | Required. Project ID of the source Cloud SQL instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
create_backup ~126
Takes a backup on a Cloud SQL instance. Always populate the project and instance fields on the request. The location (region) and description of the backup may also be optionally provided, in which case the corresponding request fields should also be populated.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | Optional. The description of this backup run. |
| instance | string | yes | Required. Cloud SQL instance ID. This does not include the project ID. |
| location | string | – | Optional. Location of the backup run. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
create_instance ~1,344
Initiates the creation of a Cloud SQL instance. * The tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * The instance creation operation can take several minutes. Use a command line tool to pause for 30 seconds before rechecking the status. * After you use the `create_instance` tool to create an instance, you can use the `create_user` tool to create an IAM user account for the user currently logged in to the project. * IMPORTANT: Set `ipv4_enabled` to 'false' if creating a Private Service Connect or a Private Service Access instance. * Set `free_trial` to 'true' to create a free trial instance. Free trial instances let you test majority of Cloud SQL features for up to 30 days without financial commitment. Subject to eligibility and availability. * The value of `data_api_access` is set to `ALLOW_DATA_API` by default. This setting lets you execute SQL statements using the `execute_sql` tool and the `executeSql` API. Unless otherwise specified, a newly created instance uses the default instance configuration of a development environment. The following is the default configuration for an instance in a development environment: ``` { "tier": "db-perf-optimized-N-2", "data_disk_size_gb": 100, "region": "us-central1", "database_version": "POSTGRES_18", "edition": "ENTERPRISE_PLUS", "availability_type": "ZONAL", "tags": [{"environment": "dev"}] } ``` The following configuration is recommended for an instance in a production environment: ``` { "tier": "db-perf-optimized-N-8", "data_disk_size_gb": 250, "region": "us-central1", "database_version": "POSTGRES_18", "edition": "ENTERPRISE_PLUS", "availability_type": "REGIONAL", "tags": [{"environment": "prod"}] } ``` The following instance configuration is recommended for SQL Server: ``` { "tier": "db-perf-optimized-N-8", "data_disk_size_gb": 250, "region": "us-central1", "database_version": "SQ…
| Name | Type | Req | Description |
|---|---|---|---|
| availabilityType | string | – | Optional. Availability type. Potential values: * `ZONAL`: The instance serves data from only one zone. Outages in that zone affect data accessibility. This is the default value. * `REGIONAL`: The ins… |
| dataCacheEnabled | boolean | – | Optional. Whether data cache is enabled for the instance. |
| dataDiskSizeGb | string | – | Optional. Data disk size in GB. Default value is 100. |
| databaseVersion | string | – | Optional. The database engine type and version. The default value is `POSTGRES_18`. For Mysql, it can be `MYSQL_8_4`, `MYSQL_8_0`, `MYSQL_5_7`, etc. For Postgres, it can be `POSTGRES_18`, `POSTGRES_1… |
| edition | string | – | Optional. The edition of the instance, can be ENTERPRISE or ENTERPRISE_PLUS. If not specified: - For Postgres and Mysql, the default value is ENTERPRISE_PLUS. - For SQL Server, the default value is E… |
| enableGoogleMlIntegration | boolean | – | Optional. When this parameter is set to true, Cloud SQL instances can connect to Vertex AI to pass requests for real-time predictions and insights to the AI. The default value is false. This applies… |
| freeTrial | boolean | – | Optional. Whether the instance is a free trial instance. If true, the instance will be created with a free trial configuration. |
| ipv4Enabled | boolean | – | Optional. Whether to enable public IP for the instance. Enabling this flag makes the resource accessible from the public internet, which is a security risk if not properly managed. It is recommended… |
| name | string | yes | Required. Name of the Cloud SQL instance. This does not include the project ID. |
| project | string | yes | Required. Project ID of the project to which the newly created Cloud SQL instances should belong. |
| psaMcpConfig | – | – | Optional. Use this to connect to the Cloud SQL instance using Private Service Access. |
| pscMcpConfig | – | – | Optional. Configuration for Private Service Connect (PSC) instance creation. |
| region | string | – | Optional. The geographical region of the Cloud SQL instance. For example, `us-central1`, `europe-west1`, and `asia-east1`. If not specified, the default value is `us-central1`. |
| tags | object | – | Optional. Input only. Tag keys and tag values that are bound to this instance. You must represent each item in the map as: `"" : ""`. For example, a single resource can have the following tags: ``` "… |
| tier | string | – | Optional. The tier (or machine type) for this instance. If not specified: - For `ENTERPRISE_PLUS` edition, the default tier is `db-perf-optimized-N-2`, which gives you 2 vCPUs and 16 GB of RAM. - For… |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
