Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs Okta for AI Agents
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Okta for AI Agents
Okta offering that gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them
Short answer
Cloudflare MCP server portals put MCP servers behind one governed endpoint; Okta says Okta for AI Agents gives AI agents a first-class identity in an Okta org.Source 1, Source 2, Source 3, Source 4 Portals decide who reaches which MCP tools through them; Okta lets admins define what each agent can access, and its MCP gateway, Agent Gateway, is in preview.Source 1, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both control access to MCP servers: portals for traffic through them, Okta through resource connections.Source 1, Source 5 Okta’s Agent Gateway, in preview, also puts tools from several MCP servers behind one endpoint.Source 6
- Where they differ
- Okta registers the agents themselves, with credentials; a portal lists MCP servers, which agents reach as MCP clients using a person’s login or a service token.Source 1, Source 7, Source 8, Source 9
- Running both
- Neither vendor publicly documents using the two together.
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Okta for AI Agents
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.Source 20 A portal puts multiple MCP servers behind one HTTP endpoint, applies Cloudflare Access policies to who can connect, and logs the requests made with its tools.Source 1
Okta for AI Agents
Okta for AI Agents is an Okta product for discovering, managing, and securing the AI agent lifecycle in an Okta org.Source 4 Okta says it registers agents in Universal Directory alongside workforce users; admins can define which resources each agent can access.Source 5, Source 10
The differences that matter
What each one registers
Cloudflare MCP server portalsAdmins add MCP servers to Cloudflare Access and choose which tools each portal exposes; each portal supports up to 80 servers.Source 1
Okta for AI AgentsAgents can be registered by hand for custom-built agents, or imported from builder platforms; Okta says they sit in Universal Directory.Source 7, Source 17
Okta’s ISPM discovers shadow agents in managed browsers; discovery on endpoints is in early access.Source 21 The Core SKU, for regulated environments, excludes ISPM.Source 22
How agents are identified
Cloudflare MCP server portalsAgents connect as MCP clients using a person’s identity provider login or an Access service token; Access policies decide who reaches the portal.Source 1, Source 9
Okta for AI AgentsAn agent added by hand identifies to Okta with a client ID, secret, key pair, or metadata document; resource connections set what it can access.Source 5, Source 8
Portal service-token sessions use the server’s admin credential upstream; a manually added Okta agent acts for a user only if that user is signed in to a linked app.Source 1, Source 8
Turning access off
Cloudflare MCP server portalsAdmins can turn off a tool so it can’t be called through the portal, and deleting a service token revokes its access.Source 1, Source 23
Okta for AI AgentsAdmins can deactivate an agent, which Okta says immediately blocks new sessions, or remove a resource connection, denying the agent’s future access requests to it.Source 19, Source 24
Cloudflare cautions that blocked users can still use a server’s direct URL, and advises making Access the server’s OAuth provider.Source 1
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | Okta for AI Agents | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One.Source 20 A portal puts multiple MCP servers behind one HTTP endpoint, with Access as a governance layer for MCP.Source 1, Source 2 | An Okta product to discover, manage, and secure the AI agent lifecycle in an Okta org.Source 4 Okta says it gives AI agents a first-class identity.Source 3 |
| Maturity | GA since 24 September 2026, after an open beta announced 26 August 2025.Source 14, Source 16 Previously called Agents Gateway in some contexts.Source 1 | Okta announced GA in a post dated 29 April 2026.Source 17 It said Agent Gateway, in preview, could be requested from 22 July 2026, with GA planned for Q3.Source 18, Source 19 |
| Control | ||
| Agent registry and discovery | Internal and third-party MCP servers, up to 80 per portal; portals show users only servers an Allow policy permits.Source 1, Source 2 Agent registry: not publicly documented. | Agents added by hand or imported, with optional owners.Source 7, Source 8 Okta’s ISPM discovers shadow agents in managed browsers; endpoint discovery is in early access.Source 21 |
