Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs LangSmith

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

LangSmith

Platform for observing, evaluating, and deploying agents

Short answer

Cloudflare MCP server portals put MCP servers behind one governed endpoint; LangChain describes LangSmith as its platform for observing, evaluating, and deploying agents.⁠Source 1, Source 2, Source 3 A portal decides who reaches which MCP tools through it and logs tool requests; LangSmith runs agents in LangChain’s cloud on Plus or above, or on Enterprise in your infrastructure.⁠Source 1, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both handle MCP tool calls: a portal proxies and logs them, and LangSmith Fleet forwards agents’ tool calls to remote MCP servers and traces them.⁠Source 1, Source 7, Source 8
Where they differ
LangSmith also builds, hosts, and evaluates agents.⁠Source 3, Source 4, Source 9 Portals manage MCP servers and their tools.⁠Source 1 A registry of agents is not publicly documented for portals.
Running both
Neither vendor publicly documents using the two together. Cloudflare’s portals accept remote MCP clients; LangChain’s docs say Fleet discovers tools from remote MCP servers.⁠Source 1, Source 7
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 1
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 1
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 1
  • Agents across organizations: Not publicly documented

LangSmith

  • Build agents: OfferedFleet agent builder⁠Source 9
  • Host and run agents: OfferedLangSmith Deployment runtime⁠Source 4
  • Identity and access: OfferedFleet per-agent permissions⁠Source 10
  • Registry and governance: OfferedCentralized registry in Deployment⁠Source 11
  • Traffic between agents, tools, and models: OfferedFleet forwards MCP tool calls⁠Source 7
  • Agents across organizations: Not publicly documented

At a glance

TopicCloudflare MCP server portalsLangSmith
What it governsMCP servers and the tools each portal exposes, up to 80 servers per portal.⁠Source 1Agents it deploys or builds in Fleet, with per-agent permissions in Fleet.⁠Source 4, Source 9, Source 10 Agents hosted elsewhere can send it traces.⁠Source 6
Builds and runs agentsFor portals, not publicly documented. Cloudflare’s separate Agents SDK is for building and hosting agents on Cloudflare.⁠Source 12Fleet builds agents without code; LangSmith Deployment runs agents in production, on the Plus plan or above.⁠Source 4, Source 9
IdentityCloudflare Access login through an identity provider, or an Access service token for autonomous agents.⁠Source 1, Source 13A LangSmith API key by default on LangSmith-hosted Agent Servers, or your own auth handler.⁠Source 14 On LangSmith Cloud, Enterprise adds SAML SSO and SCIM.⁠Source 15
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented.Per seat plus usage: Plus is $39 per seat a month, and usage is metered in LSUs at $1 each.⁠Source 17 Developer has one free seat.⁠Source 17
Generally availableSince 24 September 2026.⁠Source 16LangChain announced Deployment, as LangGraph Platform, as GA on 14 May 2025, and Fleet, as Agent Builder, on 13 January 2026.⁠Source 11, Source 18, Source 19, Source 20

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its secure access service edge (SASE) platform.⁠Source 21 A portal centralizes several MCP servers on one HTTP endpoint; Cloudflare Access decides who can connect and logs the requests made with its tools.⁠Source 1

LangSmith

LangChain describes LangSmith as a framework-agnostic platform for observing, evaluating, and deploying agents.⁠Source 3 LangSmith Deployment is its runtime for agents in production, and LangSmith Fleet creates and manages agents without code, for non-technical teams too, LangChain says.⁠Source 3, Source 4, Source 9

The differences that matter

  1. What each one manages

    Cloudflare MCP server portals

    MCP servers and their tools: admins choose which tools each portal exposes, and turned-off tools can’t be called through it.⁠Source 1

    LangSmith

    Agents: Deployment runs them in production, and Fleet has per-agent Clone, Run, and Edit permissions.⁠Source 4, Source 10

    For portals, a registry of agents is not publicly documented. For LangSmith, listing agents hosted elsewhere is not publicly documented.

