Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs Kong AI Gateway

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

Short answer

Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; Kong AI Gateway is a gateway for LLM, MCP, and agent-to-agent traffic.⁠Source 1, Source 2, Source 3, Source 4 Portals govern which MCP tools agents reach through them; Kong AI Gateway 2.x also proxies calls to agents, through data plane nodes you run.⁠Source 2, Source 4, Source 5

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can sit between MCP clients and MCP servers, authenticate callers, limit which tools they reach, and log requests.⁠Source 2, Source 4, Source 6, Source 7
Where they differ
Kong also proxies LLM and agent-to-agent (A2A) traffic, with agents registered as upstream URLs.⁠Source 4, Source 5 For portals, A2A support and a registry of agents are not publicly documented.
Running both
Neither vendor publicly documents using the two together. Cloudflare’s portals accept remote MCP clients; Kong’s docs say AI Gateway can proxy an upstream MCP server.⁠Source 2, Source 4
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 2
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 2
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 2
  • Agents across organizations: Not publicly documented

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 5
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 8
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 9
  • Agents across organizations: Not publicly documented

At a glance

TopicCloudflare MCP server portalsKong AI Gateway
What it isPuts multiple MCP servers behind one HTTP endpoint.⁠Source 2 Cloudflare says portals are part of Cloudflare One.⁠Source 1A gateway for LLM, MCP, and A2A traffic.⁠Source 4
What it governsMCP servers and their tools, up to 80 servers per portal.⁠Source 2 A registry of agents is not publicly documented.LLM, MCP, and agent-to-agent traffic.⁠Source 4 Agents are registered as upstream URLs that the gateway proxies to.⁠Source 5
Where it runsAt a hostname on your domain on Cloudflare, proxied to gateway.agents.cloudflare.com.⁠Source 2In 2.x, Kong runs the control plane in Konnect, and you run the data plane nodes that carry traffic.⁠Source 4
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 10 A separate price for portals is not publicly documented.AI Management Plus from $25 a month plus usage.⁠Source 11 Enterprise is custom, billed annually.⁠Source 11
Generally availableSince 24 September 2026, after an open beta announced in August 2025.⁠Source 10, Source 12Kong announced 2.0 as generally available on 1 September 2026.⁠Source 7 Konnect Catalog’s agent inventory is in beta.⁠Source 8

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.⁠Source 1 A portal puts multiple MCP servers behind one HTTP endpoint.⁠Source 2 Access policies set who can connect, admins choose which tools each portal exposes, and Cloudflare Access logs tool requests.⁠Source 2

Kong AI Gateway

Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.⁠Source 4 In version 2.x, Kong manages the control plane in Konnect, and you run the data plane nodes.⁠Source 4

The differences that matter

  1. What sits behind it

    Cloudflare MCP server portals

    MCP servers and their tools: admins add servers to Cloudflare Access and choose which tools and prompt templates each portal exposes.⁠Source 2

    Kong AI Gateway

    In 2.x, models, MCP servers, and agents are entities on a gateway instance; agents can be A2A or plain HTTP upstreams.⁠Source 4, Source 5

    Agents reach a portal as MCP clients, and a registry of agents for portals is not publicly documented.⁠Source 2, Source 13 Konnect Catalog’s agent inventory is in beta.⁠Source 8

  2. Who signs in, and how

    Cloudflare MCP server portals

    Users sign in with their identity provider through Cloudflare Access; autonomous agents can use a service token, authorized at the portal and again per server.⁠Source 2, Source 13

    Kong AI Gateway

    The gateway can require an API key or OpenID Connect, such as Okta or Azure AD, then check a per-agent allow or deny list.⁠Source 5, Source 6

    Cloudflare says service token sessions use the admin credential for every upstream request, not per-user OAuth; Kong forwards requests to agents without adding credentials by default.⁠Source 2, Source 5

  3. Where it runs

    Cloudflare MCP server portals

    At a hostname on your domain on Cloudflare; private MCP servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.⁠Source 2, Source 14

