Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs MuleSoft Agent Fabric
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
MuleSoft Agent Fabric
Control plane for agents, MCP servers, and APIs across platforms
Short answer
Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms.Source 1, Source 2, Source 3, Source 4 Through a portal, admins control which users and agents reach which MCP tools; Agent Fabric registers agents and orchestrates A2A-compliant ones through brokers.Source 2, Source 5, Source 6, Source 7
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
MuleSoft Agent Fabric
- Agents across organizations: Not publicly documented
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.Source 1 A portal puts multiple MCP servers behind one HTTP endpoint.Source 2 Cloudflare Access policies decide who can connect to it, and Access logs each tool request.Source 2
MuleSoft Agent Fabric
MuleSoft Agent Fabric is an AI control plane for agents, MCP servers, and APIs across platforms; MuleSoft says it builds on its existing products.Source 4, Source 14 Its parts include Agent Registry, policy enforcement through Omni Gateway, agent brokers that orchestrate A2A-compliant agents, and monitoring.Source 6, Source 7, Source 15
The differences that matter
What each one registers
Cloudflare MCP server portalsAdmins add MCP servers to Cloudflare Access and choose the tools each portal exposes.Source 2 An agent registry is not publicly documented.
MuleSoft Agent FabricAgent Registry lists agents, MCP servers, and APIs.Source 6 Scanners register what they find on supported platforms; agents they miss can be registered by hand.Source 6, Source 9
A portal supports up to 80 MCP servers.Source 2 MuleSoft lists scanner limits of one run a day and a capacity of 10,000 services.Source 16
Where access is enforced
Cloudflare MCP server portalsAccess policies decide who can use a portal and see each server; the portal attaches credentials and proxies each tool call.Source 2
MuleSoft Agent FabricOmni Gateway sits in the request path of each managed agent, API, or MCP server and can require authentication and limit which tools agents call.Source 6
Cloudflare cautions that blocked users can still reach a server by its direct URL, and advises making Access that server’s OAuth provider.Source 2
MCP and A2A traffic
Cloudflare MCP server portalsPortals proxy MCP tool calls between clients and upstream MCP servers.Source 2 A2A support is not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | MuleSoft Agent Fabric | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One.Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, with Access to authorize and audit their use.Source 2, Source 3 | AI control plane for agents, MCP servers, and APIs across platforms.Source 4 MuleSoft positions it for enterprises, with IT and security teams in control.Source 13 |
| Maturity | GA since 24 September 2026, after an open beta announced 26 August 2025.Source 10, Source 12 Once called Agents Gateway in some contexts.Source 2 | MuleSoft says it is generally available.Source 13 Release notes begin 3 October 2025; rogue-agent containment and the A2A bridge arrived 31 August 2026.Source 7, Source 26 |
| Control | ||
| Agent registry and discovery | Admins add MCP servers to Access, up to 80 per portal.Source 2 Portals show users only servers whose Allow policy they match.Source 2 Agent registry: not publicly documented. | One inventory of agents, MCP servers, and APIs, whichever platform built them.Source 6 Scanners register what they find; agents can be registered by hand.Source 6, Source 9 |
| Identity and access control | People sign in through Access with their identity provider; agents and bots can use an Access service token.Source 2, Source 5 Policies set who can connect to a portal.Source 2 | Omni Gateway can require authentication and authorization and limit which tools an agent calls.Source 6 User roles come from Anypoint Platform access management.Source 4 |
| Ownership, policy, and revocation | Admins pick a portal’s tools; turned-off tools can’t be called through it.Source 2 Service tokens can be disabled or deleted.Source 21 Owners: not publicly documented. | Governance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.Source 6 Flagged agents can be quarantined after review.Source 20 |
| Audit log and observability | Access logs each tool request, viewable per portal or per server.Source 2 Logpush export to storage or a SIEM is Enterprise-only.Source 2 | Anypoint audit log kept one year by default.Source 23 Omni Gateway can keep a traffic audit trail; Agent Visualizer shows live request flows and metrics.Source 6 |
| Connection | ||
| How agents connect | MCP clients connect to the portal’s HTTPS URL.Source 2 Private servers connect through outbound-only Cloudflare Tunnel or another connector, with Gateway routing on.Source 2, Source 17, Source 18 | Omni Gateway goes in the request path of each managed agent, API, or MCP server.Source 6 Agent network ingress gateways get a public endpoint; egress ones don’t.Source 19 |
| Agents across organizations | Third-party MCP servers can join a portal; Access can use several IdPs, such as for partners.Source 3, Source 27 Partner-controlled agents in a portal: not publicly documented. | An egress gateway enforces policy on agent networks’ calls to agents outside the network.Source 19 Partner-held access controls: not publicly documented. |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; Streamable HTTP or SSE upstream.Source 2 A2A support: not publicly documented. | Omni Gateway supports MCP and A2A.Source 8 A2A powers orchestration, observability, and governance in agent networks.Source 28 MCP Bridge turns APIs into MCP servers.Source 6 |
| Frameworks, models, and clouds supported | MCP clients that support remote servers can connect.Source 2 Upstream servers need a remote HTTP endpoint; some reject proxy-based clients such as portals.Source 2 | MuleSoft calls it vendor agnostic and names Amazon, Google, Microsoft, and Kong among ecosystems scanned.Source 13, Source 14 Brokers orchestrate only A2A-compliant agents.Source 6 |
| Operations | ||
| Deployment options and data residency | A portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.Source 2 Portal self-hosting, data residency: not publicly documented. | Agent Fabric runs on MuleSoft-hosted control planes; Omni Gateway can be self-managed.Source 29, Source 30 Self-hosting Agent Fabric’s control plane is not publicly documented. |
