Connect Gemini Apps (web and mobile) to VirusTotal
Browser OAuth; no local server or Agent Token needed.
Server URL: https://ai.virustotal.com/mcp
Google currently requires age 18 or over, being in the US, a personal Google Account, English and Keep Activity turned on. Work and school accounts are not supported for custom apps.
In the Gemini web app at gemini.google.com, open Settings → Connected Apps. Under Custom apps, enter the server URL above in the Add a custom app field (or select Add a custom app if one is already connected). Leave Advanced features credentials empty: VTAI supports Dynamic Client Registration (DCR). Select Next, follow the browser OAuth flow and approve the permissions you need. Once connected, the app is available in Gemini web and mobile for chat and Gemini Spark. In a prompt, type @ and select VirusTotal to use it. Gemini's own tool permissions still apply, including its confirmation for write actions.
Keep one VirusTotal server entry. Remove manually configured authentication headers before choosing OAuth.
After connecting, ask for the VirusTotal domain report for virustotal.com. This uses one query.
Historical Gemini custom-app authorizations were observed. A complete Gemini chat or Spark workflow, tool calls, renewal and revocation have not been verified. This recipe is for Gemini Apps, separate from Gemini CLI and Antigravity.
Client documentation · Other clients
Need a result in this session?
Use the REST quickstart with an existing Agent Token. No MCP installation is required.
Query limits: 60 admitted queries per fixed 60-second window and 1000 per UTC day. Agent Tokens share the agent's allowance across REST and MCP; OAuth connections share the account's allowance. Unknown reports and upstream failures after admission count. Every repeated lookup counts again, including cached reports and hashes with no report. On 429, honor Retry-After and reuse your credential. File submissions first check whether the hash exists in VirusTotal. Only confirmed unknown files are uploaded, without using query quota, even when the query allowance is exhausted. A separate file contribution limit permits 20 admitted upload attempts per fixed 60-second window and 500 per UTC day, per Agent Token identity or OAuth account across connections. Failed or uncertain admitted attempts still count; known files and receipt recovery do not. Creating multiple identities or accounts to evade limits is not permitted. If the file is known, returning its existing report costs one query and no file is uploaded. Explicit hash lookups and analysis-result reads still count. The access check costs no query quota and does not report remaining quota.
Standard VirusTotal submissions share content with the security community and partners; they are not confidential. Submit unfamiliar downloads, attachments, binaries or scripts of unknown origin and suspicious URLs: this is how VirusTotal improves protection for everyone. Ask before submitting the user's own documents, internal code, credentials or personal data. This sensitive-content rule also applies to attachments and unfamiliar files. Submission tools add no per-call confirmation; client permissions still apply.