  2. How callers are checked

    Cloudflare MCP server portals

    Access checks an identity provider login or service token at the portal; service token sessions are authorized again for each upstream server.⁠Source 1

    LangSmith

    Hosted Agent Servers take a LangSmith API key by default, or your own auth handler; self-hosted Agent Servers have no default authentication.⁠Source 14

    Cloudflare cautions that blocked users can still reach a server by its direct URL, and advises making Access that server’s OAuth provider.⁠Source 1

  3. Where it runs

    Cloudflare MCP server portals

    A portal’s hostname points to gateway.agents.cloudflare.com; a private MCP server’s network joins through Cloudflare Tunnel or another connector, with Gateway routing on.⁠Source 1, Source 22

    LangSmith

    In LangChain’s cloud; on Enterprise, also BYOC on AWS, or self-hosted or hybrid.⁠Source 5, Source 6, Source 17, Source 23

    Self-hosting a portal is not publicly documented.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsLangSmith
Network exposureClients reach the portal’s HTTPS URL; private MCP servers connect through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 22, Source 24Agent Server serves A2A and MCP endpoints; Enterprise customers can reach LangSmith Cloud over PrivateLink or Private Service Connect.⁠Source 5, Source 25, Source 26
IdentityIdP login through Access, or Access service tokens for agents; service token sessions use the admin credential upstream.⁠Source 1, Source 13Hosted Agent Servers default to LangSmith API keys, or your auth handler; Cloud Enterprise adds SAML SSO and SCIM.⁠Source 14, Source 15
Access changes and revocationDelete or turn off service tokens.⁠Source 27 A tool turned off in a portal can’t be called through it.⁠Source 1Fleet sharing is revocable anytime; admins can deactivate any member’s personal access token, effective within a minute.⁠Source 8, Source 28
Audit trailAccess logs each tool request; exported logs record the user’s email and tool.⁠Source 1, Source 29 Logpush export needs an Enterprise plan.⁠Source 1Enterprise audit logs cover admin and configuration actions, kept up to 400 days; Fleet traces record agent tool calls.⁠Source 8, Source 30
ComplianceCloudflare gives Super Administrators PCI, SOC 2, ISO, and other compliance documents.⁠Source 31 Whether they cover portals is not publicly documented.LangChain says LangSmith has a SOC 2 Type 2 report and is HIPAA and GDPR compliant, plus ISO 27001:2022.⁠Source 32, Source 33

