Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs IBM watsonx Orchestrate

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

IBM watsonx Orchestrate

Agent management platform to build, deploy, orchestrate, and govern AI agents

Short answer

Cloudflare MCP server portals put multiple MCP servers behind one governed endpoint that proxies tool calls, while IBM describes watsonx Orchestrate as a platform to build, deploy, and govern AI agents.⁠Source 1, Source 2, Source 3 Portals decide who can use which MCP tools through them; Orchestrate runs agents and connects them to other agents over A2A.⁠Source 1, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both give admins central policy and logs: portal admins choose each portal’s MCP tools, and Orchestrate’s controls, outside AWS GovCloud, cover unsafe content, sensitive data, model traffic, and network access.⁠Source 1, Source 2, Source 7, Source 8, Source 9
Where they differ
Orchestrate builds and runs agents.⁠Source 4 A portal sits in front of MCP servers, which agents reach as MCP clients; a registry of agents is not publicly documented for portals.⁠Source 1, Source 10
Running both
Neither vendor publicly documents using the two together.
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 1
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 1
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 1
  • Agents across organizations: Not publicly documented

IBM watsonx Orchestrate

  • Build agents: OfferedVisual builder and ADK⁠Source 11
  • Host and run agents: OfferedAgents run on watsonx Orchestrate⁠Source 4
  • Identity and access: PreviewAgent identity⁠Source 12
  • Registry and governance: OfferedAgentic Control Plane⁠Source 13
  • Traffic between agents, tools, and models: OfferedA2A calls to agent endpoints⁠Source 6
  • Agents across organizations: OfferedPartner A2A agents in catalog⁠Source 6

At a glance

TopicCloudflare MCP server portalsIBM watsonx Orchestrate
What it managesMCP servers and their tools: which ones a portal exposes, and who can use them through it.⁠Source 1AI agents, built on it or brought in from other platforms, with a central control plane.⁠Source 4, Source 14, Source 15
Where it runsAt a proxied hostname on a domain you have on Cloudflare, pointing to gateway.agents.cloudflare.com.⁠Source 1Managed SaaS on AWS or IBM Cloud, or on premises on IBM Cloud Pak for Data or IBM Software Hub.⁠Source 16, Source 17
IdentityPeople sign in with their identity provider through Cloudflare Access; agents and bots can use an Access service token.⁠Source 1, Source 10People can sign in through platform SSO over OIDC or SAML.⁠Source 18 Existing authentication types use an impersonation model; agent identity through IBM Verify or Microsoft Entra is in private preview.⁠Source 12, Source 19
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 20 A separate price for portals is not publicly documented.Monthly plans sized by active users and messages: Essentials from $530 and Standard from $6,360 USD; Premium on request.⁠Source 21 A 30-day free trial.⁠Source 21
AvailabilityGenerally available since 24 September 2026, after an open beta announced in August 2025.⁠Source 20, Source 22IBM said the unified release of watsonx Orchestrate was generally available in January 2024; the Agentic Control Plane followed in June 2026.⁠Source 23, Source 24 AI Gateway is in preview, and agent identity in private preview.⁠Source 19, Source 25

What each one is

Cloudflare MCP server portals

Cloudflare says its MCP server portals, part of Cloudflare One, put multiple MCP servers behind one HTTP endpoint that agents and other MCP clients connect to.⁠Source 1, Source 10, Source 26 Admins choose the tools each portal exposes and who can connect, and Access logs individual tool requests.⁠Source 1

IBM watsonx Orchestrate

IBM describes watsonx Orchestrate as an agent management platform to build, deploy, orchestrate, manage, and govern AI agents, wherever they are built or run.⁠Source 3 IBM says its Agentic Control Plane observes and governs agents centrally, and that its catalog lists prebuilt and custom agents.⁠Source 13, Source 15, Source 27

The differences that matter

  1. What admins control

    Cloudflare MCP server portals

    Admins choose the tools and prompt templates each portal exposes, and Access policies, including groups and device posture checks, decide who connects.⁠Source 1

    IBM watsonx Orchestrate

    On SaaS outside AWS GovCloud, controls can block unsafe content, protect data, and govern model traffic; agent controls cover native, LangGraph, and A2A agents.⁠Source 7

  2. How agents and tools connect

    Cloudflare MCP server portals

    Agents and other MCP clients call the portal’s URL, and the portal proxies each tool call to the right upstream server.⁠Source 1, Source 10

    IBM watsonx Orchestrate

    Orchestrate calls external agents at their endpoints, over A2A or an OpenAI-style chat completions API, and imports tools from MCP servers.⁠Source 5, Source 6, Source 28, Source 29

    For private MCP servers using OAuth, the authorization server’s endpoints must be public.⁠Source 1 A mode where external agents connect out to Orchestrate, with no reachable endpoint, is not publicly documented.

