What you’ll do
Setup spans two products, and some stages depend on someone other than you, so line those up before you start. Stages 1 through 6 are for the administrator who connects the MCP server, and end with you confirming the connection works. Stage 7 then gives other people access to use it. The roles each stage needs are in Required roles.Before you begin
Confirm all of these before you start. The organization policy change in particular can take time to arrange.- In C1, AI access management is enabled for your tenant, which is a one-time task for a Super Administrator. Managing AI clients and assigning toolsets then needs Super Administrator or AI Governance Administrator. See Enable AI access management.
- You need C1 tool access yourself. Tool discovery lists only the tools your access profiles allow, and someone with no toolset sees no tools at all. See Tools and toolsets. Access for the people who will use the connection comes later, in Give users access.
- A Google Cloud project with a Gemini Enterprise app already created. In the console, open Gemini Enterprise and select Create app, or see Google’s Create a Gemini Enterprise app documentation. To create one from the command line instead, see Prepare Google Cloud.
- A Gemini Enterprise subscription with licenses available to assign. A new app starts with no users licensed.
- Someone who holds
roles/orgpolicy.policyAdminat the organization level, lined up to change one to three organization policies. Project Owner does not include it. - A project where you may publish one public file. If your organization blocks public sharing, host the client metadata document from a project dedicated to it, because allowing public sharing is a project-wide change. See Host the client metadata document.
- Optional. The gcloud CLI, authenticated with
gcloud auth login, if you prefer the command line for the Google Cloud steps.
Collect the values you’ll reuse
The steps below reuse these values. Collect the first set now. The rest do not exist yet, and the table says which stage produces each one.conductor.one. If your organization is on the EU data residency instance, substitute c1eu.ai in URLs, client IDs, and hostnames.global, which is what most setups run. If your app is in a different location, substitute it everywhere locations/global appears.Required roles
These are the roles for the administrator who sets up the connection and adds MCP servers. People who only use MCP servers that are already set up need much less. See Give users access.Roles to prepare the project
You need these once for each Google Cloud project.What you need to add MCP servers
You need all of these to create the C1 data store in this guide. The same requirements apply to any MCP server you add to the app later.roles/discoveryengine.editor is not enough to add MCP servers. It can read data stores and connectors but cannot create or change them, and every step that adds a server writes to one or the other. Owners hold the missing permissions, so the gap only shows for administrators who are not Owners.
If your organization restricts which hostnames a data connector may reach, each new MCP server’s hostname must also be allowed, which needs roles/orgpolicy.policyAdmin. See Allow custom MCP data connectors.
Check and grant roles
To check what you already hold on the project:Prepare Google Cloud
Enable two APIs, then turn off the organization policy that blocks custom MCP data connectors. If you do not have a Gemini Enterprise app yet, you can create one from the command line between the two.Enable the Google Cloud APIs
The project needs two APIs. The Cloud Storage API is enabled on new projects by default, so hosting the client metadata document needs no extra API.- Console
- Command line
Optional: Create the app from the command line
Skip this if you already have an app. There is nogcloud surface for creating one, so call the API directly:
Allow custom MCP data connectors
Google Cloud blocks custom MCP data connectors by default through theconstraints/discoveryengine.managed.disableCustomMcpServerConnector organization policy. Turn it off for this project before you create the data store. The override applies at the project level, but the person applying it needs roles/orgpolicy.policyAdmin, which project Owner does not include.
If the policy is enforced, creating the data store fails at the final step with:
- Console
- Command line
discoveryengine.managed.disableCustomMcpServerConnector and open it.describe command above. The effective policy reports enforce: false, and your project can create custom MCP data connectors.
