4,500+ servers built on MCP Fusion
Vinkius
Cerbos logo
Vinkius
Google ADK logo

How to Use the Cerbos MCP in Google ADK

Gate access to Google Cloud resources using Cerbos and the Google ADK for your Gemini agents.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Cerbos MCP on Cursor AI Code Editor MCP Client Cerbos MCP on Claude Desktop App MCP Integration Cerbos MCP on OpenAI Agents SDK MCP Compatible Cerbos MCP on Visual Studio Code MCP Extension Client Cerbos MCP on GitHub Copilot AI Agent MCP Integration Cerbos MCP on Google Gemini AI MCP Integration Cerbos MCP on Lovable AI Development MCP Client Cerbos MCP on Mistral AI Agents MCP Compatible Cerbos MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Google ADK

Connect Cerbos MCP to Google ADK

Create your Vinkius account to connect Cerbos to Google ADK and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Generate Access Plans for BigQuery

The `plan_resources` tool is what you need to secure data access. It gives your agent a query plan that defines which resources a user is allowed to see, based on your central Cerbos policies. For the Google ADK, this means your agent can construct a safe BigQuery `WHERE` clause. It asks Cerbos 'what can this user see?' and gets back the exact conditions to build a secure query, preventing data leaks.

Run Centralized Permission Checks

Use the `check_resources` tool to ask a simple question: 'Can this principal do this action on these resources?' Cerbos evaluates your policies and returns a direct answer. This is critical for enterprise agents built on the Google ADK. You can check permissions on a Vertex AI endpoint or a Cloud Storage bucket before your agent attempts to use it, all against one source of truth.

Connect Your Gemini Agent to a Cerbos MCP Server

The `get_authzen_config` and `get_server_info` tools help your agent understand its environment. It can find the right AuthZEN API endpoints or check the server version for diagnostics. Your Gemini agent can use its long-context window to reason about these configurations. An agent can self-diagnose connection issues or adapt its behavior based on the Cerbos instance it's connected to. This MCP server makes your agent more aware.

Setup guide

Set up Cerbos MCP in Google ADK

Prerequisites

  • Python 3.10+ installed
  • google-adk package (pip install google-adk)
  • Active Vinkius subscription with a valid endpoint token
  1. 1

    Install Google ADK

    Run pip install google-adk to install the Agent Development Kit. MCP support is included via the McpToolset class.

  2. 2

    Connect via SSE transport

    Use McpToolset.from_server() with SseServerParams pointing to your Vinkius endpoint. Replace [YOUR_TOKEN_HERE] with your token from cloud.vinkius.com.

  3. 3

    Create an LlmAgent

    Pass the returned mcp_tools list directly to LlmAgent(tools=mcp_tools). The ADK maps each MCP tool to a native Gemini function call — no manual schema definitions required.

  4. 4

    Run with any Gemini model

    The agent works with any Gemini model (gemini-2.0-flash, gemini-2.5-pro, etc.). Copy the full example on the right to get started with Cerbos tools in your ADK agent.

agent.py
from google.adk.agents import LlmAgent
from google.adk.tools.mcp_tool.mcp_toolset import McpToolset
from google.adk.tools.mcp_tool.mcp_session_manager import SseServerParams

# Connect to the MCP via SSE
mcp_tools, exit_stack = await McpToolset.from_server(
    connection_params=SseServerParams(
        url="https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp"
    )
)

# Create your agent with auto-discovered tools
agent = LlmAgent(
    name="Cerbos_agent",
    model="gemini-2.0-flash",
    instruction="You have access to Cerbos tools via MCP.",
    tools=mcp_tools,
)

Independent Platform Disclaimer: Vinkius is an independent platform and is not affiliated with, endorsed by, sponsored by, verified by, or otherwise authorized by Cerbos. All third-party trademarks, logos, and brand names are the property of their respective owners. Their use on this website is strictly for informational purposes to identify service compatibility and interoperability.

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about Cerbos MCP in Google ADK

You add the Cerbos server as an `McpToolset` when creating your `LlmAgent`. The ADK then makes the Cerbos tools available to your Gemini model, so it can make authorization calls as part of its reasoning process.
Yes, that's a primary use case. Use the `plan_resources` tool in your agent to get a query plan from Cerbos. Then, use that plan to build a secure SQL query that only returns data the user is authorized to see.
It's not about being better, it's about decoupling. With Cerbos, you manage access rules separately from your agent code. This lets you update permissions without having to redeploy your agent on Google Cloud.
Yes. The `McpToolset` in the Google ADK has a `tool_names` filter. You can use it to expose only specific tools, like `check_resources`, to a particular agent.
Only the data needed for the check, like a principal's identifier, the resource they're trying to access, and the action. This information is processed ephemerally and is never logged or stored by the Vinkius-managed server.

Start using the Cerbos MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 6 tools

We've already built the connector for Cerbos. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 6 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.