Blocks.ai vs Cloudflare MCP server portals
Blocks.ai
Network for AI agents: a free public network, and a private network for each company
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Short answer
Cloudflare MCP server portals govern MCP servers and their tools: one endpoint, Cloudflare Access identity policies, and a log of tool requests.Source 1, Source 2 Blocks.ai governs the agents themselves: on your company’s private network, each connects out, has an owner, and starts private, and on the Pro tier, partners join as their own organizations.Source 3, Source 4, Source 5, Source 6, Source 7, Source 8
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Blocks.ai
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Blocks.ai
Blocks.ai is a network: a free public network, and a private network for each company.Source 3, Source 8 A company’s private network gives it one place to connect, govern, and audit its agents, whoever built them and wherever they run.Source 3 Blocks.ai does not build, host, or orchestrate agents.Source 15, Source 16
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.Source 21, Source 22 They put multiple MCP servers behind one HTTP endpoint; admins choose the tools each exposes, Access policies set who can connect, and tool requests are logged.Source 1
The differences that matter
What gets registered
Blocks.aiAgents: on your company’s private network, each agent connects out with no inbound ports and joins your private registry, wherever it runs.Source 3, Source 4, Source 11
Cloudflare MCP server portalsMCP servers: admins add them to Cloudflare Access, up to 80 per portal, and choose which tools each portal exposes.Source 1
Cloudflare does not publicly document a registry of agents. Blocks.ai does not publicly document governing the MCP servers its agents call.
How things connect
Blocks.aiEvery Blocks.ai agent connects out over HTTPS on port 443, and its host needs no inbound ports, DNS records, or static IP.Source 4
Cloudflare MCP server portalsMCP clients connect to the portal’s URL.Source 1 MCP servers on a private network connect through Cloudflare Tunnel (outbound-only) or another Cloudflare One connector.Source 1, Source 23, Source 24
For a private MCP server that uses OAuth, Cloudflare says the authorization and token endpoints must still be reachable on the public internet.Source 1
Agents at other companies
Blocks.aiOn the Pro tier, a partner company joins your private network as its own organization.Source 7, Source 8 You can call only the agents it shares with you.Source 5, Source 18
Cloudflare MCP server portalsCloudflare One can use several identity providers at once, which Cloudflare suggests when working with partners, contractors, or other organizations.Source 25
Portals can include third-party MCP servers.Source 2 On Blocks.ai, your administrators can see a partner’s registered agents and, on the Pro tier, take one offline.Source 5, Source 18
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Blocks.ai | Cloudflare MCP server portals | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | A network for AI agents: a free public network, and a private network for each company, with one place to connect, govern, and audit agents wherever they run.Source 3, Source 8 | Cloudflare says portals are part of Cloudflare One.Source 21 They put multiple MCP servers behind one HTTP endpoint, with Access to vet, authorize, and audit their use.Source 1, Source 2 |
| Maturity | SDK and CLI 1.0 shipped on 16 June 2026.Source 32 OIDC single sign-on, now on the Pro tier, shipped on 20 July 2026, per the release notes.Source 19, Source 33 | Generally available since 24 September 2026.Source 20 Announced in open beta on 26 August 2025.Source 34 Once called Agents Gateway in some contexts.Source 1 |
| Control | ||
| Agent registry and discovery | On your company’s private network, agents join your private registry.Source 3, Source 11 Pro-tier admins see them all.Source 3, Source 35 Others need a grant to find or call a private agent.Source 5, Source 26 | Admins add third-party and internal MCP servers to Access, up to 80 per portal.Source 1, Source 2 A registry of agents is not publicly documented. |
| Identity and access control | Each agent gets its own identity.Source 17 Only its owner and those granted access by invitation can use a private agent.Source 5, Source 9, Source 26 The Pro tier supports OIDC single sign-on.Source 19 | People sign in through Access with their identity provider; agents and bots can use a service token.Source 1, Source 14 Policies set who can reach the portal.Source 1 |
| Ownership, policy, and revocation | Pro-tier admins with the right permission can take an agent offline.Source 5, Source 36 Revoked keys and sessions stop working within about 65 seconds.Source 26 | Admins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.Source 1 Service tokens can be turned off or deleted.Source 27 |
| Audit log and observability | On the Pro tier, an audit log of control-plane changes with who, what, when, and a before-and-after diff.Source 28 Task activity is tracked separately.Source 28 | Access logs each request made with a portal’s tools, viewable per portal or per server.Source 1 Logpush export to a SIEM needs an Enterprise plan.Source 1 |
| Connection | ||
| How agents connect | Outbound only, over HTTPS on port 443.Source 4 No inbound ports, DNS records, or static IP on the agent’s host.Source 4 | MCP clients connect to the portal’s HTTPS URL.Source 1 Private MCP servers join through Cloudflare Tunnel (outbound-only) or another connector, with Gateway routing on.Source 1, Source 24 |
| Agents across organizations | On the Pro tier, a partner company joins your private network as its own organization.Source 7, Source 8 You can call only the agents it shares with you.Source 5, Source 18 | Cloudflare One can use several identity providers at once, for partners or contractors.Source 25 Sharing agents across organizations is not publicly documented. |
| Protocol support | An A2A-style task API over JSON-RPC 2.0.Source 12, Source 37 On the free public network, an MCP server lets MCP clients send tasks to agents and manage them.Source 8, Source 38 | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.Source 1 A2A support is not publicly documented. |