| Compliance attestations | Cloudflare gives account Super Administrators PCI, SOC 2, ISO, and other compliance documents.Source 24 Which ones cover portals is not publicly documented. | MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA.Source 25 An attestation naming Agent Fabric is not publicly documented. |
| Support and SLA | Support varies by Zero Trust plan, with professional services as Contract add-ons.Source 31 Cloudflare advertises a 100% uptime SLA for paid Zero Trust plans.Source 31 | MuleSoft’s SLA for subscriptions started by 1 May 2025 commits to 99.95% monthly availability, without naming Agent Fabric.Source 32 A Premier Success Plan is offered.Source 33 |
| Time and effort to get running | Needs an active domain on Cloudflare and an identity provider on Zero Trust.Source 2 Add MCP servers to Access, create a portal, then connect an MCP client.Source 2 | Needs Agent Fabric product access, turned on by an admin.Source 4 Omni Gateway is required for managed instances; rogue-agent detection needs a JWT-issuing IdP.Source 4 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 10 A separate price for portals is not publicly documented. | MuleSoft packages from $2,000 a month, billed annually.Source 11 Mule Credits meter usage.Source 11, Source 34 The Agent Fabric package lists no price: contact sales.Source 11 |
| Building | ||
| Agent building tools | Cloudflare’s separate Agents SDK is for building and hosting agents; MCP servers can be built on Workers.Source 3, Source 35 No-code builder: not publicly documented. | Agent networks are defined in YAML, brokers in Agent Script.Source 6, Source 15 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.Source 13 |
| Model access | Models used with portals: not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across AI providers.Source 36 | Brokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.Source 15 Model Proxy fronts several LLM providers and can cap a caller’s spend.Source 6, Source 37 |
| Integrations and ecosystem | Portals can be managed with Terraform.Source 2 Access works with social, open source, and corporate identity providers.Source 27 MCP server marketplace: not publicly documented. | The catalog includes curated public MCP servers from the Official MCP Registry and Informatica.Source 6 MuleSoft cites hundreds of enterprise connectors.Source 13 |
Which to choose
Choose Cloudflare MCP server portals if
- You want multiple MCP servers, internal or third-party, behind one endpoint that MCP clients supporting remote servers can use.Source 2, Source 3
- You use Cloudflare One, which Cloudflare says includes portals, and want Access selectors like groups and device posture enforced on portal servers.Source 1, Source 2
- You want admins to choose the specific tools and prompt templates each portal exposes, so turned-off tools can’t be called through it.Source 2
- You want tool-call logs in your SIEM: on Enterprise plans, Logpush exports portal logs with each user’s email and the tool called.Source 2, Source 22
Choose MuleSoft Agent Fabric if
- You want one inventory of agents, MCP servers, and APIs, with scanners that MuleSoft says cover Amazon, Google, and Microsoft.Source 6, Source 14
- You want agents orchestrated: brokers coordinate A2A-compliant agents, and an A2A bridge brings in Agentforce agents.Source 4, Source 6, Source 7, Source 26
- You already use MuleSoft’s Anypoint Platform and want agent governance that uses its access management.Source 4
- You want to cap model spending: Model Proxy can limit a caller’s token or dollar spend against a provider.Source 6, Source 37
Questions buyers ask
What does each one register?
Admins add MCP servers to Cloudflare Access; an agent registry is not publicly documented for portals.Source 2 Agents connect to a portal as MCP clients, with an Access service token or a user’s identity provider login.Source 2, Source 5 Agent Fabric’s Agent Registry lists agents, MCP servers, and APIs.Source 6
Do they support MCP and A2A?
How is each one priced?
Cloudflare says MCP server portals are available to all Cloudflare customers.Source 10 A separate price for portals is not publicly documented. MuleSoft packages start at $2,000 a month, billed annually.Source 11 MuleSoft lists its Agent Fabric package with ‘Contact sales’ and no published price.Source 11
Can either one connect agents across organizations?
Portals can include third-party MCP servers, and Access can use several identity providers at once, for example for partners.Source 3, Source 27 In agent networks, egress gateways enforce policy on calls to agents outside the network.Source 19 Neither publicly documents bringing in another organization’s agents under its control.
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
42 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abcde
Source 2: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546474849
Source 3: MCP governance · Cloudflare Agents docs Back:abcdef
Source 5: Service token support for MCP server portals · Changelog Back:abcde
Source 6: Agent Fabric Overview Back:abcdefghijklmnopqrstuvwxyz27282930313233343536
Source 8: Securing Agent Interactions with Omni Gateway Back:abc
Source 10: MCP server portals are now generally available · Changelog Back:abcde
Source 11: MuleSoft Pricing | Plans From $2,000 a Month Back:abcdefg
Source 13: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Back:abcdef
Source 14: MuleSoft Agent Fabric | Agent Governance and Orchestration Back:abc
Source 15: Building Agent Networks for Agent Fabric Back:abc
Source 16: Discovering and Cataloging External Services with Scanners Back to text
Source 17: Private MCP server support for MCP server portals · Changelog Back:ab
Source 19: Deploying Agent Network Ingress and Egress Managed Omni Gateways Back:abcd
Source 24: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 26: Enhanced MuleSoft Experience Release Notes Back:ab
Source 27: Identity providers · Cloudflare One docs Back:abc
Source 30: Requirements and Limits for Omni Gateway Back to text
Source 31: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 32: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Back to text
Source 33: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Back to text
Source 34: Understand Mule Credits Usage and Rates Back to text
Source 35: Build Agents on Cloudflare · Cloudflare Agents docs Back to text