Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs IBM watsonx Orchestrate
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
IBM watsonx Orchestrate
Agent management platform to build, deploy, orchestrate, and govern AI agents
Short answer
Cloudflare MCP server portals put multiple MCP servers behind one governed endpoint that proxies tool calls, while IBM describes watsonx Orchestrate as a platform to build, deploy, and govern AI agents.Source 1, Source 2, Source 3 Portals decide who can use which MCP tools through them; Orchestrate runs agents and connects them to other agents over A2A.Source 1, Source 4, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both give admins central policy and logs: portal admins choose each portal’s MCP tools, and Orchestrate’s controls, outside AWS GovCloud, cover unsafe content, sensitive data, model traffic, and network access.Source 1, Source 2, Source 7, Source 8, Source 9
- Where they differ
- Orchestrate builds and runs agents.Source 4 A portal sits in front of MCP servers, which agents reach as MCP clients; a registry of agents is not publicly documented for portals.Source 1, Source 10
- Running both
- Neither vendor publicly documents using the two together.
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
IBM watsonx Orchestrate
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says its MCP server portals, part of Cloudflare One, put multiple MCP servers behind one HTTP endpoint that agents and other MCP clients connect to.Source 1, Source 10, Source 26 Admins choose the tools each portal exposes and who can connect, and Access logs individual tool requests.Source 1
IBM watsonx Orchestrate
IBM describes watsonx Orchestrate as an agent management platform to build, deploy, orchestrate, manage, and govern AI agents, wherever they are built or run.Source 3 IBM says its Agentic Control Plane observes and governs agents centrally, and that its catalog lists prebuilt and custom agents.Source 13, Source 15, Source 27
The differences that matter
What admins control
Cloudflare MCP server portalsAdmins choose the tools and prompt templates each portal exposes, and Access policies, including groups and device posture checks, decide who connects.Source 1
IBM watsonx OrchestrateOn SaaS outside AWS GovCloud, controls can block unsafe content, protect data, and govern model traffic; agent controls cover native, LangGraph, and A2A agents.Source 7
How agents and tools connect
Cloudflare MCP server portalsAgents and other MCP clients call the portal’s URL, and the portal proxies each tool call to the right upstream server.Source 1, Source 10
IBM watsonx OrchestrateOrchestrate calls external agents at their endpoints, over A2A or an OpenAI-style chat completions API, and imports tools from MCP servers.Source 5, Source 6, Source 28, Source 29
For private MCP servers using OAuth, the authorization server’s endpoints must be public.Source 1 A mode where external agents connect out to Orchestrate, with no reachable endpoint, is not publicly documented.
Remote and partner agents
Cloudflare MCP server portalsPortals can include third-party MCP servers, and Cloudflare One can sign in people from several identity providers, which Cloudflare suggests for partners.Source 2, Source 30
IBM watsonx OrchestrateExcept on premises, partner A2A agents from IBM’s catalog can be collaborators.Source 6 A connection sets how Orchestrate authenticates to an external A2A agent.Source 31
For both, how another organization keeps control of its own agents once they are brought in, beyond issuing credentials, is not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | IBM watsonx Orchestrate | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One, its SASE platform.Source 26 They put multiple MCP servers behind one HTTP endpoint, with Access governing MCP.Source 1, Source 2 | IBM calls it an agent management platform to build, deploy, orchestrate, manage, and govern AI agents wherever built or run, for IT, security, and AI leaders.Source 3 |
| Maturity | GA since 24 September 2026, after an open beta announced in August 2025.Source 20, Source 22 Once called Agents Gateway in some contexts.Source 1 | IBM said watsonx Orchestrate’s unified release was GA in January 2024; the Agentic Control Plane followed in June 2026.Source 23, Source 24 Some dashboards and AI Gateway: preview.Source 15, Source 25 |
| Control | ||
| Agent registry and discovery | Admins add third-party and internal MCP servers to Cloudflare Access, up to 80 per portal.Source 1, Source 2 A registry of agents is not publicly documented. | IBM says its catalog of prebuilt and custom agents and tools can be searched.Source 27 AI Gateway’s agent directory (preview) holds imported external agents.Source 25, Source 38 |
| Identity and access control | People sign in through Access with their identity provider; agents and bots can use a service token.Source 1, Source 10 Policies set who can reach the portal.Source 1 | Platform SSO over OIDC or SAML, with user, builder, and admin roles.Source 18, Source 43 Existing authentication uses impersonation; agent identity is in private preview.Source 12, Source 19 |
| Ownership, policy, and revocation | Admins pick each portal’s tools and prompt templates; turned-off tools can’t be called through it.Source 1 Service tokens can be turned off or deleted.Source 36 | On SaaS outside AWS GovCloud, controls can block unsafe content, protect data, govern model traffic, and limit network access.Source 7 Agent owners: private preview.Source 19 |
| Audit log and observability | Access logs individual tool requests, viewable per portal or server.Source 1 Logpush exports to a SIEM, on Enterprise plans, record the user’s email and tool name.Source 1, Source 39 | Traces give a high-level view of a request, also for registered external agents.Source 44, Source 45 Audit events can go to IBM Cloud destinations, or S3 and CloudWatch on AWS.Source 8, Source 9 |