  3. Remote and partner agents

    Cloudflare MCP server portals

    Portals can include third-party MCP servers, and Cloudflare One can sign in people from several identity providers, which Cloudflare suggests for partners.⁠Source 2, Source 30

    IBM watsonx Orchestrate

    Except on premises, partner A2A agents from IBM’s catalog can be collaborators.⁠Source 6 A connection sets how Orchestrate authenticates to an external A2A agent.⁠Source 31

    For both, how another organization keeps control of its own agents once they are brought in, beyond issuing credentials, is not publicly documented.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsIBM watsonx Orchestrate
Network exposureMCP clients use the portal’s HTTPS URL.⁠Source 1 Private MCP servers can connect through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 32, Source 33Agents hosted elsewhere need an accessible endpoint.⁠Source 28 On IBM Cloud, private endpoints and a Satellite TLS tunnel are documented.⁠Source 34, Source 35
IdentityPeople sign in with their identity provider.⁠Source 1 Agents can use a service token; its upstream requests use the admin credential.⁠Source 1, Source 10Existing authentication types use an impersonation model; agent identity through IBM Verify or Microsoft Entra is in private preview.⁠Source 12, Source 19
Access changes and revocationDeleted service tokens lose access.⁠Source 36 Blocked users can reach a server’s direct URL; Cloudflare advises making Access its OAuth provider.⁠Source 1On IBM Cloud, undeploying a released agent version is logged; agents removed from AI Gateway’s directory (preview) can’t be collaborators.⁠Source 37, Source 38
Audit trailAccess logs individual tool requests.⁠Source 1 Logpush exports, on Enterprise plans only, record the user’s email and the tool called.⁠Source 1, Source 39Audit events can be routed to destinations you choose on IBM Cloud, or to your S3 and CloudWatch on AWS.⁠Source 8, Source 9
ComplianceSuper Administrators can get PCI, SOC 2, ISO, and other compliance documents; which cover portals is not publicly documented.⁠Source 40IBM says watsonx Orchestrate is FedRAMP authorized on AWS GovCloud (US).⁠Source 41 IBM says the company holds ISO/IEC 27001:2022.⁠Source 42

