Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Amazon Bedrock AgentCore vs Cloudflare MCP server portals
Amazon Bedrock AgentCore
AWS platform for building, deploying, and operating AI agents
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Short answer
Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents, while Cloudflare says its MCP server portals, a feature of Cloudflare One, put MCP servers behind one governed endpoint.Source 1, Source 2, Source 3, Source 4 AgentCore can host agents and catalogs agents as well as tools; a portal lists MCP servers and applies Cloudflare Access policies to whoever connects.Source 1, Source 3, Source 5
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Amazon Bedrock AgentCore
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Amazon Bedrock AgentCore
Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and foundation model.Source 1 Its modular services, usable together or independently, include a serverless Runtime for hosting agents, Gateway, Identity, Policy, Observability, and AWS Agent Registry.Source 1, Source 5, Source 7, Source 8, Source 16, Source 17
The differences that matter
What each one catalogs
Amazon Bedrock AgentCoreAWS Agent Registry catalogs agents, MCP servers, tools, and skills; consumers see only records approved through its workflow.Source 5, Source 18
Cloudflare MCP server portalsAdmins add MCP servers to Cloudflare Access, up to 80 per portal; a portal shows each user only servers whose Allow policy they match.Source 3
With AWS Organizations, AWS Agent Registry can create records for Runtimes and Gateways it detects in member accounts.Source 19 A portal’s MCP clients can list available servers with a built-in tool.Source 3
Identity and access for agents
Amazon Bedrock AgentCoreAgent identities are workload identities; Runtime and Gateway can accept JWTs from any OAuth 2.0 identity provider, and Policy can check each Gateway request.Source 8, Source 16, Source 20
Cloudflare MCP server portalsPeople sign in through their identity provider; autonomous agents can use an Access service token, authorized at the portal and for each server.Source 3, Source 12
Upstream, AgentCore Gateway handles outbound authentication to tools.Source 7 A portal attaches each server’s credentials, and service token sessions use that server’s admin credential.Source 3
How each one is priced
Amazon Bedrock AgentCoreConsumption-based per service, with no upfront commitment or minimum fee; Gateway calls such as InvokeTool are $0.005 per 1,000.Source 13
Cloudflare MCP server portalsCloudflare says MCP server portals are available to all Cloudflare customers.Source 14 A separate price for portals is not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Amazon Bedrock AgentCore | Cloudflare MCP server portals | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | AWS’s platform for building, deploying, and operating agents with any framework and model, for moving agents from proof of concept to production.Source 1, Source 24 | Cloudflare says portals are part of Cloudflare One, its SASE platform.Source 2 A portal puts multiple MCP servers behind one HTTP endpoint, governed through Access.Source 3, Source 4 |
| Maturity | Generally available since October 2025.Source 15 Policy GA since March 2026; AWS Agent Registry GA since August 2026.Source 15 | Generally available since 24 September 2026, after an open beta announced on 26 August 2025.Source 14, Source 32 Earlier called Agents Gateway in some contexts.Source 3 |
| Control | ||
| Agent registry and discovery | AWS Agent Registry catalogs agents, MCP servers, tools, and skills, on AWS or elsewhere, behind an approval workflow.Source 1, Source 5 Consumers see only approved records.Source 18 | Admins add MCP servers to Access, up to 80 per portal; portals show users only servers whose Allow policy they match.Source 3 Agent registry: not publicly documented. |
| Identity and access control | Agent identities are workload identities.Source 8 Runtime defaults to IAM SigV4; Runtime and Gateway can validate JWTs from any OAuth 2.0 identity provider.Source 20, Source 23 | Sign-in through Access with an identity provider, or an Access service token.Source 3, Source 12 Policies can match emails, groups, country, and device posture.Source 3 |
| Ownership, policy, and revocation | Gateway policies in natural language or Cedar set which tools an agent may call and when.Source 16 Curators can deprecate registry records to remove them from discovery.Source 19 | Admins pick each portal’s tools and prompt templates; turned-off tools can’t be called through it.Source 3 Access can auto-disable or delete unused service tokens.Source 26 |
| Audit log and observability | Metrics, spans, and logs go to CloudWatch.Source 17 CloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.Source 19, Source 27, Source 28 | Access logs individual tool requests, viewable per portal or server.Source 3 Exported logs record the user’s email and tool called; Logpush export is Enterprise only.Source 3, Source 33 |
| Connection | ||
