run_stream
Starts an already created stream, specified by the provided resource 'name' parameter. Parameters * 'name': The resource name of the stream to start. * 'name' should be in the format of: 'projects/{project name}/locations/{location}/streams/{stream name}', for example: 'projects/my-project/locati...
This record as markdown: /tools/com-googleapis-datastream-mcp/run-stream.md
What run_stream does on Mcp
AI agents invoke run_stream to trigger actions in Mcp. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
| Parameter | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Required. Name of the stream resource to start, in the format: projects/{project_id}/locations/{location}/streams/{stream_name} |
force | boolean | — | Optional. Update the stream without validating it. |
cdcStrategy | object | — | Optional. The CDC strategy of the stream. If not set, the system's default value will be used. |
Parameters from the server's own tool schema.
Why run_stream is rated High
This tool triggers an external operation (Google Cloud Datastream activation) whose effects depend on arguments and configuration state. While not immediately destructive, starting a stream can cause continuous data movement/replication which consumes resources, incurs costs, and may propagate data to downstream systems. The 'force' flag that bypasses verification increases risk.
From the tool's definition Tool 'starts an already created stream' with a 'force' parameter to bypass configuration verification. Initiates a long-running operation that activates data streaming infrastructure.
Risk signalsBulk/mass operation — affects multiple targets
Attacks that exploit this kind of access
The rule that runs run_stream safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Mcp, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For run_stream, this is the rule to start with:
run_stream stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Mcp, apply this rule, and every run_stream call is checked against it from then on.
Questions about run_stream
Starts an already created stream, specified by the provided resource 'name' parameter. Parameters * 'name': The resource name of the stream to start. * 'name' should be in the format of: 'projects/{project name}/locations/{location}/streams/{stream name}', for example: 'projects/my-project/locations/us-central1/streams/my-streams'. * 'force': Whether to run the stream without running prior configuration verification. The default is 'false'. Returns * This tool returns a long-running operation. Use the 'get_operation' tool with the returned operation name to poll its status until it completes. Operation may take several minutes; do not check more often than every ten seconds. It is categorised as a Execute tool in the Mcp MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
run_stream accepts 3 parameters: name, force, cdcStrategy. Required: name. The full parameter table on this page comes from the server's own tool schema.
Register the MCP server in PolicyLayer and add a rule for run_stream: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Mcp. Nothing to install.
run_stream is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the run_stream rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for run_stream. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
run_stream is provided by the MCP server (https://datastream.googleapis.com/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on , and thousands of servers like it.
This server
Across the catalogue