Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs DIY: a governed MCP endpoint or an in-house build
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Build it yourself (DIY)
Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools
Short answer
Cloudflare MCP server portals, which Cloudflare says are part of Cloudflare One, put MCP servers behind one endpoint with identity policies and request logs.Source 1, Source 2 DIY is not a product: you build agent connections and controls yourself, on open protocols such as MCP and A2A, wherever you choose to run them.Source 3, Source 4, Source 5
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
DIY
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.Source 1, Source 17 Admins add MCP servers to Cloudflare Access, and a portal puts them behind one URL that MCP clients connect to.Source 2 Portals have been generally available since 24 September 2026.Source 16
Build it yourself (DIY)
DIY means connecting and governing agents without buying an agent platform: MCP and A2A wired together, existing infrastructure, an in-house platform, self-hosted open source, or no central approach; Uber built an MCP registry as its control plane and a proxy gateway as its data plane.Source 7
The differences that matter
What gets governed
Cloudflare MCP server portalsMCP servers and their tools: admins add servers, pick the tools and prompt templates each portal exposes, and turned-off tools can’t be called through it.Source 2
DIYWhatever you connect: A2A is built for agents from different companies on separate servers, and Uber’s gateway applies policies to humans, services, and agents.Source 7, Source 18
For portals, a registry of agents and A2A support are not publicly documented.
Identity and access
Cloudflare MCP server portalsUsers sign in through Access with their identity provider; autonomous agents can use a service token, and upstream calls then use the admin credential.Source 2, Source 14
DIYMCP makes authorization optional and A2A leaves authorization logic to each server; Pinterest checks end-user JWTs and mesh identities on almost every MCP call.Source 3, Source 5, Source 15
Cloudflare cautions that users blocked from a server in a portal can still reach it by its direct URL, and advises making Access its OAuth provider to enforce authentication.Source 2
Where it runs
Cloudflare MCP server portalsA portal’s hostname is a proxied CNAME to Cloudflare.Source 2 MCP servers only on a private network connect through Cloudflare Tunnel or another Cloudflare One connector.Source 2, Source 8
DIYWherever you put it: Pinterest optimized for MCP servers in its internal cloud, and AWS PrivateLink privately connects a VPC to services.Source 5, Source 19
A self-hosted portal is not publicly documented. For private servers that use OAuth, the authorization and token endpoints must be reachable on the public internet.Source 2
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | DIY | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One.Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, governed through Cloudflare Access.Source 2, Source 6 | An in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which A2A calls complementary.Source 3 |
| Maturity | Generally available since 24 September 2026.Source 16 Announced in open beta on 26 August 2025.Source 24 Previously called Agents Gateway in some contexts.Source 2 | Varies by component: MCP’s latest specification revision is 2026-07-28.Source 25 The official MCP Registry is in preview and may have breaking changes.Source 26 |
| Control | ||
| Agent registry and discovery | Admins add MCP servers to Access for central management, up to 80 per portal.Source 2 A registry of agents is not publicly documented. | Build your own: Uber and Pinterest built internal MCP registries.Source 5, Source 7 The official MCP Registry is in preview and does not support private servers.Source 26 |
| Identity and access control | Sign-in through Access with an identity provider, or an Access service token.Source 2, Source 14 Policies can match emails, groups, country, and device posture.Source 2 | In A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.Source 3, Source 13 MCP authorization is optional.Source 15 |
| Ownership, policy, and revocation | Admins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.Source 2 | MCP says implementers should build consent and authorization flows.Source 25 Uber starts every MCP server and tool disabled until reviewed.Source 7 |
| Audit log and observability | Access logs each tool request, viewable per portal or per server.Source 2 Enterprise Logpush exports record the user’s email and tool called.Source 2, Source 27 | A2A docs advise auditing significant events.Source 13 Pinterest’s MCP servers share libraries that log inputs, outputs, invocation counts, and exception traces.Source 5 |
| Connection | ||
| How agents connect | Clients connect to the portal’s HTTPS URL, which proxies each tool call.Source 2 Private servers connect via Tunnel or another connector, with Gateway routing on.Source 2 | Streamable HTTP MCP servers expose an endpoint; A2A agents declare a URL, HTTPS for HTTP transports in production.Source 3, Source 21 Uber’s gateway calls out via a mesh sidecar.Source 7 |
| Agents across organizations | Cloudflare One can use several identity providers at once, for partners or contractors.Source 28 Federating other organizations’ agents: not publicly documented. | A2A is designed for agents built by different companies on separate servers.Source 18 Each server authorizes requests under its own policies.Source 3 |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 2 A2A support: not publicly documented. | MCP defines stdio and Streamable HTTP transports, latest revision 2026-07-28.Source 25, Source 29 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.Source 3 |
