Skip to main content

Overview

Gemini CLI is Google’s agentic command-line tool. This guide adds Ocean as a remote MCP server so you can query threats, metrics, phishing reports, and allow/deny lists directly from Gemini CLI. For connection details and the full tool catalog, see the MCP Server Overview.

Prerequisites

  • Gemini CLI installed (npm install -g @google/gemini-cli).
  • MCP access enabled for your tenant.
  • An Ocean account to sign in with — or, if you’re using the API key method, an Ocean API key (see Authentication).
Gemini CLI reads MCP servers from ~/.gemini/settings.json (global) or .gemini/settings.json in your project. Add Ocean with no credential and let Gemini CLI run the OAuth flow:
.gemini/settings.json
The first time Gemini CLI uses the server, it opens a browser window where you sign in with your Ocean account and approve the access it asked for. Gemini CLI stores the token and refreshes it automatically.
OAuth access to Ocean is read-only. If you need the allow/deny write tools, use an API key instead — see Authentication.

Add with an API key

Put your API key in the headers block instead:
.gemini/settings.json

Add via the CLI

Alternatively, add the server without hand-editing JSON:

Verify the connection

1

List your MCP servers

Run gemini mcp list and confirm ocean appears and shows as connected.
2

Check the tools

In a Gemini CLI session, run /mcp and confirm Ocean’s tools are listed.
3

Ask a question

Try a prompt such as “Use Ocean to list this week’s threats” and confirm Gemini calls an Ocean tool.

Troubleshooting

  • ocean not listed / failed to connect. Re-check the URL (https://api.ocean.security/mcp) and that httpUrl (not url) is used for a remote server.
  • Keeps asking you to sign in. Remove and re-add the server so Gemini CLI re-runs the OAuth flow from scratch.
  • Tools call but return 401. With an API key, the key is missing, expired, or inactive — update it. With OAuth, re-authenticate.
  • No tools shown for ocean. MCP access may not be enabled for your tenant, or your identity lacks the relevant permissions. See the overview troubleshooting.