Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs Gemini Enterprise Agent Platform

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

Gemini Enterprise Agent Platform

Google Cloud platform to build, deploy, govern, and optimize AI agents

Short answer

Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents.⁠Source 1, Source 2, Source 3, Source 4, Source 5 Portals control who reaches which MCP tools; Agent Platform catalogs agents and tools, and can give agents on supported runtimes their own identity.⁠Source 2, Source 6, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both put policy in front of MCP servers and log requests: portals through Cloudflare Access, Agent Platform through Agent Registry and Agent Gateway.⁠Source 2, Source 3, Source 8, Source 9, Source 10
Where they differ
Teams can also build and run agents on Agent Platform, which catalogs agents as well as tools.⁠Source 4, Source 6, Source 9 For portals, a registry of agents and A2A support are not publicly documented.
Running both
Neither vendor publicly documents using the two together. Cloudflare’s portals accept remote MCP clients; Google’s Agent Gateway can apply access rules to agents’ calls to third-party MCP servers.⁠Source 2, Source 9
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 2
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 2
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 2
  • Agents across organizations: Not publicly documented

Gemini Enterprise Agent Platform

  • Build agents: OfferedAgent Studio low-code canvas⁠Source 4
  • Host and run agents: OfferedAgent Runtime⁠Source 9
  • Identity and access: OfferedSPIFFE-based Agent Identity⁠Source 7
  • Registry and governance: OfferedAgent Registry⁠Source 6
  • Traffic between agents, tools, and models: OfferedAgent Gateway⁠Source 9
  • Agents across organizations: OfferedGateway calls to outside agents⁠Source 9

At a glance

TopicCloudflare MCP server portalsGemini Enterprise Agent Platform
What it isPuts multiple MCP servers behind one HTTP endpoint.⁠Source 2 Cloudflare says portals are part of Cloudflare One.⁠Source 1Google Cloud’s platform to build, deploy, govern, and optimize AI agents, described as an evolution of Vertex AI.⁠Source 4, Source 5
What it governsMCP servers and their tools, up to 80 servers per portal.⁠Source 2 A registry of agents is not publicly documented.Agents, MCP servers, and tools, cataloged in Agent Registry per Google Cloud project.⁠Source 6, Source 11
Agent identityAn agent connects with its user’s identity provider login through Cloudflare Access, or with an Access service token.⁠Source 2, Source 12Agent Identity: agents on a supported runtime, such as Agent Runtime or Cloud Run, can each have a SPIFFE-based identity.⁠Source 7
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 13 A separate price for portals is not publicly documented.Agent Registry is free; skill scanning is billed from January 2027.⁠Source 14 Agent Runtime is billed per vCPU-hour and GiB-hour of memory.⁠Source 15 Agent Gateway egress is billed at $0.085 per 15,000 requests.⁠Source 15
Generally availableSince 24 September 2026, after an open beta announced in August 2025.⁠Source 13, Source 16Agent Registry and Agent Gateway since 18 June 2026.⁠Source 17

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.⁠Source 1 A portal puts MCP servers that admins add to Cloudflare Access behind one URL for MCP clients.⁠Source 2 Access policies decide who connects, and Access logs each tool request.⁠Source 2

Gemini Enterprise Agent Platform

Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents, an evolution of Vertex AI.⁠Source 4, Source 5 Agent Registry catalogs agents and tools, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway applies policy checks to traffic.⁠Source 6, Source 7, Source 9, Source 17

The differences that matter

  1. What gets governed

    Cloudflare MCP server portals

    MCP servers and their tools: admins add servers to Access and choose which tools and prompt templates each portal exposes.⁠Source 2

    Gemini Enterprise Agent Platform

    Agents, MCP servers, and tools: Agent Registry catalogs all three, and agents on supported runtimes can get SPIFFE-based identities.⁠Source 6, Source 7

    Agents reach a portal as MCP clients, with a user’s identity provider login or an Access service token.⁠Source 2, Source 12

  2. Building and running agents

    Cloudflare MCP server portals

    A portal proxies tool calls between MCP clients and MCP servers.⁠Source 2 Building and hosting agents on Cloudflare is covered separately, in its Agents docs.⁠Source 18

    Gemini Enterprise Agent Platform

    Teams can build agents with Agent Studio or the Agent Development Kit, run them on Agent Runtime, and use over 200 models.⁠Source 4, Source 9