create_user ~1,031
Create a database user for a Cloud SQL instance. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * When you use the `create_user` tool, specify the type of user: `CLOUD_IAM_USER`, `CLOUD_IAM_SERVICE_ACCOUNT`, or `BUILT_IN`. * By default the newly created user is assigned the `cloudsqlsuperuser` role, unless you specify other database roles explicitly in the request. * You can use a newly created user with the `execute_sql` tool if the user is a currently logged in IAM user. The `execute_sql` tool executes the SQL statements using the privileges of the database user logged in using IAM database authentication. The `create_user` tool has the following limitations: * To create a built-in user with password, use the `password_secret_version` field to provide password using the Google Cloud Secret Manager. The value of `password_secret_version` should be the resource name of the secret version, like `projects/12345/locations/us-central1/secrets/my-password-secret/versions/1` or `projects/12345/locations/us-central1/secrets/my-password-secret/versions/latest`. The caller needs to have `secretmanager.secretVersions.access` permission on the secret version. * The `create_user` tool doesn't support creating a user for SQL Server. To create an IAM user in PostgreSQL: * The database username must be the IAM user's email address and all lowercase. For example, to create user for PostgreSQL IAM user `example-user@example.com`, you can use the following request: ``` { "name": "example-user@example.com", "type": "CLOUD_IAM_USER", "instance":"test-instance", "project": "test-project" } ``` The created database username for the IAM user is `example-user@example.com`. To create an IAM service account in PostgreSQL: * The database username must be created without the `.gserviceaccount.com` suffix even though the full email address for the account is`service-account-n…
| Name | Type | Req | Description |
|---|---|---|---|
| databaseRoles | array | – | Optional. Role memberships of the user. Default value is [cloudsqlsuperuser]. |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| name | string | yes | Required. The name of the user in the Cloud SQL instance. |
| passwordSecretVersion | string | – | Optional. Input only. The resource name of the Secret Manager secret holding the password for the user, only needed if `type` is `BUILT_IN`. The expected format is `projects/{project}/secrets/{secret… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| type | string | yes | Required. The user type. It determines the method to authenticate the user during login. Use type CLOUD_IAM_USER when authenticating with a Cloud IAM user. Use type CLOUD_IAM_SERVICE_ACCOUNT when aut… |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
execute_sql ~1,085
Execute any valid SQL statement, including data definition language (DDL), data control language (DCL), data query language (DQL), or data manipulation language (DML) statements, on a Cloud SQL instance. To support the `execute_sql` tool, a Cloud SQL instance must meet the following requirements: * The value of `data_api_access` must be set to `ALLOW_DATA_API`. * For built_in users password_secret_version must be set. * Otherwise, for IAM users, for a MySQL instance, the database flag `cloudsql_iam_authentication` must be set to `on`. For a PostgreSQL instance, the database flag `cloudsql.iam_authentication` must be set to `on`. * After you use the `create_instance` tool to create an instance, you can use the `create_user` tool to create an IAM user account for the user currently logged in to the project. The `execute_sql` tool has the following limitations: * If a SQL statement returns a response larger than 10 MB, then the response will be truncated. * The `execute_sql` tool has a default timeout of 30 seconds. If a query runs longer than 30 seconds, then the tool returns a `DEADLINE_EXCEEDED` error. If you receive errors similar to "IAM authentication is not enabled for the instance", then you can use the `get_instance` tool to check the value of the IAM database authentication flag for the instance. If you receive errors like "The instance doesn't allow using executeSql to access this instance", then you can use `get_instance` tool to check the `data_api_access` setting. When you receive authentication errors: 1. Check if the currently logged-in user account exists as an IAM user on the instance using the `list_users` tool. 2. If the IAM user account doesn't exist, then use the `create_user` tool to create the IAM user account for the logged-in user. 3. If the currently logged in user doesn't have the proper database user roles, then you can use `update_user` tool to grant database roles to the user. For exampl…
| Name | Type | Req | Description |
|---|---|---|---|
