Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs DIY: a governed MCP endpoint or an in-house build

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

Short answer

Cloudflare MCP server portals, which Cloudflare says are part of Cloudflare One, put MCP servers behind one endpoint with identity policies and request logs.⁠Source 1, Source 2 DIY is not a product: you build agent connections and controls yourself, on open protocols such as MCP and A2A, wherever you choose to run them.⁠Source 3, Source 4, Source 5

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can put MCP servers behind a governed proxy: a portal does this as a product, and Uber built its own MCP registry and proxy gateway.⁠Source 2, Source 6, Source 7
Where they differ
Portals list MCP servers; a registry of agents and A2A support are not publicly documented.⁠Source 2 DIY can also cover agent-to-agent traffic, for example over A2A.⁠Source 3
Running both
Cloudflare says a portal can manage internal and third-party MCP servers, including ones only on a private network.⁠Source 6, Source 8 Uber’s and Pinterest’s write-ups describe in-house builds.⁠Source 5, Source 7
Public sources · checked 2 October 2026
  • Offered
  • You build it
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 2
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 2
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 2
  • Agents across organizations: Not publicly documented

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 9
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 10
  • Identity and access: You build itYour own identity provider⁠Source 11
  • Registry and governance: You build itYour own agent registry⁠Source 12
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 7
  • Agents across organizations: You build itA2A with API management⁠Source 13

At a glance

TopicCloudflare MCP server portalsDIY
What it isPuts multiple MCP servers behind one HTTP endpoint.⁠Source 2 Cloudflare says portals are part of Cloudflare One.⁠Source 1An in-house build on open protocols such as A2A and MCP, which the A2A specification calls complementary.⁠Source 3, Source 4
What it coversMCP servers and their tools, up to 80 servers per portal.⁠Source 2 A registry of agents is not publicly documented.Whatever you build: A2A is an open standard for communication between agent systems; Uber and Pinterest each run an internal MCP registry.⁠Source 3, Source 5, Source 7
IdentityCloudflare Access login through your identity provider, or an Access service token for autonomous agents.⁠Source 2, Source 14Yours to choose: MCP authorization is optional.⁠Source 15 Keycloak’s MCP authorization support is Experimental (in preview) from MCP 2025-06-18.⁠Source 11
Where it runsThe portal hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 2Wherever you run it: Pinterest optimized for MCP servers hosted in its internal cloud.⁠Source 5
PricingCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented.Openly licensed specifications: A2A under Apache 2.0, and MCP under an open-source license.⁠Source 3, Source 4 Build and running costs are not publicly documented.

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.⁠Source 1, Source 17 Admins add MCP servers to Cloudflare Access, and a portal puts them behind one URL that MCP clients connect to.⁠Source 2 Portals have been generally available since 24 September 2026.⁠Source 16

Build it yourself (DIY)

DIY means connecting and governing agents without buying an agent platform: MCP and A2A wired together, existing infrastructure, an in-house platform, self-hosted open source, or no central approach; Uber built an MCP registry as its control plane and a proxy gateway as its data plane.⁠Source 7

The differences that matter

  1. What gets governed

    Cloudflare MCP server portals

    MCP servers and their tools: admins add servers, pick the tools and prompt templates each portal exposes, and turned-off tools can’t be called through it.⁠Source 2

    DIY

    Whatever you connect: A2A is built for agents from different companies on separate servers, and Uber’s gateway applies policies to humans, services, and agents.⁠Source 7, Source 18

    For portals, a registry of agents and A2A support are not publicly documented.

  2. Identity and access

    Cloudflare MCP server portals

    Users sign in through Access with their identity provider; autonomous agents can use a service token, and upstream calls then use the admin credential.⁠Source 2, Source 14

    DIY

    MCP makes authorization optional and A2A leaves authorization logic to each server; Pinterest checks end-user JWTs and mesh identities on almost every MCP call.⁠Source 3, Source 5, Source 15

    Cloudflare cautions that users blocked from a server in a portal can still reach it by its direct URL, and advises making Access its OAuth provider to enforce authentication.⁠Source 2

  3. Where it runs

    Cloudflare MCP server portals

    A portal’s hostname is a proxied CNAME to Cloudflare.⁠Source 2 MCP servers only on a private network connect through Cloudflare Tunnel or another Cloudflare One connector.⁠Source 2, Source 8

    DIY

    Wherever you put it: Pinterest optimized for MCP servers in its internal cloud, and AWS PrivateLink privately connects a VPC to services.⁠Source 5, Source 19

    A self-hosted portal is not publicly documented. For private servers that use OAuth, the authorization and token endpoints must be reachable on the public internet.⁠Source 2