| How agents connect | Agents can run in Runtime, or elsewhere behind a Gateway that forwards to their endpoint URL.Source 1, Source 9 Outbound-only agent connections: not publicly documented. | MCP clients connect to the portal’s HTTPS URL, and it proxies each tool call.Source 3 Private servers need Gateway routing and Cloudflare Tunnel or another connector.Source 3 |
| Agents across organizations | Registries can be shared with other AWS accounts through AWS RAM to discover, publish, or administer.Source 10 Runtime agents can be opened to other accounts.Source 25 | Cloudflare One can use several identity providers at once when working with partners.Source 34 Federating another organization’s agents: not publicly documented. |
| Protocol support | Runtime agents can serve HTTP, MCP, A2A, or AG-UI.Source 35 Gateway supports MCP 2026-07-28, 2025-11-25, 2025-06-18, and 2025-03-26 for MCP server targets.Source 36 | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 3 A2A support: not publicly documented. |
| Frameworks, models, and clouds supported | Runtime works with CrewAI, LangGraph, LlamaIndex, Google ADK, OpenAI Agents SDK, Strands Agents, and custom frameworks; Identity covers self-hosted agents.Source 1, Source 11 | MCP clients that support remote servers can connect.Source 3 Stdio-only servers can’t be added, and some servers reject proxy-based clients like portals.Source 3 |
| Operations | ||
| Deployment options and data residency | AWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.Source 1, Source 37 | A portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.Source 3 Self-hosting a portal: not publicly documented. |
| Compliance attestations | AWS lists AgentCore as FedRAMP (Class C and Class D) compliant.Source 29, Source 30 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.Source 15, Source 29 | Super Administrators can get Cloudflare’s PCI, SOC 2, ISO, and other documents in the dashboard.Source 31 Their scope for portals is not publicly documented. |
| Support and SLA | AWS says the Amazon Bedrock SLA applies to AgentCore.Source 24 Basic Support is included for all AWS customers.Source 38 | Support options vary by Zero Trust plan; professional services are Contract add-ons.Source 39 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.Source 39 |
| Time and effort to get running | The quickstart needs an AWS account with credentials, plus Node.js 20 or later for the AgentCore CLI.Source 40 It scaffolds, tests, and deploys one agent.Source 40 | Needs a domain on Cloudflare and an identity provider in Zero Trust.Source 3 Then add MCP servers, create a portal with tools and policies, and connect clients.Source 3 |
| Pricing model and public prices | Consumption-based per service, no minimum fee.Source 13 Gateway: $0.005 per 1,000 calls such as InvokeTool.Source 13 Registry: 5,000 records free monthly, then $0.400 per 1,000.Source 13 | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 14 A separate price for portals is not publicly documented. |
| Building | ||
| Agent building tools | Write the agent loop in Python with a framework such as Strands, LangGraph, or Google ADK and deploy it to Runtime, or use the managed Harness.Source 1, Source 40 | Separately from portals, Cloudflare’s Agents docs cover building and hosting agents, and remote MCP servers can be built on Workers.Source 4, Source 41 |
| Model access | Model-agnostic, AWS says: foundation models in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral.Source 24 | Not publicly documented for portals. Cloudflare’s separate Agents SDK has Workers AI built in and works with OpenAI, Anthropic, and Google Gemini.Source 42 |
| Integrations and ecosystem | Gateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import AWS Partner tools bought in AWS Marketplace.Source 7, Source 24 | Portals can be managed with Terraform.Source 3 Cloudflare One supports social, open source, and corporate identity providers.Source 34 Marketplace: not publicly documented. |
Which to choose
Choose Amazon Bedrock AgentCore if
- You want to build, host, and operate agents on one platform, with any framework and foundation model.Source 1
- You need a catalog of agents as well as tools, where only records approved through a workflow are discoverable.Source 5
- You want agent identities built on workload identities, with Cedar or natural-language policies checking tool calls through Gateway.Source 8, Source 16
- Your teams span AWS accounts: a registry shared through AWS RAM lets other accounts discover, publish, or administer records.Source 10
Choose Cloudflare MCP server portals if
- You want one governed URL for your MCP servers, with Access policies on email, group, country, and device posture.Source 3
- You run Cloudflare One: Cloudflare says portals are part of it, and they use your Zero Trust identity provider.Source 2, Source 3
- Your MCP servers are private: portals can reach them through outbound-only Cloudflare Tunnel, with Gateway routing turned on.Source 3, Source 22, Source 43
- You want tool-level control: admins pick each portal’s tools and prompt templates, and Access logs individual tool requests.Source 3
Questions buyers ask
Does either one keep a registry of agents?