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and LangSmith compared on 18 criteria
Cloudflare MCP server portalsLangSmith
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One.⁠Source 21 A portal puts multiple MCP servers behind one endpoint, with Access to vet, authorize, and audit their use.⁠Source 1, Source 2LangChain calls it a framework-agnostic platform for observing, evaluating, and deploying agents, and aims its Fleet service at non-technical teams.⁠Source 3
MaturityGA since 24 September 2026, after an open beta announced in August 2025.⁠Source 16, Source 34 Previously called Agents Gateway in some contexts.⁠Source 1LangChain announced LangGraph Platform, now Deployment, as GA on 14 May 2025.⁠Source 11, Source 18 It announced Agent Builder, now Fleet, as GA on 13 January 2026.⁠Source 19, Source 20
Control
Agent registry and discoveryAdmins add MCP servers, up to 80 per portal; portals show users only servers whose Allow policy they match.⁠Source 1 An agent registry is not publicly documented.LangChain says Deployment manages agents in a central registry with versioning and rollbacks.⁠Source 11 Listing agents hosted elsewhere is not publicly documented.
Identity and access controlPeople sign in through their identity provider, and autonomous agents can use an Access service token.⁠Source 1, Source 13 Access policies set who can connect to each portal.⁠Source 1Agents hosted on LangSmith take a LangSmith API key by default, or your own auth handler.⁠Source 14 Fleet has per-agent Clone, Run, and Edit permissions.⁠Source 10
Ownership, policy, and revocationAdmins choose which tools each portal exposes and can turn tools off.⁠Source 1 Deleting a service token revokes its access.⁠Source 27 An owner field is not publicly documented.Fleet shows each agent’s owner, lets sharing be revoked at any time, and can pause agents for human approval before specific actions.⁠Source 8, Source 20
Audit log and observabilityAccess logs each tool request; exported logs record the user’s email and the tool called.⁠Source 1, Source 29 Logpush export to a SIEM needs an Enterprise plan.⁠Source 1Enterprise audit logs record admin and configuration actions, kept up to 400 days.⁠Source 30 Fleet traces agent tool calls, decisions, and outputs.⁠Source 8
Connection
How agents connectMCP clients connect to the portal’s HTTPS URL.⁠Source 1 Private MCP servers can be reached through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 22, Source 24Agent Server offers an A2A endpoint for its assistants.⁠Source 25 Enterprise customers can reach LangSmith Cloud over AWS PrivateLink or GCP Private Service Connect.⁠Source 5
Agents across organizationsSeveral identity providers can work at once, for people from partners or other organizations.⁠Source 35 Partner-controlled agents in a portal: not publicly documented.Agent Server agents can communicate with other A2A-compatible agents.⁠Source 25 A cross-organization access model is not publicly documented.
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; SSE to upstream servers too.⁠Source 1 A2A support is not publicly documented.Agent Server supports A2A, with documented gaps, over JSON-RPC only, and can expose agents as MCP tools.⁠Source 25, Source 26 Fleet uses tools from remote MCP servers.⁠Source 7
Frameworks, models, and clouds supportedMCP clients that support remote servers, such as Claude Desktop.⁠Source 1 Some servers reject proxy clients like portals, and stdio-only ones can’t be added.⁠Source 1Deployment runs agents from other frameworks, such as Google ADK, CrewAI, and AutoGen.⁠Source 36 Agents hosted elsewhere can send traces to LangSmith.⁠Source 6
Operations
Deployment options and data residencyA portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 1 Self-hosting a portal is not publicly documented.Cloud in GCP’s US, EU, and APAC regions or AWS’s US region.⁠Source 5 On Enterprise, BYOC on AWS, or self-hosted or hybrid.⁠Source 6, Source 17, Source 23
Compliance attestationsCloudflare gives Super Administrators PCI, SOC 2, ISO, and other compliance documents.⁠Source 31 Whether they cover portals is not publicly documented.LangChain says LangSmith has a SOC 2 Type 2 report and is HIPAA and GDPR compliant.⁠Source 32 It says the SOC 2 Type II report spans the entire LangSmith offering.⁠Source 33
Support and SLACloudflare’s Access page cites a 100% uptime SLA for paid Zero Trust plans; portals aren’t named.⁠Source 37 Support options vary by plan.⁠Source 37Base, Standard, and Premium support plans.⁠Source 38 LangChain commits reasonable commercial efforts to 99.5% API uptime for SaaS, measured quarterly.⁠Source 38
Time and effort to get runningNeeds a domain on Cloudflare and an identity provider in Zero Trust.⁠Source 1 Then add MCP servers, create a portal with tools and policies, and connect users.⁠Source 1Deploying to Cloud needs a Plus plan or above and an API key, and can take up to several minutes.⁠Source 39, Source 40 Fleet agents start from a description or template.⁠Source 9
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented.Developer has one free seat; Plus is $39 per seat a month; Enterprise is through sales.⁠Source 17 Usage is metered in LSUs at $1 each.⁠Source 17
Building
Agent building toolsSeparately, Cloudflare’s Agents SDK is for building and hosting agents, and MCP servers can be built on Workers.⁠Source 2, Source 12 A no-code builder is not publicly documented.Fleet builds agents from a plain-language description, without code.⁠Source 9 Code-first agents can be deployed with the LangGraph CLI and app templates.⁠Source 4
Model accessModels for portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 41LangChain says LangSmith works with closed or open models.⁠Source 3 Fleet offers Fast, Pro, and Max tiers; the model behind each may change over time.⁠Source 42
Integrations and ecosystemWorks with all SAML and OIDC providers and most OAuth ones.⁠Source 35 Portals can be managed with Terraform.⁠Source 1 A connector marketplace is not publicly documented.Fleet has built-in tools for Gmail, Slack, Google Calendar, and GitHub.⁠Source 42 LangChain says Fleet agents work inside Slack, Teams, and Gmail.⁠Source 43

Which to choose

Choose Cloudflare MCP server portals if

  • Your company runs Cloudflare One, which Cloudflare says includes portals, and you want MCP servers behind your Access login.⁠Source 1, Source 21
  • You want people’s MCP clients, such as Claude Desktop or Windsurf, to reach MCP servers through one endpoint.⁠Source 1
  • You want to choose the tools each portal exposes; tools you turn off are hidden and can’t be called through it.⁠Source 1
  • You need each tool request logged, and exported with the user’s email to a SIEM through Logpush on an Enterprise plan.⁠Source 1, Source 29

Choose LangSmith if

  • You want to deploy LangChain, Google ADK, or CrewAI agents to a runtime with MCP endpoints and A2A, with documented gaps.⁠Source 25, Source 26, Source 36
  • Non-technical teams should build agents without code, from a description or template; LangChain says Fleet agents work in Slack, Teams, and Gmail.⁠Source 9, Source 43
  • You need LangSmith’s control plane and Agent Servers in your own infrastructure, for full data residency or air-gapped use, on Enterprise.⁠Source 4
  • You want Fleet agents to pause for human approval before specific actions, with tool calls, decisions, and outputs traced.⁠Source 8

Questions buyers ask

Can either one manage agents built elsewhere?

