AI Agent - Aug 2, 2026

Gemini Spark Connected Apps and Custom MCP: A Safe Setup Guide

Quick Answer

Gemini Spark can use Google and third-party Connected Apps, and it can connect to a custom app through a Model Context Protocol (MCP) server URL. These are not interchangeable trust boundaries. A listed integration has a provider-defined connection flow; a custom MCP server is operated outside Google’s control and can request or receive task data.

Connect only a server whose operator, actions, privacy policy, and terms you have reviewed. Start with read-only work and remove the connection when it is no longer needed.

Built-In Connections vs. Custom MCP

Google’s June Spark update named Google Tasks, Google Keep, Canva, Dropbox, Instacart, OpenTable, and Zillow Rentals among its expanding Connected Apps. Availability can vary by account, country, and surface, so the current Connected Apps settings page is the practical source of truth.

ConnectionHow it appearsCurrent decision boundary
Google or listed third-party appOffered in Gemini’s Connected Apps surfaceReview the exact permissions and the destination app’s policy
Custom appAdded from its MCP server URL in Gemini webYou must evaluate and trust the third-party server operator
Browser taskSpark works through local Chrome or a remote browserWebsite access and browser takeover rules apply instead

A custom MCP connection is not a Gemini API integration, and the separate Gemini Managed Agents API should not be used as evidence for consumer Spark access.

Current Custom-App Requirements

Google’s August 2 help content says adding a custom app currently requires:

  • Spark eligibility, age 18 or older, and a personal Google Account;
  • United States access;
  • Keep Activity enabled;
  • English;
  • the custom app’s standards-compatible MCP server URL.

Custom apps are added in the Gemini web app. Google says a connected custom app can then work in Spark on web and mobile. The current help page does not list the macOS Spark surface for custom MCP use, so do not infer Mac support from Spark’s general desktop availability.

What Data Can Leave Gemini?

Google warns that it does not control, monitor, or secure custom third-party MCP servers. A custom app may receive information from the conversation and other sources available to Spark, potentially including Connected Apps, Personal Intelligence, skills, tasks, or signed-in websites.

The main risks are:

  • a server requesting more data than the task requires;
  • task context containing sensitive or unrelated information;
  • a write action changing external data;
  • a compromised or misleading tool description;
  • data becoming subject to a third party’s retention and privacy practices.

Google’s help page says custom-app write actions currently require manual confirmation, while also warning that Gemini can make mistakes. Confirmation is a review gate, not a guarantee that the proposed write is correct.

A Least-Privilege Setup

  1. Identify the exact server operator and canonical MCP URL.
  2. Read the provider’s documentation, privacy policy, terms, and supported actions.
  3. Prefer a dedicated account or workspace with minimal data.
  4. Connect the server in Gemini web and inspect the requested account-linking permissions.
  5. Test a read-only task with a known answer.
  6. Inspect what data reached the server and whether the result cites the correct source.
  7. Test one reversible write only if the integration is intended to write.
  8. Disconnect and unlink the MCP server when the evaluation ends.

An app that can read a calendar does not automatically need email, contacts, files, or purchase permissions. Expand access only when a reviewed task requires it.

Choose the Right Spark Surface

Use the Chrome auto-browse guide when the job happens on websites, the macOS guide when it acts on local files, and the schedules guide when the task repeats or reacts to an event.

Official Sources

Source check: August 2, 2026. Verify the live Connected Apps list and each third party before sending data or approving an action.