  3. Where policy is enforced

    Cloudflare MCP server portals

    At the portal, where Access policies decide who connects; private MCP servers can join through Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 19

    Gemini Enterprise Agent Platform

    At Agent Gateway, a managed, regional component, for Agent Runtime and the Gemini Enterprise app; Model Armor can scan prompts and tool responses.⁠Source 9, Source 20

    For a private MCP server that uses OAuth, the authorization and token endpoints must be reachable on the public internet.⁠Source 2 Agent Gateway’s inbound mode supports only Agent Runtime agents.⁠Source 9

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsGemini Enterprise Agent Platform
Network exposureMCP clients reach the portal’s HTTPS URL.⁠Source 2 Private MCP servers can connect through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 21Agent Gateway can front Agent Runtime agents for inbound calls, and checks outbound calls against IAM access policies.⁠Source 9
IdentityAccess sign-in through your identity provider, or an Access service token for agents.⁠Source 2, Source 12 Independent MFA isn’t enforced for portal-authorized servers.⁠Source 2Agent Identity is generally available; its API is in preview.⁠Source 17 It can give agents on supported runtimes SPIFFE-based identities.⁠Source 7
Access changes and revocationDeleting a service token revokes it.⁠Source 22 Blocked users can use direct server URLs; Cloudflare advises making Access the OAuth provider.⁠Source 2Deny rules override allow rules.⁠Source 23 Deleting an agent leaves IAM bindings naming it, which must be removed by hand.⁠Source 7
Audit trailAccess logs each request made with a portal’s tools.⁠Source 2 Logpush export to a SIEM is on Enterprise plans only.⁠Source 2Registry admin changes are logged; other calls need Data Access logs on.⁠Source 24, Source 25 Agent Identity adds audit logs for agent actions.⁠Source 7
ComplianceSuper Administrators can get Cloudflare’s PCI, SOC 2, and ISO documents.⁠Source 26 Their scope for portals is not publicly documented.Listed in scope for ISO 27001, SOC 1, 2, and 3, and PCI DSS, and in Google Cloud’s HIPAA BAA.⁠Source 27, Source 28