| database | string | – | Optional. Name of the database on which the statement will be executed. For Postgres it's required, for MySQL it's optional. For Postgres, if your query is not scoped to an existings database, like l… |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| passwordSecretVersion | string | – | Optional. The resource name of the Secret Manager secret holding the password for the user to log into the database. The secret should be created using the regional endpoint (for API) or from the Reg… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| sqlCommenterEnabled | boolean | – | Optional. If set to true, enables sqlcommenter-style tagging. Automatically collects and populates mcp.server, mcp.tool, mcp.client, and user.identity. See https://google.github.io/sqlcommenter/ for… |
| sqlStatement | string | yes | Required. SQL statements to run on the database. It can be a single statement or a sequence of statements separated by semicolons. |
| user | string | – | Optional. The name of an existing database user to connect to the database. This field is used together with the `password_secret_version` field. When not both are set, the API caller's identity is u… |
| Name | Type | Req | Description |
|---|---|---|---|
| messages | array | – | A list of notices and warnings generated during query execution. For PostgreSQL, this includes all notices and warnings. For MySQL, this includes warnings generated by the last executed statement. To… |
| metadata | – | – | The additional metadata information regarding the execution of the SQL statements. |
| results | array | – | The list of results after executing all the SQL statements. |
| status | – | – | Contains the error from the database if the SQL execution failed. |
No examples provided.
execute_sql_readonly ~1,099
Execute any valid read only SQL statement on a Cloud SQL instance. To support the `execute_sql_readonly` tool, a Cloud SQL instance must meet the following requirements: * The value of `data_api_access` must be set to `ALLOW_DATA_API`. * For a MySQL instance, the database flag `cloudsql_iam_authentication` must be set to `on`. For a PostgreSQL instance, the database flag `cloudsql.iam_authentication` must be set to `on`. * An IAM user account or IAM service account (`CLOUD_IAM_USER` or `CLOUD_IAM_SERVICE_ACCOUNT`) is required to call the `execute_sql_readonly` tool. The tool executes the SQL statements using the privileges of the database user logged with IAM database authentication. After you use the `create_instance` tool to create an instance, you can use the `create_user` tool to create an IAM user account for the user currently logged in to the project. The `execute_sql_readonly` tool has the following limitations: * If a SQL statement returns a response larger than 10 MB, then the response will be truncated. * The tool has a default timeout of 30 seconds. If a query runs longer than 30 seconds, then the tool returns a `DEADLINE_EXCEEDED` error. If you receive errors similar to "IAM authentication is not enabled for the instance", then you can use the `get_instance` tool to check the value of the IAM database authentication flag for the instance. If you receive errors like "The instance doesn't allow using executeSql to access this instance", then you can use `get_instance` tool to check the `data_api_access` setting. When you receive authentication errors: 1. Check if the currently logged-in user account exists as an IAM user on the instance using the `list_users` tool. 2. If the IAM user account doesn't exist, then use the `create_user` tool to create the IAM user account for the logged-in user. 3. If the currently logged in user doesn't have the proper database user roles, then you can use `update_us…
| Name | Type | Req | Description |
|---|---|---|---|
| database | string | – | Optional. Name of the database on which the statement will be executed. For Postgres it's required, for MySQL it's optional. For Postgres, if your query is not scoped to an existings database, like l… |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| passwordSecretVersion | string | – | Optional. The resource name of the Secret Manager secret holding the password for the user to log into the database. The secret should be created using the regional endpoint (for API) or from the Reg… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| sqlCommenterEnabled | boolean | – | Optional. If set to true, enables sqlcommenter-style tagging. Automatically collects and populates mcp.server, mcp.tool, mcp.client, and user.identity. See https://google.github.io/sqlcommenter/ for… |
| sqlStatement | string | yes | Required. SQL statements to run on the database. It can be a single statement or a sequence of statements separated by semicolons. |
| user | string | – | Optional. The name of an existing database user to connect to the database. This field is used together with the `password_secret_version` field. When not both are set, the API caller's identity is u… |
| Name | Type | Req | Description |
|---|---|---|---|
| messages | array | – | A list of notices and warnings generated during query execution. For PostgreSQL, this includes all notices and warnings. For MySQL, this includes warnings generated by the last executed statement. To… |
| metadata | – | – | The additional metadata information regarding the execution of the SQL statements. |
| results | array | – | The list of results after executing all the SQL statements. |
| status | – | – | Contains the error from the database if the SQL execution failed. |
No examples provided.
