智能体接管你的家:Google Home MCP 服务器拆解

·阅读约11分钟·Evergreen Tools Team

2026 年 9 月 16 日,Google 向开发者开放了 Home MCP 的早期访问——一个把 Google Home 生态暴露给任意 MCP 客户端的服务器。它带来的是能力跃迁:智能体可以先列出你家里的结构、读取设备实时状态、翻查历史事件,然后执行控制动作。Google 在文档里点的客户端例子包括 Google Antigravity、Claude Cowork 与 OpenClaw,也在公告中把 Hermes 列为可调用的智能体之一。对开发者来说,这不是又一个「智能家居集成」,而是一次关于「把物理世界写权限交给模型」的公开实验——它的价值与风险写在同一条 API 上。

把物理世界写权限交给模型

把物理世界写权限交给模型

一、五个工具,构成一条完整的读写链

Home MCP 暴露的工具清单短得出人意料:list_homes 做结构发现,列出授权范围内的住宅与结构;list_home_resources 返回设备、区域布局、trait、属性与命令 schema;list_home_states 读取实时连通性与 trait 状态;list_home_history 按时间范围查询历史状态变化与事件日志;run_home_actions 向目标设备下发参数化动作命令。把它们连起来读,顺序本身就是依赖链:先发现、再解析 schema、再读、最后写。真正值得警惕的是「跳过前四步直接写」的智能体——没有 schema 的写入会把「开厨房灯」变成一次设备级的批量修改。

# 1. The five tools Home MCP exposes (from Google's tool list)
tools = {
    "list_homes":          "structure discovery: which homes and structures the grant covers",
    "list_home_resources": "devices, area layouts, traits, attributes, command schemas",
    "list_home_states":    "real-time connectivity status and trait state",
    "list_home_history":   "past state changes and event logs over a time range",
    "run_home_actions":    "parameterised action commands against target devices",
}

# Read the call order as a dependency chain: discover -> resolve -> read -> act.
# An agent that skips straight to run_home_actions is working without the
# schema it needs, which is how "turn the kitchen lights on" becomes a
# device-wide write.

二、前置条件比新闻稿更窄:订阅、云项目和 OAuth

Google 文档列出的前提条件值得逐条抄进你的可行性评估:需要一个已连设备的 Google Home 环境;需要有效的 Google Home Premium Advanced 订阅(早期访问期间);需要一个启用了 Home API 的 Google Cloud 项目;需要按 Web application 类型创建 OAuth 客户端,并获得访问批准。回调地址必须与你实际使用的客户端对应——Antigravity 用 https://antigravity.google/oauth-callback,Claude Cowork 用 https://claude.ai/api/mcp/auth_callback,OpenClaw 则使用你本地安装指定的重定向 URI。最后,OAuth 同意屏幕需要在 Audience 里把应用发布出去。翻译成人话:如果你的用户群不在 Premium Advanced 上,那么今天这只能是一个演示,而不是一个产品。

// 2. Prerequisites are narrower than the announcement implied
const homeMcpPrereqs = {
  home: "an active Google Home setup with connected devices",
  subscription: "Google Home Premium Advanced",   // required during early access
  cloud: "a Google Cloud project with the Home API enabled",
  oauth: {
    applicationType: "Web application",
    redirectUris: {
      antigravity: "https://antigravity.google/oauth-callback",
      claudeCowork: "https://claude.ai/api/mcp/auth_callback",
      openClaw: "redirect URI specified by your local installation",
    },
    publishApp: true,  // Audience > Publishing status > Publish app
  },
  client: "an MCP-compatible client, e.g. Google Antigravity, Claude Cowork, OpenClaw",
};
// If your users are not on Premium Advanced, the integration is a demo, not a product.
OAuth 回调地址必须与客户端一一对应

OAuth 回调地址必须与客户端一一对应

三、两个服务器,两种职责:Home MCP 与 Home Developer MCP

Google 同时提供了第二个服务器:Home Developer MCP,它的职责不是操作真实的家,而是给编码工具提供可信的文档依据。其语料覆盖完整的 Home API 参考与集成指南、Matter 规范、以及 OpenThread 与 Thread 文档;客户端侧宣称支持 Google Antigravity 套件(CLI、Antigravity 2.0、IDE)、Claude Code、Cursor 以及 VS Code 里的 GitHub Copilot。这个分工很关键:一个服务器负责任务执行,另一个负责让智能体在写代码时不再靠猜测 API 签名。如果你的团队同时在做「用智能体控制家」和「用智能体写家居集成代码」,请把它们当成两套独立的授权与审计对象。

# 3. Two servers, two jobs: Home MCP vs Home Developer MCP
HOME_MCP = {
    "what": "acts on a real home",
    "risk": "physical side effects; rate limits and safety protections apply",
    "revoke": "Google Home app or My Accounts page, at any time",
}

