Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs Okta for AI Agents

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

Okta for AI Agents

Okta offering that gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them

Short answer

Cloudflare MCP server portals put MCP servers behind one governed endpoint; Okta says Okta for AI Agents gives AI agents a first-class identity in an Okta org.⁠Source 1, Source 2, Source 3, Source 4 Portals decide who reaches which MCP tools through them; Okta lets admins define what each agent can access, and its MCP gateway, Agent Gateway, is in preview.⁠Source 1, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both control access to MCP servers: portals for traffic through them, Okta through resource connections.⁠Source 1, Source 5 Okta’s Agent Gateway, in preview, also puts tools from several MCP servers behind one endpoint.⁠Source 6
Where they differ
Okta registers the agents themselves, with credentials; a portal lists MCP servers, which agents reach as MCP clients using a person’s login or a service token.⁠Source 1, Source 7, Source 8, Source 9
Running both
Neither vendor publicly documents using the two together.
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 1
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 1
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 1
  • Agents across organizations: Not publicly documented

Okta for AI Agents

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent identity and credentials⁠Source 8
  • Registry and governance: OfferedUniversal Directory with human owners⁠Source 10
  • Traffic between agents, tools, and models: PreviewAgent Gateway for MCP tools⁠Source 6
  • Agents across organizations: Not publicly documented

At a glance

TopicCloudflare MCP server portalsOkta for AI Agents
What it governsMCP servers and the tools admins choose to expose, behind one portal endpoint.⁠Source 1 A registry of agents is not publicly documented.Agents, which Okta says get a first-class identity, registered in Universal Directory alongside workforce users.⁠Source 3, Source 10
How agents get accessAs MCP clients, through a person’s identity provider login or an Access service token.⁠Source 1, Source 9Manually added agents have credentials registered in Okta; resource connections set what each agent can access.⁠Source 5, Source 8
Where it runsAt a proxied hostname pointing to gateway.agents.cloudflare.com.⁠Source 1 MCP servers on a private network can connect through Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 11As a subscription on your Okta org.⁠Source 12 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 13
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 14 A separate price for portals is not publicly documented.Okta’s pricing page lists it as an add-on to Okta suite plans.⁠Source 15 A list price is not publicly documented.
Generally availableSince 24 September 2026, after an open beta announced in August 2025.⁠Source 14, Source 16Okta announced GA in a post dated 29 April 2026.⁠Source 17 Okta said customers could request Agent Gateway, in preview, from 22 July 2026, and in September that GA was planned for Q3.⁠Source 18, Source 19

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its SASE platform.⁠Source 20 A portal puts multiple MCP servers behind one HTTP endpoint, applies Cloudflare Access policies to who can connect, and logs the requests made with its tools.⁠Source 1

Okta for AI Agents

Okta for AI Agents is an Okta product for discovering, managing, and securing the AI agent lifecycle in an Okta org.⁠Source 4 Okta says it registers agents in Universal Directory alongside workforce users; admins can define which resources each agent can access.⁠Source 5, Source 10

The differences that matter

  1. What each one registers

    Cloudflare MCP server portals

    Admins add MCP servers to Cloudflare Access and choose which tools each portal exposes; each portal supports up to 80 servers.⁠Source 1

    Okta for AI Agents

    Agents can be registered by hand for custom-built agents, or imported from builder platforms; Okta says they sit in Universal Directory.⁠Source 7, Source 17

    Okta’s ISPM discovers shadow agents in managed browsers; discovery on endpoints is in early access.⁠Source 21 The Core SKU, for regulated environments, excludes ISPM.⁠Source 22

  2. How agents are identified

    Cloudflare MCP server portals

    Agents connect as MCP clients using a person’s identity provider login or an Access service token; Access policies decide who reaches the portal.⁠Source 1, Source 9

    Okta for AI Agents

    An agent added by hand identifies to Okta with a client ID, secret, key pair, or metadata document; resource connections set what it can access.⁠Source 5, Source 8

    Portal service-token sessions use the server’s admin credential upstream; a manually added Okta agent acts for a user only if that user is signed in to a linked app.⁠Source 1, Source 8

  3. Turning access off

    Cloudflare MCP server portals

    Admins can turn off a tool so it can’t be called through the portal, and deleting a service token revokes its access.⁠Source 1, Source 23

    Okta for AI Agents

    Admins can deactivate an agent, which Okta says immediately blocks new sessions, or remove a resource connection, denying the agent’s future access requests to it.⁠Source 19, Source 24

    Cloudflare cautions that blocked users can still use a server’s direct URL, and advises making Access the server’s OAuth provider.⁠Source 1