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsDIY
Network exposureClients use the portal’s HTTPS URL.⁠Source 2 Private MCP servers can connect via Cloudflare Tunnel, which connects outbound only.⁠Source 2, Source 20MCP servers on Streamable HTTP expose an HTTP endpoint.⁠Source 21 A2A agents declare a URL, HTTPS for HTTP transports in production.⁠Source 3
IdentityAccess login through your identity provider, or a service token for agents.⁠Source 2, Source 14 Independent MFA isn’t enforced for portal-authorized servers.⁠Source 2In A2A, identity is set at the HTTP layer and credentials come out of band.⁠Source 3, Source 13 MCP authorization is optional.⁠Source 15
Access changes and revocationDeleting a service token revokes it.⁠Source 22 A tool turned off in a portal can’t be called through it.⁠Source 2Each A2A server authorizes requests under its own policies, and the specification calls that logic implementation-specific.⁠Source 3
Audit trailAccess logs each request made with a portal’s tools.⁠Source 2 Logpush export of those logs is Enterprise only.⁠Source 2A2A docs advise auditing task creation, critical state changes, and agent actions, and tracing, for example with OpenTelemetry.⁠Source 13
ComplianceSuper Administrators can get Cloudflare’s PCI, SOC 2, and ISO documents.⁠Source 23 Their scope for portals is not publicly documented.Sits with the implementer: A2A docs say to ensure compliance with regulations such as GDPR, CCPA, and HIPAA.⁠Source 13

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and DIY compared on 18 criteria
Cloudflare MCP server portalsDIY
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One.⁠Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, governed through Cloudflare Access.⁠Source 2, Source 6An in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which A2A calls complementary.⁠Source 3
MaturityGenerally available since 24 September 2026.⁠Source 16 Announced in open beta on 26 August 2025.⁠Source 24 Previously called Agents Gateway in some contexts.⁠Source 2Varies by component: MCP’s latest specification revision is 2026-07-28.⁠Source 25 The official MCP Registry is in preview and may have breaking changes.⁠Source 26
Control
Agent registry and discoveryAdmins add MCP servers to Access for central management, up to 80 per portal.⁠Source 2 A registry of agents is not publicly documented.Build your own: Uber and Pinterest built internal MCP registries.⁠Source 5, Source 7 The official MCP Registry is in preview and does not support private servers.⁠Source 26
Identity and access controlSign-in through Access with an identity provider, or an Access service token.⁠Source 2, Source 14 Policies can match emails, groups, country, and device posture.⁠Source 2In A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 3, Source 13 MCP authorization is optional.⁠Source 15
Ownership, policy, and revocationAdmins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.⁠Source 2MCP says implementers should build consent and authorization flows.⁠Source 25 Uber starts every MCP server and tool disabled until reviewed.⁠Source 7
Audit log and observabilityAccess logs each tool request, viewable per portal or per server.⁠Source 2 Enterprise Logpush exports record the user’s email and tool called.⁠Source 2, Source 27A2A docs advise auditing significant events.⁠Source 13 Pinterest’s MCP servers share libraries that log inputs, outputs, invocation counts, and exception traces.⁠Source 5
Connection
How agents connectClients connect to the portal’s HTTPS URL, which proxies each tool call.⁠Source 2 Private servers connect via Tunnel or another connector, with Gateway routing on.⁠Source 2Streamable HTTP MCP servers expose an endpoint; A2A agents declare a URL, HTTPS for HTTP transports in production.⁠Source 3, Source 21 Uber’s gateway calls out via a mesh sidecar.⁠Source 7
Agents across organizationsCloudflare One can use several identity providers at once, for partners or contractors.⁠Source 28 Federating other organizations’ agents: not publicly documented.A2A is designed for agents built by different companies on separate servers.⁠Source 18 Each server authorizes requests under its own policies.⁠Source 3
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 2 A2A support: not publicly documented.MCP defines stdio and Streamable HTTP transports, latest revision 2026-07-28.⁠Source 25, Source 29 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 3
Frameworks, models, and clouds supportedWorks with MCP clients that support remote servers.⁠Source 2 Stdio-only servers can’t be added, and some servers reject proxy-based clients like portals.⁠Source 2A2A gives agents built on different frameworks, languages, or vendors a common language.⁠Source 3 Google’s ADK says it is model-agnostic and deployment-agnostic.⁠Source 9
Operations
Deployment options and data residencyThe portal hostname is a proxied CNAME to gateway.agents.cloudflare.com.⁠Source 2 A self-hosted option is not publicly documented.Wherever you run it: Pinterest optimized for MCP servers in its internal cloud.⁠Source 5 A2A docs leave protecting stored data to your own policies.⁠Source 13
Compliance attestationsCompany-wide, Super Administrators can get PCI, SOC 2, ISO, and other documents in the dashboard.⁠Source 23 Portal-specific scope is not publicly documented.Sits with the implementer: A2A docs cite regulations such as GDPR, CCPA, and HIPAA, and MCP leaves access controls and data protection to implementers.⁠Source 13, Source 25
Support and SLASupport options vary by Zero Trust plan; professional services are Contract add-ons.⁠Source 30 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.⁠Source 30Depends on the component: MCP SDKs are tiered partly by maintenance commitments.⁠Source 31 The official MCP Registry, in preview, gives no uptime guarantees.⁠Source 32
Time and effort to get runningNeeds a domain on Cloudflare and an identity provider in Zero Trust.⁠Source 2 Then add MCP servers, create a portal with tools and policies, and connect clients.⁠Source 2A curated A2A registry is a service you deploy and maintain.⁠Source 12 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 5
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented.Openly licensed specifications: A2A under Apache 2.0, and MCP under an open-source license.⁠Source 3, Source 4 Build and running costs are not publicly documented.
Building
Agent building toolsSeparately, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Cloudflare Workers.⁠Source 6, Source 33Open-source frameworks such as LangGraph and Google’s Agent Development Kit build and deploy agents.⁠Source 9, Source 10 A2A has SDKs in six languages.⁠Source 34
Model accessNot publicly documented for portals. Cloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 35Chosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.⁠Source 9
Integrations and ecosystemPortals can be managed with the Cloudflare Terraform provider.⁠Source 2 Cloudflare One supports social, open source, and corporate IdPs.⁠Source 28The official MCP Registry, in preview, has a REST API for MCP clients and aggregators to discover servers.⁠Source 26

