Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs MuleSoft Agent Fabric

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

MuleSoft Agent Fabric

Control plane for agents, MCP servers, and APIs across platforms

Short answer

Cloudflare says its MCP server portals, part of Cloudflare One, put MCP servers behind one governed endpoint; MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms.⁠Source 1, Source 2, Source 3, Source 4 Through a portal, admins control which users and agents reach which MCP tools; Agent Fabric registers agents and orchestrates A2A-compliant ones through brokers.⁠Source 2, Source 5, Source 6, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both put access control in front of MCP servers and can log the traffic: Cloudflare with Access policies and request logs, MuleSoft with Omni Gateway.⁠Source 2, Source 6, Source 8
Where they differ
Agent Fabric also registers agents and APIs, and its brokers orchestrate A2A-compliant agents.⁠Source 6, Source 7 For portals, an agent registry and A2A support are not publicly documented.
Running both
Neither vendor publicly documents using the two together. Cloudflare’s portals use Streamable HTTP MCP; MuleSoft’s MCP Connector runs MCP inside Mule applications.⁠Source 2, Source 6
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 2
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 2
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 2
  • Agents across organizations: Not publicly documented

MuleSoft Agent Fabric

  • Build agents: OfferedAgent brokers in Agent Script⁠Source 6
  • Host and run agents: OfferedAgent brokers on CloudHub 2.0⁠Source 6
  • Identity and access: OfferedOmni Gateway authentication and authorization⁠Source 6
  • Registry and governance: OfferedAgent Registry in Anypoint Exchange⁠Source 6
  • Traffic between agents, tools, and models: OfferedOmni Gateway in request path⁠Source 6
  • Agents across organizations: Not publicly documented

At a glance

TopicCloudflare MCP server portalsMuleSoft Agent Fabric
What it isOne HTTP endpoint for multiple MCP servers, with Cloudflare Access policies on who connects and logs of tool requests.⁠Source 2 Cloudflare says portals are part of Cloudflare One.⁠Source 1A control plane for agents, MCP servers, and APIs across platforms, with a registry, policy enforcement at Omni Gateway, and agent orchestration.⁠Source 4, Source 6, Source 7
What gets registeredMCP servers, which admins add to Cloudflare Access, and the tools each portal exposes.⁠Source 2 An agent registry is not publicly documented.Agents, MCP servers, and APIs.⁠Source 6 Scanners register what they find on supported platforms; agents can also be registered by hand.⁠Source 6, Source 9
How agents connectAs MCP clients, to the portal’s HTTPS URL, signing in through Access with an identity provider (IdP) or with an Access service token.⁠Source 2, Source 5Requests to each managed agent, API, or MCP server pass through Omni Gateway, placed in the request path.⁠Source 6
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 10 A separate price for portals is not publicly documented.MuleSoft packages start at $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 11 MuleSoft lists its Agent Fabric package with ‘Contact sales’ and no published price.⁠Source 11
Generally availableSince 24 September 2026, after an open beta announced on 26 August 2025.⁠Source 10, Source 12MuleSoft says it is generally available, with new capabilities each month.⁠Source 13 Its release notes begin on 3 October 2025.⁠Source 7

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.⁠Source 1 A portal puts multiple MCP servers behind one HTTP endpoint.⁠Source 2 Cloudflare Access policies decide who can connect to it, and Access logs each tool request.⁠Source 2

MuleSoft Agent Fabric

MuleSoft Agent Fabric is an AI control plane for agents, MCP servers, and APIs across platforms; MuleSoft says it builds on its existing products.⁠Source 4, Source 14 Its parts include Agent Registry, policy enforcement through Omni Gateway, agent brokers that orchestrate A2A-compliant agents, and monitoring.⁠Source 6, Source 7, Source 15

The differences that matter

  1. What each one registers

    Cloudflare MCP server portals

    Admins add MCP servers to Cloudflare Access and choose the tools each portal exposes.⁠Source 2 An agent registry is not publicly documented.

    MuleSoft Agent Fabric

    Agent Registry lists agents, MCP servers, and APIs.⁠Source 6 Scanners register what they find on supported platforms; agents they miss can be registered by hand.⁠Source 6, Source 9

    A portal supports up to 80 MCP servers.⁠Source 2 MuleSoft lists scanner limits of one run a day and a capacity of 10,000 services.⁠Source 16

  2. Where access is enforced

    Cloudflare MCP server portals

    Access policies decide who can use a portal and see each server; the portal attaches credentials and proxies each tool call.⁠Source 2

    MuleSoft Agent Fabric

    Omni Gateway sits in the request path of each managed agent, API, or MCP server and can require authentication and limit which tools agents call.⁠Source 6

    Cloudflare cautions that blocked users can still reach a server by its direct URL, and advises making Access that server’s OAuth provider.⁠Source 2

  3. MCP and A2A traffic

    Cloudflare MCP server portals

    Portals proxy MCP tool calls between clients and upstream MCP servers.⁠Source 2 A2A support is not publicly documented.