get_instance ~70
Get the details of a Cloud SQL instance.
| Name | Type | Req | Description |
|---|---|---|---|
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| location | string | – | Optional. Region of the Cloud SQL instance. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| availableMaintenanceVersions | array | – | Output only. List all maintenance versions applicable on the instance |
| backendType | string | – | The backend type. `SECOND_GEN`: Cloud SQL database instance. `EXTERNAL`: A database server that is not managed by Google. This property is read-only; use the `tier` property in the `settings` object… |
| connectionName | string | – | Connection name of the Cloud SQL instance used in connection strings. |
| createTime | string | – | Output only. The time when the instance was created in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| currentDiskSize | string | – | The current disk usage of the instance in bytes. This property has been deprecated. Use the "cloudsql.googleapis.com/database/disk/bytes_used" metric in Cloud Monitoring API instead. Please see [this… |
| databaseCenterIntegrationEnabled | boolean | – | Optional. If true, instance metadata is sent to the Database Center. If false, instance metadata is not sent to the Database Center. |
| databaseInstalledVersion | string | – | Output only. Stores the current database version running on the instance including minor version such as `MYSQL_8_0_18`. |
| databaseVersion | string | – | The database engine type and version. The `databaseVersion` field cannot be changed after instance creation. |
| deploymentInfo | – | – | Output only. Deployment info for the instance. This is set if the instance is currently part of any blue-green setup. |
| diskEncryptionConfiguration | – | – | Disk encryption configuration specific to an instance. |
| diskEncryptionStatus | – | – | Disk encryption status specific to an instance. |
| dnsName | string | – | Output only. The dns name of the instance. |
| dnsNames | array | – | Output only. The list of DNS names used by this instance. |
| etag | string | – | This field is deprecated and will be removed from a future version of the API. Use the `settings.settingsVersion` field instead. |
| failoverReplica | – | – | The name and status of the failover replica. |
| gceZone | string | – | The Compute Engine zone that the instance is currently serving from. This value could be different from the zone that was specified when the instance was created if the instance has failed over to it… |
| geminiConfig | – | – | Gemini instance configuration. |
| includeReplicasForMajorVersionUpgrade | boolean | – | Input only. Determines whether an in-place major version upgrade of replicas happens when an in-place major version upgrade of a primary instance is initiated. |
| instanceType | string | – | The instance type. |
| ipAddresses | array | – | The assigned IP addresses for the instance. |
| ipv6Address | string | – | The IPv6 address assigned to the instance. (Deprecated) This property was applicable only to First Generation instances. |
| kind | string | – | This is always `sql#instance`. |
| maintenanceVersion | string | – | The current software version on the instance. |
| masterInstanceName | string | – | The name of the instance which will act as primary in the replication setup. |
| maxDiskSize | string | – | The maximum disk size of the instance in bytes. |
| name | string | – | Name of the Cloud SQL instance. This does not include the project ID. |
| nodeCount | integer | – | The number of read pool nodes in a read pool. |
| nodes | array | – | Output only. Entries containing information about each read pool node of the read pool. |
| onPremisesConfiguration | – | – | Configuration specific to on-premises instances. |
| outOfDiskReport | – | – | This field represents the report generated by the proactive database wellness job for OutOfDisk issues. * Writers: * the proactive database wellness job for OOD. * Readers: * the proactive database w… |
| primaryDnsName | string | – | Output only. DEPRECATED: please use write_endpoint instead. |
| project | string | – | The project ID of the project containing the Cloud SQL instance. The Google apps domain is prefixed if applicable. |
| pscServiceAttachmentLink | string | – | Output only. The link to service attachment of PSC instance. |
| region | string | – | The geographical region of the Cloud SQL instance. It can be one of the [regions](https://cloud.google.com/sql/docs/mysql/locations#location-r) where Cloud SQL operates: For example, `asia-east1`, `e… |
| replicaConfiguration | – | – | Configuration specific to failover replicas and read replicas. |
| replicaNames | array | – | The replicas of the instance. |
| replicationCluster | – | – | Optional. A primary instance and disaster recovery (DR) replica pair. A DR replica is a cross-region replica that you designate for failover in the event that the primary instance experiences regiona… |