If your organization restricts outbound hostnames
If your organization restricts outbound hostnames
constraints/discoveryengine.managed.allowedEgressFqdns, which limits the hosts a data connector may reach. It applies only to projects with VPC Service Controls enabled, or to projects your organization has added to the constraint’s enforced list, so most setups never meet it. Check it with:NOT_FOUND: Requested entity was not found. That is the healthy answer and means nothing is restricting egress.If it does apply, allow the two hostnames your tenant uses. Use hostnames only, not full URLs. This is a boolean constraint that takes parameters, not a list of allowed values. Save this as egress.yaml and apply it with gcloud org-policies set-policy egress.yaml, keeping any hostnames your organization already allows:<your-tenant>-mcp.c1eu.ai and <your-tenant>.c1eu.ai instead.Prepare Gemini Enterprise
Set the identity provider, license yourself, and sign in to the web app once, in that order. The data store form cannot be submitted without an identity provider, and tool discovery fails later for anyone who is unlicensed or has never opened the web app.Set the identity provider
Gemini Enterprise needs an identity provider selected for the location your app runs in. Until one is set, creating a data connector fails with You must configure your access control settings before you continue. Set it in the console or from the command line.- Console
- Command line
global, and select the edit icon.Assign Gemini Enterprise licenses
A new Gemini Enterprise app has a subscription but no licensed users, and the users list reads No existing users. Assign a license to yourself now, because you need one to finish setup. Licenses for the people who will use the connection come later, in Give users access.- Console
- Command line
If no active subscription is listed after you bought licenses
If no active subscription is listed after you bought licenses
us, from an app in global. To see where they went, list your billing account’s subscriptions and read licenseConfigDistributions:Sign in to the web app
Open the Gemini Enterprise web app once, as yourself. Tool discovery runs as the signed-in user, and it fails for anyone who has never opened the web app, with only a generic Failed to reload custom actions to show for it. Signing in through Verify Auth when you create the data store does not count, because that authorizes the connector, not the web app. Get the web app URL in the console or from the command line.- Console
- Command line
https://vertexaisearch.cloud.google.com/home/cid/<id>, where <id> is a generated identifier.https://vertexaisearch.cloud.google.com/home/cid/c1-gemini-app loads a 400 page that reads You are not assigned an active license, even for users who hold one. The error points at licensing, but the cause is the URL.lastLoginTime is present:
lastLoginTime has never opened the web app, and tool discovery will fail for them.
Host the client metadata document
Gemini Enterprise signs each user in to C1 with OAuth, so it needs a client ID. For C1, a client ID is a URL. It points at a small public JSON file that describes the client, called a Client ID Metadata Document, and C1 fetches it to identify the client. Neither Google nor C1 hosts one for Gemini Enterprise yet, so you host it. For why, see Frequently asked questions about connecting Gemini Enterprise. This stage is command line only. The document must be reachable without authentication, and a public Cloud Storage bucket works.gemini-enterprise-oauth-client.json, replacing YOUR_BUCKET with your bucket name. Two fields are unforgiving: client_id must exactly equal the URL the file is served from, and redirect_uris must contain Google’s redirect endpoint verbatim.client_id matches the URL you requested:If an organization policy blocks the public binding
If an organization policy blocks the public binding
roles/orgpolicy.policyAdmin. To change either in the console, use the same IAM & Admin > Organization policies flow described there, searching for the constraint name below instead.Domain restricted sharing. If constraints/iam.allowedPolicyMemberDomains is enforced, granting allUsers fails with:allUsers as an allowed value, so the override has to permit all values. Save this as drs.yaml and apply it with gcloud org-policies set-policy drs.yaml:constraints/storage.publicAccessPrevention is enforced, the binding is refused regardless of the constraint above. Save this as pap.yaml and apply it with gcloud org-policies set-policy pap.yaml:412 for a short while, and describe --effective may report the new value before enforcement catches up. Retry the binding rather than assuming the override is wrong, and confirm success by fetching the document URL.Create the data store
Connect the C1 MCP gateway to your Gemini Enterprise app. This is the one step that only works in the console. See Frequently asked questions about connecting Gemini Enterprise for why. Before you open the form, check these. Each one, if missed, fails the form or the steps after it:- Prepare Gemini Enterprise is finished. If you leave the form partway through to set the identity provider, you return to a partially reset form and it is easy to submit it incomplete.
- Your client ID URL resolves, as in Host the client metadata document, and you have your tenant’s OAuth endpoints from Collect the values you’ll reuse.
- You use the Custom MCP Server card, not a server imported from Agent Registry. A connector created from a registry import fails tool discovery with
Failed to reload custom actionsand aFAILED_PRECONDITIONerror.
