Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs CrewAI AMP

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

CrewAI AMP

Platform for deploying, monitoring, and scaling CrewAI crews and agents

Short answer

Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; CrewAI AMP is a platform to build, deploy, and run CrewAI crews.⁠Source 1, Source 2, Source 3, Source 4 A portal controls which MCP tools people and agents reach and logs tool requests; AMP runs crews on managed infrastructure and can connect to MCP servers.⁠Source 2, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both work with MCP and both log activity: a portal proxies MCP tool calls and logs tool requests, and AMP can connect crews to MCP servers and records execution traces.⁠Source 2, Source 6, Source 7
Where they differ
AMP builds crews in Crew Studio and runs them on managed infrastructure.⁠Source 4, Source 8, Source 9 A portal manages MCP servers and their tools.⁠Source 2 For portals, a registry of agents is not publicly documented.
Running both
Neither vendor publicly documents using the two together. Cloudflare’s portals accept remote MCP clients; CrewAI’s AMP can connect to internet-reachable Streamable HTTP MCP servers.⁠Source 2, Source 6
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 2
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 2
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 2
  • Agents across organizations: Not publicly documented

CrewAI AMP

  • Build agents: OfferedCrew Studio visual editor⁠Source 9
  • Host and run agents: OfferedManaged infrastructure for crews⁠Source 4
  • Identity and access: OfferedPer-deployment allow lists⁠Source 10
  • Registry and governance: OfferedAgent Repositories⁠Source 11
  • Traffic between agents, tools, and models: OfferedCustom MCP server connections⁠Source 6
  • Agents across organizations: PreviewPublic A2A agents⁠Source 12

At a glance

TopicCloudflare MCP server portalsCrewAI AMP
What it isPuts multiple MCP servers behind one HTTP endpoint, governed through Cloudflare Access.⁠Source 2, Source 3 Cloudflare says portals are part of Cloudflare One.⁠Source 1CrewAI’s platform for deploying, monitoring, and scaling crews and agents in production, built in code or in Crew Studio.⁠Source 4
What it governsMCP servers and the tools each portal exposes, up to 80 servers per portal.⁠Source 2CrewAI Crews and Flows deployed as automations, and agent definitions shared through Agent Repositories.⁠Source 11, Source 13
Where it runsA portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 2Crews deploy to managed infrastructure.⁠Source 4 The Enterprise plan can run on CrewAI cloud, your own VPC, or your own infrastructure.⁠Source 14
IdentityCloudflare Access login through your identity provider, or an Access service token for autonomous agents.⁠Source 2, Source 5The Enterprise plan lists role-based access control and SSO with Microsoft Entra or Okta.⁠Source 14 Calls to a deployed crew need a bearer token.⁠Source 15
PricingCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented.Basic is free, with 50 workflow executions a month.⁠Source 14 Enterprise is custom-priced.⁠Source 14

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.⁠Source 1 A portal gathers several MCP servers behind one HTTP endpoint, applies Cloudflare Access policies to who can connect, and logs each tool request.⁠Source 2 Portals became generally available on 24 September 2026.⁠Source 16

CrewAI AMP

CrewAI AMP (Agent Management Platform) is CrewAI’s platform for deploying, monitoring, and scaling crews and agents in production, extending its open-source framework.⁠Source 4 Teams build crews in code, or in Crew Studio with natural language and a visual workflow editor.⁠Source 4, Source 9

The differences that matter

  1. What each one manages

    Cloudflare MCP server portals

    MCP servers and their tools: admins add servers, choose the tools and prompt templates each portal exposes, and turned-off tools can’t be called through it.⁠Source 2

    CrewAI AMP

    CrewAI crews and flows: teams build crews in code or Crew Studio and deploy both as automations; Agent Repositories, on both plans, share agent definitions.⁠Source 4, Source 11, Source 13, Source 14

    For portals, a registry of agents is not publicly documented. For AMP, a registry that lists agents built outside CrewAI is not publicly documented.

  2. Identity and access

    Cloudflare MCP server portals

    People sign in through Cloudflare Access with their identity provider; autonomous agents can use a service token, whose upstream calls use the admin credential.⁠Source 2, Source 5

    CrewAI AMP

    The Enterprise plan lists role-based access control, which can make a deployment private to allow-listed users and roles; crew API calls need a bearer token.⁠Source 10, Source 14, Source 15

    Cloudflare says a blocked user can reach a server by its direct URL, and advises making Access its OAuth provider.⁠Source 2 A separate identity per AMP agent is not publicly documented.

