Gemini CLI setup guide

How to connect Gemini CLI to a remote MCP server

Add one server to settings.json, sign in once in your browser, and Gemini CLI can look up and update your customer records from the terminal.

Last updated Oct 3, 2026

Last checked against Gemini CLI on [DATE OF TEST]. Spot an error? Tell us

To connect Gemini CLI to a remote Model Context Protocol (MCP) server, add the server’s URL under mcpServers in ~/.gemini/settings.json with the httpUrl key. Then run /mcp auth <name> inside Gemini CLI, and it opens your browser so you can sign in. This Gemini CLI MCP guide uses Zyflow, and the same two steps work for other remote servers that use Streamable HTTP and OAuth.

Zyflow is a lightweight small-business CRM your AI app keeps up to date (Claude, Cursor, ChatGPT Business, any MCP app). Every AI change is labeled.

Before you start:

  • Gemini CLI, up to date. Since June 18, 2026, Google requires a paid Gemini API key or a Gemini Code Assist Standard or Enterprise license to use it. Free use and Google AI Pro or Ultra subscriptions no longer include it.3
  • A browser on the same computer. Working over SSH, on a server or in a container? Use an API key.
  • A free Zyflow account. Create it first, so the browser step only asks you to log in.

Add Zyflow to Gemini CLI’s settings.json

Open ~/.gemini/settings.json (create it if it doesn’t exist) and add Zyflow under mcpServers with the httpUrl key. Nothing secret goes in this file; signing in comes next.

{
  "mcpServers": {
    "zyflow": {
      "httpUrl": "https://app.zyflowcrm.com/mcp"
    }
  }
}
  • If the file already has settings, put the zyflow entry inside your existing mcpServers object and check that the JSON is still valid.
  • If you rename the entry, leave out underscores. Gemini CLI names tools mcp_{server}_{tool} and splits the name at the first underscore.

httpUrl is for servers that use Streamable HTTP, the current MCP transport. url is for older Server-Sent Events (SSE) servers. Zyflow uses Streamable HTTP, so use httpUrl.

Gemini CLI’s MCP server reference (updated Sep 2, 2026) documents every Gemini CLI setting on this page.

Or add it with one command

gemini mcp add --transport http --scope user zyflow https://app.zyflowcrm.com/mcp

Keep both flags. Without --transport http, the command treats the URL as a local program. Without --scope user, Zyflow works in the current project only.

User or project settings?

~/.gemini/settings.json applies in every folder. A .gemini/settings.json file inside a project applies only in that project. On Windows, the user file is %USERPROFILE%\.gemini\settings.json.

Sign in with /mcp auth zyflow

Run /mcp auth zyflow inside Gemini CLI, then approve the connection in your browser. You pick one workspace, and you never paste a password or key into Gemini CLI.

  1. Start Gemini CLI and run /mcp auth zyflow.

  2. Your browser opens on Zyflow.

  3. Log in to Zyflow.

  4. Choose the one workspace Gemini CLI may use.

  5. Approve, then go back to the terminal.

Finish approving within 10 minutes, or run /mcp auth zyflow again.

What happens behind the scenes

When Gemini CLI first calls Zyflow, it gets a 401 that points it to Zyflow’s sign-in. Gemini CLI registers itself as a client and listens for the callback on a random localhost port; Zyflow accepts any loopback port. Sign-in uses OAuth 2.1 with PKCE, and Zyflow returns the iss value that recent Gemini CLI versions check. The token works for that one workspace only, and Gemini CLI keeps it in ~/.gemini/mcp-oauth-tokens.json. Access tokens last 60 minutes and Gemini CLI refreshes them on its own. Refresh tokens rotate on every use and last 90 days.

Check the connection

Run /mcp list inside Gemini CLI, or gemini mcp list in your shell. The zyflow entry should show as Connected, with its tools listed.

Get your Zyflow link

Free plan. No card.