| Identity and access control | Access policies set who can connect, by identity provider login or service token.Source 1, Source 9 Selectors such as email, group, country, and device posture are enforced.Source 1 | Resource connections set what each agent can access.Source 5 For agents added by hand, admins list which apps, services, and other agents may call each one.Source 8 |
| Ownership, policy, and revocation | Admins choose each portal’s tools, can turn a tool off in the portal, and can auto-disable unused service tokens.Source 1, Source 23 Owner field: not publicly documented. | Agents added by hand take optional owners, up to five individuals.Source 8 Okta says admins can deactivate an agent and set which agents may call others.Source 18, Source 19 |
| Audit log and observability | Access logs tool requests, viewable per portal or server; exports record user email and tool name.Source 1, Source 31 Logpush to a SIEM: Enterprise plans only.Source 1 | Agent events land in Okta’s System Log; log streaming can send them to Amazon EventBridge or Splunk Cloud.Source 4, Source 27 Agent Gateway (preview) shows 30 days of activity.Source 32 |
| Connection | ||
| How agents connect | MCP clients use the portal’s HTTPS URL.Source 1 Private servers can connect via outbound-only Cloudflare Tunnel, with Gateway routing on.Source 1, Source 11, Source 25 | Okta issues the tokens; in its agent-to-agent flow, the caller passes its token on.Source 12, Source 26 Agent Gateway, in preview, can be an agent’s remote MCP endpoint.Source 13 |
| Agents across organizations | Partner-controlled agents in a portal: not publicly documented. Cloudflare One can use several identity providers at once for partners and contractors.Source 33 | Not publicly documented (checked 2 October 2026) |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 1 A2A support: not publicly documented. | MCP servers as agent resources; Agent Gateway for MCP tools is in preview.Source 5, Source 6 Okta for AI Agents’ docs don’t mention the A2A protocol. |
| Frameworks, models, and clouds supported | MCP clients that support remote MCP servers; setup steps for Claude Desktop, OpenCode, Windsurf, and others.Source 1 Some servers reject portals as proxy clients.Source 1 | Okta says it covers agents from any vendor, framework, or cloud, including homegrown Python or LangChain agents and agents in purchased software.Source 3, Source 17, Source 18, Source 34 |
| Operations | ||
| Deployment options and data residency | A portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.Source 1 Self-hosting a portal is not publicly documented. | A subscription on an Okta org.Source 12 Okta says Core SKU agents register inside the org’s regulated cell.Source 29 Agent Gateway, in preview, has an Okta-hosted URL.Source 13 |
| Compliance attestations | Account Super Administrators can get Cloudflare’s PCI, SOC 2, ISO, and other documents.Source 28 Which ones cover portals is not publicly documented. | Okta says its Core SKU is GA for FedRAMP and HIPAA environments.Source 29 Okta says the company holds SOC 2 and ISO/IEC 27001.Source 30 Product scope: not publicly documented. |
| Support and SLA | Cloudflare lists a 100% uptime SLA for paid Zero Trust plans.Source 35 Support varies by plan; professional services are Contract add-ons.Source 35 | Okta suites include online support 24 hours a day, five days a week; Premier Success Plans are sold separately.Source 15 |
| Time and effort to get running | An active domain on Cloudflare and an identity provider on Zero Trust; then add servers, create a portal, and connect an MCP client.Source 1 | An Okta org with the product.Source 12 Okta says it has prebuilt integrations for Salesforce Agentforce, Amazon Bedrock AgentCore, and ServiceNow AI Platform.Source 17 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 14 A separate price for portals is not publicly documented. | Okta says it is a separate subscription.Source 3 Its pricing page lists it as an add-on to Okta suite plans.Source 15 A list price is not publicly documented. |
| Building | ||
| Agent building tools | Cloudflare’s separate Agents SDK is for building and hosting agents; MCP servers can be built on Workers.Source 2, Source 36 A no-code builder is not publicly documented. | Not publicly documented (checked 2 October 2026) |