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and IBM watsonx Orchestrate compared on 18 criteria
Cloudflare MCP server portalsIBM watsonx Orchestrate
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One, its SASE platform.⁠Source 26 They put multiple MCP servers behind one HTTP endpoint, with Access governing MCP.⁠Source 1, Source 2IBM calls it an agent management platform to build, deploy, orchestrate, manage, and govern AI agents wherever built or run, for IT, security, and AI leaders.⁠Source 3
MaturityGA since 24 September 2026, after an open beta announced in August 2025.⁠Source 20, Source 22 Once called Agents Gateway in some contexts.⁠Source 1IBM said watsonx Orchestrate’s unified release was GA in January 2024; the Agentic Control Plane followed in June 2026.⁠Source 23, Source 24 Some dashboards and AI Gateway: preview.⁠Source 15, Source 25
Control
Agent registry and discoveryAdmins add third-party and internal MCP servers to Cloudflare Access, up to 80 per portal.⁠Source 1, Source 2 A registry of agents is not publicly documented.IBM says its catalog of prebuilt and custom agents and tools can be searched.⁠Source 27 AI Gateway’s agent directory (preview) holds imported external agents.⁠Source 25, Source 38
Identity and access controlPeople sign in through Access with their identity provider; agents and bots can use a service token.⁠Source 1, Source 10 Policies set who can reach the portal.⁠Source 1Platform SSO over OIDC or SAML, with user, builder, and admin roles.⁠Source 18, Source 43 Existing authentication uses impersonation; agent identity is in private preview.⁠Source 12, Source 19
Ownership, policy, and revocationAdmins pick each portal’s tools and prompt templates; turned-off tools can’t be called through it.⁠Source 1 Service tokens can be turned off or deleted.⁠Source 36On SaaS outside AWS GovCloud, controls can block unsafe content, protect data, govern model traffic, and limit network access.⁠Source 7 Agent owners: private preview.⁠Source 19
Audit log and observabilityAccess logs individual tool requests, viewable per portal or server.⁠Source 1 Logpush exports to a SIEM, on Enterprise plans, record the user’s email and tool name.⁠Source 1, Source 39Traces give a high-level view of a request, also for registered external agents.⁠Source 44, Source 45 Audit events can go to IBM Cloud destinations, or S3 and CloudWatch on AWS.⁠Source 8, Source 9
Connection
How agents connectMCP clients use the portal’s HTTPS URL, and it proxies each tool call.⁠Source 1 Private servers join via outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 32, Source 33Calls external agents at running, accessible endpoints.⁠Source 6, Source 28 IBM lists outbound IPs to allowlist.⁠Source 16 On IBM Cloud: private endpoints and a Satellite TLS tunnel.⁠Source 34, Source 35
Agents across organizationsThird-party MCP servers can be added; Cloudflare One can use several identity providers for partners.⁠Source 2, Source 30 Partner-controlled agents: not publicly documented.Except on premises, partner A2A agents from IBM’s catalog can be collaborators.⁠Source 6 A connection sets how Orchestrate authenticates to an external A2A agent.⁠Source 31
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 1 A2A support is not publicly documented.Calls external A2A agents over JSON-RPC 2.0 only, and exposes its own through A2A endpoints.⁠Source 5, Source 46 Imports MCP server tools; OAuth 2.1 and DCR aren’t supported.⁠Source 29
Frameworks, models, and clouds supportedMCP clients that support remote MCP servers.⁠Source 1 Some MCP servers reject proxy clients such as portals, and stdio-only servers can’t be added.⁠Source 1IBM says it supports native, Langflow, LangGraph, and A2A agents.⁠Source 47 Agents with OpenAI-style chat endpoints, and Copilot Studio agents, can be added.⁠Source 5
Operations
Deployment options and data residencyA proxied hostname on a domain you have on Cloudflare, pointing to gateway.agents.cloudflare.com.⁠Source 1 Self-hosting a portal is not publicly documented.Managed SaaS in AWS and IBM Cloud regions, or on premises on IBM Cloud Pak for Data or IBM Software Hub.⁠Source 16, Source 17 The control plane isn’t supported in AWS GovCloud (US).⁠Source 15
Compliance attestationsSuper Administrators can get PCI, SOC 2, ISO, and other compliance documents in the dashboard.⁠Source 40 Which ones cover portals is not publicly documented.IBM says watsonx Orchestrate is FedRAMP authorized, deployed on AWS GovCloud (US).⁠Source 41 IBM says the company holds ISO/IEC 27001:2022.⁠Source 42 Premium: HIPAA-ready option.⁠Source 21
Support and SLASupport varies by Zero Trust plan, with professional services as Contract add-ons.⁠Source 48 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.⁠Source 48On AWS, IBM states a 99.9% availability SLA.⁠Source 49 On IBM Cloud, it points to the base IBM Cloud Service Description for the SLA.⁠Source 50 Support cases can be opened.⁠Source 51
Time and effort to get runningNeeds a domain on Cloudflare and an identity provider on Zero Trust.⁠Source 1 Then add MCP servers, create a portal with tools and policies, and connect users.⁠Source 1IBM’s admin guide covers setup and user access; platform SSO is set up with IBM.⁠Source 18, Source 52 AI Gateway discovery, in preview, needs a platform connection.⁠Source 25
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 20 A separate price for portals is not publicly documented.Essentials from $530 and Standard from $6,360 USD a month, sized by active users and messages; Premium on request.⁠Source 21 A 30-day free trial.⁠Source 21
Building
Agent building toolsCloudflare’s separate Agents SDK is for building and hosting agents, and MCP servers can be built on Workers.⁠Source 2, Source 53 A no-code builder is not publicly documented.IBM says it offers a drag-and-drop visual builder.⁠Source 11 Its Agent Development Kit is a Python library and CLI.⁠Source 4 IBM says Langflow workflows can become tools.⁠Source 11
Model accessModels included with or required by portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across providers.⁠Source 54IBM-hosted and third-party models, varying by cloud and region.⁠Source 55 Most regions default to GPT-OSS 120B via Groq.⁠Source 55 Other providers’ models can be registered.⁠Source 56
Integrations and ecosystemConnection steps for Claude Desktop, Workers AI Playground, OpenCode, Windsurf, and other MCP clients.⁠Source 1 Portals can be managed with Terraform.⁠Source 1IBM says its catalog of IBM and partner agents shows how each connects to systems like Microsoft 365, Salesforce, and SAP.⁠Source 27 Partners join via IBM Agent Connect.⁠Source 57