Use Zyflow from Gemini CLI

Talk to Gemini CLI the way you’d brief a colleague. It picks which Zyflow tools to call, and Zyflow, which runs no AI of its own, keeps the record. Try these first:

  • Add Maya Chen at Northwind as a customer. Her email is maya@northwind.example.
  • Had a call with Maya at Northwind. She wants the revised quote by Friday.
  • What do we know about Northwind?
  • What’s on my plate today?
  • Undo that.

After the second prompt, Gemini CLI logs the call on Maya’s record, sets the follow-up and reads back the date: Fri, 9 Oct. If you have two Sams and say “Had a call with Sam,” Zyflow sends Gemini CLI both (Sam Ortiz at Halden and Sam Lee at Fieldhouse) with what tells them apart. Gemini CLI then asks you which one you mean.4

Keep the final say on changes

Your AI will get things wrong sometimes. Plan for that. Gemini CLI asks before each tool call unless “trust” is on for the server. Keep that confirmation for anything that changes records: choose “Always allow this tool” only for lookups such as get_customer and search, and leave trust off for Zyflow. In Zyflow, each change shows the app that made it, with an Undo,1 and AI apps can only move things to the 30-day trash.

To block deletes, merges and bulk edits from Gemini CLI, add this inside the zyflow entry:

"excludeTools": ["delete_record", "delete_files", "merge_records", "bulk_update"]

Slash commands and Notes for your AI

Zyflow’s 5 prompts appear in Gemini CLI as slash commands: /daily_briefing, /prepare_meeting, /log_conversation, /draft_follow_up and /find_duplicates. Before a call, /prepare_meeting --customer=”Northwind” has Gemini CLI pull up the record and suggest three talking points.

Notes for your AI (your standing instructions in Zyflow) reach Gemini CLI too. Gemini CLI adds each server’s instructions to its own system instructions.5

Use an API key on a server, over SSH or for read-only access

Gemini CLI’s sign-in needs a browser and a localhost callback on the same machine. It doesn’t work in headless sessions, over SSH without X11 forwarding, or in containers. Send a Zyflow API key in a Bearer header instead. A key is also how you give Gemini CLI read-only access.

  1. On the Connect page, under API keys, choose New key.

  2. Name it after the machine, for example “Gemini CLI on build server.” History shows that name on every change the key makes.

  3. Pick Read and write or Read only, then copy the key. Zyflow shows it only once.

  4. Add it to the zyflow entry in ~/.gemini/settings.json:

{
  "mcpServers": {
    "zyflow": {
      "httpUrl": "https://app.zyflowcrm.com/mcp",
      "headers": { "Authorization": "Bearer YOUR_ZYFLOW_API_KEY" }
    }
  }
}

Or with one command:

gemini mcp add --transport http --scope user -H "Authorization: Bearer YOUR_ZYFLOW_API_KEY" zyflow https://app.zyflowcrm.com/mcp

Keep the key in user settings, never in a project file that goes to git. Gemini CLI doesn’t expand variables in headers, so the key sits in the file as plain text. A read-only key can look things up, and Zyflow refuses its writes. Any key, even a read-only one, can read and export the whole workspace. Keys don’t expire; revoke one on the Connect page any time.

The Gemini app isn’t supported yet (Gemini CLI is)

We haven’t tested a custom connection in the Gemini app (gemini.google.com and its phone apps) or in Gemini Enterprise, so this guide has no steps for them yet.3

Want Zyflow in a chat app today? Claude works on every plan, and ChatGPT can write on Business, Enterprise or Edu plans.2

Troubleshooting Gemini CLI MCP connections

Most problems come from one of three things: url in place of httpUrl, the defaults of gemini mcp add, or a sign-in that can’t open a browser. Quoted text in the table is the exact message Zyflow or Gemini CLI shows.