    Kong AI Gateway

    In 2.x, Kong runs the control plane in Konnect, and you run the data plane nodes; Kong also sells Kong-run gateways.⁠Source 4, Source 11, Source 15, Source 16

    Self-hosting a portal is not publicly documented. Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering.⁠Source 11

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsKong AI Gateway
Network exposureClients reach the portal’s HTTPS URL; private MCP servers connect via outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 14, Source 17In 2.x, your data plane nodes proxy to agents registered as upstream URLs, authenticating to the control plane over mTLS.⁠Source 4, Source 5
IdentityA user’s identity provider login through Access (any SAML or OIDC provider), or an Access service token for autonomous agents.⁠Source 2, Source 13, Source 18Can require an API key, or OpenID Connect through Okta, Azure AD, Google, or another OIDC provider, before routing.⁠Source 5, Source 6
Access changes and revocationDeleting a service token revokes it.⁠Source 19 Blocked users can use direct server URLs; Cloudflare advises making Access the OAuth provider.⁠Source 2Each AI Agent has an enabled switch; a Request Termination policy can end an agent’s requests with a set response.⁠Source 5, Source 20, Source 21
Audit trailAccess logs requests made with a portal’s tools.⁠Source 2 Logpush export to a SIEM, Enterprise plans only, records the user’s email.⁠Source 2, Source 22A2A audit logs: task IDs, method calls, latencies, errors.⁠Source 23 Konnect audit logs (Enterprise): webhook delivery, kept 7 days in Konnect.⁠Source 11, Source 24
ComplianceCloudflare offers PCI, SOC 2, ISO, and other compliance documents in its dashboard.⁠Source 25 Which cover portals is not publicly documented.Kong Inc. lists ISO 27001, SOC 2, PCI DSS, and CSA STAR.⁠Source 26 Which products they cover is not publicly documented.