  3. Where it runs

    Cloudflare MCP server portals

    A portal’s hostname points to gateway.agents.cloudflare.com.⁠Source 2 Private MCP servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.⁠Source 2, Source 17

    CrewAI AMP

    Crews deploy to managed infrastructure; the Enterprise plan can run on CrewAI cloud, your own VPC, or your own infrastructure.⁠Source 4, Source 14

    For portals, self-hosting is not publicly documented. For AMP, data residency commitments are not publicly documented.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsCrewAI AMP
Network exposureClients use the portal’s HTTPS URL.⁠Source 2 Private MCP servers can connect through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 18Each deployed crew’s API is protected by a bearer token.⁠Source 15, Source 19 Custom MCP servers must be reachable from the internet.⁠Source 6
IdentityAccess login through your identity provider, or a service token for agents.⁠Source 2, Source 5 Independent MFA isn’t enforced for portal-authorized servers.⁠Source 2Enterprise lists role-based access control and SSO with Microsoft Entra or Okta.⁠Source 14 Per-agent identity is not publicly documented.
Access changes and revocationDeleting a service token revokes its access.⁠Source 20 A tool turned off in a portal can’t be called through it.⁠Source 2On Enterprise, the manage settings permission allows deleting an automation.⁠Source 10, Source 14 Revoking a Platform API service account (beta) disables it immediately.⁠Source 21, Source 22
Audit trailAccess logs each request made with a portal’s tools; exported logs include the user’s email.⁠Source 2, Source 23 Logpush export is Enterprise only.⁠Source 2Execution traces, exportable to your own OpenTelemetry collector.⁠Source 7, Source 24 AMP’s docs don’t describe a platform-wide audit log of admin events.
ComplianceSuper Administrators can get Cloudflare’s PCI, SOC 2, and ISO documents.⁠Source 25 Which ones cover portals is not publicly documented.CrewAI says it maintains a SOC 2 Type 2 certified security program.⁠Source 26 Its trust center lists a HIPAA audit report.⁠Source 26

