google-agents-cli-publish
google/agents-cli
Publish and register agents with Gemini Enterprise via Agent-to-Agent or ADK modes.
What is google-agents-cli-publish?
Registers deployed agents with Gemini Enterprise for fleet management and discovery. Use this when publishing an ADK agent to Agent Runtime, registering an A2A agent on Cloud Run/GKE, managing agents in Agent Registry, or setting up MCP server registration. Supports both interactive and programmatic (CI/CD) workflows.
- Register agents in ADK mode (native :streamQuery invocation on Agent Runtime) or A2A mode (Agent-to-Agent protocol on Cloud Run/GKE)
- Auto-detect agent runtime ID and registration type from deployment_metadata.json
- List, update, and delete registered agents in Gemini Enterprise
- Support interactive prompts or fully programmatic flag/environment-variable workflows
- Configure OAuth authorization, display names, descriptions, and tool metadata
- Manage agent fleet across multiple deployment targets (Agent Runtime, Cloud Run, GKE)
How to install google-agents-cli-publish
npx skills add https://github.com/google/agents-cli --skill google-agents-cli-publish- agents-cli installed (uv tool install google-agents-cli)
- Agent must be deployed and reachable (Agent Runtime, Cloud Run, or GKE)
- Gemini Enterprise app must exist in Google Cloud Console
- deployment_metadata.json created by agents-cli deploy (Agent Runtime only; auto-detection)
- For A2A on Cloud Run: roles/run.servicesInvoker granted to Discovery Engine service account
- Text-based agent (live/voice agents not supported by Gemini Enterprise)
How to use google-agents-cli-publish
- 1.Ensure your agent is deployed and reachable at its endpoint
- 2.Create a Gemini Enterprise app in Google Cloud Console if not already done
- 3.For ADK agents on Agent Runtime: run agents-cli publish gemini-enterprise --registration-type adk --agent-runtime-id <ID> --gemini-enterprise-app-id <ID> --display-name <name>
- 4.For A2A agents on Cloud Run/GKE: run agents-cli publish gemini-enterprise --agent-card-url <URL> --gemini-enterprise-app-id <ID>
- 5.Optionally pass --interactive to be guided through prompts, or use environment variables (AGENT_RUNTIME_ID, GEMINI_ENTERPRISE_APP_ID, etc.) for CI/CD
- 6.Verify registration by running agents-cli publish gemini-enterprise --list to see all registered agents
Use cases
- Publish a production ADK agent to Gemini Enterprise after deploying to Agent Runtime
- Register a Cloud Run agent via A2A protocol for discovery in Gemini Enterprise apps
- Automate agent registration in CI/CD pipelines using environment variables
- List all registered agents in a Gemini Enterprise app to verify deployments
- Update agent metadata (display name, description) without redeploying
- Backend engineers deploying agents to production
- DevOps/SRE teams automating agent registration in CI/CD
- Developers managing multi-agent fleets in Gemini Enterprise
- Teams integrating agents with MCP servers
google-agents-cli-publish FAQ
ADK registration invokes the agent natively via :streamQuery on Agent Runtime's reasoning engine (recommended for ADK agents). A2A registration uses the Agent-to-Agent protocol and works on Cloud Run, GKE, or as a fallback on Agent Runtime; it requires an agent card URL.
No. Gemini Enterprise only supports text-based agents; live/voice (bidi) agents are not supported because Gemini Enterprise has no /run_live transport.
Pass all required flags or set environment variables (AGENT_RUNTIME_ID, GEMINI_ENTERPRISE_APP_ID, GEMINI_DISPLAY_NAME, etc.) and run the command non-interactively. No --interactive flag needed.
Grant roles/run.servicesInvoker to the Discovery Engine service account (service-<PROJECT_NUMBER>@gcp-sa-discoveryengine.iam.gserviceaccount.com) on the Cloud Run service.
Yes. Re-run the publish command with the same agent-runtime-id or agent-card-url and new --display-name or --description values to update the registration.