    MuleSoft Agent Fabric

    Agent brokers orchestrate A2A-compliant agents; an A2A bridge presents Agentforce agents, which aren’t A2A-compliant on their own, as compliant.⁠Source 4, Source 6, Source 7

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsMuleSoft Agent Fabric
Network exposureClients use the portal’s HTTPS URL.⁠Source 2 Private servers can connect via outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 2, Source 17, Source 18Omni Gateway sits in each managed instance’s request path; agent network ingress gateways get a public endpoint, egress gateways don’t.⁠Source 6, Source 19
IdentityPeople sign in through Access with their IdP; agents can use service tokens.⁠Source 2, Source 5 Independent MFA isn’t enforced through a portal.⁠Source 2Omni Gateway can require authentication and authorization.⁠Source 6 For rogue-agent detection, agents are set up as service identities in your IdP.⁠Source 20
Access changes and revocationDeleting a service token revokes its access.⁠Source 21 A tool turned off in a portal can’t be called through it.⁠Source 2Admins can quarantine a flagged agent, stopping it from acting; nothing is quarantined without review, and it’s reversible.⁠Source 20
Audit trailAccess logs each tool request in a portal.⁠Source 2 Enterprise-plan Logpush exports record the user’s email and the tool called.⁠Source 2, Source 22Anypoint Platform keeps a queryable audit log, one year by default; Omni Gateway can keep a traffic audit trail.⁠Source 6, Source 23
ComplianceCloudflare gives Super Administrators PCI, SOC 2, ISO, and other documents.⁠Source 24 Portals’ coverage: not publicly documented.MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 25

