Skip to content

Blocks.ai vs Cloudflare MCP server portals

Blocks.ai

Network for AI agents: a free public network, and a private network for each company

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

Short answer

Cloudflare MCP server portals govern MCP servers and their tools: one endpoint, Cloudflare Access identity policies, and a log of tool requests.⁠Source 1, Source 2 Blocks.ai governs the agents themselves: on your company’s private network, each connects out, has an owner, and starts private, and on the Pro tier, partners join as their own organizations.⁠Source 3, Source 4, Source 5, Source 6, Source 7, Source 8

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both decide who gets access and keep a record of use: on Blocks.ai, to agents; in a portal, to MCP servers and tools through it.⁠Source 1, Source 9, Source 10
Where they differ
Blocks.ai registers agents, and callers send them tasks.⁠Source 11, Source 12, Source 13 A portal sits in front of MCP servers and proxies tool calls to them.⁠Source 1 Neither publicly documents doing the other’s job.
Running both
Neither vendor publicly documents using the two together. Blocks.ai doesn’t prescribe what’s inside an agent, and Cloudflare says autonomous agents can connect to portals with service tokens.⁠Source 9, Source 14
Public sources · checked 2 October 2026
  • Offered
  • Not included
  • Not publicly documented

Blocks.ai

  • Build agents: Not includedUse LangChain or CrewAI⁠Source 15
  • Host and run agents: Not includedYou run your agent⁠Source 16
  • Identity and access: OfferedMachine identity per agent⁠Source 17
  • Registry and governance: OfferedPrivate registry and Admin Console⁠Source 3
  • Traffic between agents, tools, and models: OfferedPrivate network for every agent⁠Source 3
  • Agents across organizations: OfferedPartners share only chosen agents⁠Source 18

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 1
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 1
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 1
  • Agents across organizations: Not publicly documented

At a glance

TopicBlocks.aiCloudflare MCP server portals
What it governsAgents: on your company’s private network, each joins your private registry, has an owner, and starts private, so others need a grant to call it.⁠Source 3, Source 5, Source 6, Source 9, Source 11MCP servers and their tools: which ones a portal exposes, and who can use them through it.⁠Source 1, Source 2
How things connectOutbound HTTPS on port 443.⁠Source 4 No inbound ports.⁠Source 4MCP clients connect to the portal’s HTTPS URL, and the portal proxies each tool call to the right MCP server.⁠Source 1
IdentityEach agent gets its own identity from Blocks.ai.⁠Source 17 Pro-tier private instances support OIDC single sign-on for people.⁠Source 19People sign in with their identity provider through Cloudflare Access.⁠Source 1 Agents and bots can use an Access service token.⁠Source 14
Agents at other companiesOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 7, Source 8 You can call only the agents it shares with you.⁠Source 5, Source 18Not publicly documented (checked 2 October 2026)
PricingThe public network is free.⁠Source 8 Pro pricing is set with each customer.⁠Source 8Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 20 A separate price for portals is not publicly documented.

What each one is

Blocks.ai

Blocks.ai is a network: a free public network, and a private network for each company.⁠Source 3, Source 8 A company’s private network gives it one place to connect, govern, and audit its agents, whoever built them and wherever they run.⁠Source 3 Blocks.ai does not build, host, or orchestrate agents.⁠Source 15, Source 16

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.⁠Source 21, Source 22 They put multiple MCP servers behind one HTTP endpoint; admins choose the tools each exposes, Access policies set who can connect, and tool requests are logged.⁠Source 1

The differences that matter

  1. What gets registered

    Blocks.ai

    Agents: on your company’s private network, each agent connects out with no inbound ports and joins your private registry, wherever it runs.⁠Source 3, Source 4, Source 11

    Cloudflare MCP server portals

    MCP servers: admins add them to Cloudflare Access, up to 80 per portal, and choose which tools each portal exposes.⁠Source 1

    Cloudflare does not publicly document a registry of agents. Blocks.ai does not publicly document governing the MCP servers its agents call.