| rootPassword | string | – | Initial root password. Use only on creation. You must set root passwords before you can connect to PostgreSQL instances. |
| satisfiesPzi | boolean | – | Output only. This status indicates whether the instance satisfies PZI. The status is reserved for future use. |
| satisfiesPzs | boolean | – | This status indicates whether the instance satisfies PZS. The status is reserved for future use. |
| scheduledMaintenance | – | – | The start time of any upcoming scheduled maintenance for this instance. |
| secondaryGceZone | string | – | The Compute Engine zone that the failover instance is currently serving from for a regional instance. This value could be different from the zone that was specified when the instance was created if t… |
| selfLink | string | – | The URI of this resource. |
| serverCaCert | – | – | SSL configuration. |
| serviceAccountEmailAddress | string | – | The service account email address assigned to the instance.\This property is read-only. |
| settings | – | – | The user settings. |
| sqlNetworkArchitecture | string | – | – |
| state | string | – | The current serving state of the Cloud SQL instance. |
| suspensionReason | array | – | If the instance state is SUSPENDED, the reason for the suspension. |
| switchTransactionLogsToCloudStorageEnabled | boolean | – | Input only. Whether Cloud SQL is enabled to switch storing point-in-time recovery log files from a data disk to Cloud Storage. |
| tags | object | – | Optional. Input only. Immutable. Tag keys and tag values that are bound to this instance. You must represent each item in the map as: `"" : ""`. For example, a single resource can have the following… |
| upgradableDatabaseVersions | array | – | Output only. All database versions that are available for upgrade. |
| writeEndpoint | string | – | Output only. The dns name of the primary instance in a replication group. |
No examples provided.
get_operation ~106
Get the status of a long-running operation. A long-running operation can take several minutes to complete. If an operation takes an extended amount of time, then use a command line tool to pause for 30 seconds before rechecking the status of the operation.
| Name | Type | Req | Description |
|---|---|---|---|
| location | string | – | Optional. Region of the Cloud SQL instance. |
| operation | string | yes | Required. Instance operation ID. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
import_data ~625
Import data into a Cloud SQL instance. If the file doesn't start with `gs://`, then the assumption is that the file is stored locally. If the file is local, then the file must be uploaded to Cloud Storage before you can make the actual `import_data` call. To upload the file to Cloud Storage, you can use the `gcloud` or `gsutil` commands. Before you upload the file to Cloud Storage, consider whether you want to use an existing bucket or create a new bucket in the provided project. After the file is uploaded to Cloud Storage, the instance service account must have sufficient permissions to read the uploaded file from the Cloud Storage bucket. This can be accomplished as follows: 1. Use the `get_instance` tool to get the email address of the instance service account. From the output of the tool, get the value of the `serviceAccountEmailAddress` field. 2. Grant the instance service account the `storage.objectAdmin` role on the provided Cloud Storage bucket. Use a command like `gcloud storage buckets add-iam-policy-binding` or a request to the Cloud Storage API. It can take from two to up to seven minutes or more for the role to be granted and the permissions to be propagated to the service account in Cloud Storage. If you encounter a permissions error after updatingthe IAM policy, then wait a few minutes and try again. After permissions are granted, you can import the data. We recommend that you leave optional parameters empty and use the system defaults. The file type can typically be determined by the file extension. For example, if the file is a SQL file, `.sql` or `.csv` for CSV file. The following is a sample SQL `importContext` for MySQL. ``` { "uri": "gs://sample-gcs-bucket/sample-file.sql", "kind": "sql#importContext", "fileType": "SQL" } ``` There is no `database` parameter present for MySQL since the database name is expected to be present in the SQL file. Specify only one URI. No other fields are required outside of `importCo…
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | – | – |
| instance | string | – | Cloud SQL instance ID. This does not include the project ID. |
| location | string | – | Optional. Region of the Cloud SQL instance. |
| project | string | – | Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
list_instances ~235
List all Cloud SQL instances in the project.