Which to choose

Choose Cloudflare MCP server portals if

  • Your people and agents already use MCP clients, such as Claude Desktop or Windsurf, and need one endpoint for multiple MCP servers.⁠Source 1, Source 10
  • You use Cloudflare One, which Cloudflare says includes portals, and want Access selectors like groups and device posture enforced on portal servers.⁠Source 1, Source 26
  • You want to choose the tools and prompt templates each portal offers; tools you turn off can’t be called through it.⁠Source 1
  • You want tool-call logs with the user’s email and tool name in your SIEM, through Logpush on an Enterprise plan.⁠Source 1, Source 39

Choose IBM watsonx Orchestrate if

  • You want to build and govern agents: IBM says it has a drag-and-drop visual builder, plus the Agent Development Kit.⁠Source 4, Source 7, Source 11
  • You need to run it on premises, where IBM says some agent controls aren’t available, or as managed SaaS.⁠Source 16, Source 17, Source 58
  • You want agents built elsewhere in one place, including LangGraph and A2A agents, and any with an OpenAI-style chat completions endpoint.⁠Source 5, Source 7, Source 14
  • You want a catalog that IBM says lists prebuilt IBM and partner agents and shows how each connects to systems like SAP.⁠Source 27

Questions buyers ask

Does Cloudflare MCP server portals keep a registry of agents?

Portals manage MCP servers: admins add them to Cloudflare Access, up to 80 per portal.⁠Source 1 A registry of agents is not publicly documented. Agents reach a portal as MCP clients, for example with an Access service token.⁠Source 1, Source 10

Can IBM watsonx Orchestrate discover agents on other platforms?

In preview, AI Gateway can discover agents registered in Amazon Bedrock AgentCore, Gemini Enterprise Agent Platform, and Azure AI Foundry, and import selected ones into its agent directory.⁠Source 25, Source 38, Source 59, Source 60, Source 61 It is in preview and not available in three regions, including AWS GovCloud (US).⁠Source 25

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 20 A separate price for portals is not publicly documented. Orchestrate’s Essentials plan starts at $530 USD per month, Standard at $6,360, with a 30-day free trial.⁠Source 21

Do they support MCP and A2A?

Portals proxy MCP tool calls between MCP clients and upstream MCP servers; A2A support is not publicly documented.⁠Source 1 Orchestrate imports tools from MCP servers, but not with OAuth 2.1 or Dynamic Client Registration.⁠Source 29 It calls external A2A agents and exposes its agents through A2A endpoints.⁠Source 5, Source 46

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

68 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344454647

  2. Source 2: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcdefg

  3. Source 3: IBM watsonx Orchestrate IBM · checked Back:abc

  4. Source 4: Welcome to IBM watsonx Orchestrate Agent Development Kit IBM · checked Back:abcdef

  5. Source 5: Connect to external agents (watsonx Orchestrate ADK docs) IBM · checked Back:abcdef

  6. Source 6: Partner A2A (Agent2Agent) agents IBM · checked Back:abcdefg

  7. Source 7: Protecting assets with controls IBM · checked Back:abcde

  8. Source 8: Activity tracking events on IBM Cloud IBM · checked Back:abc

  9. Source 9: Enabling external logging for AWS IBM · checked Back:abc

  10. Source 10: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcdefgh

  11. Source 11: AI Agent Builder | IBM watsonx Orchestrate IBM · checked Back:abcd

  12. Source 12: Agent identity overview IBM · checked Back:abcd

  13. Source 13: AI Agent Control Plane | IBM watsonx Orchestrate IBM · checked Back:ab

  14. Source 14: Overview - Agents (watsonx Orchestrate ADK docs) IBM · checked Back:ab

  15. Source 15: Agentic Control Plane IBM · checked Back:abcd

  16. Source 16: Regional availability and outbound IP addresses IBM · checked Back:abcd

  17. Source 17: Installing on IBM watsonx Orchestrate On-premises IBM · checked Back:abc

  18. Source 18: Configuring SSO for platform access IBM · checked Back:abc

  19. Source 19: Prerequisites for configuring agent identity IBM · checked Back:abcde

  20. Source 20: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcde

  21. Source 21: IBM watsonx Orchestrate Pricing IBM · checked Back:abcdef

  22. Source 22: MCP server portals · Changelog Cloudflare · checked Back:ab

  23. Source 23: The AI Assistant for everyone: watsonx Orchestrate combines generative AI and automation to boost productivity | IBM IBM · checked Back:ab