| Frameworks, models, and clouds supported | Works with MCP clients that support remote servers.Source 2 Stdio-only servers can’t be added, and some servers reject proxy-based clients like portals.Source 2 | A2A gives agents built on different frameworks, languages, or vendors a common language.Source 3 Google’s ADK says it is model-agnostic and deployment-agnostic.Source 9 |
| Operations | ||
| Deployment options and data residency | The portal hostname is a proxied CNAME to gateway.agents.cloudflare.com.Source 2 A self-hosted option is not publicly documented. | Wherever you run it: Pinterest optimized for MCP servers in its internal cloud.Source 5 A2A docs leave protecting stored data to your own policies.Source 13 |
| Compliance attestations | Company-wide, Super Administrators can get PCI, SOC 2, ISO, and other documents in the dashboard.Source 23 Portal-specific scope is not publicly documented. | Sits with the implementer: A2A docs cite regulations such as GDPR, CCPA, and HIPAA, and MCP leaves access controls and data protection to implementers.Source 13, Source 25 |
| Support and SLA | Support options vary by Zero Trust plan; professional services are Contract add-ons.Source 30 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.Source 30 | Depends on the component: MCP SDKs are tiered partly by maintenance commitments.Source 31 The official MCP Registry, in preview, gives no uptime guarantees.Source 32 |
| Time and effort to get running | Needs a domain on Cloudflare and an identity provider in Zero Trust.Source 2 Then add MCP servers, create a portal with tools and policies, and connect clients.Source 2 | A curated A2A registry is a service you deploy and maintain.Source 12 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.Source 5 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 16 A separate price for portals is not publicly documented. | Openly licensed specifications: A2A under Apache 2.0, and MCP under an open-source license.Source 3, Source 4 Build and running costs are not publicly documented. |
| Building | ||
| Agent building tools | Separately, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Cloudflare Workers.Source 6, Source 33 | Open-source frameworks such as LangGraph and Google’s Agent Development Kit build and deploy agents.Source 9, Source 10 A2A has SDKs in six languages.Source 34 |
| Model access | Not publicly documented for portals. Cloudflare says its separate AI Gateway manages model traffic across AI providers.Source 35 | Chosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.Source 9 |
| Integrations and ecosystem | Portals can be managed with the Cloudflare Terraform provider.Source 2 Cloudflare One supports social, open source, and corporate IdPs.Source 28 | The official MCP Registry, in preview, has a REST API for MCP clients and aggregators to discover servers.Source 26 |
Which to choose
Choose Cloudflare MCP server portals if
- You already use Cloudflare: Cloudflare says portals are part of Cloudflare One and available to all its customers.Source 1, Source 16
- You want MCP servers behind one endpoint, with Access policies on emails, groups, country, and device posture.Source 2
- You want to choose the tools and prompt templates each portal exposes, and turned-off tools can’t be called through it.Source 2
- You want tool-request logs per portal or per server, exportable to a SIEM with Logpush on Enterprise plans.Source 2
Choose DIY if
- Your agents call other agents, not only tools: A2A is an open standard for that, and isn’t publicly documented for portals.Source 3
- You want your own routing and security logic applied to MCP servers, which Pinterest optimized for in its internal cloud.Source 5
- You want your own review rules: Uber starts every MCP server and tool disabled until reviewed; Pinterest reviews all but one-off experiments.Source 5, Source 7
- You already run a service mesh or internal access-control system and want it to check MCP calls, as Uber and Pinterest do.Source 5, Source 7
Questions buyers ask
Are Cloudflare MCP server portals an alternative to building it yourself?
Do Cloudflare MCP server portals support A2A?
Can autonomous agents use a portal without a person signing in?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
40 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abcde
Source 2: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546474849
Source 3: Agent2Agent (A2A) Protocol Specification Back:abcdefghijklmnopqrs
Source 4: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) Back:abcde
Source 5: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog Back:abcdefghijklmn
Source 6: MCP governance · Cloudflare Agents docs Back:abcde
Source 7: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog Back:abcdefghijkl
Source 8: Private MCP server support for MCP server portals · Changelog Back:abc
Source 11: Integrating with Model Context Protocol (MCP) - Keycloak Back:ab
Source 14: Service token support for MCP server portals · Changelog Back:abcde
Source 15: Authorization - Model Context Protocol specification 2026-07-28 Back:abcd
Source 16: MCP server portals are now generally available · Changelog Back:abcdef
Source 17: Cloudflare One · Cloudflare One docs Back to text
Source 19: What is AWS PrivateLink? - Amazon Virtual Private Cloud Back to text
Source 20: Cloudflare Tunnel · Cloudflare One docs Back to text
Source 21: Streamable HTTP - Model Context Protocol specification 2026-07-28 Back:ab
Source 22: Service tokens · Cloudflare One docs Back to text
Source 23: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 25: Specification - Model Context Protocol 2026-07-28 Back:abcd
Source 26: The MCP Registry - Model Context Protocol Back:abc
Source 27: MCP Portal Logs · Cloudflare Logs docs Back to text
Source 28: Identity providers · Cloudflare One docs Back:abc
Source 29: Transports - Model Context Protocol specification 2026-07-28 Back to text
Source 30: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 32: MCP Registry Aggregators - Model Context Protocol Back to text
Source 33: Build Agents on Cloudflare · Cloudflare Agents docs Back to text