Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

DIY vs Gemini Enterprise Agent Platform: an in-house build or Google Cloud’s agent platform

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

Gemini Enterprise Agent Platform

Google Cloud platform to build, deploy, govern, and optimize AI agents

Short answer

DIY is not a product: you connect and govern agents wherever they run, on open protocols like A2A and MCP, which leave authorization to the implementer.⁠Source 1, Source 2, Source 3, Source 4 Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents, with a per-project registry and a gateway for Agent Runtime and the Gemini Enterprise app.⁠Source 5, Source 6, Source 7, Source 8

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can catalog MCP servers and control which agents reach them: Agent Platform through Agent Registry and IAM policies, DIY through builds like Uber’s registry and gateway.⁠Source 8, Source 9, Source 10
Where they differ
Agent Platform’s registry and gateway are Google Cloud services; the gateway covers Agent Runtime and the Gemini Enterprise app.⁠Source 7, Source 8, Source 9, Source 11 DIY runs where you put it, such as Pinterest’s internal cloud.⁠Source 12
Running both
Google says Agent Registry can list agents hosted outside Google Cloud, and Agent Platform supports open-source frameworks such as its Agent Development Kit.⁠Source 13, Source 14
Public sources · checked 2 October 2026
  • Offered
  • You build it

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 15
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 16
  • Identity and access: You build itYour own identity provider⁠Source 17
  • Registry and governance: You build itYour own agent registry⁠Source 18
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 10
  • Agents across organizations: You build itA2A with API management⁠Source 19

Gemini Enterprise Agent Platform

  • Build agents: OfferedAgent Studio low-code canvas⁠Source 5
  • Host and run agents: OfferedAgent Runtime⁠Source 8
  • Identity and access: OfferedSPIFFE-based Agent Identity⁠Source 20
  • Registry and governance: OfferedAgent Registry⁠Source 9
  • Traffic between agents, tools, and models: OfferedAgent Gateway⁠Source 8
  • Agents across organizations: OfferedGateway calls to outside agents⁠Source 8

At a glance

TopicDIYGemini Enterprise Agent Platform
What it isNot a product: an in-house build on protocols such as A2A, an open standard, and MCP, which the A2A specification calls complementary.⁠Source 1Google Cloud’s platform to build, deploy, govern, and optimize AI agents, described as an evolution of Vertex AI.⁠Source 5, Source 6
Where governed agents runWherever you run them: Pinterest, for example, optimized for MCP servers hosted in its internal cloud.⁠Source 12Agent Gateway can govern traffic for Agent Runtime and the Gemini Enterprise app.⁠Source 8 Agents hosted elsewhere can be added to Agent Registry by manual registration.⁠Source 13
Agent identityUp to you: in A2A, identity is established at the HTTP layer, and MCP authorization is optional.⁠Source 3, Source 19Agents on Agent Runtime, the Gemini Enterprise app, or Cloud Run can each have a SPIFFE-based Agent Identity; on Agent Runtime it is opt-in.⁠Source 20, Source 21 Agent Identity is generally available; the Agent Identity API is in preview.⁠Source 22
Agents at other companiesA2A is designed for agents built by different companies and running on separate servers; each server authorizes requests under its own policies.⁠Source 1, Source 23Agents on Agent Runtime or in the Gemini Enterprise app can call outside tools, MCP servers, and agents through Agent Gateway.⁠Source 8 IAM access to Agent Runtime agents for other organizations is not publicly documented.
Pricing modelThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 2 Build and running costs are not publicly documented.Agent Runtime compute is $0.085 per vCPU-hour.⁠Source 24 Agent Gateway egress costs $0.085 per 15,000 requests.⁠Source 24 Agent Registry is free; skill scanning is billed from January 2027.⁠Source 25

What each one is

Build it yourself (DIY)

DIY means connecting and governing agents yourself: open protocols such as MCP and A2A, your existing gateway, identity provider, and service mesh, an in-house platform, self-hosted open-source frameworks, or no central approach; Uber and Pinterest have each written about building their own MCP registry.⁠Source 10, Source 12

Gemini Enterprise Agent Platform

Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, govern, and optimize agents, an evolution of Vertex AI.⁠Source 5, Source 6 Agent Registry catalogs agents and MCP servers, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway can govern agent traffic.⁠Source 8, Source 9, Source 11, Source 20

The differences that matter

  1. Where agents run and are governed

    DIY

    Wherever you put them: Pinterest optimized for MCP servers in its internal cloud, and Uber’s gateway sends requests through its service mesh sidecar.⁠Source 10, Source 12

    Gemini Enterprise Agent Platform

    Agent Gateway can govern traffic for Agent Runtime and the Gemini Enterprise app; agents hosted elsewhere can be listed in Agent Registry by manual registration.⁠Source 8, Source 13