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and CrewAI AMP compared on 18 criteria
Cloudflare MCP server portalsCrewAI AMP
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One, its SASE platform.⁠Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, governed through Access.⁠Source 2, Source 3Platform for deploying, monitoring, and scaling CrewAI crews and agents in production, extending CrewAI’s open-source framework.⁠Source 4
MaturityGenerally available since 24 September 2026, after an open beta announced on 26 August 2025.⁠Source 16, Source 27 Once called Agents Gateway in some contexts.⁠Source 2CrewAI’s platform took the AMP name in October 2025.⁠Source 28, Source 29 The Platform API is in beta.⁠Source 22
Control
Agent registry and discoveryAdmins add MCP servers to Cloudflare Access for central management, up to 80 per portal.⁠Source 2 A registry of agents is not publicly documented.Agent Repositories, on both plans, share agent definitions; Automations is the hub for deployed crews.⁠Source 11, Source 14, Source 30 Listing non-CrewAI agents: not publicly documented.
Identity and access controlUsers sign in through Cloudflare Access with their identity provider.⁠Source 2 Autonomous agents can use an Access service token instead of a browser OAuth flow.⁠Source 5The Enterprise plan lists SSO (Microsoft Entra, Okta) and role-based access control, which can make a deployment private to allow-listed users and roles.⁠Source 10, Source 14
Ownership, policy, and revocationAdmins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.⁠Source 2 Service tokens can be turned off or deleted.⁠Source 20On Enterprise, custom roles can set most features to Manage, Read, or No access.⁠Source 10, Source 14 Flows can pause for human review.⁠Source 31 Per-agent owners are not publicly documented.
Audit log and observabilityAccess logs each request made with a portal’s tools, viewable per portal or per server.⁠Source 2 Logpush export to storage or a SIEM is Enterprise only.⁠Source 2Execution traces from inputs to outputs, with OpenTelemetry export to your own collector.⁠Source 7, Source 24 AMP’s docs don’t describe a platform-wide audit log of admin events.
Connection
How agents connectMCP clients connect to the portal’s HTTPS URL.⁠Source 2 Private-network servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.⁠Source 2, Source 17Crews deploy to managed infrastructure, each crew’s API protected by a bearer token.⁠Source 4, Source 19 Custom MCP servers must be reachable from the internet.⁠Source 6
Agents across organizationsSeveral identity providers at once, for people at partners or contractors.⁠Source 32 Partner-controlled agents in a portal: not publicly documented.CrewAI agents can delegate tasks to remote A2A agents by URL.⁠Source 33 Bringing another company’s agents into AMP, with access it controls: not publicly documented.
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 2 A2A support is not publicly documented.Can connect to external MCP servers and export an automation as MCP.⁠Source 6, Source 30 A2A server agents on AMP are in preview; CrewAI agents can delegate to remote A2A agents.⁠Source 12, Source 33
Frameworks, models, and clouds supportedMCP clients that support remote servers; setup steps cover Claude Desktop, Windsurf, and others.⁠Source 2 Some MCP servers reject proxy-based clients like portals.⁠Source 2Deploys CrewAI Crews and Flows as automations.⁠Source 13 AMP’s docs don’t describe deploying agents built with other frameworks.
Operations
Deployment options and data residencyA portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 2 Self-hosting a portal is not publicly documented.The Enterprise plan can run on CrewAI cloud, your own VPC, or your own infrastructure.⁠Source 14 Data residency commitments are not publicly documented.
Compliance attestationsSuper Administrators can get Cloudflare’s PCI, SOC 2, ISO, and other compliance documents.⁠Source 25 Which ones cover portals is not publicly documented.CrewAI says it maintains a SOC 2 Type 2 certified security program.⁠Source 26 Its trust center lists SOC 2 Type 2 (June 2026) and HIPAA (February 2026) audit reports.⁠Source 26
Support and SLASupport options vary by plan, with professional services as Contract add-ons.⁠Source 34 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.⁠Source 34Community support on both plans; Enterprise adds dedicated and Slack or Teams support.⁠Source 14 An uptime SLA is not publicly documented.
Time and effort to get runningNeeds an active domain on Cloudflare and an identity provider on Cloudflare Zero Trust; then add servers, create a portal, and connect a client.⁠Source 2The deploy guide assumes a crew or flow that runs locally; CrewAI says a first deployment typically takes around a minute.⁠Source 19 Enterprise lists 45-day onboarding.⁠Source 14
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented.Basic is free, with 50 workflow executions a month.⁠Source 14 Enterprise is custom-priced.⁠Source 14
Building
Agent building toolsSeparately, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Cloudflare Workers.⁠Source 3, Source 35Code or Crew Studio, for building crews through a conversational interface and automations with a visual workflow editor.⁠Source 4, Source 8, Source 9
Model accessCloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 36 Models for portals themselves are not publicly documented.CrewAI’s docs say any LLM provider CrewAI supports can be used, with your own API key; the Crew Studio setup guide lists OpenAI or Azure.⁠Source 8
Integrations and ecosystemSupports all SAML and OIDC providers and most OAuth providers.⁠Source 32 Portals can be managed with Terraform.⁠Source 2 A connector marketplace is not publicly documented.CrewAI says Crew Studio can connect to over 1,000 applications.⁠Source 37 A Marketplace lists integrations and tools.⁠Source 38 CrewAI says Databricks is a managed integration.⁠Source 39

Which to choose

Choose Cloudflare MCP server portals if

  • You use Cloudflare One, which Cloudflare says includes portals, and want MCP servers behind your Access login and identity provider.⁠Source 1, Source 2
  • You want to choose which MCP tools each portal exposes, with Access policies deciding who can connect.⁠Source 2
  • You need each MCP tool request logged, and exported with the user’s email to a SIEM through Logpush on an Enterprise plan.⁠Source 2, Source 23
  • Your MCP servers are private, and you want them in a portal through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 17, Source 18

Choose CrewAI AMP if

  • You build with CrewAI and want one platform to deploy, monitor, and scale crews and flows in production.⁠Source 4, Source 13
  • You want people to build agents without writing code, using Crew Studio’s natural language and visual workflow editor, as CrewAI says.⁠Source 9, Source 40
  • You want your crews hosted: on managed infrastructure, or on the Enterprise plan in your own VPC.⁠Source 4, Source 14
  • You want flows that pause for human review, and execution traces you can export to your own OpenTelemetry collector.⁠Source 24, Source 31

Questions buyers ask

Is a Cloudflare MCP server portal an agent registry?