| Connection | ||
| How agents connect | MCP clients use the portal’s HTTPS URL, and it proxies each tool call.Source 1 Private servers join via outbound-only Cloudflare Tunnel, with Gateway routing on.Source 1, Source 32, Source 33 | Calls external agents at running, accessible endpoints.Source 6, Source 28 IBM lists outbound IPs to allowlist.Source 16 On IBM Cloud: private endpoints and a Satellite TLS tunnel.Source 34, Source 35 |
| Agents across organizations | Third-party MCP servers can be added; Cloudflare One can use several identity providers for partners.Source 2, Source 30 Partner-controlled agents: not publicly documented. | Except on premises, partner A2A agents from IBM’s catalog can be collaborators.Source 6 A connection sets how Orchestrate authenticates to an external A2A agent.Source 31 |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 1 A2A support is not publicly documented. | Calls external A2A agents over JSON-RPC 2.0 only, and exposes its own through A2A endpoints.Source 5, Source 46 Imports MCP server tools; OAuth 2.1 and DCR aren’t supported.Source 29 |
| Frameworks, models, and clouds supported | MCP clients that support remote MCP servers.Source 1 Some MCP servers reject proxy clients such as portals, and stdio-only servers can’t be added.Source 1 | IBM says it supports native, Langflow, LangGraph, and A2A agents.Source 47 Agents with OpenAI-style chat endpoints, and Copilot Studio agents, can be added.Source 5 |
| Operations | ||
| Deployment options and data residency | A proxied hostname on a domain you have on Cloudflare, pointing to gateway.agents.cloudflare.com.Source 1 Self-hosting a portal is not publicly documented. | Managed SaaS in AWS and IBM Cloud regions, or on premises on IBM Cloud Pak for Data or IBM Software Hub.Source 16, Source 17 The control plane isn’t supported in AWS GovCloud (US).Source 15 |
| Compliance attestations | Super Administrators can get PCI, SOC 2, ISO, and other compliance documents in the dashboard.Source 40 Which ones cover portals is not publicly documented. | IBM says watsonx Orchestrate is FedRAMP authorized, deployed on AWS GovCloud (US).Source 41 IBM says the company holds ISO/IEC 27001:2022.Source 42 Premium: HIPAA-ready option.Source 21 |
| Support and SLA | Support varies by Zero Trust plan, with professional services as Contract add-ons.Source 48 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.Source 48 | On AWS, IBM states a 99.9% availability SLA.Source 49 On IBM Cloud, it points to the base IBM Cloud Service Description for the SLA.Source 50 Support cases can be opened.Source 51 |
| Time and effort to get running | Needs a domain on Cloudflare and an identity provider on Zero Trust.Source 1 Then add MCP servers, create a portal with tools and policies, and connect users.Source 1 | IBM’s admin guide covers setup and user access; platform SSO is set up with IBM.Source 18, Source 52 AI Gateway discovery, in preview, needs a platform connection.Source 25 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 20 A separate price for portals is not publicly documented. | Essentials from $530 and Standard from $6,360 USD a month, sized by active users and messages; Premium on request.Source 21 A 30-day free trial.Source 21 |
| Building | ||
| Agent building tools | Cloudflare’s separate Agents SDK is for building and hosting agents, and MCP servers can be built on Workers.Source 2, Source 53 A no-code builder is not publicly documented. | IBM says it offers a drag-and-drop visual builder.Source 11 Its Agent Development Kit is a Python library and CLI.Source 4 IBM says Langflow workflows can become tools.Source 11 |
| Model access | Models included with or required by portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across providers.Source 54 | IBM-hosted and third-party models, varying by cloud and region.Source 55 Most regions default to GPT-OSS 120B via Groq.Source 55 Other providers’ models can be registered.Source 56 |
| Integrations and ecosystem | Connection steps for Claude Desktop, Workers AI Playground, OpenCode, Windsurf, and other MCP clients.Source 1 Portals can be managed with Terraform.Source 1 | IBM says its catalog of IBM and partner agents shows how each connects to systems like Microsoft 365, Salesforce, and SAP.Source 27 Partners join via IBM Agent Connect.Source 57 |
Which to choose
Choose Cloudflare MCP server portals if
- Your people and agents already use MCP clients, such as Claude Desktop or Windsurf, and need one endpoint for multiple MCP servers.Source 1, Source 10
- You use Cloudflare One, which Cloudflare says includes portals, and want Access selectors like groups and device posture enforced on portal servers.Source 1, Source 26
- You want to choose the tools and prompt templates each portal offers; tools you turn off can’t be called through it.Source 1
- You want tool-call logs with the user’s email and tool name in your SIEM, through Logpush on an Enterprise plan.Source 1, Source 39
Choose IBM watsonx Orchestrate if
- You want to build and govern agents: IBM says it has a drag-and-drop visual builder, plus the Agent Development Kit.Source 4, Source 7, Source 11
- You need to run it on premises, where IBM says some agent controls aren’t available, or as managed SaaS.Source 16, Source 17, Source 58
- You want agents built elsewhere in one place, including LangGraph and A2A agents, and any with an OpenAI-style chat completions endpoint.Source 5, Source 7, Source 14
- You want a catalog that IBM says lists prebuilt IBM and partner agents and shows how each connects to systems like SAP.Source 27
Questions buyers ask
Does Cloudflare MCP server portals keep a registry of agents?
