Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs Kong AI Gateway
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Kong AI Gateway
Gateway that governs LLM, MCP, and agent-to-agent traffic
Short answer
Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; Kong AI Gateway is a gateway for LLM, MCP, and agent-to-agent traffic.Source 1, Source 2, Source 3, Source 4 Portals govern which MCP tools agents reach through them; Kong AI Gateway 2.x also proxies calls to agents, through data plane nodes you run.Source 2, Source 4, Source 5
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Kong AI Gateway
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.Source 1 A portal puts multiple MCP servers behind one HTTP endpoint.Source 2 Access policies set who can connect, admins choose which tools each portal exposes, and Cloudflare Access logs tool requests.Source 2
The differences that matter
What sits behind it
Cloudflare MCP server portalsMCP servers and their tools: admins add servers to Cloudflare Access and choose which tools and prompt templates each portal exposes.Source 2
Kong AI GatewayIn 2.x, models, MCP servers, and agents are entities on a gateway instance; agents can be A2A or plain HTTP upstreams.Source 4, Source 5
Agents reach a portal as MCP clients, and a registry of agents for portals is not publicly documented.Source 2, Source 13 Konnect Catalog’s agent inventory is in beta.Source 8
Who signs in, and how
Cloudflare MCP server portalsUsers sign in with their identity provider through Cloudflare Access; autonomous agents can use a service token, authorized at the portal and again per server.Source 2, Source 13
Kong AI GatewayThe gateway can require an API key or OpenID Connect, such as Okta or Azure AD, then check a per-agent allow or deny list.Source 5, Source 6
Cloudflare says service token sessions use the admin credential for every upstream request, not per-user OAuth; Kong forwards requests to agents without adding credentials by default.Source 2, Source 5
Where it runs
Cloudflare MCP server portalsAt a hostname on your domain on Cloudflare; private MCP servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.Source 2, Source 14
Kong AI GatewayIn 2.x, Kong runs the control plane in Konnect, and you run the data plane nodes; Kong also sells Kong-run gateways.Source 4, Source 11, Source 15, Source 16
Self-hosting a portal is not publicly documented. Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering.Source 11
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | Kong AI Gateway | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One, its SASE platform.Source 1 A portal puts multiple MCP servers behind one HTTP endpoint.Source 2 | One gateway for LLM, MCP, and A2A traffic.Source 4 All three run through one data plane, with shared authentication, observability, and policy features.Source 4 |
| Maturity | GA since 24 September 2026, after an open beta announced on 26 August 2025.Source 10, Source 12 Previously called Agents Gateway in some contexts.Source 2 | Kong announced AI Gateway in February 2024 and 2.0 as generally available on 1 September 2026.Source 7, Source 27 Konnect Catalog’s agent inventory is in beta.Source 8 |
| Control | ||
| Agent registry and discovery | Admins add MCP servers to Cloudflare Access to manage them centrally, up to 80 per portal.Source 2 A registry of agents is not publicly documented. | In 2.x, each AI Agent entity, A2A or plain HTTP, is scoped to one gateway instance.Source 4, Source 5 Konnect Catalog’s agent inventory is in beta.Source 8 |
| Identity and access control | A user’s identity provider login through Cloudflare Access, or an Access service token for autonomous agents.Source 2, Source 13 Access policies set who can connect.Source 2 | Can require an API key or OpenID Connect login, such as Okta or Azure AD, before routing, and check a per-agent allow or deny list.Source 5, Source 6 |
| Ownership, policy, and revocation | Admins choose which tools and prompt templates each portal exposes; turned-off tools can’t be called through it.Source 2 An owner field is not publicly documented. | Per-agent policies: input validation, logging, rate limits.Source 5 The PII Sanitizer, for model requests, is a Plus add-on.Source 11, Source 28 Owner field: not publicly documented. |
| Audit log and observability | Access logs requests made with a portal’s tools.Source 2 Exported logs record the user’s email and tool name; Logpush export is on Enterprise plans only.Source 2, Source 22 | A2A audit logs record task IDs, method calls, latencies, and errors.Source 23 A2A telemetry can go to Konnect and OpenTelemetry.Source 5 Bodies go to Konnect only if you opt in.Source 4 |
| Connection | ||
| How agents connect | MCP clients connect to the portal’s HTTPS URL.Source 2 Private servers connect via outbound-only Cloudflare Tunnel, with Gateway routing on.Source 2, Source 14, Source 17 | Each agent is registered as an upstream URL the gateway proxies to.Source 5 In 2.x, data plane nodes you run forward allowed traffic and stay connected to Konnect.Source 4 |
| Agents across organizations | Portals can include third-party MCP servers.Source 3 A way for another company to register its own agents in a portal is not publicly documented. | Not publicly documented (checked 2 October 2026) |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 2 A2A support is not publicly documented. | A2A over JSON-RPC and REST bindings.Source 5 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).Source 29 |
| Frameworks, models, and clouds supported | MCP clients that support remote servers, such as Claude Desktop.Source 2 Stdio-only MCP servers can’t be added, and some servers reject proxy clients.Source 2 | Kong says it governs A2A traffic without changing how agents are built.Source 30 Agents that don’t use A2A can pass through as plain HTTP.Source 5 |
| Operations | ||
| Deployment options and data residency | At a hostname on your domain on Cloudflare, proxied to gateway.agents.cloudflare.com.Source 2 Self-hosting a portal is not publicly documented. | 2.x: a Konnect-managed control plane in a region you choose, and data plane nodes you run.Source 4, Source 31 Kong also sells Kong-run Dedicated Cloud and serverless AI gateways.Source 11, Source 15, Source 16 |
| Compliance attestations | Cloudflare offers PCI, SOC 2, ISO, and other compliance documents to account Super Administrators.Source 25 Which cover portals is not publicly documented. | Kong Inc. lists ISO 27001, SOC 2 (report under NDA), PCI DSS, and CSA STAR.Source 26 FIPS 140-3 mode from 2.2, not submitted for NIST validation.Source 32 |
| Support and SLA | Cloudflare states a 100% uptime SLA for paid Zero Trust plans.Source 33 Support options vary by plan; Contract plans can add professional services.Source 33 | Konnect targets 99.9% monthly availability; Kong lists a 99.99% SLA for Dedicated Cloud Gateways, none for serverless.Source 11 Enterprise support: up to 24x7.Source 11 |
| Time and effort to get running | Needs a domain on Cloudflare and an identity provider in Zero Trust.Source 2 Then add MCP servers to Access, create a portal, and connect an MCP client.Source 2 | A quickstart script creates a Konnect control plane and a local Docker data plane.Source 34 To route A2A traffic, create an AI Agent entity and attach policies.Source 35 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 10 A separate price for portals is not publicly documented. | Plus from $25 a month plus usage.Source 11 Plus control planes a month: hybrid $200, Dedicated Cloud $500, serverless $25.Source 11 Enterprise is custom.Source 11 |
| Building | ||
| Agent building tools | Separately from portals, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Workers.Source 3, Source 36 | Kong says it can generate MCP tools and servers from Kong-managed APIs.Source 9 Tools for building agents in Kong AI Gateway are not publicly documented. |
| Model access | AI models included with portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across AI providers.Source 37 | One API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.Source 4, Source 34, Source 38 |
| Integrations and ecosystem | Portals can be managed with Terraform.Source 2 Cloudflare One supports all SAML and OIDC identity providers.Source 18 A marketplace of MCP servers is not publicly documented. | A Policies Hub of policies and integrations.Source 20 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.Source 4 |
Which to choose
Choose Cloudflare MCP server portals if
- You want many MCP servers behind one URL, with admins choosing which tools and prompt templates each portal exposes.Source 2
- You use Cloudflare One, which Cloudflare says includes portals, and want Access policies, such as groups and device posture, on portal servers.Source 1, Source 2
- You want MCP portals on your own Cloudflare domain, which Cloudflare says are available to all its customers.Source 2, Source 10
- Some MCP servers are private, and you want them in a portal over Cloudflare Tunnel, with Gateway routing on.Source 2, Source 14
Choose Kong AI Gateway if
- You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.Source 4
- You want agent-to-agent calls governed, with per-agent allow or deny lists, rate limits, and A2A audit logs.Source 5, Source 23
- You want to run the data plane while Kong manages the control plane, in a region you choose, outside the traffic path.Source 4, Source 31
- You want one API to many model providers, such as OpenAI, Anthropic, Gemini, and Mistral, using credentials you supply.Source 4, Source 34, Source 38
Questions buyers ask
Is this page about Cloudflare AI Gateway?
Do they support MCP and A2A?
Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; A2A support is not publicly documented.Source 2 Kong AI Gateway accepts four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1), and detects A2A requests over JSON-RPC and REST bindings.Source 5, Source 29
Can either one be self-hosted?
Self-hosting a portal is not publicly documented; a portal’s hostname points to gateway.agents.cloudflare.com.Source 2 Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering; the 2.x AI entities are hybrid, with a Konnect-managed control plane.Source 4, Source 11
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
43 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abcde
Source 2: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344454647
Source 4: AI Gateway architecture - Kong Docs Back:abcdefghijklmnopqrstuvwxy
Source 5: AI Agents - Kong AI Gateway docs Back:abcdefghijklmnopqrs
Source 6: AI Auth Strategies - Kong AI Gateway docs Back:abcd
Source 7: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Back:abc
Source 10: MCP server portals are now generally available · Changelog Back:abcdef
Source 13: Service token support for MCP server portals · Changelog Back:abcd
Source 14: Private MCP server support for MCP server portals · Changelog Back:abcd
Source 19: Service tokens · Cloudflare One docs Back to text
Source 21: Request Termination - Configuration Reference - Policy | Kong Docs Back to text
Source 23: Route A2A traffic through AI Gateway - Kong Docs Back:abc
Source 24: Konnect and Dev Portal audit logs - Kong Docs Back to text
Source 25: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 27: Announcing Kong’s New Open Source AI Gateway with Multi-LLM Support, No-Code AI Plugins, Advanced Prompt Engineering, and More Back to text
Source 28: AI PII Sanitizer - Policy | Kong Docs Back to text
Source 29: MCP version support - Kong AI Gateway docs Back:ab
Source 30: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Back to text
Source 32: FIPS 140-3 compliance in AI Gateway - Kong Docs Back to text
Source 33: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 35: Route A2A agent traffic through AI Gateway - Kong Docs Back to text
Source 36: Build Agents on Cloudflare · Cloudflare Agents docs Back to text