Full instructions (SKILL.md)
Source of truth, from google/agents-cli.
name: google-agents-cli-publish description: > This skill should be used when the user wants to "publish an agent", "publish my ADK agent", "register an agent with Gemini Enterprise", "publish to Gemini Enterprise", or needs guidance on the agents-cli publish gemini-enterprise command. Also use when the user wants to "manage agents in Agent Registry", "list/update/delete registered agents", or "register an MCP server". Covers ADK vs A2A registration modes, programmatic and interactive usage, flag reference, auto-detection from deployment metadata, Agent Registry fleet management, and troubleshooting. Part of the agents-cli skills suite. Do NOT use for deployment (use google-agents-cli-deploy). metadata: author: Google license: Apache-2.0 version: 1.7.0 requires: bins: - agents-cli install: "uv tool install google-agents-cli"
Gemini Enterprise Registration
Requires: A deployed agent. For Agent Runtime,
deployment_metadata.json(created byagents-cli deploy) enables auto-detection. For Cloud Run or GKE, provide the agent card URL and flags directly.
Prerequisites
- Agent must be deployed — the agent must be running and reachable
- Gemini Enterprise app must exist — Create one in Google Cloud Console → Gemini Enterprise → Apps before registering
deployment_metadata.json(Agent Runtime only) — Created automatically byagents-cli deploy; contains the agent runtime ID, deployment target, the A2A flag, and the agent directory- Text-based agent — Live/voice (bidi) agents are not supported by Gemini Enterprise, which has no
/run_livetransport. Register a text-based agent instead.
Required Permissions for A2A on Cloud Run
roles/run.servicesInvokergranted to the Discovery Engine service account (service-<PROJECT_NUMBER>@gcp-sa-discoveryengine.iam.gserviceaccount.com) on the Cloud Run service.
Registration Modes
A2A Registration
Every scaffolded agent serves the Agent-to-Agent protocol. A2A is the default — and only — registration type on Cloud Run and GKE (no reasoning engine to invoke natively). It also works on Agent Runtime via --registration-type a2a. For an ADK agent there the CLI warns against it, because Gemini Enterprise can invoke Agent Runtime natively via :streamQuery — prefer ADK registration in that case. For an agent built on another framework there is no ADK app to invoke natively, so A2A is the right mode on every target and the warning is expected. Pass the agent card URL and the command fetches the card and registers it; display name and description default to the card's name/description.
# A2A on Cloud Run / GKE. The card path depends on the project's language:
# Python -> /a2a/{app_name}/.well-known/agent-card.json
# Go -> /.well-known/agent-card.json
agents-cli publish gemini-enterprise \
--agent-card-url https://my-service-abc123.us-east1.run.app/a2a/app/.well-known/agent-card.json \
--gemini-enterprise-app-id projects/123456/locations/global/collections/default_collection/engines/my-app
Pass --display-name / --description to override the card defaults. On Agent Runtime, the card URL auto-builds from deployment_metadata.json if you omit --agent-card-url.
ADK Registration (default on Agent Runtime)
ADK projects only. The agent must be deployed to Agent Runtime as an ADK app, since registration invokes it through
:streamQuery. An agent on another framework registers over A2A, so deploy it to Cloud Run or GKE and publish from there.
This is the default and recommended registration for ADK agents on Agent Runtime: Gemini Enterprise invokes the agent natively via :streamQuery on its reasoning engine resource, authenticating end-to-end. Under the hood, :streamQuery dispatches to the AdkApp's streaming_agent_run_with_events method — when debugging an ADK invocation, search the runtime's reasoning_engine_stderr logs for that method name to trace the failure. It's also the path to use when the agent needs an OAuth authorization (--authorization-id). The agent is registered directly via its reasoning engine resource name; no agent card URL is needed.
agents-cli publish gemini-enterprise \
--registration-type adk \
--agent-runtime-id projects/123456/locations/us-east1/reasoningEngines/789 \
--gemini-enterprise-app-id projects/123456/locations/global/collections/default_collection/engines/my-app \
--display-name "My Agent" \
--description "Handles customer queries" \
--tool-description "Answers questions about products"
Programmatic Mode (CI/CD)
The command is non-interactive by default — pass all required values via flags or environment variables. This makes it safe for CI/CD pipelines.