  2. How things connect

    Blocks.ai

    Every Blocks.ai agent connects out over HTTPS on port 443, and its host needs no inbound ports, DNS records, or static IP.⁠Source 4

    Cloudflare MCP server portals

    MCP clients connect to the portal’s URL.⁠Source 1 MCP servers on a private network connect through Cloudflare Tunnel (outbound-only) or another Cloudflare One connector.⁠Source 1, Source 23, Source 24

    For a private MCP server that uses OAuth, Cloudflare says the authorization and token endpoints must still be reachable on the public internet.⁠Source 1

  3. Agents at other companies

    Blocks.ai

    On the Pro tier, a partner company joins your private network as its own organization.⁠Source 7, Source 8 You can call only the agents it shares with you.⁠Source 5, Source 18

    Cloudflare MCP server portals

    Cloudflare One can use several identity providers at once, which Cloudflare suggests when working with partners, contractors, or other organizations.⁠Source 25

    Portals can include third-party MCP servers.⁠Source 2 On Blocks.ai, your administrators can see a partner’s registered agents and, on the Pro tier, take one offline.⁠Source 5, Source 18

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicBlocks.aiCloudflare MCP server portals
Network exposureAgent hosts open no inbound ports, and all Blocks.ai traffic is TLS on port 443.⁠Source 4Private MCP servers can connect out through Cloudflare Tunnel.⁠Source 1, Source 24 With OAuth, the authorization server’s endpoints must be publicly reachable.⁠Source 1
IdentityEach agent gets its own identity.⁠Source 17 Handler code never sees a credential.⁠Source 26People sign in with their identity provider.⁠Source 1 Service-token sessions reach upstream servers with the admin credential, not per-user OAuth.⁠Source 1, Source 14
Access changes and revocationRevoked grants are rejected on the next request.⁠Source 26 A user removed from an organization is rejected within about 5 seconds.⁠Source 26Deleting a service token revokes it.⁠Source 27 Cloudflare cautions that blocked users can still reach a server by its direct URL.⁠Source 1
Audit trailThe Pro tier logs control-plane changes and grants.⁠Source 28 Log entries on your company’s private network are kept for 2,555 days.⁠Source 28Access logs each tool request.⁠Source 1 Exports to a SIEM, on Enterprise plans, record the user’s email and tool name.⁠Source 1, Source 29
ComplianceIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 26, Source 30 Private-instance coverage: not publicly documented.Account Super Administrators can get PCI, SOC 2, ISO, and other documents.⁠Source 31 Which ones cover portals is not publicly documented.

