Your Agent Can Now Run the House: Inside Google's Home MCP Server

·11 min read·Evergreen Tools Team

On September 16, 2026, Google opened early access to Home MCP, a server that exposes the Google Home ecosystem to any MCP-capable agent. The capability jump is real: an agent can enumerate the structure of your home, read live device state, query historical events, and then execute control actions. Google's own docs name Google Antigravity, Claude Cowork and OpenClaw as example clients, and the launch coverage adds Hermes to the list of agents that can call the tools. For developers this is less another smart-home integration than a public experiment in handing write access over physical space to a model - and the value and the risk ship on the same API surface.

Write access to physical space, handed to a model

Write access to physical space, handed to a model

1. Five Tools That Form One Read-Write Chain

The published tool list is short. list_homes handles structure discovery, returning the homes and structures a grant covers. list_home_resources returns devices, area layouts, traits, attributes and command schemas. list_home_states reads real-time connectivity and trait state. list_home_history queries past state changes and event logs over a time range. run_home_actions issues parameterised action commands against target devices. Read in order, they are a dependency chain: discover, resolve the schema, read, then write. What deserves scrutiny is the agent that skips the first four steps - an unparameterised write turns turn on the kitchen lights into a device-wide mutation.

# 1. The five tools Home MCP exposes (from Google's tool list)
tools = {
    "list_homes":          "structure discovery: which homes and structures the grant covers",
    "list_home_resources": "devices, area layouts, traits, attributes, command schemas",
    "list_home_states":    "real-time connectivity status and trait state",
    "list_home_history":   "past state changes and event logs over a time range",
    "run_home_actions":    "parameterised action commands against target devices",
}

# Read the call order as a dependency chain: discover -> resolve -> read -> act.
# An agent that skips straight to run_home_actions is working without the
# schema it needs, which is how "turn the kitchen lights on" becomes a
# device-wide write.

2. The Prerequisites Are Narrower Than the Headline

Google lists the prerequisites plainly, and they belong in your feasibility assessment verbatim. You need an active Google Home setup with connected devices; an active Google Home Premium Advanced subscription during early access; a Google Cloud project with the Home API enabled; and an OAuth client created as a Web application plus access approval. The redirect URIs are client-specific: Antigravity uses https://antigravity.google/oauth-callback, Claude Cowork uses https://claude.ai/api/mcp/auth_callback, and OpenClaw uses whatever your local installation specifies. You also need to publish the app on the OAuth consent screen under Audience. In practice: if your users are not on Home Premium Advanced, this is a demo today, not a product.

// 2. Prerequisites are narrower than the announcement implied
const homeMcpPrereqs = {
  home: "an active Google Home setup with connected devices",
  subscription: "Google Home Premium Advanced",   // required during early access
  cloud: "a Google Cloud project with the Home API enabled",
  oauth: {
    applicationType: "Web application",
    redirectUris: {
      antigravity: "https://antigravity.google/oauth-callback",
      claudeCowork: "https://claude.ai/api/mcp/auth_callback",
      openClaw: "redirect URI specified by your local installation",
    },
    publishApp: true,  // Audience > Publishing status > Publish app
  },
  client: "an MCP-compatible client, e.g. Google Antigravity, Claude Cowork, OpenClaw",
};
// If your users are not on Premium Advanced, the integration is a demo, not a product.
Redirect URIs must match the client you actually use

Redirect URIs must match the client you actually use

3. Two Servers, Two Jobs: Home MCP and Home Developer MCP

Google shipped a second server alongside Home MCP. Home Developer MCP is not for operating a house; it grounds coding tools in verified documentation, covering the complete Home API references and integration guides, the Matter specification, and OpenThread and Thread documentation. On the client side it works with the Google Antigravity suite (CLI, Antigravity 2.0 and the IDE) plus Claude Code, Cursor, and GitHub Copilot in VS Code. The split matters. One server performs actions against a real environment; the other stops a coding agent from guessing API signatures. If your team is doing both, treat them as two separate grants with two separate audit trails.