Via flags
agents-cli publish gemini-enterprise \
--agent-runtime-id "$AGENT_RUNTIME_ID" \
--gemini-enterprise-app-id "$GEMINI_ENTERPRISE_APP_ID" \
--display-name "Production Agent" \
--registration-type adk
Via environment variables
Most flags have an env var alternative (--metadata-file, --interactive, and --list do not):
export AGENT_RUNTIME_ID="projects/123456/locations/us-east1/reasoningEngines/789"
export GEMINI_ENTERPRISE_APP_ID="projects/123456/locations/global/collections/default_collection/engines/my-app"
export GEMINI_DISPLAY_NAME="Production Agent"
export GEMINI_DESCRIPTION="Handles customer queries"
agents-cli publish gemini-enterprise
Interactive Mode (--interactive)
Pass --interactive (or -i) to be guided through any missing values with interactive prompts. The command will list available Gemini Enterprise apps, offer to auto-detect the agent runtime ID from metadata, and prompt for display name and description.
agents-cli publish gemini-enterprise --interactive
Complete Flag Reference
| Flag | Env Var | Description |
|---|---|---|
--agent-runtime-id | AGENT_RUNTIME_ID | Agent Runtime resource name (auto-detected from deployment_metadata.json) |
--gemini-enterprise-app-id | ID or GEMINI_ENTERPRISE_APP_ID | Gemini Enterprise app full resource name |
--display-name | GEMINI_DISPLAY_NAME | Display name in Gemini Enterprise |
--description | GEMINI_DESCRIPTION | Agent description |
--tool-description | GEMINI_TOOL_DESCRIPTION | Tool description (ADK mode only, defaults to description) |
--registration-type | REGISTRATION_TYPE | adk or a2a (defaults to adk for an ADK agent on Agent Runtime, a2a everywhere else, including any non-ADK framework) |
--agent-card-url | AGENT_CARD_URL | Agent card URL for A2A registration |
--deployment-target | DEPLOYMENT_TARGET | agent_runtime, cloud_run, or gke (sets the default registration type — ADK on Agent Runtime, A2A on Cloud Run / GKE — and the A2A auth method) |
--project-id | GOOGLE_CLOUD_PROJECT | GCP project ID for billing |
--project-number | PROJECT_NUMBER | GCP project number (used for Gemini Enterprise lookup) |
--authorization-id | GEMINI_AUTHORIZATION_ID | OAuth authorization resource name |
--metadata-file | — | Path to deployment metadata (default: deployment_metadata.json) |
--interactive / -i | — | Enable interactive prompts |
--list | — | List Gemini Enterprise apps in the current project and exit |
Auto-Detection from Metadata
When deployment_metadata.json exists, the command automatically:
- Reads the agent runtime ID (
remote_agent_runtime_id) - Determines the registration type: defaults to ADK (native
:streamQuery) on Agent Runtime, and A2A on Cloud Run / GKE (which have no reasoning engine). A project scaffolded with another framework serves no ADK app, so it defaults to A2A on every target. Override with--registration-type. - Determines the deployment target for authentication
This means that for the simplest case (an ADK agent on Agent Runtime, registered as ADK), you only need to provide the Gemini Enterprise app ID:
agents-cli publish gemini-enterprise \
--gemini-enterprise-app-id projects/123456/locations/global/collections/default_collection/engines/my-app
SDK Compatibility (Python only)
Agent Runtime deployments may encounter "Session not found" errors with google-cloud-aiplatform versions <= 1.128.0. In interactive mode (--interactive), the command checks the SDK version from uv.lock and offers to upgrade. In programmatic mode, ensure your SDK is up to date before registering.
