Articles ยท Gemini AI Tools

Remote MCP stays off until it can be secured

An MCP URL box is easy to treat as a convenient way to plug any tool server into Gemini. On a public site that is also an SSRF and exfiltration path. Remote MCP Playground exists so the route is honest: the host flag is off, the cost class is unknown, and the API does not connect to a URL you type. Localhost, private ranges, metadata hosts, and arbitrary remote MCP endpoints are not fetched by DevNestro. Turning the flag on after a security review still does not let anonymous visitors supply a server address.

Why this is worth doing in the browser

People search for Gemini MCP because Google documents remote MCP for some accounts. Implementing that as an open URL field would let a visitor ask this host—or Google through this host—to touch an internal admin port. The original product rule is fail closed if a safe design is not ready. This page follows that rule. Related tools include the function-calling playground for a display-only schema and the agent playground for Gemini’s built-in tools. There is no claim MCP is available, official, or coming on a date.

How to use the tool

Read the disabled notice. Optionally type a prompt to confirm the refusal. Try MCP. The request fails closed. Clear resets the form. Nothing is sent to an MCP server.

  1. Do not expect a live MCP session on the public free host.
  2. Do not paste internal or metadata URLs. They are not contacted.
  3. A refused request is the designed result, not a broken page.
  4. Use function calling or the agent playground for supported demos.

Privacy

DevNestro does not connect to user-supplied MCP URLs and does not send those addresses to Gemini. If a future reviewed configuration ever sent a prompt, that would be cloud AI, not browser-only processing. The current host keeps the flag off. There is no MCP traffic archive.

Need an agent demo today? Leave Remote MCP closed and open Function Calling Playground or Gemini Agent Playground instead.

Open Remote MCP Playground

An unhandled error has occurred. Reload Dismiss

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.