Gemini CLI and Zyflow: symptom, cause, fix
Symptom Cause Fix
zyflow shows Disconnected after you add it Not signed in yet Run /mcp auth zyflow
Won’t connect, and the entry uses url url is for SSE servers Change url to httpUrl
gemini mcp add tried to run the URL as a program No --transport http, so it used stdio Remove the entry, then add it again with --transport http
Zyflow is missing in other folders Added to one project only (the default scope) Remove the entry, then add it again with --scope user
No browser opens, or the callback fails Running over SSH, on a server or in a container Use an API key
“This connection request has expired” Approving took more than 10 minutes Run /mcp auth zyflow again
Asked to sign in again every hour A refresh bug in older Gemini CLI versions Update Gemini CLI, then run /mcp auth zyflow
“The access token is invalid, expired or revoked. Reconnect Zyflow.” Disconnected on the Connect page Run /mcp auth zyflow
“This connection is read-only. Reconnect with write access to change records.” A read-only key Use a Read and write key
“Too many requests. Slow down and retry shortly.” A short burst limit Wait a moment, then retry
“MCP issues detected. Run /mcp list for status.” Gemini CLI found a problem with an MCP server when it started Run /mcp list and fix the server it flags

Questions

What does it cost to use Zyflow from Gemini CLI?

Zyflow costs nothing to start. The Free plan needs no card, and Gemini CLI’s calls to Zyflow are never billed.6 Gemini CLI itself needs a paid Gemini API key or a Gemini Code Assist Standard or Enterprise license from Google.3

What does Zyflow receive from Gemini CLI?

Only what Gemini CLI sends in its tool calls, such as a name to look up or a call to log. Zyflow doesn’t get your code, your files or the rest of the session unless a tool call carries them. Zyflow runs no AI model and doesn’t train one on your data.

How do I disconnect Gemini CLI?

On the Connect page, find it under Connected apps and choose Disconnect. It loses access right away, and your records stay as they are. Then run gemini mcp remove --scope user zyflow to take the zyflow entry out of your settings.

Will Gemini CLI know what I told Claude?

Yes, if it was saved in Zyflow. Facts sit on the customer’s record, and every app connected to that workspace reads the same record. Tell Claude on Monday; Gemini CLI can look it up on Tuesday.

One workspace per connection

You sign in and approve, like “Sign in with Google”. Your AI app never gets your password, and it can’t touch billing, members or keys.

  1. 1 Undo works within your plan’s history window: 30 days on Free, up to 3 years on paid plans. Deleted items can be restored for 30 days on every plan. Settings changes, such as pipelines, custom fields and tag renames, are logged but can’t be undone. ↩
  2. 2 Writing to Zyflow from ChatGPT needs developer mode on a ChatGPT Business, Enterprise or Edu plan. It’s in beta, on the web, and an admin switches it on. Claude works on every plan. Checked October 2026. ↩
  3. 3 Gemini support means Gemini CLI. Since June 18, 2026, Google serves Gemini CLI only to people with a paid Gemini API key or a Gemini Code Assist Standard or Enterprise license. The Gemini app isn’t supported. ↩
  4. 4 Your AI asks only if your AI app passes Zyflow’s question on to you. Name matching understands English connecting words, such as “Sam at Halden”. ↩
  5. 5 About 1,500 characters of Notes for your AI reach each app when it connects. Whether a model follows them depends on the model. ↩
  6. 6 Your AI app’s calls to Zyflow, through MCP or the REST API, are never billed on any plan, and there are no AI credits. Short burst limits stop runaway scripts. Your AI app’s own subscription and usage limits still apply. ↩
  7. 7 Export gives you six CSV files, or one JSON file with your records, documents, change history (up to 100,000 changes) and links to every file. File contents download separately from Files. ↩

Last updated Oct 3, 2026

One link for any MCP app.

Gemini CLI is made by Google. Zyflow isn’t affiliated with or endorsed by Google.

Get your Zyflow link

Free plan. No card.