Agent Registry (agents and MCP servers)
Agent Registry (Preview) is the Google Cloud fleet-wide catalog of agents and MCP servers, separate from a Gemini Enterprise app.
Agents deployed to a managed runtime (Agent Runtime on Gemini Enterprise
Agent Platform) are auto-registered — no extra step after agents-cli deploy.
Manage them with gcloud (requires roles/agentregistry.editor):
# List / inspect agents
gcloud agent-registry agents list --project PROJECT --location LOCATION
gcloud agent-registry agents describe AGENT_NAME
# Update endpoint/metadata — edit the Service resource, not the Agent
gcloud agent-registry services update AGENT_NAME \
--display-name "..." --description "..." \
--interfaces "url=ENDPOINT_URL,protocolBinding=http-json"
# Register an external MCP server: not auto-introspected, so upload a
# toolspec.json (its tools/list response, max 10 KB). No us/eu multi-region.
gcloud agent-registry services create SERVER_NAME --location=LOCATION \
--mcp-server-spec-type=tool-spec --mcp-server-spec-content=toolspec.json \
--interfaces="url=SERVER_URL,protocolBinding=jsonrpc" # or http-json, grpc
# Remove: delete the underlying runtime agent (auto-registered) OR, for
# manually registered agents/servers, delete the Service resource
gcloud agent-registry services delete NAME
Terraform: google_agent_registry_service with an mcp_server_spec block.
Docs: https://docs.cloud.google.com/agent-registry/manage-agents · https://docs.cloud.google.com/agent-registry/register-mcp-servers
Troubleshooting
| Issue | Solution |
|---|---|
| "Session not found" after registration | SDK version issue — upgrade google-cloud-aiplatform (see SDK Compatibility above), redeploy, then re-register |
--registration-type is required | Non-interactive mode needs --registration-type when no deployment_metadata.json exists |
| "Gemini Enterprise App ID is required" | Provide --gemini-enterprise-app-id or set the ID / GEMINI_ENTERPRISE_APP_ID env var |
| Re-publishing the same agent | Registration is idempotent — re-running updates the existing registration in place instead of creating a duplicate |
| HTTP 403 on registration | Check that your account has Discovery Engine Editor permissions on the Gemini Enterprise project |
| Debugging ADK invocation failures on Agent Runtime | Gemini Enterprise calls the agent via the AdkApp's streaming_agent_run_with_events method (the native :streamQuery contract). Grep the runtime's reasoning_engine_stderr logs for streaming_agent_run_with_events to find the underlying error |
| "Could not fetch agent card" | Verify the agent is running and the URL is correct; for Cloud Run, ensure gcloud auth login is done. A Live/voice agent drops its A2A card and cannot be published — Gemini Enterprise does not support Live agents |
Related Skills
/google-agents-cli-deploy— Deployment targets, CI/CD pipelines, and production workflows (also covers Agent Gateway governed ingress/egress and Semantic Governance awareness)/google-agents-cli-workflow— Development workflow, coding guidelines, and operational rules/google-agents-cli-scaffold— Project creation and enhancement withagents-cli scaffold create/scaffold enhance
Related skills
More from google/agents-cli and the wider catalog.

google-agents-cli-scaffold
Scaffold new agent projects and add deployment, CI/CD, and infrastructure to existing ones.

google-agents-cli-workflow
CLI toolkit for building, evaluating, and deploying agents on Google Cloud with the Agent Development Kit.

google-agents-cli-adk-code
Quick reference for ADK agent code patterns, tools, callbacks, and state management.

google-agents-cli-deploy
Deploy agents to Agent Runtime, Cloud Run, or GKE with agents-cli.

mantis-architecture
Synthesizes codebase analysis and learnings into an interlinked Markdown Knowledge Base for architecture documentation.

mantis-review
Independently validates security findings against source code to filter false positives.