Skip to content

Site Scanner MCP Server — Gemini Enterprise setup guide

Connect Gemini Enterprise to Evinced Site Scanner MCP and ask Gemini about your accessibility scan results in plain language. An admin adds the connector once; then each person connects their own Evinced account.

Part 1 · Before you start

Google Cloud admin, once

  1. Check the MCP policy

Evinced has already enabled Gemini Enterprise sign-in on its side.

You need admin access to Gemini Enterprise, an Evinced Site Scanner account, and about 15 minutes.

Every value used in steps 4, 6 and 7. Copy them exactly.

Field Value
MCP Server URL https://site-scanner-mcp.evinced.io/mcp
Authorization URL https://site-scanner-mcp.evinced.io/authorize
Authorization URL Parameters Leave empty
Token URL https://site-scanner-mcp.evinced.io/token
Client ID iIHIYWjC4dNEWfjVw4g0knyUpgmNolGS
Client Secret Leave empty
Scopes openid profile email offline_access
Enable PKCE Support On
Use HTTP Basic Authentication Off
Data connector name Evinced Site Scanner
Actions to enable All of them

A Google Cloud admin checks this once.

Google Cloud can stop Gemini Enterprise from connecting to custom MCP servers. If the policy below reads Enforced for your project, turn it off for that project only; the rest of your organization keeps it. You need the Organization Policy Administrator role.

  1. Open IAM & Admin › Organization policies, find Disable custom MCP server connector for Gemini Enterprise, and click Manage policy.
  2. Under Policy source, choose Override parent’s policy.
  3. Under Rules, keep one rule set to Not enforced (Add a rule if there is none).
  4. Click Set policy. Its status then reads Not enforced.
The Edit policy page for Disable custom MCP server connector for Gemini Enterprise, with Override parent's policy as action 2, a rule set to Not enforced as action 3 and the Set policy button as action 4.

A Gemini Enterprise admin does this once.

In the Google Cloud console, open Gemini Enterprise in your project and select your app.

  1. Open Connected data stores.
  2. Click + New data store.
The Gemini Enterprise console, with Connected data stores in the menu as action 1 and the New data store button as action 2.

On Select a data source, scroll down to MCP servers.

  1. On the Custom MCP Server card, click Add MCP server.
The Select a data source page scrolled to MCP servers, with the Custom MCP Server card highlighted as action 1.

Keep OAuth 2.0 selected. Leave Authorization URL Parameters and Client Secret empty.

  1. MCP Server URL

    https://site-scanner-mcp.evinced.io/mcp
  2. Authorization URL

    https://site-scanner-mcp.evinced.io/authorize
  3. Token URL

    https://site-scanner-mcp.evinced.io/token
  4. Client ID

    iIHIYWjC4dNEWfjVw4g0knyUpgmNolGS
  5. Scopes

    openid profile email offline_access
  6. Enable PKCE Support: on

  7. Use HTTP Basic Authentication: off

  8. Click Verify Auth.

The custom MCP server form, with actions 1 to 8 marking the server, authorization and token URLs, the client ID, the scopes, PKCE on, HTTP Basic authentication off and the Verify Auth button.

Verify Auth opens the Evinced sign-in in a pop-up.

  1. Enter your Evinced email, click Continue, and finish signing in. The pop-up closes on its own.

    The Evinced log-in pop-up, with the email field and Continue button highlighted as action 1.
  2. Check for Successfully logged in.

    Back in Gemini Enterprise, a green Successfully logged in message under the PKCE and HTTP Basic authentication settings, highlighted as action 2.
  3. Scroll down and click Continue.

Location stays global (Global). The tag and the sensitive data protection policy are optional.

  1. Data connector name: Evinced Site Scanner
  2. Click Create. You land on the new connector’s page, and Evinced Site Scanner is listed under Connected data stores.
The Configure your data connector page, with the data connector name Evinced Site Scanner as action 1 and the Create button as action 2.

A new connector starts with every tool turned off. Gemini calls them actions.

  1. On the connector’s page, click Go to actions.

    The new connector's page, with a banner saying its actions are disabled and the Go to actions button highlighted as action 1.
  2. Click Reload custom actions and sign in to Evinced in the pop-up. The Site Scanner tools appear, all Disabled.

  3. Tick Select all rows.

  4. Click Enable actions. It appears once rows are selected.

  5. Check that every action shows Enabled.

    The Actions tab, with Reload custom actions as action 2, the select-all checkbox as action 3, and every Site Scanner action's status reading Enabled.

Everyone does this once, each with their own Evinced account.

Gemini works only with what your Evinced account can access.

  1. Open your Gemini Enterprise app and click Sources, the sliders icon under the prompt box.
  2. Next to Evinced Site Scanner, click Authorise (Authorize in US English) and sign in with your Evinced account.
  3. The pop-up closes and the Evinced Site Scanner toggle is on.
The Gemini Enterprise prompt box with the Sources menu open: the Sources icon as action 1 and the Authorise link next to Evinced Site Scanner as action 2.
Before: 1 Sources, 2 Authorise
The Sources menu with the Evinced Site Scanner toggle switched on, highlighted as connected.
After: connected

The whoami tool only reads. It’s the quickest way to check which account Gemini is using.

  1. Start a chat and ask:

    Use the Evinced Site Scanner connector to run its whoami tool.
  2. Gemini shows the tool it wants to run. Click Send.

    Gemini Enterprise asks before it runs the whoami tool, with the Send button highlighted as action 2.
  3. Gemini replies with the Evinced account and tenant it’s using.

    Gemini's answer listing the connected account, active tenant and plan level, highlighted as your account and tenant. The values are censored.
    Account details censored for this guide

Ask in plain language. Gemini picks the Site Scanner tool that fits.

  1. Ask about your sites, for example:

    List my Evinced Site Scanner properties with their latest scan date and score.
  2. Check the details Gemini will send (here, how many properties) and click Send.

    A review card for List Evinced Properties with a limit of 5, and the Send button highlighted as action 2.
  3. Gemini answers from your live Site Scanner data.

    Gemini's answer listing five Evinced properties with their name, latest scan date and accessibility score. The values are censored.
    Property names, dates and scores censored for this guide
What you see What to do
“Operation denied by org policy” when you click Create Your organization still blocks custom MCP servers for Gemini Enterprise. Complete step 1, wait a few minutes (up to 15), and click Create again.
“Callback URL mismatch” when you click Verify Auth Evinced’s sign-in doesn’t recognise Gemini Enterprise. Email support@evinced.com.
“No actions are enabled” after you create the connector Gemini can’t use any tool yet. Complete step 7: reload the actions, select all, and click Enable actions.
Evinced Site Scanner shows “Authorise” (or “Authorize”) in the Gemini app That’s expected the first time. Click it and sign in with your Evinced account (step 8).
What the org policy error looks like
A Google Cloud error: Something went wrong, Operation denied by org policy, naming the disableCustomMcpServerConnector constraint from step 1. Project and tracking numbers are censored.

Evinced Site Scanner is live in Gemini Enterprise. Each person connects their own Evinced account once, and Gemini asks before each tool call.

The Connected data stores list showing Evinced Site Scanner as a Custom MCP Server with status Active.