Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs Gemini Enterprise Agent Platform
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Gemini Enterprise Agent Platform
Google Cloud platform to build, deploy, govern, and optimize AI agents
Short answer
Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents.Source 1, Source 2, Source 3, Source 4, Source 5 Portals control who reaches which MCP tools; Agent Platform catalogs agents and tools, and can give agents on supported runtimes their own identity.Source 2, Source 6, Source 7
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Gemini Enterprise Agent Platform
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.Source 1 A portal puts MCP servers that admins add to Cloudflare Access behind one URL for MCP clients.Source 2 Access policies decide who connects, and Access logs each tool request.Source 2
Gemini Enterprise Agent Platform
Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents, an evolution of Vertex AI.Source 4, Source 5 Agent Registry catalogs agents and tools, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway applies policy checks to traffic.Source 6, Source 7, Source 9, Source 17
The differences that matter
What gets governed
Cloudflare MCP server portalsMCP servers and their tools: admins add servers to Access and choose which tools and prompt templates each portal exposes.Source 2
Gemini Enterprise Agent PlatformAgents, MCP servers, and tools: Agent Registry catalogs all three, and agents on supported runtimes can get SPIFFE-based identities.Source 6, Source 7
Agents reach a portal as MCP clients, with a user’s identity provider login or an Access service token.Source 2, Source 12
Building and running agents
Where policy is enforced
Cloudflare MCP server portalsAt the portal, where Access policies decide who connects; private MCP servers can join through Cloudflare Tunnel, with Gateway routing on.Source 2, Source 19
Gemini Enterprise Agent PlatformAt Agent Gateway, a managed, regional component, for Agent Runtime and the Gemini Enterprise app; Model Armor can scan prompts and tool responses.Source 9, Source 20
For a private MCP server that uses OAuth, the authorization and token endpoints must be reachable on the public internet.Source 2 Agent Gateway’s inbound mode supports only Agent Runtime agents.Source 9
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | Gemini Enterprise Agent Platform | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One, its SASE platform.Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, governed through Access.Source 2, Source 3 | Google Cloud platform to build, deploy, govern, and optimize AI agents, which Google calls an evolution of Vertex AI, for developers and technical teams.Source 4, Source 5 |
| Maturity | GA since 24 September 2026, after an open beta announced 26 August 2025.Source 13, Source 16 Once called Agents Gateway, a different product from Google’s Agent Gateway.Source 2 | Google says it launched 22 April 2026.Source 29 Registry and Gateway GA since 18 June 2026.Source 17 Agent Identity is generally available; the Agent Identity API is in preview.Source 17 |
| Control | ||
| Agent registry and discovery | Admins add MCP servers to Cloudflare Access for central management, up to 80 per portal.Source 2 A registry of agents is not publicly documented. | Agent Registry: a per-project catalog of agents, MCP servers, and tools.Source 6, Source 11 Agents on supported runtimes can be registered automatically, others manually.Source 30, Source 31 |
| Identity and access control | Sign-in through Access with an identity provider, or an Access service token.Source 2, Source 12 Policies can match emails, groups, country, and device posture checks.Source 2 | Agents on supported runtimes can each have a SPIFFE-based identity.Source 7 By default, Agent Gateway blocks connections without an IAM policy grant.Source 9 |
| Ownership, policy, and revocation | Admins pick each portal’s tools and prompt templates; turned-off tools can’t be called through it.Source 2 An owner field is not publicly documented. | Allow and deny access policies (deny overrides allow), enforce and dry-run modes, and Model Armor filters.Source 9, Source 23 An agent owner field is not publicly documented. |
| Audit log and observability | Access logs each tool request, viewable per portal or per server.Source 2 Exported logs record the user’s email and tool called; Logpush is Enterprise-plan only.Source 2, Source 32 | Registry admin changes get Admin Activity audit logs; other calls need Data Access logs turned on.Source 24, Source 25 Gateway logs record access requests.Source 10 |
| Connection | ||
| How agents connect | MCP clients connect to the portal’s HTTPS URL, and it proxies each tool call.Source 2 Private servers join via Cloudflare Tunnel, with Gateway routing on.Source 2, Source 19 | Agent Gateway can govern traffic in and out of Agent Runtime, and out of the Gemini Enterprise app.Source 9 Outside agents can be registered by endpoint or agent card.Source 33 |
| Agents across organizations | Cloudflare One can use several identity providers at once, for partners or contractors.Source 34 Federating other organizations’ agents: not publicly documented. | Agent Runtime agents can call agents anywhere via Agent Gateway.Source 9 Federating other organizations’ agents: not publicly documented. |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 2 A2A support is not publicly documented. | Agent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.Source 8, Source 9, Source 31 A2A agents on Agent Runtime are in preview.Source 35 |
| Frameworks, models, and clouds supported | Works with MCP clients that support remote servers.Source 2 Stdio-only servers can’t be added, and some servers reject proxy-based clients like portals.Source 2 | Built with the Agent Development Kit or any open-source framework, using Gemini or Model Garden models.Source 36 Agents outside Google Cloud can be registered manually.Source 33 |
| Operations | ||
| Deployment options and data residency | A portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.Source 2 Self-hosting a portal is not publicly documented. | Managed, regional Agent Gateway; agent infrastructure data rests in the selected supported location.Source 20, Source 37 Self-hosted registry or gateway: not publicly documented. |