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and Gemini Enterprise Agent Platform compared on 18 criteria
Cloudflare MCP server portalsGemini Enterprise Agent Platform
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One, its SASE platform.⁠Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, governed through Access.⁠Source 2, Source 3Google Cloud platform to build, deploy, govern, and optimize AI agents, which Google calls an evolution of Vertex AI, for developers and technical teams.⁠Source 4, Source 5
MaturityGA since 24 September 2026, after an open beta announced 26 August 2025.⁠Source 13, Source 16 Once called Agents Gateway, a different product from Google’s Agent Gateway.⁠Source 2Google says it launched 22 April 2026.⁠Source 29 Registry and Gateway GA since 18 June 2026.⁠Source 17 Agent Identity is generally available; the Agent Identity API is in preview.⁠Source 17
Control
Agent registry and discoveryAdmins add MCP servers to Cloudflare Access for central management, up to 80 per portal.⁠Source 2 A registry of agents is not publicly documented.Agent Registry: a per-project catalog of agents, MCP servers, and tools.⁠Source 6, Source 11 Agents on supported runtimes can be registered automatically, others manually.⁠Source 30, Source 31
Identity and access controlSign-in through Access with an identity provider, or an Access service token.⁠Source 2, Source 12 Policies can match emails, groups, country, and device posture checks.⁠Source 2Agents on supported runtimes can each have a SPIFFE-based identity.⁠Source 7 By default, Agent Gateway blocks connections without an IAM policy grant.⁠Source 9
Ownership, policy, and revocationAdmins pick each portal’s tools and prompt templates; turned-off tools can’t be called through it.⁠Source 2 An owner field is not publicly documented.Allow and deny access policies (deny overrides allow), enforce and dry-run modes, and Model Armor filters.⁠Source 9, Source 23 An agent owner field is not publicly documented.
Audit log and observabilityAccess logs each tool request, viewable per portal or per server.⁠Source 2 Exported logs record the user’s email and tool called; Logpush is Enterprise-plan only.⁠Source 2, Source 32Registry admin changes get Admin Activity audit logs; other calls need Data Access logs turned on.⁠Source 24, Source 25 Gateway logs record access requests.⁠Source 10
Connection
How agents connectMCP clients connect to the portal’s HTTPS URL, and it proxies each tool call.⁠Source 2 Private servers join via Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 19Agent Gateway can govern traffic in and out of Agent Runtime, and out of the Gemini Enterprise app.⁠Source 9 Outside agents can be registered by endpoint or agent card.⁠Source 33
Agents across organizationsCloudflare One can use several identity providers at once, for partners or contractors.⁠Source 34 Federating other organizations’ agents: not publicly documented.Agent Runtime agents can call agents anywhere via Agent Gateway.⁠Source 9 Federating other organizations’ agents: not publicly documented.
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 2 A2A support is not publicly documented.Agent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.⁠Source 8, Source 9, Source 31 A2A agents on Agent Runtime are in preview.⁠Source 35
Frameworks, models, and clouds supportedWorks with MCP clients that support remote servers.⁠Source 2 Stdio-only servers can’t be added, and some servers reject proxy-based clients like portals.⁠Source 2Built with the Agent Development Kit or any open-source framework, using Gemini or Model Garden models.⁠Source 36 Agents outside Google Cloud can be registered manually.⁠Source 33
Operations
Deployment options and data residencyA portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 2 Self-hosting a portal is not publicly documented.Managed, regional Agent Gateway; agent infrastructure data rests in the selected supported location.⁠Source 20, Source 37 Self-hosted registry or gateway: not publicly documented.
Compliance attestationsCompany-wide, Super Administrators can get PCI, SOC 2, ISO, and other documents in the dashboard.⁠Source 26 Portal-specific scope is not publicly documented.Google lists Agent Platform in scope for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS, and in the Google Cloud HIPAA BAA.⁠Source 27, Source 28
Support and SLASupport options vary by Zero Trust plan; professional services are Contract add-ons.⁠Source 38 Cloudflare advertises a 100% uptime SLA for paid Zero Trust plans.⁠Source 38Google Cloud support packages, including 24/7 coverage.⁠Source 39 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime is not publicly documented.
Time and effort to get runningNeeds a domain on Cloudflare and an identity provider in Zero Trust.⁠Source 2 Then add MCP servers, create a portal with tools and policies, and connect clients.⁠Source 2A Google Cloud project with the Agent Registry API enabled, plus the Identity-Aware Proxy API for gateway policy.⁠Source 11 Google recommends dry-run mode in staging.⁠Source 23
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 13 A separate price for portals is not publicly documented.Agent Registry is free; skill scanning is billed from January 2027.⁠Source 14 Agent Runtime: $0.085 per vCPU-hour.⁠Source 15 Agent Gateway egress: $0.085 per 15,000 requests.⁠Source 15
Building
Agent building toolsSeparately from portals, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Workers.⁠Source 3, Source 18Agent Studio (a low-code canvas), the open-source Agent Development Kit, and Agent Garden prebuilt agents and templates.⁠Source 4, Source 36 A Managed Agents API is in preview.⁠Source 4
Model accessNot publicly documented for portals. Cloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 40More than 200 models, including Gemini, third-party, and open-source models.⁠Source 4 Google says Model Garden supports Anthropic’s Claude.⁠Source 29
Integrations and ecosystemPortals can be managed with Terraform.⁠Source 2 Cloudflare One supports social, open source, and corporate identity providers.⁠Source 34 A marketplace is not publicly documented.Agents in Agent Registry can be made available in Google’s Gemini Enterprise app.⁠Source 20 Google’s own remote MCP servers are registered automatically.⁠Source 8

Which to choose

Choose Cloudflare MCP server portals if

  • You want many MCP servers behind one endpoint that MCP clients such as Claude Desktop or Windsurf can connect to.⁠Source 2
  • You already use Cloudflare One, which Cloudflare says includes portals, now generally available to all Cloudflare customers.⁠Source 1, Source 13
  • You want Access policies on MCP use, matching emails, groups, country, and device posture, and per-portal control of which tools appear.⁠Source 2
  • You want tool-request logs per portal or per server, exportable to a SIEM with Logpush on Enterprise plans.⁠Source 2

Choose Gemini Enterprise Agent Platform if

  • You want to build, deploy, and govern agents on one platform, with Agent Studio and the open-source Agent Development Kit.⁠Source 4, Source 36
  • You want a registry of the agents themselves, which can register agents on supported Google Cloud runtimes automatically.⁠Source 6, Source 30
  • You want SPIFFE-based identities for agents on supported runtimes, and Agent Gateway blocking connections by default without an IAM grant.⁠Source 7, Source 9
  • You want a wide choice of models: Google says Model Garden offers more than 200, including Anthropic’s Claude.⁠Source 4, Source 29

Questions buyers ask

How are agents identified in each one?