Custom MCP.conductor.one on the default instance, or c1eu.ai on the EU data residency instance. The third column is where this form most often goes wrong.Enable the actions
Gemini Enterprise calls MCP tools actions, and imports every one of them turned off. Choose which to enable, then turn them on in the data store’s Actions tab. The app’s own Actions page only links back there. A data store supports a maximum of 100 enabled actions, and a shorter list makes the agent’s tool selection more accurate.Reach every tool without spending your action budget
The C1 gateway publishes far more tools than the 100 a data store can enable. Rather than choosing a hundred of them, enable these twelve. They let the agent find and run any tool your access profiles allow:search_tools. The enabled set only decides what is offered. Every call is still evaluated against the calling user’s access profiles, so this changes what the agent can find, never what a person is allowed to do.
get_execution alongside execute. A program that runs longer than about 25 seconds returns a pending status and an execution ID instead of a result, and get_execution is what collects it. Without it those runs cannot be recovered and the agent reports a failure for work that actually succeeded.Turn on the actions
Wait for the connector state to reach Active before you start, because the reload fails while the connector is still creating. Discovering the tool list happens only in the console. After that, you can set the enabled actions in the console or from the command line.- Console
- Command line
Verify the Gemini Enterprise connection
Confirm the connection works before you give anyone else access. Seeing actions listed does not prove it: the setup is confirmed only when a user calls a C1 tool and C1 records the call against that person. You are already licensed and signed in, so that user can be you.storage.googleapis.com. That is expected while you host the document yourself.Give users access
This section covers only what a person needs to use MCP servers that are already set up. None of it lets them add or change MCP servers, and they need none of the roles in Required roles. Each user needs all of these:Grant access to users
An administrator grants these, withroles/discoveryengine.admin and project Owner or roles/resourcemanager.projectIamAdmin.
roles/discoveryengine.user on the project:What each user does
Each user does this once, for themselves. Enabling actions as an administrator authorizes nobody, and until a user authorizes, the assistant answers that it has no C1 integration, even though the actions are enabled and the connector is Active. These steps are written so you can send them to your users as they are.Troubleshoot Gemini Enterprise connection errors
Errors are grouped by when they appear: while setting up, while discovering tools, or while people use the connector.Errors while setting up the connection
Errors while discovering tools
Errors while people use the connector
What this integration cannot do
These constraints come from Gemini Enterprise and Google Cloud.- VPC Service Controls and Private Service Connect are not supported for custom MCP data stores. If your Google Cloud perimeter requires either, this integration cannot run inside it.
- Gemini Enterprise supports egress mode only. It calls out to your MCP server; your MCP server cannot call in.
- A data store supports a maximum of 100 enabled actions.
Frequently asked questions about connecting Gemini Enterprise
Why do I have to host the client metadata document myself?
Why do I have to host the client metadata document myself?
https://<your-tenant>.conductor.one/auth/v1/client-metadata/gemini-enterprise, but it has not shipped, so every tenant returns a 404 from that URL. It is a stopgap rather than the end state, because a client identity carries the most weight when the client’s own vendor publishes it. Contact the C1 support team for timing.When Google publishes a client metadata document for Gemini Enterprise, use that URL as the client ID and retire whatever you were hosting.Why not register a client through dynamic registration instead?
Why not register a client through dynamic registration instead?
Can I create the data store from the command line?
Can I create the data store from the command line?
Why does the Client Secret not matter?
Why does the Client Secret not matter?
Do I need Agent Gateway or Agent Registry?
Do I need Agent Gateway or Agent Registry?
use_agent_gateway_egress: false, so its traffic never passes through Agent Gateway, and a setup built with no gateway and no registry discovers tools and serves live tool calls normally. C1 governs the tool calls.Agent Registry is a catalog of approved MCP servers. Listing the C1 gateway there is a separate exercise that changes nothing about this integration. If you do list it, still create your data connector from the Custom MCP Server card: a connector imported from the registry fails tool discovery.How do I cut off access in a hurry?
How do I cut off access in a hurry?
Can I see what tools Gemini Enterprise called?
Can I see what tools Gemini Enterprise called?
Pages related to governing AI tool access
These pages cover the C1 side of the integration.- Tools and toolsets covers the access profiles that decide which tools each user can call.
- Manage AI clients covers lifecycle states, the kill switch, and allowed client types.
- Connect to the C1 MCP covers the same gateway from desktop AI assistants.
- Audit AI tool usage covers what C1 logs for every tool call.