| Model access | Models for portals: not publicly documented. Cloudflare’s separate Agents SDK works with Workers AI, OpenAI, Anthropic, and Google Gemini.Source 37 | Not publicly documented (checked 2 October 2026) |
| Integrations and ecosystem | Portals can be managed with Terraform.Source 1 Logpush exports portal logs on Enterprise plans.Source 1, Source 38 Social, open-source, and corporate identity providers work.Source 33 | Okta’s imports include Salesforce Agentforce, Amazon Bedrock AgentCore, and Microsoft Copilot Studio.Source 34 Okta says Slack and Notion support Cross App Access.Source 3 |
Which to choose
Choose Cloudflare MCP server portals if
- You want many MCP servers behind one endpoint, with admins choosing which tools each portal exposes.Source 1
- You want each user shown only the MCP servers their Access policy allows, with group, country, and device posture checks.Source 1
- Some MCP servers run only on your private network, and you want them reached through outbound-only Cloudflare Tunnel, with Gateway routing on.Source 1, Source 11, Source 25
- You use Cloudflare One, which Cloudflare says includes portals, and want portal traffic in your Gateway HTTP logs with your other traffic.Source 1, Source 20
Choose Okta for AI Agents if
- You want agents registered alongside workforce users in Universal Directory, which Okta says assigns owners, with owners optional for hand-added agents.Source 8, Source 10
- Your agents come from builder platforms such as Salesforce Agentforce or Amazon Bedrock AgentCore, and you want them imported into Okta.Source 7, Source 34
- You want to control which agents may call other agents, with Okta issuing resource-scoped tokens that expire, Okta says.Source 18, Source 26
- You run HIPAA or other regulated environments, where Okta says its Core SKU registers agents inside your org’s regulated cell.Source 29
Questions buyers ask
Does Okta offer an MCP gateway like Cloudflare’s portals?
Do they support MCP and A2A?
Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; their A2A support is not publicly documented.Source 1 Okta says its Cross App Access protocol is the official Enterprise-Managed Authorization extension for MCP.Source 3 Okta for AI Agents’ docs don’t mention the A2A protocol.
How is each one priced?
Can either one connect agents across organizations?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
44 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546
Source 3: Okta brings first-class identity to AI agents with Agent SSO Back:abcdefgh
Source 5: AI agent resource connections (Okta Help Center) Back:abcdefg
Source 7: Add and register AI agents (Okta Help Center) Back:abcd
Source 8: Add AI agents manually (Okta Help Center) Back:abcdefghij
Source 9: Service token support for MCP server portals · Changelog Back:abcde
Source 11: Private MCP server support for MCP server portals · Changelog Back:abcd
Source 12: Set up AI agent token exchange (Okta Developer) Back:abcd
Source 13: Add an Agent Gateway (Okta Help Center) Back:abcd
Source 14: MCP server portals are now generally available · Changelog Back:abcde
Source 17: Okta for AI Agents is now generally available Back:abcde
Source 18: Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance Back:abcde
Source 19: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance Back:abcdef
Source 20: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abc
Source 21: Okta Identity Security Posture Management (ISPM) release announcements Back:ab
Source 22: Discover and assess AI agents (Okta Help Center) Back to text
Source 24: Connect AI agents to resources (Okta Help Center) Back to text
Source 26: Agent-to-agent connections (Okta Help Center) Back:abc
Source 28: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 29: Okta is the first independent and neutral identity platform to bring AI agent governance to highly regulated environments Back:abcd
Source 30: Okta Security Trust Center | Powered by SafeBase Back:ab
Source 31: MCP Portal Logs · Cloudflare Logs docs Back to text
Source 32: View Agent Gateway activity (Okta Help Center) Back to text
Source 33: Identity providers · Cloudflare One docs Back:abc
Source 34: Apps that support AI agent imports (Okta Help Center) Back:abc
Source 35: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 36: Build Agents on Cloudflare · Cloudflare Agents docs Back to text
Source 37: Using AI Models · Cloudflare Agents docs Back to text
Source 38: Logpush integration · Cloudflare One docs Back to text
Source 39: Secure MCP servers · Cloudflare One docs Back to text