AgentCore does: AWS Agent Registry catalogs agents, MCP servers, tools, and skills, including ones hosted outside AWS.Source 1, Source 5 Admins add MCP servers to Cloudflare Access, and a portal lists the ones available to each user; a registry of agents is not publicly documented for portals.Source 3
Do they support MCP and A2A?
How is each one priced?
Can either one connect agents across organizations?
AgentCore works across AWS accounts: registries can be shared through AWS RAM, even outside your AWS Organization, and Runtime agents can be opened to other accounts.Source 10, Source 25 Cloudflare One can use several identity providers at once for partners; federating another organization’s agents is not publicly documented.Source 34
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
51 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) Back:abcdefghijklmnopq
Source 2: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abcde
Source 3: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz27282930313233343536373839404142434445
Source 4: MCP governance · Cloudflare Agents docs Back:abcde
Source 5: AWS Agent Registry: Discover and manage agents, tools, and resources Back:abcdefghi
Source 6: Supported targets for Amazon Bedrock AgentCore gateways Back to text
Source 7: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models Back:abcd
Source 8: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity Back:abcdefg
Source 9: HTTP passthrough targets - AgentCore Gateway Back:abc
Source 10: Sharing a registry across accounts with AWS RAM Back:abcde
Source 12: Service token support for MCP server portals · Changelog Back:abcd
Source 14: MCP server portals are now generally available · Changelog Back:abcdef
Source 15: Release notes - Amazon Bedrock AgentCore Back:abcd
Source 16: Policy in Amazon Bedrock AgentCore: Control Agent Interactions Back:abcde
Source 17: Observe your agent applications on Amazon Bedrock AgentCore Observability Back:ab
Source 18: Concepts and terminology - AWS Agent Registry Back:ab
Source 21: Connect to private resources in your VPC using VPC Lattice Back to text
Source 23: Authenticate and authorize with Inbound Auth and Outbound Auth Back:ab
Source 25: Resource-based policies for Amazon Bedrock AgentCore Back:abc
Source 27: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail Back:ab
Source 28: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore Back:ab
Source 29: Compliance validation for Amazon Bedrock AgentCore Back:abc
Source 30: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services Back:ab
Source 31: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 33: MCP Portal Logs · Cloudflare Logs docs Back to text
Source 34: Identity providers · Cloudflare One docs Back:abc
Source 35: Understand the AgentCore Runtime service contract Back:ab
Source 37: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations Back to text
Source 39: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 40: Get started with Amazon Bedrock AgentCore Back:abc
Source 41: Build Agents on Cloudflare · Cloudflare Agents docs Back to text
Source 42: Using AI Models · Cloudflare Agents docs Back to text
Source 43: Private MCP server support for MCP server portals · Changelog Back to text
Source 44: Deploy A2A servers in AgentCore Runtime Back to text