Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs CrewAI AMP
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
CrewAI AMP
Platform for deploying, monitoring, and scaling CrewAI crews and agents
Short answer
Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; CrewAI AMP is a platform to build, deploy, and run CrewAI crews.Source 1, Source 2, Source 3, Source 4 A portal controls which MCP tools people and agents reach and logs tool requests; AMP runs crews on managed infrastructure and can connect to MCP servers.Source 2, Source 4, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
CrewAI AMP
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.Source 1 A portal gathers several MCP servers behind one HTTP endpoint, applies Cloudflare Access policies to who can connect, and logs each tool request.Source 2 Portals became generally available on 24 September 2026.Source 16
CrewAI AMP
CrewAI AMP (Agent Management Platform) is CrewAI’s platform for deploying, monitoring, and scaling crews and agents in production, extending its open-source framework.Source 4 Teams build crews in code, or in Crew Studio with natural language and a visual workflow editor.Source 4, Source 9
The differences that matter
What each one manages
Cloudflare MCP server portalsMCP servers and their tools: admins add servers, choose the tools and prompt templates each portal exposes, and turned-off tools can’t be called through it.Source 2
CrewAI AMPCrewAI crews and flows: teams build crews in code or Crew Studio and deploy both as automations; Agent Repositories, on both plans, share agent definitions.Source 4, Source 11, Source 13, Source 14
For portals, a registry of agents is not publicly documented. For AMP, a registry that lists agents built outside CrewAI is not publicly documented.
Identity and access
Cloudflare MCP server portalsPeople sign in through Cloudflare Access with their identity provider; autonomous agents can use a service token, whose upstream calls use the admin credential.Source 2, Source 5
CrewAI AMPThe Enterprise plan lists role-based access control, which can make a deployment private to allow-listed users and roles; crew API calls need a bearer token.Source 10, Source 14, Source 15
Cloudflare says a blocked user can reach a server by its direct URL, and advises making Access its OAuth provider.Source 2 A separate identity per AMP agent is not publicly documented.
Where it runs
Cloudflare MCP server portalsA portal’s hostname points to gateway.agents.cloudflare.com.Source 2 Private MCP servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.Source 2, Source 17
CrewAI AMPCrews deploy to managed infrastructure; the Enterprise plan can run on CrewAI cloud, your own VPC, or your own infrastructure.Source 4, Source 14
For portals, self-hosting is not publicly documented. For AMP, data residency commitments are not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | CrewAI AMP | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One, its SASE platform.Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, governed through Access.Source 2, Source 3 | Platform for deploying, monitoring, and scaling CrewAI crews and agents in production, extending CrewAI’s open-source framework.Source 4 |
| Maturity | Generally available since 24 September 2026, after an open beta announced on 26 August 2025.Source 16, Source 27 Once called Agents Gateway in some contexts.Source 2 | CrewAI’s platform took the AMP name in October 2025.Source 28, Source 29 The Platform API is in beta.Source 22 |
| Control | ||
| Agent registry and discovery | Admins add MCP servers to Cloudflare Access for central management, up to 80 per portal.Source 2 A registry of agents is not publicly documented. | Agent Repositories, on both plans, share agent definitions; Automations is the hub for deployed crews.Source 11, Source 14, Source 30 Listing non-CrewAI agents: not publicly documented. |
| Identity and access control | Users sign in through Cloudflare Access with their identity provider.Source 2 Autonomous agents can use an Access service token instead of a browser OAuth flow.Source 5 | The Enterprise plan lists SSO (Microsoft Entra, Okta) and role-based access control, which can make a deployment private to allow-listed users and roles.Source 10, Source 14 |
| Ownership, policy, and revocation | Admins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.Source 2 Service tokens can be turned off or deleted.Source 20 | On Enterprise, custom roles can set most features to Manage, Read, or No access.Source 10, Source 14 Flows can pause for human review.Source 31 Per-agent owners are not publicly documented. |
| Audit log and observability | Access logs each request made with a portal’s tools, viewable per portal or per server.Source 2 Logpush export to storage or a SIEM is Enterprise only.Source 2 | Execution traces from inputs to outputs, with OpenTelemetry export to your own collector.Source 7, Source 24 AMP’s docs don’t describe a platform-wide audit log of admin events. |
| Connection | ||
| How agents connect | MCP clients connect to the portal’s HTTPS URL.Source 2 Private-network servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.Source 2, Source 17 | Crews deploy to managed infrastructure, each crew’s API protected by a bearer token.Source 4, Source 19 Custom MCP servers must be reachable from the internet.Source 6 |
| Agents across organizations | Several identity providers at once, for people at partners or contractors.Source 32 Partner-controlled agents in a portal: not publicly documented. | CrewAI agents can delegate tasks to remote A2A agents by URL.Source 33 Bringing another company’s agents into AMP, with access it controls: not publicly documented. |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 2 A2A support is not publicly documented. | Can connect to external MCP servers and export an automation as MCP.Source 6, Source 30 A2A server agents on AMP are in preview; CrewAI agents can delegate to remote A2A agents.Source 12, Source 33 |