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and MuleSoft Agent Fabric compared on 18 criteria
Cloudflare MCP server portalsMuleSoft Agent Fabric
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One.⁠Source 1 A portal puts multiple MCP servers behind one HTTP endpoint, with Access to authorize and audit their use.⁠Source 2, Source 3AI control plane for agents, MCP servers, and APIs across platforms.⁠Source 4 MuleSoft positions it for enterprises, with IT and security teams in control.⁠Source 13
MaturityGA since 24 September 2026, after an open beta announced 26 August 2025.⁠Source 10, Source 12 Once called Agents Gateway in some contexts.⁠Source 2MuleSoft says it is generally available.⁠Source 13 Release notes begin 3 October 2025; rogue-agent containment and the A2A bridge arrived 31 August 2026.⁠Source 7, Source 26
Control
Agent registry and discoveryAdmins add MCP servers to Access, up to 80 per portal.⁠Source 2 Portals show users only servers whose Allow policy they match.⁠Source 2 Agent registry: not publicly documented.One inventory of agents, MCP servers, and APIs, whichever platform built them.⁠Source 6 Scanners register what they find; agents can be registered by hand.⁠Source 6, Source 9
Identity and access controlPeople sign in through Access with their identity provider; agents and bots can use an Access service token.⁠Source 2, Source 5 Policies set who can connect to a portal.⁠Source 2Omni Gateway can require authentication and authorization and limit which tools an agent calls.⁠Source 6 User roles come from Anypoint Platform access management.⁠Source 4
Ownership, policy, and revocationAdmins pick a portal’s tools; turned-off tools can’t be called through it.⁠Source 2 Service tokens can be disabled or deleted.⁠Source 21 Owners: not publicly documented.Governance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.⁠Source 6 Flagged agents can be quarantined after review.⁠Source 20
Audit log and observabilityAccess logs each tool request, viewable per portal or per server.⁠Source 2 Logpush export to storage or a SIEM is Enterprise-only.⁠Source 2Anypoint audit log kept one year by default.⁠Source 23 Omni Gateway can keep a traffic audit trail; Agent Visualizer shows live request flows and metrics.⁠Source 6
Connection
How agents connectMCP clients connect to the portal’s HTTPS URL.⁠Source 2 Private servers connect through outbound-only Cloudflare Tunnel or another connector, with Gateway routing on.⁠Source 2, Source 17, Source 18Omni Gateway goes in the request path of each managed agent, API, or MCP server.⁠Source 6 Agent network ingress gateways get a public endpoint; egress ones don’t.⁠Source 19
Agents across organizationsThird-party MCP servers can join a portal; Access can use several IdPs, such as for partners.⁠Source 3, Source 27 Partner-controlled agents in a portal: not publicly documented.An egress gateway enforces policy on agent networks’ calls to agents outside the network.⁠Source 19 Partner-held access controls: not publicly documented.
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; Streamable HTTP or SSE upstream.⁠Source 2 A2A support: not publicly documented.Omni Gateway supports MCP and A2A.⁠Source 8 A2A powers orchestration, observability, and governance in agent networks.⁠Source 28 MCP Bridge turns APIs into MCP servers.⁠Source 6
Frameworks, models, and clouds supportedMCP clients that support remote servers can connect.⁠Source 2 Upstream servers need a remote HTTP endpoint; some reject proxy-based clients such as portals.⁠Source 2MuleSoft calls it vendor agnostic and names Amazon, Google, Microsoft, and Kong among ecosystems scanned.⁠Source 13, Source 14 Brokers orchestrate only A2A-compliant agents.⁠Source 6
Operations
Deployment options and data residencyA portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 2 Portal self-hosting, data residency: not publicly documented.Agent Fabric runs on MuleSoft-hosted control planes; Omni Gateway can be self-managed.⁠Source 29, Source 30 Self-hosting Agent Fabric’s control plane is not publicly documented.
Compliance attestationsCloudflare gives account Super Administrators PCI, SOC 2, ISO, and other compliance documents.⁠Source 24 Which ones cover portals is not publicly documented.MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 25 An attestation naming Agent Fabric is not publicly documented.
Support and SLASupport varies by Zero Trust plan, with professional services as Contract add-ons.⁠Source 31 Cloudflare advertises a 100% uptime SLA for paid Zero Trust plans.⁠Source 31MuleSoft’s SLA for subscriptions started by 1 May 2025 commits to 99.95% monthly availability, without naming Agent Fabric.⁠Source 32 A Premier Success Plan is offered.⁠Source 33
Time and effort to get runningNeeds an active domain on Cloudflare and an identity provider on Zero Trust.⁠Source 2 Add MCP servers to Access, create a portal, then connect an MCP client.⁠Source 2Needs Agent Fabric product access, turned on by an admin.⁠Source 4 Omni Gateway is required for managed instances; rogue-agent detection needs a JWT-issuing IdP.⁠Source 4
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 10 A separate price for portals is not publicly documented.MuleSoft packages from $2,000 a month, billed annually.⁠Source 11 Mule Credits meter usage.⁠Source 11, Source 34 The Agent Fabric package lists no price: contact sales.⁠Source 11
Building
Agent building toolsCloudflare’s separate Agents SDK is for building and hosting agents; MCP servers can be built on Workers.⁠Source 3, Source 35 No-code builder: not publicly documented.Agent networks are defined in YAML, brokers in Agent Script.⁠Source 6, Source 15 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 13
Model accessModels used with portals: not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 36Brokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.⁠Source 15 Model Proxy fronts several LLM providers and can cap a caller’s spend.⁠Source 6, Source 37
Integrations and ecosystemPortals can be managed with Terraform.⁠Source 2 Access works with social, open source, and corporate identity providers.⁠Source 27 MCP server marketplace: not publicly documented.The catalog includes curated public MCP servers from the Official MCP Registry and Informatica.⁠Source 6 MuleSoft cites hundreds of enterprise connectors.⁠Source 13

Which to choose

Choose Cloudflare MCP server portals if

  • You want multiple MCP servers, internal or third-party, behind one endpoint that MCP clients supporting remote servers can use.⁠Source 2, Source 3
  • You use Cloudflare One, which Cloudflare says includes portals, and want Access selectors like groups and device posture enforced on portal servers.⁠Source 1, Source 2
  • You want admins to choose the specific tools and prompt templates each portal exposes, so turned-off tools can’t be called through it.⁠Source 2
  • You want tool-call logs in your SIEM: on Enterprise plans, Logpush exports portal logs with each user’s email and the tool called.⁠Source 2, Source 22

Choose MuleSoft Agent Fabric if

  • You want one inventory of agents, MCP servers, and APIs, with scanners that MuleSoft says cover Amazon, Google, and Microsoft.⁠Source 6, Source 14
  • You want agents orchestrated: brokers coordinate A2A-compliant agents, and an A2A bridge brings in Agentforce agents.⁠Source 4, Source 6, Source 7, Source 26
  • You already use MuleSoft’s Anypoint Platform and want agent governance that uses its access management.⁠Source 4
  • You want to cap model spending: Model Proxy can limit a caller’s token or dollar spend against a provider.⁠Source 6, Source 37

Questions buyers ask

What does each one register?