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and Kong AI Gateway compared on 18 criteria
Cloudflare MCP server portalsKong AI Gateway
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One, its SASE platform.⁠Source 1 A portal puts multiple MCP servers behind one HTTP endpoint.⁠Source 2One gateway for LLM, MCP, and A2A traffic.⁠Source 4 All three run through one data plane, with shared authentication, observability, and policy features.⁠Source 4
MaturityGA since 24 September 2026, after an open beta announced on 26 August 2025.⁠Source 10, Source 12 Previously called Agents Gateway in some contexts.⁠Source 2Kong announced AI Gateway in February 2024 and 2.0 as generally available on 1 September 2026.⁠Source 7, Source 27 Konnect Catalog’s agent inventory is in beta.⁠Source 8
Control
Agent registry and discoveryAdmins add MCP servers to Cloudflare Access to manage them centrally, up to 80 per portal.⁠Source 2 A registry of agents is not publicly documented.In 2.x, each AI Agent entity, A2A or plain HTTP, is scoped to one gateway instance.⁠Source 4, Source 5 Konnect Catalog’s agent inventory is in beta.⁠Source 8
Identity and access controlA user’s identity provider login through Cloudflare Access, or an Access service token for autonomous agents.⁠Source 2, Source 13 Access policies set who can connect.⁠Source 2Can require an API key or OpenID Connect login, such as Okta or Azure AD, before routing, and check a per-agent allow or deny list.⁠Source 5, Source 6
Ownership, policy, and revocationAdmins choose which tools and prompt templates each portal exposes; turned-off tools can’t be called through it.⁠Source 2 An owner field is not publicly documented.Per-agent policies: input validation, logging, rate limits.⁠Source 5 The PII Sanitizer, for model requests, is a Plus add-on.⁠Source 11, Source 28 Owner field: not publicly documented.
Audit log and observabilityAccess logs requests made with a portal’s tools.⁠Source 2 Exported logs record the user’s email and tool name; Logpush export is on Enterprise plans only.⁠Source 2, Source 22A2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 23 A2A telemetry can go to Konnect and OpenTelemetry.⁠Source 5 Bodies go to Konnect only if you opt in.⁠Source 4
Connection
How agents connectMCP clients connect to the portal’s HTTPS URL.⁠Source 2 Private servers connect via outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 14, Source 17Each agent is registered as an upstream URL the gateway proxies to.⁠Source 5 In 2.x, data plane nodes you run forward allowed traffic and stay connected to Konnect.⁠Source 4
Agents across organizationsPortals can include third-party MCP servers.⁠Source 3 A way for another company to register its own agents in a portal is not publicly documented.Not publicly documented (checked 2 October 2026)
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 2 A2A support is not publicly documented.A2A over JSON-RPC and REST bindings.⁠Source 5 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).⁠Source 29
Frameworks, models, and clouds supportedMCP clients that support remote servers, such as Claude Desktop.⁠Source 2 Stdio-only MCP servers can’t be added, and some servers reject proxy clients.⁠Source 2Kong says it governs A2A traffic without changing how agents are built.⁠Source 30 Agents that don’t use A2A can pass through as plain HTTP.⁠Source 5
Operations
Deployment options and data residencyAt a hostname on your domain on Cloudflare, proxied to gateway.agents.cloudflare.com.⁠Source 2 Self-hosting a portal is not publicly documented.2.x: a Konnect-managed control plane in a region you choose, and data plane nodes you run.⁠Source 4, Source 31 Kong also sells Kong-run Dedicated Cloud and serverless AI gateways.⁠Source 11, Source 15, Source 16
Compliance attestationsCloudflare offers PCI, SOC 2, ISO, and other compliance documents to account Super Administrators.⁠Source 25 Which cover portals is not publicly documented.Kong Inc. lists ISO 27001, SOC 2 (report under NDA), PCI DSS, and CSA STAR.⁠Source 26 FIPS 140-3 mode from 2.2, not submitted for NIST validation.⁠Source 32
Support and SLACloudflare states a 100% uptime SLA for paid Zero Trust plans.⁠Source 33 Support options vary by plan; Contract plans can add professional services.⁠Source 33Konnect targets 99.9% monthly availability; Kong lists a 99.99% SLA for Dedicated Cloud Gateways, none for serverless.⁠Source 11 Enterprise support: up to 24x7.⁠Source 11
Time and effort to get runningNeeds a domain on Cloudflare and an identity provider in Zero Trust.⁠Source 2 Then add MCP servers to Access, create a portal, and connect an MCP client.⁠Source 2A quickstart script creates a Konnect control plane and a local Docker data plane.⁠Source 34 To route A2A traffic, create an AI Agent entity and attach policies.⁠Source 35
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 10 A separate price for portals is not publicly documented.Plus from $25 a month plus usage.⁠Source 11 Plus control planes a month: hybrid $200, Dedicated Cloud $500, serverless $25.⁠Source 11 Enterprise is custom.⁠Source 11
Building
Agent building toolsSeparately from portals, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Workers.⁠Source 3, Source 36Kong says it can generate MCP tools and servers from Kong-managed APIs.⁠Source 9 Tools for building agents in Kong AI Gateway are not publicly documented.
Model accessAI models included with portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 37One API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.⁠Source 4, Source 34, Source 38
Integrations and ecosystemPortals can be managed with Terraform.⁠Source 2 Cloudflare One supports all SAML and OIDC identity providers.⁠Source 18 A marketplace of MCP servers is not publicly documented.A Policies Hub of policies and integrations.⁠Source 20 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.⁠Source 4

Which to choose

Choose Cloudflare MCP server portals if

  • You want many MCP servers behind one URL, with admins choosing which tools and prompt templates each portal exposes.⁠Source 2
  • You use Cloudflare One, which Cloudflare says includes portals, and want Access policies, such as groups and device posture, on portal servers.⁠Source 1, Source 2
  • You want MCP portals on your own Cloudflare domain, which Cloudflare says are available to all its customers.⁠Source 2, Source 10
  • Some MCP servers are private, and you want them in a portal over Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 14

Choose Kong AI Gateway if

  • You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 4
  • You want agent-to-agent calls governed, with per-agent allow or deny lists, rate limits, and A2A audit logs.⁠Source 5, Source 23
  • You want to run the data plane while Kong manages the control plane, in a region you choose, outside the traffic path.⁠Source 4, Source 31
  • You want one API to many model providers, such as OpenAI, Anthropic, Gemini, and Mistral, using credentials you supply.⁠Source 4, Source 34, Source 38

Questions buyers ask

Is this page about Cloudflare AI Gateway?