Which to choose

Choose Cloudflare MCP server portals if

  • You already use Cloudflare: Cloudflare says portals are part of Cloudflare One and available to all its customers.⁠Source 1, Source 16
  • You want MCP servers behind one endpoint, with Access policies on emails, groups, country, and device posture.⁠Source 2
  • You want to choose the tools and prompt templates each portal exposes, and turned-off tools can’t be called through it.⁠Source 2
  • You want tool-request logs per portal or per server, exportable to a SIEM with Logpush on Enterprise plans.⁠Source 2

Choose DIY if

  • Your agents call other agents, not only tools: A2A is an open standard for that, and isn’t publicly documented for portals.⁠Source 3
  • You want your own routing and security logic applied to MCP servers, which Pinterest optimized for in its internal cloud.⁠Source 5
  • You want your own review rules: Uber starts every MCP server and tool disabled until reviewed; Pinterest reviews all but one-off experiments.⁠Source 5, Source 7
  • You already run a service mesh or internal access-control system and want it to check MCP calls, as Uber and Pinterest do.⁠Source 5, Source 7

Questions buyers ask

Are Cloudflare MCP server portals an alternative to building it yourself?

For MCP servers, in part: a portal gives one endpoint with Access identity policies and request logs.⁠Source 2 Uber and Pinterest built their own MCP registries.⁠Source 5, Source 7 For portals, a registry of agents and A2A support are not publicly documented.

Do Cloudflare MCP server portals support A2A?

A2A support is not publicly documented for portals. Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.⁠Source 2 In a DIY build, A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 3

Can autonomous agents use a portal without a person signing in?

Yes, with an Access service token instead of a browser OAuth flow.⁠Source 14 The session is authorized at the portal and again for each upstream server, and upstream requests use the admin credential, not per-user OAuth.⁠Source 2

How are Cloudflare MCP server portals priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented. For DIY, the A2A and MCP specifications are openly licensed.⁠Source 3, Source 4

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

40 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abcde

  2. Source 2: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546474849

  3. Source 3: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnopqrs

  4. Source 4: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) github.com · checked Back:abcde

  5. Source 5: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefghijklmn

  6. Source 6: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcde

  7. Source 7: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcdefghijkl

  8. Source 8: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:abc

  9. Source 9: google/adk-python README (GitHub) github.com · checked Back:abcd

  10. Source 10: langchain-ai/langgraph README (GitHub) github.com · checked Back:ab

  11. Source 11: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back:ab

  12. Source 12: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:ab

  13. Source 13: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefgh

  14. Source 14: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcde

  15. Source 15: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:abcd

  16. Source 16: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcdef

  17. Source 17: Cloudflare One · Cloudflare One docs Cloudflare · checked Back to text

  18. Source 18: a2aproject/A2A README (GitHub) github.com · checked Back:ab

  19. Source 19: What is AWS PrivateLink? - Amazon Virtual Private Cloud docs.aws.amazon.com · checked Back to text

  20. Source 20: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back to text

  21. Source 21: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  22. Source 22: Service tokens · Cloudflare One docs Cloudflare · checked Back to text

  23. Source 23: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  24. Source 24: MCP server portals · Changelog Cloudflare · checked Back to text

  25. Source 25: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcd

  26. Source 26: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abc

  27. Source 27: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back to text

  28. Source 28: Identity providers · Cloudflare One docs Cloudflare · checked Back:abc

  29. Source 29: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  30. Source 30: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  31. Source 31: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  32. Source 32: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  33. Source 33: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back to text

  34. Source 34: A2A protocol roadmap a2a-protocol.org · checked Back to text

  35. Source 35: AI Security | Cloudflare Cloudflare · checked Back to text

  36. Source 36: Your company's private network Blocks.ai · checked Back to text

  37. Source 37: Network requirements Blocks.ai · checked Back to text

  38. Source 38: Solutions: Agent sprawl Blocks.ai · checked Back to text

  39. Source 39: Solutions: Partner networks Blocks.ai · checked Back to text

  40. Source 40: Pricing Blocks.ai · checked Back to text