| Name | Type | Req | Description |
|---|---|---|---|
| filter | string | – | A filter expression that filters resources listed in the response. The expression is in the form of field:value. For example, 'instanceType:CLOUD_SQL_INSTANCE'. Fields can be nested as needed as per… |
| location | string | – | Optional. Region of the Cloud SQL instance. |
| maxResults | integer | – | The maximum number of instances to return. The service may return fewer than this value. If unspecified, at most 500 instances are returned. The maximum value is 1000; values above 1000 are coerced t… |
| pageToken | string | – | A previously-returned page token representing part of the larger set of results to view. |
| project | string | – | Project ID of the project for which to list Cloud SQL instances. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | – | List of mcp instance resources. |
| kind | string | – | This is always sql#instancesList. |
| nextPageToken | string | – | The continuation token, used to page through large result sets. Provide this value in a subsequent request to return the next page of results. |
| warnings | array | – | List of warnings that occurred while handling the request. |
No examples provided.
list_users ~67
List all database users for a Cloud SQL instance.
| Name | Type | Req | Description |
|---|---|---|---|
| instance | string | – | Database instance ID. This does not include the project ID. |
| location | string | – | Optional. Region of the Cloud SQL instance. |
| project | string | – | Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | – | List of user resources in the instance. |
| kind | string | – | This is always `sql#usersList`. |
| nextPageToken | string | – | Unused. |
No examples provided.
postgres_upgrade_precheck ~415
Checks if a Cloud SQL for PostgreSQL instance is ready for a major version upgrade to the specified target version. The `target_database_version` MUST be provided in the request (e.g., `POSTGRES_15`). This tool helps identify potential issues *before* attempting the actual upgrade, reducing the risk of failure or downtime. This tool is only supported for PostgreSQL primary instances and does not run on read replicas. The precheck typically evaluates: - Database schema compatibility with the target version. - Cloud SQL limitations and unsupported features. - Instance resource constraints (e.g., number of relations). - Compatibility of current database settings and extensions. - Overall instance health and readiness. This tool returns a long-running operation. Use the `get_operation` tool with the operation name returned by this call to poll its status. IMPORTANT: Once the operation status is DONE, the detailed precheck results are available within the `Operation` resource. You will need to inspect the response from `get_operation`. The findings are located in the `pre_check_major_version_upgrade_context.pre_check_response` field. The findings are structured, indicating: - INFO: General information. - WARNING: Potential issues that don't block the upgrade but should be reviewed. - ERROR: Critical issues that MUST be resolved before attempting the upgrade. Each finding should include a message and any required actions. Addressing any reported issues is crucial before proceeding with the major version upgrade. If `pre_check_response` is empty or missing, it indicates that no issues were identified during the precheck. Running this precheck does not impact the instance's availability.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Required. The context for request to perform the pre-check major version upgrade operation. |
| instance | string | yes | Required. Cloud SQL instance ID. This does not include the project ID. |
| location | string | – | Optional. Region of the Cloud SQL instance. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
restore_backup ~451
Restores a backup to a Cloud SQL instance. The target_instance and target_project must be provided and populated in the request. The backup identifier can be provided in several ways: 1. A backup_run_id (which is an integer). 2. A backup URI of the format `projects/{project-id}/backups/{backup-uid}`. 3. A backup URI of the format `projects/{project-id}/locations/{location}/backupVaults/{backupvault}/dataSources/{datasource}/backups/{backup-uid}`. Use the identifier to populate the `backup_id` field in the request. The source_project must be populated in the request. If the identifier is a backup_run_id, the source_project will be provided. If the identifier is a backup URI, the source_project may need to be extracted from the URI. Do not confuse the extracted source_project with the target_project, which will be provided in other ways. In addition, if the identifier is a backup_run_id, the source_instance must be provided and populated in the request. Do not try to create the instance before the restore, the restore itself will create the instance if needed. Confirm the parameters with the user before executing the restore.