HOME_DEVELOPER_MCP = {
    "what": "grounds coding tools in verified docs",
    "corpus": [
        "complete Home API references and integration guides",
        "the Matter specification",
        "OpenThread and Thread documentation",
    ],
    "clients": ["Google Antigravity CLI / 2.0 / IDE", "Claude Code", "Cursor",
                "GitHub Copilot in VS Code"],
}

def pick(goal):
    return HOME_MCP if goal == "operate a house" else HOME_DEVELOPER_MCP

四、把安全清单当架构,而不是当免责声明

Google 的文档写得很克制,也很实在:连接真实家庭意味着智能体可以代表你控制设备;Home MCP 会执行限流与安全保护,例如禁止开锁这类敏感动作;但如果把正在被家人使用的 Google Home 接进去,你应当告知他们智能体可以控制设备并访问家庭数据;更稳妥的做法是另建一个家,专门放开发和测试设备。授权可以随时从 Google Home App 或 My Accounts 页面撤销。把这些句子翻译成工程约束:写入能力默认关闭;任何涉及门锁、警报、车库门、温控计划的动作必须有人工确认;上线前必须有一个与生产家庭隔离的测试环境。基础模型的能力越强,这层约束越不是可选项。

# 4. Treat the safety list as architecture, not as marketing
CONTROL_SURFACE = {
    "rate_limits": "enforced by the server during early access",
    "prohibited": ["sensitive actions such as unlocking doors"],  # per Google's docs
    "consent": "anyone living in the home should be told the agent can act",
    "isolation": "create a second home for development instead of pointing at the family one",
}

def deploy_checklist(grant):
    failures = []
    if grant["home"] == "household" and not grant["members_informed"]:
        failures.append("household not informed")
    if not grant["separate_dev_home"]:
        failures.append("no test home isolated from production")
    if "unlock" in grant["requested_actions"]:
        failures.append("request includes a prohibited class of action")
    return failures or ["ok to enable for a pilot user group"]
安全清单应当写成架构约束

安全清单应当写成架构约束

五、给团队的一份最小可行契约

早期访问阶段,最务实的做法是先把「读取」跑通,把「写入」留在人工确认之后。可以这样落地:只授予 list_homes、list_home_resources、list_home_states、list_home_history 四个范围,把 run_home_actions 暂时扣住,理由是「智能体还没有可评审的计划格式」;对门锁、警报、车库门与温控计划类动作强制人工确认;在接入前通知全部家庭成员;把撤销路径写进运行手册;并且为这次授权设一个 30 天的复核日期。Google 自己也说明了当前访问是限量的——英语、美国、Home Premium Advanced 用户优先。把这段时间用在把契约写清楚,比用在抢先用上更划算。

{
  "agent_tool_contract": {
    "server": "home-mcp",
    "scope_grant": ["list_homes", "list_home_resources", "list_home_states",
                    "list_home_history"],
    "scope_withheld": ["run_home_actions"],
    "reason_withheld": "write access stays off until the agent has a reviewable plan format",
    "confirmation_required_for": [
      "any action touching locks, alarms, garage doors or climate schedules"
    ],
    "human_notified": "all household members",
    "revocation_path": "Google Home app / My Accounts page",
    "review_due": "30 days",
    "notes": "early access - access is rolling out in English to Home Premium Advanced users in the US"
  }
}

📌 常见问题 FAQ

Home MCP 和普通的智能家居 API 集成有什么不同?

普通集成由你写死每个动作;Home MCP 把设备、trait 与命令 schema 通过标准 MCP 工具暴露给模型,由模型在运行时决定调用哪个工具、传什么参数。控制权从代码转移到了提示词与工具描述上,所以授权范围和审计比以往更重要。

早期访问有什么门槛?

根据 Google 的开发者文档:需要有效的 Google Home Premium Advanced 订阅、一个启用了 Home API 的 Google Cloud 项目、按 Web application 创建的 OAuth 客户端以及访问批准。访问正在以英语向美国的 Premium Advanced 用户滚动开放。

智能体能开我家的门锁吗?

Google 文档明确写了限流与安全保护,并把「开锁」这类敏感动作列为禁止项。但文档也提醒,接入你自己选择的智能体可能带来非预期行为,所以不要把「服务器有保护」当作「你的智能体一定安全」。

开发者文档那个 MCP 服务器是做什么的?

Home Developer MCP 面向编码场景:它把 Home API 参考与集成指南、Matter 规范、OpenThread 与 Thread 文档作为可信语料提供给编码工具,支持 Antigravity、Claude Code、Cursor 和 VS Code 中的 GitHub Copilot。

怎么撤销智能体的访问权限?

文档给出的路径是随时通过 Google Home App 或 My Accounts 页面撤销。工程上建议把这句写进运行手册,并在接入家庭成员共用的家庭前先取得同意。