Admins add MCP servers to Cloudflare Access; an agent registry is not publicly documented for portals.⁠Source 2 Agents connect to a portal as MCP clients, with an Access service token or a user’s identity provider login.⁠Source 2, Source 5 Agent Fabric’s Agent Registry lists agents, MCP servers, and APIs.⁠Source 6

Do they support MCP and A2A?

Omni Gateway supports MCP and A2A, and A2A powers orchestration in agent networks.⁠Source 8, Source 28 Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.⁠Source 2 A2A support in portals is not publicly documented.

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 10 A separate price for portals is not publicly documented. MuleSoft packages start at $2,000 a month, billed annually.⁠Source 11 MuleSoft lists its Agent Fabric package with ‘Contact sales’ and no published price.⁠Source 11

Can either one connect agents across organizations?

Portals can include third-party MCP servers, and Access can use several identity providers at once, for example for partners.⁠Source 3, Source 27 In agent networks, egress gateways enforce policy on calls to agents outside the network.⁠Source 19 Neither publicly documents bringing in another organization’s agents under its control.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

42 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abcde

  2. Source 2: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546474849

  3. Source 3: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcdef

  4. Source 4: Get Started with Agent Fabric Salesforce · checked Back:abcdefghij

  5. Source 5: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcde

  6. Source 6: Agent Fabric Overview Salesforce · checked Back:abcdefghijklmnopqrstuvwxyz27282930313233343536

  7. Source 7: Agent Fabric Release Notes Salesforce · checked Back:abcdefgh

  8. Source 8: Securing Agent Interactions with Omni Gateway Salesforce · checked Back:abc

  9. Source 9: Register Services Manually Salesforce · checked Back:abc

  10. Source 10: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcde

  11. Source 11: MuleSoft Pricing | Plans From $2,000 a Month Salesforce · checked Back:abcdefg

  12. Source 12: MCP server portals · Changelog Cloudflare · checked Back:ab

  13. Source 13: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Salesforce · checked Back:abcdef

  14. Source 14: MuleSoft Agent Fabric | Agent Governance and Orchestration Salesforce · checked Back:abc

  15. Source 15: Building Agent Networks for Agent Fabric Salesforce · checked Back:abc

  16. Source 16: Discovering and Cataloging External Services with Scanners Salesforce · checked Back to text

  17. Source 17: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:ab

  18. Source 18: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:ab

  19. Source 19: Deploying Agent Network Ingress and Egress Managed Omni Gateways Salesforce · checked Back:abcd

  20. Source 20: Detect and Contain Rogue Agents Salesforce · checked Back:abc

  21. Source 21: Service tokens · Cloudflare One docs Cloudflare · checked Back:ab

  22. Source 22: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back:ab

  23. Source 23: Audit Logging in Anypoint Platform Salesforce · checked Back:ab

  24. Source 24: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  25. Source 25: Anypoint Platform Trust Center Salesforce · checked Back:ab

  26. Source 26: Enhanced MuleSoft Experience Release Notes Salesforce · checked Back:ab

  27. Source 27: Identity providers · Cloudflare One docs Cloudflare · checked Back:abc

  28. Source 28: Using A2A Protocol in Agent Networks Salesforce · checked Back:ab

  29. Source 29: Salesforce Hyperforce Overview Salesforce · checked Back to text

  30. Source 30: Requirements and Limits for Omni Gateway Salesforce · checked Back to text

  31. Source 31: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  32. Source 32: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Salesforce · checked Back to text

  33. Source 33: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Salesforce · checked Back to text

  34. Source 34: Understand Mule Credits Usage and Rates Salesforce · checked Back to text

  35. Source 35: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back to text

  36. Source 36: AI Security | Cloudflare Cloudflare · checked Back to text

  37. Source 37: Creating and Managing Model Proxies Salesforce · checked Back:ab

  38. Source 38: Your company's private network Blocks.ai · checked Back to text

  39. Source 39: Network requirements Blocks.ai · checked Back to text

  40. Source 40: Solutions: Agent sprawl Blocks.ai · checked Back to text

  41. Source 41: Solutions: Partner networks Blocks.ai · checked Back to text

  42. Source 42: Pricing Blocks.ai · checked Back to text