| Name | Type | Req | Description |
|---|---|---|---|
| backupId | string | yes | Required. The identifier of the backup to restore. This will be one of the following: 1. An int64 containing a backup_run_id. 2. A backup name of the format 'projects/{project}/backups/{backup-uid}'.… |
| sourceInstance | string | – | Optional. The Cloud SQL instance ID of the source instance containing the backup. Only necessary if the backup_id is a backup_run_id. |
| sourceProject | string | yes | Required. The project ID of the source instance containing the backup. |
| targetInstance | string | yes | Required. Cloud SQL instance ID of the target. This does not include the project ID. |
| targetProject | string | yes | Required. Project ID of the target project. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
update_instance ~415
Partially updates the configuration settings of a Cloud SQL instance. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * Some update operations, such as changing the edition upgrade or instance tier, etc might cause the instance to restart, resulting in downtime. Before you proceed with such operations, get confirmation from the user.
| Name | Type | Req | Description |
|---|---|---|---|
| dataApiAccess | string | – | Optional. The settings for controlling data API access to an instance. |
| dataCacheConfig | – | – | Optional. Configuration for the data cache. A data cache can improve performance for read-heavy workloads by caching frequently accessed data in-memory. |
| dataDiskSizeGb | string | – | Optional. Data disk size in GB. |
| databaseFlags | array | – | Optional. The database flags. |
| edition | string | – | Optional. The edition of the instance, can be ENTERPRISE or ENTERPRISE_PLUS. |
| googleMlIntegrationEnabled | boolean | – | Optional. Enables Cloud SQL instances to connect to Vertex AI to pass requests for real-time predictions and insights to the AI. The default value is false. This applies only to Cloud SQL for MySQL a… |
| instance | string | yes | Required. Cloud SQL instance ID. This does not include the project ID. |
| ipv4Enabled | boolean | – | Optional. Whether to enable public IP for the instance. Enabling this flag makes the resource accessible from the public internet, which is a security risk if not properly managed. It is recommended… |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| psaMcpConfig | – | – | Optional. Configuration for Private Service Access (PSA) instance update. |
| pscMcpConfig | – | – | Optional. Configuration for Private Service Connect (PSC) instance update. |
| tier | string | – | Optional. The tier (or machine type) for this instance. format: db-custom-{CPUs}-{Memory}. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
update_user ~812
Update a database user for a Cloud SQL instance. A common use case for the `update_user` is to grant a user the `cloudsqlsuperuser` role, which can provide a user with many required permissions. This tool only supports updating users to assign database roles. * This tool returns a long-running operation. Use the `get_operation` tool to poll its status until the operation completes. * Before calling the `update_user` tool, always check the existing configuration of the user such as the user type with `list_users` tool. * As a special case for MySQL, if the `list_users` tool returns a full email address for the `iamEmail` field, for example `{name=test-account, iamEmail=test-account@project-id.iam.gserviceaccount.com}`, then in your `update_user` request, use the full email address in the `iamEmail` field in the `name` field of your toolrequest. For example, `name=test-account@project-id.iam.gserviceaccount.com`. Key parameters for updating user roles: * `database_roles`: A list of database roles to be assigned to the user. * `revokeExistingRoles`: A boolean field (default: false) that controls how existing roles are handled. How role updates work: 1. **If `revokeExistingRoles` is true:** * Any existing roles granted to the user but NOT in the provided `database_roles` list will be REVOKED. * Revoking only applies to non-system roles. System roles like `cloudsqliamuser` etc won't be revoked. * Any roles in the `database_roles` list that the user does NOT already have will be GRANTED. * If `database_roles` is empty, then ALL existing non-system roles are revoked. 2. **If `revokeExistingRoles` is false (default):** * Any roles in the `database_roles` list that the user does NOT already have will be GRANTED. * Existing roles NOT in the `database_roles` list are KEPT. * If `database_roles` is empty, then there is no change to the user's roles. Examples: * Existing Roles: `[roleA, roleB]` * Re…
| Name | Type | Req | Description |
|---|---|---|---|