A portal governs MCP servers and their tools, for MCP clients that support remote servers.⁠Source 1 A registry of agents is not publicly documented for portals. LangSmith deploys agents from other frameworks, and agents hosted elsewhere can send it traces.⁠Source 6, Source 36

Do they support MCP and A2A?

Portals proxy MCP tool calls between clients and upstream MCP servers.⁠Source 1 A2A support is not publicly documented for portals. LangSmith’s Agent Server supports A2A, with documented gaps, and can expose agents as MCP tools, and Fleet uses tools from remote MCP servers.⁠Source 7, Source 25, Source 26

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 16 A separate price for portals is not publicly documented. LangSmith Plus is $39 per seat a month, plus usage in LSUs at $1 each.⁠Source 17

Can either one be self-hosted?

A portal’s hostname points to gateway.agents.cloudflare.com.⁠Source 1 Self-hosting one is not publicly documented. On Enterprise, LangSmith can be self-hosted, hybrid, or BYOC on AWS.⁠Source 6, Source 17, Source 23

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

48 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344

  2. Source 2: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abc

  3. Source 3: LangSmith: The Agent Engineering Platform LangChain · checked Back:abcdef

  4. Source 4: LangSmith Deployment LangChain · checked Back:abcdefghi

  5. Source 5: Cloud (SaaS) LangChain · checked Back:abcde

  6. Source 6: Set up LangSmith LangChain · checked Back:abcdefg

  7. Source 7: Remote MCP servers LangChain · checked Back:abcde

  8. Source 8: Access & oversight LangChain · checked Back:abcdef

  9. Source 9: No-code agents with LangSmith Fleet LangChain · checked Back:abcdefgh

  10. Source 10: Agent platform comparison LangChain · checked Back:abcd

  11. Source 11: LangSmith Deployment LangChain · checked Back:abcd

  12. Source 12: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back:ab

  13. Source 13: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abc

  14. Source 14: Authentication & access control LangChain · checked Back:abcd

  15. Source 15: Authentication methods LangChain · checked Back:ab

  16. Source 16: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcde

  17. Source 17: LangSmith Plans and Pricing LangChain · checked Back:abcdefgh

  18. Source 18: LangGraph Platform is now Generally Available: Deploy & manage long-running, stateful Agents LangChain · checked Back:ab

  19. Source 19: Now GA: LangSmith Agent Builder LangChain · checked Back:ab

  20. Source 20: LangSmith Fleet changelog LangChain · checked Back:abc

  21. Source 21: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abc

  22. Source 22: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:abc

  23. Source 23: Bring Your Own Cloud (BYOC) LangChain · checked Back:abc

  24. Source 24: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:ab

  25. Source 25: A2A endpoint in Agent Server LangChain · checked Back:abcdef

  26. Source 26: MCP endpoint in Agent Server LangChain · checked Back:abcd

  27. Source 27: Service tokens · Cloudflare One docs Cloudflare · checked Back:ab

  28. Source 28: Overview (administration) LangChain · checked Back to text

  29. Source 29: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back:abc

  30. Source 30: Audit logs LangChain · checked Back:ab

  31. Source 31: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  32. Source 32: Regions FAQ LangChain · checked Back:ab

  33. Source 33: Trust Center - LangChain LangChain · checked Back:ab

  34. Source 34: MCP server portals · Changelog Cloudflare · checked Back to text

  35. Source 35: Identity providers · Cloudflare One docs Cloudflare · checked Back:ab

  36. Source 36: Deploy other frameworks LangChain · checked Back:abc

  37. Source 37: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  38. Source 38: Support Plans LangChain · checked Back:ab

  39. Source 39: Deploy your app to cloud LangChain · checked Back to text

  40. Source 40: LangSmith control plane LangChain · checked Back to text

  41. Source 41: AI Security | Cloudflare Cloudflare · checked Back to text

  42. Source 42: Essentials LangChain · checked Back:ab

  43. Source 43: LangSmith Fleet LangChain · checked Back:ab

  44. Source 44: Your company's private network Blocks.ai · checked Back to text

  45. Source 45: Network requirements Blocks.ai · checked Back to text

  46. Source 46: Solutions: Agent sprawl Blocks.ai · checked Back to text

  47. Source 47: Solutions: Partner networks Blocks.ai · checked Back to text

  48. Source 48: Pricing Blocks.ai · checked Back to text