    Google documents an egress gateway in a dedicated governance project covering Agent Runtime agents in other projects of the same organization and region.⁠Source 26

  2. Agent registry

    DIY

    Build your own: A2A prescribes no standard API for curated registries, and Uber and Pinterest each built an MCP registry.⁠Source 10, Source 12, Source 18

    Gemini Enterprise Agent Platform

    Agent Registry works per Google Cloud project: agents on supported runtimes can be registered automatically; other projects and outside hosts need manual registration.⁠Source 7, Source 27, Source 28

    The official MCP Registry lists publicly accessible MCP servers; it is in preview and does not support private servers.⁠Source 29

  3. Access control

    DIY

    Each A2A server authorizes requests under its own policies, and MCP authorization is optional; Uber applies its internal access-control policies at its gateway.⁠Source 1, Source 3, Source 10

    Gemini Enterprise Agent Platform

    By default, outbound calls through Agent Gateway are blocked unless an IAM access policy grants access.⁠Source 8

    Google’s inbound mode, where the gateway controls which clients reach an agent, is supported only for agents on Agent Runtime.⁠Source 8

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicDIYGemini Enterprise Agent Platform
Network exposureMCP servers on Streamable HTTP expose an HTTP endpoint, and A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 30Agent Gateway manages mTLS connections and applies policy checks to traffic; its inbound mode supports only Agent Runtime agents.⁠Source 8
IdentityIn A2A, credentials are obtained out of band; Pinterest checks end-user JWTs and mesh identities on almost every MCP call.⁠Source 1, Source 12With Agent Identity, agents can authenticate to MCP servers, endpoints, and other agents as themselves or for an end user.⁠Source 20
Access changes and revocationYours to build: each A2A server authorizes requests under its own policies, in logic the specification calls implementation-specific.⁠Source 1Deny rules override allow rules.⁠Source 31 Deleting an agent leaves its IAM bindings as inactive grants, to be removed by hand.⁠Source 20
Audit trailA2A docs advise auditing task creation, critical state changes, and agent actions, and tracing, for example with OpenTelemetry.⁠Source 19Registry admin changes are logged; other calls need Data Access logs on.⁠Source 32, Source 33 Gateway logs record access requests.⁠Source 34
ComplianceA2A docs advise complying with privacy regulations such as GDPR, CCPA, and HIPAA; MCP leaves data protections to implementers.⁠Source 4, Source 19Listed in scope for ISO 27001, SOC 1, 2, and 3, and PCI DSS, and in Google Cloud’s HIPAA BAA.⁠Source 35, Source 36