# 3. Two servers, two jobs: Home MCP vs Home Developer MCP
HOME_MCP = {
    "what": "acts on a real home",
    "risk": "physical side effects; rate limits and safety protections apply",
    "revoke": "Google Home app or My Accounts page, at any time",
}

HOME_DEVELOPER_MCP = {
    "what": "grounds coding tools in verified docs",
    "corpus": [
        "complete Home API references and integration guides",
        "the Matter specification",
        "OpenThread and Thread documentation",
    ],
    "clients": ["Google Antigravity CLI / 2.0 / IDE", "Claude Code", "Cursor",
                "GitHub Copilot in VS Code"],
}

def pick(goal):
    return HOME_MCP if goal == "operate a house" else HOME_DEVELOPER_MCP

4. Read the Safety List as Architecture, Not as a Disclaimer

Google's documentation is unusually direct. Connecting a real home lets the agent control devices on your behalf. Home MCP enforces rate limits and safety protections, such as prohibiting sensitive actions like unlocking doors. If the home is shared, you should tell the other household members that your agent can control devices and access home data, or create an additional home for development and testing. Access can be revoked at any time from the Google Home app or the My Accounts page. Translate that into engineering constraints: write scope off by default; human confirmation for anything touching locks, alarms, garage doors or climate schedules; a test home isolated from the production one before rollout.

# 4. Treat the safety list as architecture, not as marketing
CONTROL_SURFACE = {
    "rate_limits": "enforced by the server during early access",
    "prohibited": ["sensitive actions such as unlocking doors"],  # per Google's docs
    "consent": "anyone living in the home should be told the agent can act",
    "isolation": "create a second home for development instead of pointing at the family one",
}

def deploy_checklist(grant):
    failures = []
    if grant["home"] == "household" and not grant["members_informed"]:
        failures.append("household not informed")
    if not grant["separate_dev_home"]:
        failures.append("no test home isolated from production")
    if "unlock" in grant["requested_actions"]:
        failures.append("request includes a prohibited class of action")
    return failures or ["ok to enable for a pilot user group"]
The safety list is an architecture constraint

The safety list is an architecture constraint

5. A Minimum Viable Contract for Your Team

During early access the pragmatic move is to make reads work and keep writes behind a human. Grant only list_homes, list_home_resources, list_home_states and list_home_history, and withhold run_home_actions with a stated reason - the agent does not yet produce a reviewable plan format. Require confirmation for locks, alarms, garage doors and climate schedules. Tell every household member before you connect anything. Write the revocation path into your runbook and set a 30-day review date for the grant itself. Google is explicit that access is rolling out in English to Home Premium Advanced users in the US, so the scarce resource right now is not early access - it is a contract precise enough to survive a model upgrade.

{
  "agent_tool_contract": {
    "server": "home-mcp",
    "scope_grant": ["list_homes", "list_home_resources", "list_home_states",
                    "list_home_history"],
    "scope_withheld": ["run_home_actions"],
    "reason_withheld": "write access stays off until the agent has a reviewable plan format",
    "confirmation_required_for": [
      "any action touching locks, alarms, garage doors or climate schedules"
    ],
    "human_notified": "all household members",
    "revocation_path": "Google Home app / My Accounts page",
    "review_due": "30 days",
    "notes": "early access - access is rolling out in English to Home Premium Advanced users in the US"
  }
}

📌 Frequently Asked Questions

How is Home MCP different from a normal smart-home API integration?

In a normal integration you write each action in code. Home MCP exposes devices, traits and command schemas as standard MCP tools, so the model decides at runtime which tool to call and with which parameters. Control shifts from code to prompts and tool descriptions, which is exactly why scope and audit matter more than before.

What are the early access requirements?

Per Google's developer documentation: an active Google Home Premium Advanced subscription, a Google Cloud project with the Home API enabled, an OAuth client of type Web application, and access approval. Access is rolling out in English to Home Premium Advanced users in the US.

Can an agent unlock my doors?

Google's documentation states that Home MCP enforces rate limits and safety protections such as prohibiting sensitive actions like unlocking doors. It also warns that depending on your agent, connecting it can result in unexpected or even undesired behaviour - so server-side protection is not the same as a safe agent.

What is the developer MCP server for?

Home Developer MCP grounds AI coding tools in verified technical documentation: Home API references and integration guides, the Matter specification, and OpenThread and Thread documentation. It supports the Antigravity suite, Claude Code, Cursor, and GitHub Copilot in VS Code.

How do I revoke an agent's access?

The documented path is the Google Home app or your My Accounts page, at any time. Operationally, put that sentence in your runbook and get consent from household members before you connect a shared home.