Google Home opens up to Claude, OpenClaw and any other MCP agent

Google has opened early access to Home MCP, letting any agent that speaks the Model Context Protocol read and control a Google Home. Claude, OpenClaw, Hermes and Antigravity are all named as clients. Unlocking doors stays blocked, and Europe is not included yet.


The new $99 Google Home Speaker, Google's first smart speaker in six years, built for the Gemini for Home assistant.
Image Credits Credit: Google

“Connecting a real-life home to an AI agent allows that agent to control devices on your behalf,” Google warns in its developer documentation. “Depending on your agent, connecting it to Home MCP can result in unexpected or even undesired behaviour.”

That warning sits inside the setup guide for Google Home MCP. Google opened it to early access on 16 September. It lets outside AI agents read and control a Google Home.

Any agent that supports the Model Context Protocol can connect. Google names Antigravity, Claude, Hermes and OpenClaw. A connected agent reaches every device and the event history behind it. That runs from Nest doorbells and thermostats to Matter light bulbs.

What an agent can do with your house

Google listed four things its early testers built. An agent can summarise footage across cameras. A parent can ask what the children did when they got home, and get the clips back.

It can also read device state history. That covers how many loads of laundry ran in a week, or how long the lights stayed on.

Then it can speak to you. An agent that finishes a long task can push an audio message through a Google Home speaker. It can also generate a custom dashboard, replacing the Google Home app’s own interface with one an agent built.

“This gives your favourite AI agent real-world physical context,” Taylor Lehman, group product manager for Google Home and Nest, wrote in the announcement.

The setup is not for everyone

The reach is consumer. The installation is not. A user creates a Google Cloud project, enables the Home API, then configures an OAuth consent screen. After that comes a client ID and secret, the right redirect URI for their agent, and publishing the app.

Google suggests asking the agent itself to do the configuration. The prompt it supplies for that still points at a preprod sandbox endpoint, which tells you how early this is.

Early access covers Google Home Premium Advanced subscribers in the United States, in English. That is the $20 a month tier, CNET reported. TechCrunch asked about other tiers and markets, and Google would not say.

Automations are missing too. Creating and managing them through Home MCP is not supported yet, Google says. It also flags latency and experimental device traits as known issues.

The parts Google locked down

Some limits are hard. Home MCP enforces rate limits and blocks sensitive actions. Google gives unlocking doors as its example of what an agent may not do, and access can be revoked from the Google Home app at any time.

Facial recognition needs a second, separate consent. A user must be a manager of the home structure. They must also run a compatible Nest camera or doorbell with familiar face detection on, then visit a consent link tied to their own client ID and home.

Google also asks people to tell the rest of the household. If a home is shared, it says, the others should know that your agent can control devices and read home data. Its suggested alternative is to create a separate home for testing.

The attack surface nobody has priced

Handing an agent the keys to a house arrives with a known problem. Prompt injection hides instructions inside ordinary content, which the agent then follows. CNET notes that researchers demonstrated it against early versions of Gemini in the smart home, and that Google patched those.

The pattern is not theoretical elsewhere. Spain’s data protection authority reported its first breach by an agent this week.

In August, researchers at Zenity found malicious AI skills with 1.7 million installs. Attackers have already tricked a chatbot into hijacking accounts.

None of that makes Home MCP unsafe. It moves the safety question from Google to whichever agent a user connects, and Google says as much in its own warning.

First of the big three

Apple Home and Amazon Alexa have shipped nothing like this. That makes Google the first of the three large platforms to open a house to third-party agents, CNET reported. Enthusiasts have done it for years through Home Assistant, but that route requires the sort of person who already runs Home Assistant.

Europe gets none of it yet. The flagship demonstration here is an agent summarising camera footage of children. The questions about what leaves the home, and on whose terms, are sharper on this side of the Atlantic, and Google has not said when it will answer them.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Also tagged with


Published
Back to top