| databaseRoles | array | – | Optional. List of database roles to grant to the user. body.database_roles will be ignored for update request. |
| host | string | – | Optional. Host of the user in the instance. |
| instance | string | yes | Required. Database instance ID. This does not include the project ID. |
| name | string | yes | Required. Name of the user in the instance. |
| project | string | yes | Required. Project ID of the project that contains the instance. |
| revokeExistingRoles | boolean | – | Optional. revoke the existing roles granted to the user. |
| type | string | yes | Required. The user type. It determines the method to authenticate the user during login. The default is the database's built-in user type. |
| Name | Type | Req | Description |
|---|---|---|---|
| acquireSsrsLeaseContext | – | – | The context for acquire SSRS lease operation, if applicable. |
| apiWarning | – | – | An Admin API warning message. |
| backupContext | – | – | The context for backup operation, if applicable. |
| endTime | string | – | The time this operation finished in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| error | – | – | If errors occurred during processing of this operation, this field will be populated. |
| exportContext | – | – | The context for export operation, if applicable. |
| importContext | – | – | The context for import operation, if applicable. |
| insertTime | string | – | The time this operation was enqueued in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| kind | string | – | This is always `sql#operation`. |
| name | string | – | An identifier that uniquely identifies the operation. You can use this identifier to retrieve the Operations resource that has information about the operation. |
| operationType | string | – | The type of the operation. Valid values are: * `CREATE` * `DELETE` * `UPDATE` * `RESTART` * `IMPORT` * `EXPORT` * `BACKUP_VOLUME` * `RESTORE_VOLUME` * `CREATE_USER` * `DELETE_USER` * `CREATE_DATABASE… |
| preCheckMajorVersionUpgradeContext | – | – | This field is only populated when the operation_type is PRE_CHECK_MAJOR_VERSION_UPGRADE. The PreCheckMajorVersionUpgradeContext message itself contains the details for that pre-check, such as the tar… |
| selfLink | string | – | The URI of this resource. |
| startTime | string | – | The time this operation actually started in UTC timezone in [RFC 3339](https://tools.ietf.org/html/rfc3339) format, for example `2012-11-15T16:19:00.094Z`. |
| startWorkloadCaptureContext | – | – | The context for the `StartWorkloadCapture` operation, which contains details to start recording the workload (SQL queries) on a Cloud SQL instance. |
| startWorkloadReplayContext | – | – | The context for the `StartWorkloadReplay` operation, which contains details about starting the execution of a captured workload (recorded read and write SQL queries) on a replay instance (the Cloud S… |
| status | string | – | The status of an operation. |
| stopWorkloadCaptureContext | – | – | The context for the `StopWorkloadCapture` operation, which contains details to stop recording the workload (SQL queries) on a Cloud SQL instance. |
| stopWorkloadReplayContext | – | – | The context for the `StopWorkloadReplay` operation, which contains details about stopping the execution of a captured workload (recorded read and write SQL queries) on a replay instance. |
| subOperationType | – | – | Optional. The sub operation based on the operation type. |
| targetId | string | – | Name of the resource on which this operation runs. |
| targetLink | string | – | – |
| targetProject | string | – | The project ID of the target instance related to this operation. |
| user | string | – | The email address of the user who initiated this operation. |
No examples provided.
What is the com.googleapis.sqladmin/mcp server?
com.googleapis.sqladmin/mcp is listed in the public MCP registry as com.googleapis.sqladmin/mcp. Create, manage, and query your Google Cloud SQL resources. This page covers its hosted endpoint (https://sqladmin.googleapis.com/mcp).
Is the com.googleapis.sqladmin/mcp server safe to use?
com.googleapis.sqladmin/mcp scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the com.googleapis.sqladmin/mcp server expose?
com.googleapis.sqladmin/mcp exposes 15 tools: list_instances, get_instance, create_instance, execute_sql, execute_sql_readonly, and 10 more. Their descriptions and schemas cost roughly 8,023 tokens of context every time the server is loaded.
Does the com.googleapis.sqladmin/mcp server require authentication?
No. We connected to com.googleapis.sqladmin/mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the com.googleapis.sqladmin/mcp server still maintained?
com.googleapis.sqladmin/mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.