No. It covers Cloudflare MCP server portals, which put multiple MCP servers behind one endpoint.⁠Source 2 Cloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 37 Cloudflare previously referred to portals as Agents Gateway in some contexts.⁠Source 2

Do they support MCP and A2A?

Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; A2A support is not publicly documented.⁠Source 2 Kong AI Gateway accepts four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1), and detects A2A requests over JSON-RPC and REST bindings.⁠Source 5, Source 29

Can either one be self-hosted?

Self-hosting a portal is not publicly documented; a portal’s hostname points to gateway.agents.cloudflare.com.⁠Source 2 Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering; the 2.x AI entities are hybrid, with a Konnect-managed control plane.⁠Source 4, Source 11

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 10 A separate price for portals is not publicly documented. Kong’s AI Management Plus starts at $25 a month plus usage; Enterprise is custom.⁠Source 11

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

43 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abcde

  2. Source 2: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344454647

  3. Source 3: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abc

  4. Source 4: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrstuvwxy

  5. Source 5: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqrs

  6. Source 6: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back:abcd

  7. Source 7: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:abc

  8. Source 8: Agents in Catalog - Kong Docs Kong · checked Back:abcde

  9. Source 9: Kong AI Gateway product page Kong · checked Back:ab

  10. Source 10: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcdef

  11. Source 11: Kong Pricing & Plans Kong · checked Back:abcdefghijklmn

  12. Source 12: MCP server portals · Changelog Cloudflare · checked Back:ab

  13. Source 13: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcd

  14. Source 14: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:abcd

  15. Source 15: Dedicated Cloud Gateways - Kong Docs Kong · checked Back:ab

  16. Source 16: Serverless Gateways - Kong Docs Kong · checked Back:ab

  17. Source 17: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:ab

  18. Source 18: Identity providers · Cloudflare One docs Cloudflare · checked Back:ab

  19. Source 19: Service tokens · Cloudflare One docs Cloudflare · checked Back to text

  20. Source 20: Kong AI Gateway Policies - Kong Docs Kong · checked Back:ab

  21. Source 21: Request Termination - Configuration Reference - Policy | Kong Docs Kong · checked Back to text

  22. Source 22: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back:ab

  23. Source 23: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:abc

  24. Source 24: Konnect and Dev Portal audit logs - Kong Docs Kong · checked Back to text

  25. Source 25: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  26. Source 26: Trust Center - Kong Inc. Kong · checked Back:ab

  27. Source 27: Announcing Kong’s New Open Source AI Gateway with Multi-LLM Support, No-Code AI Plugins, Advanced Prompt Engineering, and More Kong · checked Back to text

  28. Source 28: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  29. Source 29: MCP version support - Kong AI Gateway docs Kong · checked Back:ab

  30. Source 30: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back to text

  31. Source 31: Geographic regions - Kong Docs Kong · checked Back:ab

  32. Source 32: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back to text

  33. Source 33: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  34. Source 34: Kong AI Gateway | Kong Docs Kong · checked Back:abc

  35. Source 35: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back to text

  36. Source 36: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back to text

  37. Source 37: AI Security | Cloudflare Cloudflare · checked Back:ab

  38. Source 38: AI Gateway providers - Kong Docs Kong · checked Back:ab

  39. Source 39: Your company's private network Blocks.ai · checked Back to text

  40. Source 40: Network requirements Blocks.ai · checked Back to text

  41. Source 41: Solutions: Agent sprawl Blocks.ai · checked Back to text

  42. Source 42: Solutions: Partner networks Blocks.ai · checked Back to text

  43. Source 43: Pricing Blocks.ai · checked Back to text