What a portal lists is MCP servers: admins add them to Cloudflare Access, and agents connect as MCP clients, with a user’s login or an Access service token.⁠Source 2, Source 5 A registry of agents is not publicly documented.

Can CrewAI AMP run agents built with other frameworks?

AMP deploys CrewAI Crews and Flows as automations.⁠Source 13 AMP’s docs don’t describe deploying agents built with other frameworks. CrewAI agents can delegate tasks to remote A2A agents, and AMP can connect to external MCP servers.⁠Source 6, Source 33

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented. CrewAI’s Basic plan is free; Enterprise is custom-priced.⁠Source 14

Do they support MCP and A2A?

Portals proxy MCP tool calls and support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients.⁠Source 2 For portals, A2A support is not publicly documented. AMP can connect to MCP servers and export automations as MCP; A2A server agents on AMP are in preview.⁠Source 6, Source 12, Source 30

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

46 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abcde

  2. Source 2: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546

  3. Source 3: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcd

  4. Source 4: CrewAI AMP (platform docs introduction) CrewAI · checked Back:abcdefghijklmno

  5. Source 5: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcdef

  6. Source 6: Custom MCP Servers CrewAI · checked Back:abcdefghi

  7. Source 7: Traces CrewAI · checked Back:abc

  8. Source 8: Enable Crew Studio CrewAI · checked Back:abc

  9. Source 9: Crew Studio CrewAI · checked Back:abcde

  10. Source 10: Role-Based Access Control (RBAC) CrewAI · checked Back:abcde

  11. Source 11: Agent Repositories CrewAI · checked Back:abcd

  12. Source 12: A2A on AMP CrewAI · checked Back:abc

  13. Source 13: Prepare for Deployment CrewAI · checked Back:abcde

  14. Source 14: Pricing | CrewAI CrewAI · checked Back:abcdefghijklmnopqrs

  15. Source 15: Kickoff Crew CrewAI · checked Back:abc

  16. Source 16: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcde

  17. Source 17: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:abc

  18. Source 18: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:ab

  19. Source 19: Deploy to AMP CrewAI · checked Back:abc

  20. Source 20: Service tokens · Cloudflare One docs Cloudflare · checked Back:ab

  21. Source 21: Service accounts CrewAI · checked Back to text

  22. Source 22: Introduction (CrewAI Platform API) CrewAI · checked Back:ab

  23. Source 23: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back:ab

  24. Source 24: OpenTelemetry Export CrewAI · checked Back:abc

  25. Source 25: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  26. Source 26: Trust Center - CrewAI CrewAI · checked Back:abcd

  27. Source 27: MCP server portals · Changelog Cloudflare · checked Back to text

  28. Source 28: CrewAI AMP - The Agent Management Platform CrewAI · checked Back to text

  29. Source 29: Changelog (CrewAI docs) CrewAI · checked Back to text

  30. Source 30: Automations CrewAI · checked Back:abc

  31. Source 31: Flow HITL Management CrewAI · checked Back:ab

  32. Source 32: Identity providers · Cloudflare One docs Cloudflare · checked Back:ab

  33. Source 33: Agent-to-Agent (A2A) Protocol (CrewAI framework docs) CrewAI · checked Back:abc

  34. Source 34: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  35. Source 35: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back to text

  36. Source 36: AI Security | Cloudflare Cloudflare · checked Back to text

  37. Source 37: Crew Studio: The Automated Agent Builder CrewAI · checked Back to text

  38. Source 38: Marketplace CrewAI · checked Back to text

  39. Source 39: Stop giving your agents database credentials CrewAI · checked Back to text

  40. Source 40: CrewAI agent management platform page CrewAI · checked Back to text

  41. Source 41: Why Blocks? Blocks.ai · checked Back to text

  42. Source 42: What is Blocks? Blocks.ai · checked Back to text

  43. Source 43: Your company's private network Blocks.ai · checked Back to text

  44. Source 44: Network requirements Blocks.ai · checked Back to text

  45. Source 45: Solutions: Agent sprawl Blocks.ai · checked Back to text

  46. Source 46: Connect CrewAI to Blocks Blocks.ai · checked Back to text