Stop your agent guessing Google Cloud flags: wire in the Developer Knowledge MCP server
Google runs an official documentation search for coding agents. Ten minutes to connect it to Claude Code, with the key kept out of git.

Ask an agent for the flags to create a Cloud Run job with a VPC connector, and the command it gives back can look right and still fail. The flag was renamed, or it lives in the beta component, or it never existed. The agent isn’t lying. It’s recalling documentation that was current when its training data was cut.
Google publishes a fix for its own products: the Developer Knowledge API and its MCP server, which put the official docs behind three tools an agent can call. It went generally available on 16 April 2026, according to the release notes , and it keeps growing. If your agent writes against Google Cloud, Firebase, Android, Flutter, Go or the Gemini tooling, connecting it takes about ten minutes. Below is the setup for Claude Code, including the part most examples skip: keeping the API key out of your repository.
Everything here comes from Google’s and Anthropic’s documentation. It describes documented behaviour, not output from a live session.
What the server gives the agent
Three tools, per the MCP setup page :
search_documentsreturns relevant excerpts with the names of the documents they came from.get_documentstakes those names and returns the full page as Markdown.answer_queryreturns a generated answer drawn from the same corpus.
That second tool replaced two older ones. get_document and batch_get_documents were removed on 8 March 2026 in favour of a single get_documents, so an older tutorial that names them is out of date.
The corpus covers more than cloud docs. The release notes list additions over the year: adk.dev, antigravity.google, geminicli.com and go.dev in April, cloud.google.com, dart.dev, docs.flutter.dev and mapsplatform.google.com in May, genkit.dev in August, and knowledge.workspace.google.com on 1 October. The limits are plain: public documentation only, English only, and nothing from your private sources.
Step 1: enable the API and create a key
You need a Google Cloud project. Two commands, both from the setup page:
gcloud services enable developerknowledge.googleapis.com --project=PROJECT_ID
gcloud services api-keys create --project=PROJECT_ID --display-name="DK API Key"
Then restrict the key to the Developer Knowledge API, either in the console’s Credentials page or on the key itself. Google’s page says to do this, and it’s the step that matters: a key that can only call a documentation search is a boring thing to leak.
API keys are the recommended route for Claude Code, Cursor, Copilot and Codex. The alternatives are an Application Default Credentials bearer token, which expires after an hour and so suits a quick test more than a daily setup, and OAuth 2.0 with the devprofiles.full_control scope. Dynamic Client Registration isn’t supported, which rules out clients that expect to register themselves.
Step 2: add it to Claude Code without committing the key
Google’s page shows this command:
claude mcp add google-developer-knowledge \
--transport http https://developerknowledge.googleapis.com/mcp \
--header "X-Goog-Api-Key: YOUR_API_KEY"
Run as written, it stores the key in your local Claude Code configuration. Anthropic’s MCP docs
give three scopes: local (the default, kept in ~/.claude.json and private to you in this project), project (written to .mcp.json and shared through version control) and user (all your projects, also in ~/.claude.json).
For one developer, the default is fine. For a team, put the server in .mcp.json so everyone gets it, and let each person supply their own key through an environment variable. Claude Code expands ${VAR} in a server’s url and headers:
{
"mcpServers": {
"google-developer-knowledge": {
"type": "http",
"url": "https://developerknowledge.googleapis.com/mcp",
"headers": {
"X-Goog-Api-Key": "${GOOGLE_DK_API_KEY}"
}
}
}
}
Export GOOGLE_DK_API_KEY in your shell profile and the file is safe to commit. If the variable is unset and has no default, Claude Code doesn’t fail quietly. It warns in claude mcp list and /mcp, then loads the server with the literal ${GOOGLE_DK_API_KEY} text as the header value, which Google will reject. A warning there means a missing variable, not a broken server.
Check it:
claude mcp list
Inside a session, /mcp shows the same status. In an interactive session Claude Code asks you to approve a project-scoped server the first time it sees it. Google’s setup page suggests a test prompt: if the agent calls search_documents or answer_query and comes back with Google documentation, you’re connected.