Can IBM watsonx Orchestrate discover agents on other platforms?
In preview, AI Gateway can discover agents registered in Amazon Bedrock AgentCore, Gemini Enterprise Agent Platform, and Azure AI Foundry, and import selected ones into its agent directory.Source 25, Source 38, Source 59, Source 60, Source 61 It is in preview and not available in three regions, including AWS GovCloud (US).Source 25
How is each one priced?
Do they support MCP and A2A?
Portals proxy MCP tool calls between MCP clients and upstream MCP servers; A2A support is not publicly documented.Source 1 Orchestrate imports tools from MCP servers, but not with OAuth 2.1 or Dynamic Client Registration.Source 29 It calls external A2A agents and exposes its agents through A2A endpoints.Source 5, Source 46
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
68 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344454647
Source 2: MCP governance · Cloudflare Agents docs Back:abcdefg
Source 4: Welcome to IBM watsonx Orchestrate Agent Development Kit Back:abcdef
Source 5: Connect to external agents (watsonx Orchestrate ADK docs) Back:abcdef
Source 10: Service token support for MCP server portals · Changelog Back:abcdefgh
Source 11: AI Agent Builder | IBM watsonx Orchestrate Back:abcd
Source 13: AI Agent Control Plane | IBM watsonx Orchestrate Back:ab
Source 14: Overview - Agents (watsonx Orchestrate ADK docs) Back:ab
Source 16: Regional availability and outbound IP addresses Back:abcd
Source 17: Installing on IBM watsonx Orchestrate On-premises Back:abc
Source 19: Prerequisites for configuring agent identity Back:abcde
Source 20: MCP server portals are now generally available · Changelog Back:abcde
Source 23: The AI Assistant for everyone: watsonx Orchestrate combines generative AI and automation to boost productivity | IBM Back:ab
Source 24: Agentic Control Plane in IBM watsonx Orchestrate: One place to control every AI agent Back:ab
Source 26: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abc
Source 28: Adding agents from third-party platforms Back:abc
Source 32: Private MCP server support for MCP server portals · Changelog Back:ab
Source 37: List of events for activity tracking Back to text
Source 40: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 41: IBM Expands FedRAMP Portfolio with Authorization of 11 Software Solutions, Including watsonx Back:ab
Source 42: ISO 27001 - IBM Corporation Certificate (Bureau Veritas, ISO/IEC 27001:2022) Back:ab
Source 44: Overview - Traces (watsonx Orchestrate ADK docs) Back to text
Source 45: Exporting observability traces with OpenTelemetry (watsonx Orchestrate ADK docs) Back to text
Source 47: Manage all your AI agents in one place with watsonx Orchestrate Back to text
Source 48: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 49: High availability, business continuity, backups and disaster recovery on AWS Back to text
Source 50: Licenses and entitlements for watsonx Orchestrate on IBM Cloud Back to text
Source 53: Build Agents on Cloudflare · Cloudflare Agents docs Back to text
Source 56: Choosing your LLM (watsonx Orchestrate ADK docs) Back to text
Source 57: IBM Agent Connect (watsonx Orchestrate ADK docs) Back to text
Source 59: Connecting and configuring Amazon Bedrock Back to text
Source 60: Connecting and configuring Gemini Enterprise Agent Platform Back to text
Source 61: Connecting and configuring Microsoft Azure AI Foundry Back to text