  24. Source 24: Agentic Control Plane in IBM watsonx Orchestrate: One place to control every AI agent IBM · checked Back:ab

  25. Source 25: Governing assets with AI Gateway IBM · checked Back:abcdef

  26. Source 26: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abc

  27. Source 27: IBM watsonx Orchestrate Agent Catalog IBM · checked Back:abcd

  28. Source 28: Adding agents from third-party platforms IBM · checked Back:abc

  29. Source 29: MCP servers IBM · checked Back:abc

  30. Source 30: Identity providers · Cloudflare One docs Cloudflare · checked Back:ab

  31. Source 31: Adding an agent-to-agent connection IBM · checked Back:ab

  32. Source 32: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:ab

  33. Source 33: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:ab

  34. Source 34: Using private network endpoints IBM · checked Back:ab

  35. Source 35: Configuring TLS tunnel IBM · checked Back:ab

  36. Source 36: Service tokens · Cloudflare One docs Cloudflare · checked Back:ab

  37. Source 37: List of events for activity tracking IBM · checked Back to text

  38. Source 38: Managing the agent directory IBM · checked Back:abc

  39. Source 39: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back:abc

  40. Source 40: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  41. Source 41: IBM Expands FedRAMP Portfolio with Authorization of 11 Software Solutions, Including watsonx IBM · checked Back:ab

  42. Source 42: ISO 27001 - IBM Corporation Certificate (Bureau Veritas, ISO/IEC 27001:2022) IBM · checked Back:ab

  43. Source 43: Roles on IBM watsonx Orchestrate IBM · checked Back to text

  44. Source 44: Overview - Traces (watsonx Orchestrate ADK docs) IBM · checked Back to text

  45. Source 45: Exporting observability traces with OpenTelemetry (watsonx Orchestrate ADK docs) IBM · checked Back to text

  46. Source 46: Agent-to-Agent (A2A) Protocol endpoints IBM · checked Back:ab

  47. Source 47: Manage all your AI agents in one place with watsonx Orchestrate IBM · checked Back to text

  48. Source 48: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  49. Source 49: High availability, business continuity, backups and disaster recovery on AWS IBM · checked Back to text

  50. Source 50: Licenses and entitlements for watsonx Orchestrate on IBM Cloud IBM · checked Back to text

  51. Source 51: Getting help and support IBM · checked Back to text

  52. Source 52: Getting started as an administrator IBM · checked Back to text

  53. Source 53: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back to text

  54. Source 54: AI Security | Cloudflare Cloudflare · checked Back to text

  55. Source 55: Available AI models IBM · checked Back:ab

  56. Source 56: Choosing your LLM (watsonx Orchestrate ADK docs) IBM · checked Back to text

  57. Source 57: IBM Agent Connect (watsonx Orchestrate ADK docs) IBM · checked Back to text

  58. Source 58: Managing asset controls IBM · checked Back to text

  59. Source 59: Connecting and configuring Amazon Bedrock IBM · checked Back to text

  60. Source 60: Connecting and configuring Gemini Enterprise Agent Platform IBM · checked Back to text

  61. Source 61: Connecting and configuring Microsoft Azure AI Foundry IBM · checked Back to text

  62. Source 62: Why Blocks? Blocks.ai · checked Back to text

  63. Source 63: What is Blocks? Blocks.ai · checked Back to text

  64. Source 64: Your company's private network Blocks.ai · checked Back to text

  65. Source 65: Network requirements Blocks.ai · checked Back to text

  66. Source 66: Solutions: Agent sprawl Blocks.ai · checked Back to text

  67. Source 67: Solutions: Partner networks Blocks.ai · checked Back to text

  68. Source 68: Pricing Blocks.ai · checked Back to text