Step 3: install the skill, so the agent reaches for it
Connecting the server isn’t the same as the agent using it. Left alone, it can answer from memory without ever calling the tool. Google ships an agent skill for exactly this, announced in its 7 October post :
npx skills add google/skills --skill retrieving-developer-knowledge
The google/skills repository is Google’s own and Apache-2.0 licensed. The skill is plain instructions in a SKILL.md file, with a REST fallback described in supporting files. As the skill describes it, the lookup runs in the current context rather than being handed to a subagent, and it tells the agent which tool to pick:
answer_queryfor conceptual questions.search_documentswith two to five keywords for CLI flags and exact syntax.get_documentswhen an excerpt isn’t enough and the full page is needed.
Two instructions in it are worth copying into your own habits. First, an auth error, an empty result or an error payload counts as a failed lookup, not as “no docs found”. Second, if the lookup fails, the agent should say the answer isn’t grounded in documentation. That one line is what separates a tool that reduces guessing from one that hides it.
It also covers quota. On a 429, the skill switches from answer_query to keyword search, which is a sensible order: a generated answer is the expensive call, and excerpts are usually enough for a flag.
Read the skill before you install it, as with anything that becomes part of your agent’s instructions. It’s short.
Prompting it to check the docs
With the skill in place, the agent still needs to know when a docs check is required. A few lines in CLAUDE.md do it:
## Google product documentation
- Before writing or changing any gcloud, Firebase, Android, Flutter or Go
standard-library call you haven't seen in this repo, look it up with the
google-developer-knowledge tools. Don't write flags or API names from memory.
- Use search_documents for flags and syntax. Use answer_query for how-it-works questions.
- If the lookup fails or returns nothing, say so before continuing.
Keep it that narrow. A context file that says “always verify everything” gets ignored, and one that names the trigger gets followed.
Using it outside the agent
The same backend is available without MCP, which is handy for scripts and for checking what the agent saw. The announcement lists gcloud commands, which reached general availability on 22 September 2026 according to the release notes:
gcloud developer-knowledge answer-query --query="How do I create a BigQuery dataset?"
gcloud developer-knowledge documents search-chunks --query="Firestore transactions"
gcloud developer-knowledge documents describe "documents/docs.cloud.google.com/storage/docs/creating-buckets"
The post also shows piping an error file straight in with --query="$(cat error.txt)". Remember that this sends the error text to Google, so scrub secrets and customer data from it first.
Client libraries now exist for C#, Go, Java, Node.js, PHP, Python and Ruby (release notes, 8 October). Search results carry a relevance_score from 0.0 to 1.0 on each chunk, which is useful if you build your own retrieval step and want to drop weak matches.
What goes wrong
Network and policy limits come first. The server isn’t supported on restricted.googleapis.com or on Private Service Connect endpoints with VPC Service Controls. If your agents run in a locked-down perimeter, this is the stopping point, and the fix is a policy conversation, not a config change.
Model Armor, if your project uses it, can produce false positives on its prompt injection and jailbreak filter when documentation text goes through it. Google’s page recommends the HIGH_AND_ABOVE setting.
The service itself has bad days. The release notes for 9 October record degraded AnswerQuery with truncated responses and a fix in progress. A truncated generated answer looks plausible, which is the dangerous kind of failure. When a flag matters, have the agent confirm it with search_documents or get_documents rather than trusting a summary. That’s the same reasoning behind the skill’s preference for keyword search on exact syntax.
Unattended runs deserve a thought. In claude -p, Agent SDK and cloud sessions, Claude Code can’t show the approval prompt, so project-scoped servers in .mcp.json load without asking. That’s fine for a Google documentation server you chose. It’s worth knowing for the day someone else’s .mcp.json lands in a repo your headless job runs against, because disabledMcpjsonServers and --strict-mcp-config are the controls for blocking servers there.
It’s also not a substitute for reading the changelog of a library you depend on. The corpus is Google’s documentation, not your pinned versions. If your code targets an older SDK, the docs describe the current one.
When to skip it
Skip it if you rarely touch Google products, because every tool a server exposes adds to what the agent has to consider on each turn. Skip it if the agent already works from vendored or pinned docs in the repo, which are version-accurate in a way a live corpus can’t be.
For a team that does build on Google Cloud or Firebase every week, the cost is a few lines of config and one key, and the return is fewer commands that fail on the first run.
First 15 minutes
Enable the API, create a restricted key, put it in GOOGLE_DK_API_KEY, and add the .mcp.json block above. Run claude mcp list and confirm the server reads as connected. Then ask the agent for a command you know has changed recently and check that it calls search_documents before answering.