Google turns REST into MCP tools with one flag, and its own record has no MCP server

Google turns REST into MCP tools with one flag, and its own record has no MCP server

Google Cloud API Gateway can now serve an existing REST API as MCP tools, and the configuration is one line in the OpenAPI document. In Turn your REST APIs into MCP tools with Google Cloud API Gateway, Sanjay Pujare, Paul Howell, and Geir Sjurseth open with the problem the whole MCP wave is circling: “Most enterprise capability sits behind REST APIs that agents cannot see.” Set mcp: true under the x-google-api-management extension, deploy, and “API Gateway generates an MCP-aware configuration and begins serving MCP on the /mcp base path, with no extra infrastructure to provision.” Each operation becomes a tool, with a per-operation x-google-mcp-tool extension to rename it, rewrite its description, or hide it.

There are no adoption numbers, only limits, and the limits are the useful part. Operations returning an empty body are not exposed, deeply nested schemas may not render fully in the tool list, a gateway serves up to 1,000 tools, and “MCP and model routing cannot be enabled in the same API config,” which puts this release and the model-routing release this series covered two weeks ago on separate gateways. The governance claim is the one that will sell it: “MCP and REST traffic share exactly one policy path, and a given operation draws on one quota allocation however it is invoked.” The security note is candid. “By default tools/list is unauthenticated, which is convenient for development but publishes your tool names and input schemas to anyone who asks.” And the writing advice is correct and rarely said: “A tool’s description is the primary signal an LLM uses to decide when to call it, so write when and why to use the tool, not just what it returns.”

The catalog can hold Google to its own flag. The Google Cloud API Gateway provider page lists one API page, the Google Cloud API Gateway Projects API, the management surface where the API config carrying the extension is created and deployed. The agentic access profile maps 11 operations, 6 of them acting. The MCP server dimension on the record is unlit. The product that turns any REST API into an MCP server with one flag has not, as far as the catalog can find, flipped the flag on itself.

The Kin Score is 50.0, developing band, up from 49.5 when this series last wrote about the gateway. Discoverability carries it at 66.1 and developer ergonomics at 58.3, with access clarity at 55.3, contract quality at 50.2, and contract governance at 9.8. The Agent Readiness score is 19.8, agent-aware, and the unlit list is what it was: OpenAPI examples, error semantics, agent skills, the well-known catalog, every identity dimension. The post asks API owners to write tool descriptions that say when and why. The gateway’s own contract, the one an agent would read to manage the gateway, still carries no examples and no described errors. One flag turns a REST API into tools. The record is waiting for the one on Google’s own.

← The most programmable vendor in the Gartner Magic Quadrants is Harness, and seven quadrants go to a vendor Gartner did not name a Leader
APIs.io Insights reads 343,299 job postings for the APIs 984 companies name, and joins them to the catalog →