| Frameworks, models, and clouds supported | MCP clients that support remote servers; setup steps cover Claude Desktop, Windsurf, and others.Source 2 Some MCP servers reject proxy-based clients like portals.Source 2 | Deploys CrewAI Crews and Flows as automations.Source 13 AMP’s docs don’t describe deploying agents built with other frameworks. |
| Operations | ||
| Deployment options and data residency | A portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.Source 2 Self-hosting a portal is not publicly documented. | The Enterprise plan can run on CrewAI cloud, your own VPC, or your own infrastructure.Source 14 Data residency commitments are not publicly documented. |
| Compliance attestations | Super Administrators can get Cloudflare’s PCI, SOC 2, ISO, and other compliance documents.Source 25 Which ones cover portals is not publicly documented. | CrewAI says it maintains a SOC 2 Type 2 certified security program.Source 26 Its trust center lists SOC 2 Type 2 (June 2026) and HIPAA (February 2026) audit reports.Source 26 |
| Support and SLA | Support options vary by plan, with professional services as Contract add-ons.Source 34 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.Source 34 | Community support on both plans; Enterprise adds dedicated and Slack or Teams support.Source 14 An uptime SLA is not publicly documented. |
| Time and effort to get running | Needs an active domain on Cloudflare and an identity provider on Cloudflare Zero Trust; then add servers, create a portal, and connect a client.Source 2 | The deploy guide assumes a crew or flow that runs locally; CrewAI says a first deployment typically takes around a minute.Source 19 Enterprise lists 45-day onboarding.Source 14 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 16 A separate price for portals is not publicly documented. | Basic is free, with 50 workflow executions a month.Source 14 Enterprise is custom-priced.Source 14 |
| Building | ||
| Agent building tools | Separately, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Cloudflare Workers.Source 3, Source 35 | Code or Crew Studio, for building crews through a conversational interface and automations with a visual workflow editor.Source 4, Source 8, Source 9 |
| Model access | Cloudflare says its separate AI Gateway manages model traffic across AI providers.Source 36 Models for portals themselves are not publicly documented. | CrewAI’s docs say any LLM provider CrewAI supports can be used, with your own API key; the Crew Studio setup guide lists OpenAI or Azure.Source 8 |
| Integrations and ecosystem | Supports all SAML and OIDC providers and most OAuth providers.Source 32 Portals can be managed with Terraform.Source 2 A connector marketplace is not publicly documented. | CrewAI says Crew Studio can connect to over 1,000 applications.Source 37 A Marketplace lists integrations and tools.Source 38 CrewAI says Databricks is a managed integration.Source 39 |
Which to choose
Choose Cloudflare MCP server portals if
- You use Cloudflare One, which Cloudflare says includes portals, and want MCP servers behind your Access login and identity provider.Source 1, Source 2
- You want to choose which MCP tools each portal exposes, with Access policies deciding who can connect.Source 2
- You need each MCP tool request logged, and exported with the user’s email to a SIEM through Logpush on an Enterprise plan.Source 2, Source 23
- Your MCP servers are private, and you want them in a portal through outbound-only Cloudflare Tunnel, with Gateway routing on.Source 2, Source 17, Source 18
Choose CrewAI AMP if
- You build with CrewAI and want one platform to deploy, monitor, and scale crews and flows in production.Source 4, Source 13
- You want people to build agents without writing code, using Crew Studio’s natural language and visual workflow editor, as CrewAI says.Source 9, Source 40
- You want your crews hosted: on managed infrastructure, or on the Enterprise plan in your own VPC.Source 4, Source 14
- You want flows that pause for human review, and execution traces you can export to your own OpenTelemetry collector.Source 24, Source 31
Questions buyers ask
Is a Cloudflare MCP server portal an agent registry?
Can CrewAI AMP run agents built with other frameworks?
How is each one priced?
Do they support MCP and A2A?
Portals proxy MCP tool calls and support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients.Source 2 For portals, A2A support is not publicly documented. AMP can connect to MCP servers and export automations as MCP; A2A server agents on AMP are in preview.Source 6, Source 12, Source 30
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
46 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abcde
Source 2: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546
Source 4: CrewAI AMP (platform docs introduction) Back:abcdefghijklmno
Source 5: Service token support for MCP server portals · Changelog Back:abcdef
Source 7: Traces Back:abc
Source 12: A2A on AMP Back:abc
Source 16: MCP server portals are now generally available · Changelog Back:abcde
Source 17: Private MCP server support for MCP server portals · Changelog Back:abc
Source 25: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 28: CrewAI AMP - The Agent Management Platform Back to text
Source 33: Agent-to-Agent (A2A) Protocol (CrewAI framework docs) Back:abc
Source 34: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 35: Build Agents on Cloudflare · Cloudflare Agents docs Back to text
Source 37: Crew Studio: The Automated Agent Builder Back to text
Source 39: Stop giving your agents database credentials Back to text
Source 40: CrewAI agent management platform page Back to text