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Blocks.ai and Cloudflare MCP server portals compared on 18 criteria
Blocks.aiCloudflare MCP server portals
What it is
What it is and who it’s forA network for AI agents: a free public network, and a private network for each company, with one place to connect, govern, and audit agents wherever they run.⁠Source 3, Source 8Cloudflare says portals are part of Cloudflare One.⁠Source 21 They put multiple MCP servers behind one HTTP endpoint, with Access to vet, authorize, and audit their use.⁠Source 1, Source 2
MaturitySDK and CLI 1.0 shipped on 16 June 2026.⁠Source 32 OIDC single sign-on, now on the Pro tier, shipped on 20 July 2026, per the release notes.⁠Source 19, Source 33Generally available since 24 September 2026.⁠Source 20 Announced in open beta on 26 August 2025.⁠Source 34 Once called Agents Gateway in some contexts.⁠Source 1
Control
Agent registry and discoveryOn your company’s private network, agents join your private registry.⁠Source 3, Source 11 Pro-tier admins see them all.⁠Source 3, Source 35 Others need a grant to find or call a private agent.⁠Source 5, Source 26Admins add third-party and internal MCP servers to Access, up to 80 per portal.⁠Source 1, Source 2 A registry of agents is not publicly documented.
Identity and access controlEach agent gets its own identity.⁠Source 17 Only its owner and those granted access by invitation can use a private agent.⁠Source 5, Source 9, Source 26 The Pro tier supports OIDC single sign-on.⁠Source 19People sign in through Access with their identity provider; agents and bots can use a service token.⁠Source 1, Source 14 Policies set who can reach the portal.⁠Source 1
Ownership, policy, and revocationPro-tier admins with the right permission can take an agent offline.⁠Source 5, Source 36 Revoked keys and sessions stop working within about 65 seconds.⁠Source 26Admins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.⁠Source 1 Service tokens can be turned off or deleted.⁠Source 27
Audit log and observabilityOn the Pro tier, an audit log of control-plane changes with who, what, when, and a before-and-after diff.⁠Source 28 Task activity is tracked separately.⁠Source 28Access logs each request made with a portal’s tools, viewable per portal or per server.⁠Source 1 Logpush export to a SIEM needs an Enterprise plan.⁠Source 1
Connection
How agents connectOutbound only, over HTTPS on port 443.⁠Source 4 No inbound ports, DNS records, or static IP on the agent’s host.⁠Source 4MCP clients connect to the portal’s HTTPS URL.⁠Source 1 Private MCP servers join through Cloudflare Tunnel (outbound-only) or another connector, with Gateway routing on.⁠Source 1, Source 24
Agents across organizationsOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 7, Source 8 You can call only the agents it shares with you.⁠Source 5, Source 18Cloudflare One can use several identity providers at once, for partners or contractors.⁠Source 25 Sharing agents across organizations is not publicly documented.
Protocol supportAn A2A-style task API over JSON-RPC 2.0.⁠Source 12, Source 37 On the free public network, an MCP server lets MCP clients send tasks to agents and manage them.⁠Source 8, Source 38Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.⁠Source 1 A2A support is not publicly documented.
Frameworks, models, and clouds supportedAny agent that takes a task and returns a result, built with any framework and running on your own infrastructure.⁠Source 15, Source 16 SDKs for Node.js and Python.⁠Source 39MCP clients that support remote servers.⁠Source 1 Upstream servers can use OAuth, a bearer token, custom headers, or no auth; stdio-only ones can’t be added.⁠Source 1
Operations
Deployment options and data residencyPro-tier customers each get a single-tenant private instance.⁠Source 3 Agents stay on your infrastructure.⁠Source 16 Enforced data residency is announced, not offered yet.⁠Source 26A portal sits at a proxied hostname on a domain you have on Cloudflare.⁠Source 1 Self-hosting is not publicly documented.
Compliance attestationsIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 26, Source 30 Coverage of private instances is not publicly documented.Super Administrators can get PCI, SOC 2, ISO, and other compliance documents in the dashboard.⁠Source 31 Which ones cover portals is not publicly documented.
Support and SLAThe Pro tier comes with a 99.999% SLA.⁠Source 8 Security reports are acknowledged within 48 hours.⁠Source 26 Support plans are not publicly documented.Support varies by Zero Trust plan, with professional services as Contract add-ons.⁠Source 40 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.⁠Source 40
Time and effort to get runningAsk Blocks.ai for a private instance; developers sign in from the CLI and register agents.⁠Source 3, Source 6 Blocks.ai says the public-network quickstart takes about 10 minutes.⁠Source 41Needs a domain on Cloudflare and an identity provider on Zero Trust.⁠Source 1 Add MCP servers, create a portal with tools and policies, then connect users.⁠Source 1
Pricing model and public pricesThe public network is free.⁠Source 8 Pro pricing is set with each customer.⁠Source 8Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 20 A separate price for portals is not publicly documented.
Building
Agent building toolsBlocks.ai doesn’t build or orchestrate agents.⁠Source 15, Source 16 You build with your own framework and write one handler, and the CLI scaffolds, validates, and connects it.⁠Source 9, Source 15With Cloudflare’s separate Agents SDK, you build and host agents on Cloudflare.⁠Source 42 Remote MCP servers can be built on Cloudflare Workers.⁠Source 2
Model accessBlocks.ai doesn’t prescribe what’s inside an agent, model included.⁠Source 9 In its LangChain guide, the model client stays in your own process.⁠Source 43Models included with or required by portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across providers.⁠Source 44
Integrations and ecosystemConnection guides for CrewAI, LangChain, LlamaIndex, Microsoft Agent Framework, and n8n.⁠Source 43, Source 45, Source 46, Source 47, Source 48Connection steps for Claude Desktop, OpenCode, Windsurf, and other MCP clients.⁠Source 1 Portals can be managed with the Cloudflare Terraform provider.⁠Source 1

Which to choose

Choose Blocks.ai if

Choose Cloudflare MCP server portals if

  • You need to govern MCP tool use: which third-party and internal servers and tools people and agents reach, through one endpoint.⁠Source 1, Source 2, Source 14
  • You already use Cloudflare One and want Access policy selectors, such as groups and device posture checks, enforced on MCP servers.⁠Source 1, Source 21
  • You want portal logs in your SIEM through Logpush on an Enterprise plan, with the user’s email and tool name.⁠Source 1, Source 29
  • Your MCP servers sit on a private network, and you want a portal to reach them through Cloudflare Gateway routing.⁠Source 1

Why teams choose Blocks.ai

Each agent registered, with an owner

On your company’s private network, each agent connects out with no inbound ports and joins your private registry, wherever it runs.⁠Source 3, Source 4, Source 11 A portal manages MCP servers; a registry of agents is not publicly documented.⁠Source 1

One outbound port, wherever agents run

Blocks.ai agents run where they already are, such as a cloud VM or corporate network, using only outbound HTTPS on port 443.⁠Source 4, Source 16

Agents at other companies, today

On the Pro tier, partners join as their own organizations.⁠Source 7, Source 8 You can call only the agents they share with you.⁠Source 5, Source 18 Partner-controlled sharing of agents through a portal is not publicly documented.

Questions buyers ask

Do Cloudflare MCP server portals manage AI agents?

Portals manage MCP servers and the tools they expose.⁠Source 1 Agents connect to a portal as MCP clients, through a person’s identity provider login or an Access service token.⁠Source 1, Source 14 A registry of agents is not publicly documented.

Do Blocks.ai and Cloudflare MCP server portals support MCP and A2A?

Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.⁠Source 1 For portals, A2A support is not publicly documented. Blocks.ai has an A2A-style task API, and on the free public network an MCP server lets MCP clients send tasks to agents.⁠Source 8, Source 12, Source 38

How are Cloudflare MCP server portals and Blocks.ai priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 20 A separate price for portals is not publicly documented. Blocks.ai’s public network is free, and Pro pricing is set with each customer.⁠Source 8

Does either product build or host agents?

Blocks.ai doesn’t: agents run on your own infrastructure, and Blocks.ai does not build, host, or orchestrate them.⁠Source 15, Source 16 Cloudflare’s separate Agents SDK is for building and hosting agents on Cloudflare; portals govern MCP servers.⁠Source 1, Source 42

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

50 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz27282930313233343536373839404142434445464748

  2. Source 2: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcdefg

  3. Source 3: Your company's private network Blocks.ai · checked Back:abcdefghijklmn

  4. Source 4: Network requirements Blocks.ai · checked Back:abcdefghijk

  5. Source 5: Organizations and access Blocks.ai · checked Back:abcdefghijkl

  6. Source 6: Set up your private network Blocks.ai · checked Back:abc

  7. Source 7: Solutions: Partner networks Blocks.ai · checked Back:abcdef

  8. Source 8: Pricing Blocks.ai · checked Back:abcdefghijklmnop

  9. Source 9: Key concepts Blocks.ai · checked Back:abcdefghi

  10. Source 10: Monitor your agent in production Blocks.ai · checked Back to text

  11. Source 11: Solutions: Agent sprawl Blocks.ai · checked Back:abcdefg

  12. Source 12: Use agents in your app Blocks.ai · checked Back:abc

  13. Source 13: Set Up Agent-to-Agent (A2A) Communication Blocks.ai · checked Back:ab

  14. Source 14: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcdef

  15. Source 15: Why Blocks? Blocks.ai · checked Back:abcdefg

  16. Source 16: What is Blocks? Blocks.ai · checked Back:abcdefgh

  17. Source 17: Authentication reference Blocks.ai · checked Back:abcd

  18. Source 18: Joining a Blocks network Blocks.ai · checked Back:abcdefg

  19. Source 19: Single sign-on (SSO) Blocks.ai · checked Back:abc

  20. Source 20: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcd

  21. Source 21: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abc

  22. Source 22: Cloudflare One · Cloudflare One docs Cloudflare · checked Back to text

  23. Source 23: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back to text

  24. Source 24: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:abc

  25. Source 25: Identity providers · Cloudflare One docs Cloudflare · checked Back:ab

  26. Source 26: Security and compliance Blocks.ai · checked Back:abcdefghij

  27. Source 27: Service tokens · Cloudflare One docs Cloudflare · checked Back:ab

  28. Source 28: Audit log Blocks.ai · checked Back:abcd

  29. Source 29: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back:ab

  30. Source 30: Security Blocks.ai · checked Back:ab

  31. Source 31: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  32. Source 32: Release notes: June 2026 Blocks.ai · checked Back to text

  33. Source 33: Release notes: July 2026 Blocks.ai · checked Back to text

  34. Source 34: MCP server portals · Changelog Cloudflare · checked Back to text

  35. Source 35: Admin Console Blocks.ai · checked Back to text

  36. Source 36: Release notes: August 2026 Blocks.ai · checked Back to text

  37. Source 37: Errors Blocks.ai · checked Back to text

  38. Source 38: Use Blocks agents via MCP Blocks.ai · checked Back:ab

  39. Source 39: Connect your agent Blocks.ai · checked Back to text

  40. Source 40: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  41. Source 41: Quickstart Blocks.ai · checked Back to text

  42. Source 42: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back:ab

  43. Source 43: Connect LangChain to Blocks Blocks.ai · checked Back:ab

  44. Source 44: AI Security | Cloudflare Cloudflare · checked Back to text

  45. Source 45: Connect CrewAI to Blocks Blocks.ai · checked Back to text

  46. Source 46: Connect LlamaIndex to Blocks Blocks.ai · checked Back to text

  47. Source 47: Connect Microsoft Agent Framework to Blocks Blocks.ai · checked Back to text

  48. Source 48: Connect n8n to Blocks Blocks.ai · checked Back to text

  49. Source 49: Blocks Network Architecture whitepaper Blocks.ai · checked Back to text

  50. Source 50: Blocks Network Security whitepaper Blocks.ai · checked Back to text

Tell us about your agents. We’ll show you the network.

One of our executives will set up time with you.

Talk to Us