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

DIY and Gemini Enterprise Agent Platform compared on 18 criteria
DIYGemini Enterprise Agent Platform
What it is
What it is and who it’s forNot a product: an in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which A2A calls complementary.⁠Source 1Google Cloud platform to build, deploy, govern, and optimize AI agents, described as an evolution of Vertex AI, for developers and technical teams.⁠Source 5, Source 6
MaturityVaries by component: MCP’s latest specification revision is 2026-07-28.⁠Source 4 The official MCP Registry is in preview and may have breaking changes.⁠Source 29Launched 22 April 2026.⁠Source 37 Agent Registry and Agent Gateway generally available since 18 June 2026.⁠Source 22 Agent Identity is generally available; its API is in preview.⁠Source 22
Control
Agent registry and discoveryBuild your own: A2A prescribes no standard API for curated registries; the official MCP Registry, in preview, doesn’t support private servers.⁠Source 18, Source 29Agent Registry: a per-project catalog of agents, MCP servers, and tools.⁠Source 7, Source 9 Agents on supported runtimes can be registered automatically, others manually.⁠Source 27, Source 28
Identity and access controlIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 1, Source 19 MCP authorization is optional.⁠Source 3Agents on supported runtimes can have a SPIFFE-based Agent Identity.⁠Source 20 By default, outbound gateway calls are blocked without an IAM access policy.⁠Source 8
Ownership, policy, and revocationMCP says implementers should build consent and authorization flows.⁠Source 4 Uber starts every MCP server and tool disabled until its owning team reviews it.⁠Source 10Allow and deny access policies, enforce and dry-run modes, and Model Armor content filters.⁠Source 8, Source 31 An agent owner field is not publicly documented.
Audit log and observabilityA2A docs advise auditing significant events and distributed tracing, for example with OpenTelemetry.⁠Source 19 Pinterest’s MCP servers log inputs and outputs.⁠Source 12Registry admin changes go to Admin Activity logs; other calls need Data Access logs on.⁠Source 32, Source 33 Gateway traffic is in Cloud Logging, routable to Pub/Sub for export.⁠Source 8, Source 38
Connection
How agents connectMCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 30 AWS PrivateLink privately links a VPC to services.⁠Source 39Agent Gateway: inbound for Agent Runtime agents, outbound for Agent Runtime and the Gemini Enterprise app.⁠Source 8 Outside agents are registered by URL or agent card.⁠Source 13
Agents across organizationsA2A is built for agents from different companies on separate servers, and each server authorizes requests under its own policies.⁠Source 1, Source 23Agent Runtime and Gemini Enterprise app agents can call outside agents via Agent Gateway.⁠Source 8 Other organizations’ IAM access: not publicly documented.
Protocol supportMCP defines stdio and Streamable HTTP transports and permits custom ones.⁠Source 40 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 1Agent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.⁠Source 8, Source 28, Source 41 A2A agents on Agent Runtime are in preview.⁠Source 42
Frameworks, models, and clouds supportedA2A gives agents built on different frameworks, languages, or vendors a common language.⁠Source 1 Google’s open-source ADK says it is model- and deployment-agnostic.⁠Source 15Build with the Agent Development Kit or any other open-source framework, using Gemini or other Model Garden models.⁠Source 14 Outside agents can be registered manually.⁠Source 13
Operations
Deployment options and data residencyWherever you run it: Pinterest optimized for MCP servers in its internal cloud.⁠Source 12 A2A docs leave protecting stored data to your own security policies.⁠Source 19Agent Gateway is managed and regional.⁠Source 11 Agent data at rest stays in a supported location you pick.⁠Source 43 Self-hosting the registry or gateway: not publicly documented.
Compliance attestationsSits with the implementer: A2A docs advise complying with GDPR, CCPA, and HIPAA as relevant; MCP leaves data protections to implementers.⁠Source 4, Source 19Listed for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS, and in the HIPAA BAA.⁠Source 35, Source 36 Access Transparency isn’t available for Agent Registry.⁠Source 22
Support and SLADepends on the component: MCP SDKs are tiered partly by maintenance commitments; the official MCP Registry, in preview, gives no uptime guarantees.⁠Source 44, Source 45Google Cloud support packages, some with 24/7 coverage.⁠Source 46 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime is not publicly documented.
Time and effort to get runningA curated A2A registry is a service you deploy and maintain.⁠Source 18 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 12A Google Cloud project with the Agent Registry API enabled, plus the Identity-Aware Proxy API for gateway policy.⁠Source 7 Google recommends dry-run mode in staging.⁠Source 31
Pricing model and public pricesThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 2 Build and running costs are not publicly documented.Agent Registry is free; skill scanning is billed from January 2027.⁠Source 25 Agent Gateway egress costs $0.085 per 15,000 requests.⁠Source 24
Building
Agent building toolsFrameworks such as LangGraph and Google’s open-source Agent Development Kit build and deploy agents.⁠Source 15, Source 16 The A2A project hosts SDKs in six languages.⁠Source 47Agent Studio, a low-code canvas; the Agent Development Kit; and Agent Garden prebuilt agents and templates.⁠Source 5 A Managed Agents API is in preview.⁠Source 5
Model accessYour choice: Google’s open-source ADK, for one, says it is optimized for Gemini and model-agnostic.⁠Source 15More than 200 models through Model Garden, including Gemini, third-party models such as Anthropic’s Claude, and open-source models.⁠Source 5, Source 37
Integrations and ecosystemThe official MCP Registry, in preview, has a REST API for clients and aggregators to discover MCP servers.⁠Source 29Agents in Agent Registry can be made available to users of Google’s Gemini Enterprise app.⁠Source 11 Google’s own remote MCP servers are registered automatically.⁠Source 41

Which to choose

Choose DIY if

  • You want agent calls checked by systems you already run, as Uber and Pinterest do with internal access control and mesh identities.⁠Source 10, Source 12
  • Your agents run outside Google Cloud, and you want controls beside them, as Pinterest applies its security logic in its internal cloud.⁠Source 12
  • You want your own review rules: Uber starts every MCP server and tool disabled until reviewed; Pinterest reviews all but one-off experiments.⁠Source 10, Source 12
  • You want no agent platform contract: the A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 2

Choose Gemini Enterprise Agent Platform if

  • You want to build, deploy, and govern agents on one platform, with Agent Studio and the open-source Agent Development Kit.⁠Source 5, Source 14
  • Your agents run on Google Cloud, where agents on supported runtimes, such as Google Kubernetes Engine, can be registered automatically.⁠Source 27, Source 28
  • You want outbound agent calls blocked by default unless an IAM policy allows them, with Model Armor scanning prompts and tool responses.⁠Source 8
  • You want vendor support and attestations: support packages, some with 24/7 coverage, and ISO 27001, SOC 2, and PCI DSS scope.⁠Source 35, Source 46

Questions buyers ask

Can Google’s Agent Development Kit be used without Agent Platform?