| Compliance attestations | Company-wide, Super Administrators can get PCI, SOC 2, ISO, and other documents in the dashboard.Source 26 Portal-specific scope is not publicly documented. | Google lists Agent Platform in scope for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS, and in the Google Cloud HIPAA BAA.Source 27, Source 28 |
| Support and SLA | Support options vary by Zero Trust plan; professional services are Contract add-ons.Source 38 Cloudflare advertises a 100% uptime SLA for paid Zero Trust plans.Source 38 | Google Cloud support packages, including 24/7 coverage.Source 39 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime is not publicly documented. |
| Time and effort to get running | Needs a domain on Cloudflare and an identity provider in Zero Trust.Source 2 Then add MCP servers, create a portal with tools and policies, and connect clients.Source 2 | A Google Cloud project with the Agent Registry API enabled, plus the Identity-Aware Proxy API for gateway policy.Source 11 Google recommends dry-run mode in staging.Source 23 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 13 A separate price for portals is not publicly documented. | Agent Registry is free; skill scanning is billed from January 2027.Source 14 Agent Runtime: $0.085 per vCPU-hour.Source 15 Agent Gateway egress: $0.085 per 15,000 requests.Source 15 |
| Building | ||
| Agent building tools | Separately from portals, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Workers.Source 3, Source 18 | Agent Studio (a low-code canvas), the open-source Agent Development Kit, and Agent Garden prebuilt agents and templates.Source 4, Source 36 A Managed Agents API is in preview.Source 4 |
| Model access | Not publicly documented for portals. Cloudflare says its separate AI Gateway manages model traffic across AI providers.Source 40 | More than 200 models, including Gemini, third-party, and open-source models.Source 4 Google says Model Garden supports Anthropic’s Claude.Source 29 |
| Integrations and ecosystem | Portals can be managed with Terraform.Source 2 Cloudflare One supports social, open source, and corporate identity providers.Source 34 A marketplace is not publicly documented. | Agents in Agent Registry can be made available in Google’s Gemini Enterprise app.Source 20 Google’s own remote MCP servers are registered automatically.Source 8 |
Which to choose
Choose Cloudflare MCP server portals if
- You want many MCP servers behind one endpoint that MCP clients such as Claude Desktop or Windsurf can connect to.Source 2
- You already use Cloudflare One, which Cloudflare says includes portals, now generally available to all Cloudflare customers.Source 1, Source 13
- You want Access policies on MCP use, matching emails, groups, country, and device posture, and per-portal control of which tools appear.Source 2
- You want tool-request logs per portal or per server, exportable to a SIEM with Logpush on Enterprise plans.Source 2
Choose Gemini Enterprise Agent Platform if
- You want to build, deploy, and govern agents on one platform, with Agent Studio and the open-source Agent Development Kit.Source 4, Source 36
- You want a registry of the agents themselves, which can register agents on supported Google Cloud runtimes automatically.Source 6, Source 30
- You want SPIFFE-based identities for agents on supported runtimes, and Agent Gateway blocking connections by default without an IAM grant.Source 7, Source 9
- You want a wide choice of models: Google says Model Garden offers more than 200, including Anthropic’s Claude.Source 4, Source 29
Questions buyers ask
How are agents identified in each one?
A portal identifies the user through Cloudflare Access and their identity provider; autonomous agents can use an Access service token, and their upstream requests then use the admin credential.Source 2, Source 12 Agent Platform can give agents on supported runtimes their own SPIFFE-based Agent Identity.Source 7
Do they support MCP and A2A?
Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; A2A support is not publicly documented.Source 2 Agent Registry catalogs MCP servers and A2A agents, and Agent Gateway carries MCP and A2A traffic.Source 8, Source 9, Source 31 A2A agents on Agent Runtime are in preview.Source 35
Can either one govern agents that run somewhere else?
Remote MCP clients can connect to a portal, which can reach private MCP servers through Cloudflare Tunnel, with Gateway routing on.Source 2, Source 19 Agent Registry lists agents outside Google Cloud by manual registration; Agent Gateway can govern traffic for Agent Runtime and the Gemini Enterprise app.Source 9, Source 33
How is each one priced?
Cloudflare says MCP server portals are available to all Cloudflare customers.Source 13 A separate price for portals is not publicly documented. Google’s Agent Registry is free; skill scanning is billed from January 2027.Source 14 Agent Runtime is $0.085 per vCPU-hour, and gateway egress $0.085 per 15,000 requests.Source 15
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
47 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abcde
Source 2: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344454647
Source 5: Gemini Enterprise Agent Platform (formerly Vertex AI) Back:abcd
Source 12: Service token support for MCP server portals · Changelog Back:abcde
Source 13: MCP server portals are now generally available · Changelog Back:abcdef
Source 15: Gemini Enterprise Agent Platform pricing Back:abcde
Source 17: Gemini Enterprise Agent Platform release notes Back:abcde
Source 18: Build Agents on Cloudflare · Cloudflare Agents docs Back:ab
Source 19: Private MCP server support for MCP server portals · Changelog Back:abc
Source 21: Cloudflare Tunnel · Cloudflare One docs Back to text
Source 22: Service tokens · Cloudflare One docs Back to text
Source 26: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 27: Google Cloud Platform Services in Scope by Compliance Program Back:ab
Source 29: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Back:abc
Source 32: MCP Portal Logs · Cloudflare Logs docs Back to text
Source 36: Build with Gemini Enterprise Agent Platform Back:abc
Source 37: Supported locations for agents in Agent Platform Back to text
Source 38: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab