Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs LangSmith
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
LangSmith
Platform for observing, evaluating, and deploying agents
Short answer
Cloudflare MCP server portals put MCP servers behind one governed endpoint; LangChain describes LangSmith as its platform for observing, evaluating, and deploying agents.Source 1, Source 2, Source 3 A portal decides who reaches which MCP tools through it and logs tool requests; LangSmith runs agents in LangChain’s cloud on Plus or above, or on Enterprise in your infrastructure.Source 1, Source 4, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
LangSmith
- Agents across organizations: Not publicly documented
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its secure access service edge (SASE) platform.Source 21 A portal centralizes several MCP servers on one HTTP endpoint; Cloudflare Access decides who can connect and logs the requests made with its tools.Source 1
LangSmith
LangChain describes LangSmith as a framework-agnostic platform for observing, evaluating, and deploying agents.Source 3 LangSmith Deployment is its runtime for agents in production, and LangSmith Fleet creates and manages agents without code, for non-technical teams too, LangChain says.Source 3, Source 4, Source 9
The differences that matter
What each one manages
Cloudflare MCP server portalsMCP servers and their tools: admins choose which tools each portal exposes, and turned-off tools can’t be called through it.Source 1
LangSmithAgents: Deployment runs them in production, and Fleet has per-agent Clone, Run, and Edit permissions.Source 4, Source 10
For portals, a registry of agents is not publicly documented. For LangSmith, listing agents hosted elsewhere is not publicly documented.
How callers are checked
Cloudflare MCP server portalsAccess checks an identity provider login or service token at the portal; service token sessions are authorized again for each upstream server.Source 1
LangSmithHosted Agent Servers take a LangSmith API key by default, or your own auth handler; self-hosted Agent Servers have no default authentication.Source 14
Cloudflare cautions that blocked users can still reach a server by its direct URL, and advises making Access that server’s OAuth provider.Source 1
Where it runs
Cloudflare MCP server portalsA portal’s hostname points to gateway.agents.cloudflare.com; a private MCP server’s network joins through Cloudflare Tunnel or another connector, with Gateway routing on.Source 1, Source 22
LangSmithIn LangChain’s cloud; on Enterprise, also BYOC on AWS, or self-hosted or hybrid.Source 5, Source 6, Source 17, Source 23
Self-hosting a portal is not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | LangSmith | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One.Source 21 A portal puts multiple MCP servers behind one endpoint, with Access to vet, authorize, and audit their use.Source 1, Source 2 | LangChain calls it a framework-agnostic platform for observing, evaluating, and deploying agents, and aims its Fleet service at non-technical teams.Source 3 |
| Maturity | GA since 24 September 2026, after an open beta announced in August 2025.Source 16, Source 34 Previously called Agents Gateway in some contexts.Source 1 | LangChain announced LangGraph Platform, now Deployment, as GA on 14 May 2025.Source 11, Source 18 It announced Agent Builder, now Fleet, as GA on 13 January 2026.Source 19, Source 20 |
| Control | ||
| Agent registry and discovery | Admins add MCP servers, up to 80 per portal; portals show users only servers whose Allow policy they match.Source 1 An agent registry is not publicly documented. | LangChain says Deployment manages agents in a central registry with versioning and rollbacks.Source 11 Listing agents hosted elsewhere is not publicly documented. |
| Identity and access control | People sign in through their identity provider, and autonomous agents can use an Access service token.Source 1, Source 13 Access policies set who can connect to each portal.Source 1 | Agents hosted on LangSmith take a LangSmith API key by default, or your own auth handler.Source 14 Fleet has per-agent Clone, Run, and Edit permissions.Source 10 |
| Ownership, policy, and revocation | Admins choose which tools each portal exposes and can turn tools off.Source 1 Deleting a service token revokes its access.Source 27 An owner field is not publicly documented. | Fleet shows each agent’s owner, lets sharing be revoked at any time, and can pause agents for human approval before specific actions.Source 8, Source 20 |
| Audit log and observability | Access logs each tool request; exported logs record the user’s email and the tool called.Source 1, Source 29 Logpush export to a SIEM needs an Enterprise plan.Source 1 | Enterprise audit logs record admin and configuration actions, kept up to 400 days.Source 30 Fleet traces agent tool calls, decisions, and outputs.Source 8 |
| Connection | ||
| How agents connect | MCP clients connect to the portal’s HTTPS URL.Source 1 Private MCP servers can be reached through outbound-only Cloudflare Tunnel, with Gateway routing on.Source 1, Source 22, Source 24 | Agent Server offers an A2A endpoint for its assistants.Source 25 Enterprise customers can reach LangSmith Cloud over AWS PrivateLink or GCP Private Service Connect.Source 5 |
| Agents across organizations | Several identity providers can work at once, for people from partners or other organizations.Source 35 Partner-controlled agents in a portal: not publicly documented. | Agent Server agents can communicate with other A2A-compatible agents.Source 25 A cross-organization access model is not publicly documented. |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; SSE to upstream servers too.Source 1 A2A support is not publicly documented. | Agent Server supports A2A, with documented gaps, over JSON-RPC only, and can expose agents as MCP tools.Source 25, Source 26 Fleet uses tools from remote MCP servers.Source 7 |
