Give Gemini CLI tools that are already a real backend.

Gemini CLI reads MCP servers from its settings file and can then call your interfaces as tools from the terminal. The tools are your own interfaces — the same routes your apps call, with the same auth in front of them and the same traces behind them.

Set up Gemini CLI

Gemini CLI reads its MCP servers from ~/.gemini/settings.json. Add the deployment there. The endpoint is the one Air Pipe serves for that organisation and environment; the header carries whatever credential the interfaces behind it already require.

The tools are routes you already have

An interface becomes a tool with an mcp: block on it — no second implementation, no separate server to run. The tool's input schema is generated from the assert tests the interface already carries, so the signature an agent sees cannot drift from what the route actually validates.

Same auth, same traces, no new blast radius

Exposing a route to Gemini CLI does not open a side door. The forwarded credential is checked by the same JWT verification and network access control that guards the HTTP route, and every tool call produces the same OpenTelemetry trace and Prometheus metrics as an ordinary request. An agent that misbehaves is visible in the tooling you already run.

Frequently asked questions