A portal identifies the user through Cloudflare Access and their identity provider; autonomous agents can use an Access service token, and their upstream requests then use the admin credential.⁠Source 2, Source 12 Agent Platform can give agents on supported runtimes their own SPIFFE-based Agent Identity.⁠Source 7

Do they support MCP and A2A?

Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; A2A support is not publicly documented.⁠Source 2 Agent Registry catalogs MCP servers and A2A agents, and Agent Gateway carries MCP and A2A traffic.⁠Source 8, Source 9, Source 31 A2A agents on Agent Runtime are in preview.⁠Source 35

Can either one govern agents that run somewhere else?

Remote MCP clients can connect to a portal, which can reach private MCP servers through Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 19 Agent Registry lists agents outside Google Cloud by manual registration; Agent Gateway can govern traffic for Agent Runtime and the Gemini Enterprise app.⁠Source 9, Source 33

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 13 A separate price for portals is not publicly documented. Google’s Agent Registry is free; skill scanning is billed from January 2027.⁠Source 14 Agent Runtime is $0.085 per vCPU-hour, and gateway egress $0.085 per 15,000 requests.⁠Source 15

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

47 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abcde

  2. Source 2: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344454647

  3. Source 3: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcd

  4. Source 4: Agent Platform overview Google · checked Back:abcdefghijkl

  5. Source 5: Gemini Enterprise Agent Platform (formerly Vertex AI) Google · checked Back:abcd

  6. Source 6: Agent Registry overview Google · checked Back:abcdefgh

  7. Source 7: Agent Identity overview Google · checked Back:abcdefghijk

  8. Source 8: Register MCP servers Google · checked Back:abcd

  9. Source 9: Agent Gateway overview Google · checked Back:abcdefghijklmnopqrs

  10. Source 10: Monitor traffic through Agent Gateway Google · checked Back:ab

  11. Source 11: Set up Agent Registry Google · checked Back:abc

  12. Source 12: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcde

  13. Source 13: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcdef

  14. Source 14: Agent Registry pricing Google · checked Back:abc

  15. Source 15: Gemini Enterprise Agent Platform pricing Google · checked Back:abcde

  16. Source 16: MCP server portals · Changelog Cloudflare · checked Back:ab

  17. Source 17: Gemini Enterprise Agent Platform release notes Google · checked Back:abcde

  18. Source 18: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back:ab

  19. Source 19: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:abc

  20. Source 20: Import A2A agents from Agent Registry Google · checked Back:abc

  21. Source 21: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back to text

  22. Source 22: Service tokens · Cloudflare One docs Cloudflare · checked Back to text

  23. Source 23: IAM Access policies overview Google · checked Back:abc

  24. Source 24: Agent Registry audit logging Google · checked Back:ab

  25. Source 25: Cloud Audit Logs overview Google · checked Back:ab

  26. Source 26: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  27. Source 27: Google Cloud Platform Services in Scope by Compliance Program Google · checked Back:ab

  28. Source 28: HIPAA compliance on Google Cloud Google · checked Back:ab

  29. Source 29: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Google · checked Back:abc

  30. Source 30: Use automatic registration Google · checked Back:ab

  31. Source 31: Register agents Google · checked Back:abc

  32. Source 32: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back to text

  33. Source 33: Use manual registration Google · checked Back:abc

  34. Source 34: Identity providers · Cloudflare One docs Cloudflare · checked Back:ab

  35. Source 35: Create an Agent2Agent agent Google · checked Back:ab

  36. Source 36: Build with Gemini Enterprise Agent Platform Google · checked Back:abc

  37. Source 37: Supported locations for agents in Agent Platform Google · checked Back to text

  38. Source 38: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  39. Source 39: Getting help for agents Google · checked Back to text

  40. Source 40: AI Security | Cloudflare Cloudflare · checked Back to text

  41. Source 41: Why Blocks? Blocks.ai · checked Back to text

  42. Source 42: What is Blocks? Blocks.ai · checked Back to text

  43. Source 43: Your company's private network Blocks.ai · checked Back to text

  44. Source 44: Network requirements Blocks.ai · checked Back to text

  45. Source 45: Solutions: Agent sprawl Blocks.ai · checked Back to text

  46. Source 46: Solutions: Partner networks Blocks.ai · checked Back to text

  47. Source 47: Pricing Blocks.ai · checked Back to text