| Frameworks, models, and clouds supported | MCP clients that support remote servers, such as Claude Desktop.Source 1 Some servers reject proxy clients like portals, and stdio-only ones can’t be added.Source 1 | Deployment runs agents from other frameworks, such as Google ADK, CrewAI, and AutoGen.Source 36 Agents hosted elsewhere can send traces to LangSmith.Source 6 |
| Operations | ||
| Deployment options and data residency | A portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.Source 1 Self-hosting a portal is not publicly documented. | Cloud in GCP’s US, EU, and APAC regions or AWS’s US region.Source 5 On Enterprise, BYOC on AWS, or self-hosted or hybrid.Source 6, Source 17, Source 23 |
| Compliance attestations | Cloudflare gives Super Administrators PCI, SOC 2, ISO, and other compliance documents.Source 31 Whether they cover portals is not publicly documented. | LangChain says LangSmith has a SOC 2 Type 2 report and is HIPAA and GDPR compliant.Source 32 It says the SOC 2 Type II report spans the entire LangSmith offering.Source 33 |
| Support and SLA | Cloudflare’s Access page cites a 100% uptime SLA for paid Zero Trust plans; portals aren’t named.Source 37 Support options vary by plan.Source 37 | Base, Standard, and Premium support plans.Source 38 LangChain commits reasonable commercial efforts to 99.5% API uptime for SaaS, measured quarterly.Source 38 |
| Time and effort to get running | Needs a domain on Cloudflare and an identity provider in Zero Trust.Source 1 Then add MCP servers, create a portal with tools and policies, and connect users.Source 1 | Deploying to Cloud needs a Plus plan or above and an API key, and can take up to several minutes.Source 39, Source 40 Fleet agents start from a description or template.Source 9 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 16 A separate price for portals is not publicly documented. | Developer has one free seat; Plus is $39 per seat a month; Enterprise is through sales.Source 17 Usage is metered in LSUs at $1 each.Source 17 |
| Building | ||
| Agent building tools | Separately, Cloudflare’s Agents SDK is for building and hosting agents, and MCP servers can be built on Workers.Source 2, Source 12 A no-code builder is not publicly documented. | Fleet builds agents from a plain-language description, without code.Source 9 Code-first agents can be deployed with the LangGraph CLI and app templates.Source 4 |
| Model access | Models for portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across AI providers.Source 41 | LangChain says LangSmith works with closed or open models.Source 3 Fleet offers Fast, Pro, and Max tiers; the model behind each may change over time.Source 42 |
| Integrations and ecosystem | Works with all SAML and OIDC providers and most OAuth ones.Source 35 Portals can be managed with Terraform.Source 1 A connector marketplace is not publicly documented. | Fleet has built-in tools for Gmail, Slack, Google Calendar, and GitHub.Source 42 LangChain says Fleet agents work inside Slack, Teams, and Gmail.Source 43 |
Which to choose
Choose Cloudflare MCP server portals if
- Your company runs Cloudflare One, which Cloudflare says includes portals, and you want MCP servers behind your Access login.Source 1, Source 21
- You want people’s MCP clients, such as Claude Desktop or Windsurf, to reach MCP servers through one endpoint.Source 1
- You want to choose the tools each portal exposes; tools you turn off are hidden and can’t be called through it.Source 1
- You need each tool request logged, and exported with the user’s email to a SIEM through Logpush on an Enterprise plan.Source 1, Source 29
Choose LangSmith if
- You want to deploy LangChain, Google ADK, or CrewAI agents to a runtime with MCP endpoints and A2A, with documented gaps.Source 25, Source 26, Source 36
- Non-technical teams should build agents without code, from a description or template; LangChain says Fleet agents work in Slack, Teams, and Gmail.Source 9, Source 43
- You need LangSmith’s control plane and Agent Servers in your own infrastructure, for full data residency or air-gapped use, on Enterprise.Source 4
- You want Fleet agents to pause for human approval before specific actions, with tool calls, decisions, and outputs traced.Source 8
Questions buyers ask
Can either one manage agents built elsewhere?
Do they support MCP and A2A?
Portals proxy MCP tool calls between clients and upstream MCP servers.Source 1 A2A support is not publicly documented for portals. LangSmith’s Agent Server supports A2A, with documented gaps, and can expose agents as MCP tools, and Fleet uses tools from remote MCP servers.Source 7, Source 25, Source 26
How is each one priced?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
48 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344
Source 3: LangSmith: The Agent Engineering Platform Back:abcdef
Source 12: Build Agents on Cloudflare · Cloudflare Agents docs Back:ab
Source 13: Service token support for MCP server portals · Changelog Back:abc
Source 16: MCP server portals are now generally available · Changelog Back:abcde
Source 18: LangGraph Platform is now Generally Available: Deploy & manage long-running, stateful Agents Back:ab
Source 21: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abc
Source 22: Private MCP server support for MCP server portals · Changelog Back:abc
Source 30: Audit logs Back:ab
Source 31: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 32: Regions FAQ Back:ab
Source 37: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 42: Essentials Back:ab