| Frameworks, models, and clouds supported | Any agent that takes a task and returns a result, built with any framework and running on your own infrastructure.Source 15, Source 16 SDKs for Node.js and Python.Source 39 | MCP clients that support remote servers.Source 1 Upstream servers can use OAuth, a bearer token, custom headers, or no auth; stdio-only ones can’t be added.Source 1 |
| Operations | ||
| Deployment options and data residency | Pro-tier customers each get a single-tenant private instance.Source 3 Agents stay on your infrastructure.Source 16 Enforced data residency is announced, not offered yet.Source 26 | A portal sits at a proxied hostname on a domain you have on Cloudflare.Source 1 Self-hosting is not publicly documented. |
| Compliance attestations | In scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.Source 26, Source 30 Coverage of private instances is not publicly documented. | Super Administrators can get PCI, SOC 2, ISO, and other compliance documents in the dashboard.Source 31 Which ones cover portals is not publicly documented. |
| Support and SLA | The Pro tier comes with a 99.999% SLA.Source 8 Security reports are acknowledged within 48 hours.Source 26 Support plans are not publicly documented. | Support varies by Zero Trust plan, with professional services as Contract add-ons.Source 40 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.Source 40 |
| Time and effort to get running | Ask Blocks.ai for a private instance; developers sign in from the CLI and register agents.Source 3, Source 6 Blocks.ai says the public-network quickstart takes about 10 minutes.Source 41 | Needs a domain on Cloudflare and an identity provider on Zero Trust.Source 1 Add MCP servers, create a portal with tools and policies, then connect users.Source 1 |
| Pricing model and public prices | The public network is free.Source 8 Pro pricing is set with each customer.Source 8 | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 20 A separate price for portals is not publicly documented. |
| Building | ||
| Agent building tools | Blocks.ai doesn’t build or orchestrate agents.Source 15, Source 16 You build with your own framework and write one handler, and the CLI scaffolds, validates, and connects it.Source 9, Source 15 | With Cloudflare’s separate Agents SDK, you build and host agents on Cloudflare.Source 42 Remote MCP servers can be built on Cloudflare Workers.Source 2 |
| Model access | Blocks.ai doesn’t prescribe what’s inside an agent, model included.Source 9 In its LangChain guide, the model client stays in your own process.Source 43 | Models included with or required by portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across providers.Source 44 |
| Integrations and ecosystem | Connection guides for CrewAI, LangChain, LlamaIndex, Microsoft Agent Framework, and n8n.Source 43, Source 45, Source 46, Source 47, Source 48 | Connection steps for Claude Desktop, OpenCode, Windsurf, and other MCP clients.Source 1 Portals can be managed with the Cloudflare Terraform provider.Source 1 |
Which to choose
Choose Blocks.ai if
- You need to govern the agents themselves: register each one, give it an owner, and decide who can call it.Source 5, Source 9, Source 11
- You want partners to join as their own organizations on the Pro tier, and your side to call only what each shares.Source 5, Source 7, Source 8, Source 18
- People and other agents must call your agents where they run, behind firewalls or proxies with no inbound ports.Source 4, Source 9, Source 13, Source 16, Source 49
- You want agents from many frameworks, models, and clouds in your private registry, on your company’s private network, without re-platforming.Source 3, Source 9, Source 11, Source 15
Choose Cloudflare MCP server portals if
- You need to govern MCP tool use: which third-party and internal servers and tools people and agents reach, through one endpoint.Source 1, Source 2, Source 14
- You already use Cloudflare One and want Access policy selectors, such as groups and device posture checks, enforced on MCP servers.Source 1, Source 21
- You want portal logs in your SIEM through Logpush on an Enterprise plan, with the user’s email and tool name.Source 1, Source 29
- Your MCP servers sit on a private network, and you want a portal to reach them through Cloudflare Gateway routing.Source 1
Why teams choose Blocks.ai
Each agent registered, with an owner
On your company’s private network, each agent connects out with no inbound ports and joins your private registry, wherever it runs.Source 3, Source 4, Source 11 A portal manages MCP servers; a registry of agents is not publicly documented.Source 1
One outbound port, wherever agents run
Blocks.ai agents run where they already are, such as a cloud VM or corporate network, using only outbound HTTPS on port 443.Source 4, Source 16
Questions buyers ask
Do Cloudflare MCP server portals manage AI agents?
Do Blocks.ai and Cloudflare MCP server portals support MCP and A2A?
Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.Source 1 For portals, A2A support is not publicly documented. Blocks.ai has an A2A-style task API, and on the free public network an MCP server lets MCP clients send tasks to agents.Source 8, Source 12, Source 38
How are Cloudflare MCP server portals and Blocks.ai priced?
Does either product build or host agents?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
50 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz27282930313233343536373839404142434445464748
Source 2: MCP governance · Cloudflare Agents docs Back:abcdefg
Source 3: Your company's private network Back:abcdefghijklmn
Source 13: Set Up Agent-to-Agent (A2A) Communication Back:ab
Source 14: Service token support for MCP server portals · Changelog Back:abcdef
Source 20: MCP server portals are now generally available · Changelog Back:abcd
Source 21: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abc
Source 22: Cloudflare One · Cloudflare One docs Back to text
Source 23: Private MCP server support for MCP server portals · Changelog Back to text
Source 28: Audit log Back:abcd
Source 30: Security Back:ab
Source 31: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 40: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 42: Build Agents on Cloudflare · Cloudflare Agents docs Back:ab
Source 47: Connect Microsoft Agent Framework to Blocks Back to text
Source 49: Blocks Network Architecture whitepaper Back to text