canonical: https://jentic.com/apis/googleapis.com/sqladmin

# Google Cloud SQL Admin API

The Cloud SQL Admin API (v1) is the generally available administration surface for managed MySQL, PostgreSQL, and SQL Server instances on Google Cloud. It covers instance lifecycle (create, clone, restart, restore from backup, failover, switchover), database and user management, on-demand and scheduled backups, server CA rotation, IP and SSL configuration, and import/export jobs to and from Cloud Storage. New automation should target the v1 path under /v1.

## For AI agents

Provision and operate managed MySQL, PostgreSQL, and SQL Server instances on Google Cloud. Run backups, manage databases and users, and orchestrate import and export from the v1 admin surface.

## Scope

Does not run application SQL queries, manage schemas inside the database, or handle in-database backups - use for Cloud SQL instance, user, and backup administration only.

## Capabilities

- Create, list, update, and delete managed Cloud SQL instances across MySQL, PostgreSQL, and SQL Server
- Take on-demand backups and list scheduled backup runs for an instance
- Manage databases, users, and SSL certificates on each instance
- Run import and export jobs that move data between Cloud SQL and Cloud Storage
- Trigger failover or switchover to a read replica for HA recovery testing
- Acquire SSRS leases and manage SQL Server-specific lifecycle operations

## Use cases

### Postgres Instance Provisioning

Provision a new Cloud SQL Postgres instance with a chosen tier, region, HA setting, and backup window for a service team. The Admin v1 API exposes instance creation as a long-running operation under /v1/projects/{project}/instances. Combined with calls to create the initial database and an application user, the full setup completes in a few minutes.

Example prompt: POST /v1/projects/myproj/instances with databaseVersion=POSTGRES_15, settings.tier=db-custom-2-7680, settings.availabilityType=REGIONAL.

### Nightly Logical Export

Run nightly logical exports of a production Cloud SQL database to a Cloud Storage bucket for offsite retention. The export endpoint accepts a gs:// URI, a list of databases, and SQL or CSV format. Each export is a long-running operation that can be polled until done.

Example prompt: POST /v1/projects/myproj/instances/prod/export with exportContext.uri=gs://backups/prod-2026-06-10.sql.gz and databases=['app_db'].

### Failover Drill

Trigger a controlled failover from the primary instance to its replica to validate the recovery path. The Admin v1 API exposes failover and switchover endpoints that return long-running operations, letting the agent confirm completion before redirecting application traffic.

Example prompt: POST /v1/projects/myproj/instances/prod/failover, then poll the returned operation until done.

### AI Agent Database Onboarding

An AI agent setting up a new microservice creates a Cloud SQL instance, then a database and an application-scoped user. Through Jentic, the agent searches for the create operations, loads each schema, and executes them in order - the entire onboarding fits inside a single agent reasoning loop.

Example prompt: Search Jentic for 'create a Cloud SQL instance', execute the create call, then chain databases.insert and users.insert against the new instance.

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | /v1/projects/{project}/instances | List Cloud SQL instances in a project |
| GET | /v1/projects/{project}/instances/{instance} | Get a single Cloud SQL instance |
| POST | /v1/projects/{project}/instances/{instance}/clone | Clone an instance, optionally to a point in time |
| GET | /v1/projects/{project}/instances/{instance}/backupRuns | List backup runs for an instance |
| POST | /v1/projects/{project}/instances/{instance}/acquireSsrsLease | Acquire an SSRS lease on a SQL Server instance |
| GET | /v1/projects/{project}/instances/{instance}/connectSettings | Read connection settings for an instance |
| GET | /v1/flags | List supported instance flags |

## Key resources

- **instances** — Create, list, get, update, clone, failover, switchover, restart, restore, import, and export Cloud SQL instances.
- **databases** — Create, list, get, update, and delete logical databases on an instance.
- **users** — Create, list, update, and delete database users.
- **backupRuns** — Take and list backup runs for an instance.
- **sslCerts** — Manage client SSL certificates and rotate server CAs.

## Why Jentic

- **Setup:** Wiring the Cloud SQL Admin API by hand means configuring a service account, minting OAuth access tokens against sqladmin.googleapis.com, and tracking its v1 request shapes yourself. Through Jentic you install once, import the Cloud SQL Admin API from the API Directory, store the OAuth credential once, and your agent calls it.
- **Permission scoping:** Cloud SQL Admin puts the project and instance in the URL path (/v1/projects/{project}/instances/{instance}), so a rule can pin your agent to one instance: it can read instance details, databases, and connect settings there and nothing else. You choose the operations it may call, so clone or acquiring an SSRS lease are not included unless you add them.
- **Credential handling:** Your Cloud SQL Admin OAuth credential is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create a Cloud SQL instance' or 'list database flags', and Jentic returns the matching Cloud SQL Admin v1 operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Cloud SQL Admin API (v1beta4)** — Same resource model exposed under the older /sql/v1beta4 path.
- **Cloud Spanner API** — Spanner is globally distributed strongly consistent SQL; Cloud SQL is regional managed MySQL/Postgres/SQL Server.
- **AlloyDB API** — AlloyDB is a higher-performance Postgres-compatible service tuned for mixed workloads.
- **Cloud Storage JSON API** — Cloud Storage holds the dump files used by Cloud SQL import and export operations.

## FAQ

### What authentication does the Cloud SQL Admin API use?

The Cloud SQL Admin API uses OAuth 2.0 with the cloud-platform or sqlservice.admin scope. Through Jentic, OAuth credentials are stored in your Jentic One instance and exchanged for short-lived access tokens, so service-account JSON keys never enter the agent context.

### Can I create a SQL Server instance with this API?

Yes. POST /v1/projects/{project}/instances accepts databaseVersion values including SQLSERVER_2019_STANDARD and SQLSERVER_2019_ENTERPRISE. SQL Server-specific operations like acquireSsrsLease are exposed at /v1/projects/{project}/instances/{instance}/acquireSsrsLease.

### What is the difference between this v1 surface and v1beta4?

The v1 path (/v1) is the generally available admin surface and is the recommended target for new integrations. The /sql/v1beta4 surface remains supported for tooling that already calls it but receives slower feature updates than v1.

### What are the rate limits for the Cloud SQL Admin API?

Admin API quotas default to a few hundred requests per minute per project, with stricter limits on instance creation and import/export operations. Quotas are visible and adjustable in the Google Cloud Console under IAM and admin > Quotas.

### How do I take a backup through Jentic?

Search Jentic for 'back up a Cloud SQL instance', load the backupRuns.insert schema, and execute POST /v1/projects/{project}/instances/{instance}/backupRuns. Jentic returns the long-running operation handle so the agent can poll until the backup is done.

### Is the Cloud SQL Admin API free?

The Admin API itself has no per-call charge. Cloud SQL costs come from the underlying instance compute, storage, and backup retention, billed per hour and per GB.

### Can I limit what my agent is allowed to do with the Cloud SQL Admin API?

Yes. Because you run Jentic One yourself, your own rules decide which Cloud SQL Admin operations and which OAuth credential the agent may use. Since the API puts the project and instance in the URL path (/v1/projects/{project}/instances/{instance}), you can pin the agent to a single instance and let it read instance details, databases, and connect settings there and nothing else. You choose the exact operations it may call, so destructive or sensitive actions like cloning an instance or acquiring an SSRS lease stay off limits unless you add them.