ADK is an open-source, code-first Python framework, and its README says it is model-agnostic and deployment-agnostic.⁠Source 15 Agent Platform supports building with ADK or any other open-source framework.⁠Source 14

Do they support MCP and A2A?

In a DIY build you implement them: MCP defines stdio and Streamable HTTP transports, and A2A defines JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 1, Source 40 Agent Registry catalogs MCP servers and A2A agents, Agent Gateway carries both, and A2A agents on Agent Runtime are in preview.⁠Source 8, Source 28, Source 41, Source 42

Is Gemini Enterprise Agent Platform the same as Gemini Enterprise?

Agent Platform is Google Cloud’s platform to build, deploy, govern, and optimize agents.⁠Source 5, Source 6 Google’s Gemini Enterprise app is separate: agents in Agent Registry can be associated with it to make them available to its end users.⁠Source 11

How do the costs compare?

For DIY, the specifications are openly licensed, and build and running costs are not publicly documented.⁠Source 1, Source 2 Agent Registry is free; skill scanning is billed from January 2027.⁠Source 25 Agent Gateway egress costs $0.085 per 15,000 requests, and Agent Runtime compute is billed per vCPU-hour.⁠Source 24

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

52 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnopqr

  2. Source 2: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) github.com · checked Back:abcde

  3. Source 3: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:abcd

  4. Source 4: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcde

  5. Source 5: Agent Platform overview Google · checked Back:abcdefghij

  6. Source 6: Gemini Enterprise Agent Platform (formerly Vertex AI) Google · checked Back:abcde

  7. Source 7: Set up Agent Registry Google · checked Back:abcde

  8. Source 8: Agent Gateway overview Google · checked Back:abcdefghijklmnopqrstuv

  9. Source 9: Agent Registry overview Google · checked Back:abcde

  10. Source 10: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcdefghi

  11. Source 11: Import A2A agents from Agent Registry Google · checked Back:abcde

  12. Source 12: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefghijkl

  13. Source 13: Use manual registration Google · checked Back:abcdef

  14. Source 14: Build with Gemini Enterprise Agent Platform Google · checked Back:abcd

  15. Source 15: google/adk-python README (GitHub) github.com · checked Back:abcde

  16. Source 16: langchain-ai/langgraph README (GitHub) github.com · checked Back:ab

  17. Source 17: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back to text

  18. Source 18: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:abcd

  19. Source 19: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefgh

  20. Source 20: Agent Identity overview Google · checked Back:abcdef

  21. Source 21: Use Agent Identity with Agent Runtime Google · checked Back to text

  22. Source 22: Gemini Enterprise Agent Platform release notes Google · checked Back:abcd

  23. Source 23: a2aproject/A2A README (GitHub) github.com · checked Back:ab

  24. Source 24: Gemini Enterprise Agent Platform pricing Google · checked Back:abcd

  25. Source 25: Agent Registry pricing Google · checked Back:abc

  26. Source 26: Set up Agent Gateway Google · checked Back to text

  27. Source 27: Use automatic registration Google · checked Back:abc

  28. Source 28: Register agents Google · checked Back:abcde

  29. Source 29: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abcd

  30. Source 30: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  31. Source 31: IAM Access policies overview Google · checked Back:abc

  32. Source 32: Agent Registry audit logging Google · checked Back:ab

  33. Source 33: Cloud Audit Logs overview Google · checked Back:ab

  34. Source 34: Monitor traffic through Agent Gateway Google · checked Back to text

  35. Source 35: Google Cloud Platform Services in Scope by Compliance Program Google · checked Back:abc

  36. Source 36: HIPAA compliance on Google Cloud Google · checked Back:ab

  37. Source 37: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Google · checked Back:ab

  38. Source 38: Route log entries Google · checked Back to text

  39. Source 39: What is AWS PrivateLink? - Amazon Virtual Private Cloud docs.aws.amazon.com · checked Back to text

  40. Source 40: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  41. Source 41: Register MCP servers Google · checked Back:abc

  42. Source 42: Create an Agent2Agent agent Google · checked Back:ab

  43. Source 43: Supported locations for agents in Agent Platform Google · checked Back to text

  44. Source 44: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  45. Source 45: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  46. Source 46: Getting help for agents Google · checked Back:ab

  47. Source 47: A2A protocol roadmap a2a-protocol.org · checked Back to text

  48. Source 48: Your company's private network Blocks.ai · checked Back to text

  49. Source 49: Network requirements Blocks.ai · checked Back to text

  50. Source 50: Solutions: Agent sprawl Blocks.ai · checked Back to text

  51. Source 51: Why Blocks? Blocks.ai · checked Back to text

  52. Source 52: What is Blocks? Blocks.ai · checked Back to text