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsOkta for AI Agents
Network exposureClients use the portal’s HTTPS URL.⁠Source 1 Private servers can use outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 11, Source 25Whether an agent needs an inbound endpoint is not publicly documented. Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 13
IdentityPeople log in via their identity provider; agents can use service tokens.⁠Source 1, Source 9 Access’s independent MFA isn’t enforced on portal-authorized servers.⁠Source 1Manually added agents identify with a client ID, secret, key pair, or metadata document; agent-to-agent tokens are resource-scoped and expire.⁠Source 8, Source 26
Access changes and revocationDeleting a service token revokes its access.⁠Source 23 A tool turned off in a portal can’t be called through it.⁠Source 1Okta says deactivating an agent immediately blocks new sessions; expanded runtime kill switch capabilities are planned for Q4 GA.⁠Source 19
Audit trailAccess logs individual requests made with a portal’s tools.⁠Source 1 Logpush export to a SIEM is on Enterprise plans only.⁠Source 1Agent events land in Okta’s System Log; log streaming can send them to Amazon EventBridge or Splunk Cloud.⁠Source 4, Source 27
ComplianceSuper Administrators can get Cloudflare’s PCI, SOC 2, and ISO documents.⁠Source 28 Their scope for portals is not publicly documented.Okta says its Core SKU is GA for FedRAMP and HIPAA, and the company holds SOC 2 and ISO 27001.⁠Source 29, Source 30

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and Okta for AI Agents compared on 18 criteria
Cloudflare MCP server portalsOkta for AI Agents
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One.⁠Source 20 A portal puts multiple MCP servers behind one HTTP endpoint, with Access as a governance layer for MCP.⁠Source 1, Source 2An Okta product to discover, manage, and secure the AI agent lifecycle in an Okta org.⁠Source 4 Okta says it gives AI agents a first-class identity.⁠Source 3
MaturityGA since 24 September 2026, after an open beta announced 26 August 2025.⁠Source 14, Source 16 Previously called Agents Gateway in some contexts.⁠Source 1Okta announced GA in a post dated 29 April 2026.⁠Source 17 It said Agent Gateway, in preview, could be requested from 22 July 2026, with GA planned for Q3.⁠Source 18, Source 19
Control
Agent registry and discoveryInternal and third-party MCP servers, up to 80 per portal; portals show users only servers an Allow policy permits.⁠Source 1, Source 2 Agent registry: not publicly documented.Agents added by hand or imported, with optional owners.⁠Source 7, Source 8 Okta’s ISPM discovers shadow agents in managed browsers; endpoint discovery is in early access.⁠Source 21
Identity and access controlAccess policies set who can connect, by identity provider login or service token.⁠Source 1, Source 9 Selectors such as email, group, country, and device posture are enforced.⁠Source 1Resource connections set what each agent can access.⁠Source 5 For agents added by hand, admins list which apps, services, and other agents may call each one.⁠Source 8
Ownership, policy, and revocationAdmins choose each portal’s tools, can turn a tool off in the portal, and can auto-disable unused service tokens.⁠Source 1, Source 23 Owner field: not publicly documented.Agents added by hand take optional owners, up to five individuals.⁠Source 8 Okta says admins can deactivate an agent and set which agents may call others.⁠Source 18, Source 19
Audit log and observabilityAccess logs tool requests, viewable per portal or server; exports record user email and tool name.⁠Source 1, Source 31 Logpush to a SIEM: Enterprise plans only.⁠Source 1Agent events land in Okta’s System Log; log streaming can send them to Amazon EventBridge or Splunk Cloud.⁠Source 4, Source 27 Agent Gateway (preview) shows 30 days of activity.⁠Source 32
Connection
How agents connectMCP clients use the portal’s HTTPS URL.⁠Source 1 Private servers can connect via outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 11, Source 25Okta issues the tokens; in its agent-to-agent flow, the caller passes its token on.⁠Source 12, Source 26 Agent Gateway, in preview, can be an agent’s remote MCP endpoint.⁠Source 13
Agents across organizationsPartner-controlled agents in a portal: not publicly documented. Cloudflare One can use several identity providers at once for partners and contractors.⁠Source 33Not publicly documented (checked 2 October 2026)
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 1 A2A support: not publicly documented.MCP servers as agent resources; Agent Gateway for MCP tools is in preview.⁠Source 5, Source 6 Okta for AI Agents’ docs don’t mention the A2A protocol.
Frameworks, models, and clouds supportedMCP clients that support remote MCP servers; setup steps for Claude Desktop, OpenCode, Windsurf, and others.⁠Source 1 Some servers reject portals as proxy clients.⁠Source 1Okta says it covers agents from any vendor, framework, or cloud, including homegrown Python or LangChain agents and agents in purchased software.⁠Source 3, Source 17, Source 18, Source 34
Operations
Deployment options and data residencyA portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 1 Self-hosting a portal is not publicly documented.A subscription on an Okta org.⁠Source 12 Okta says Core SKU agents register inside the org’s regulated cell.⁠Source 29 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 13
Compliance attestationsAccount Super Administrators can get Cloudflare’s PCI, SOC 2, ISO, and other documents.⁠Source 28 Which ones cover portals is not publicly documented.Okta says its Core SKU is GA for FedRAMP and HIPAA environments.⁠Source 29 Okta says the company holds SOC 2 and ISO/IEC 27001.⁠Source 30 Product scope: not publicly documented.
Support and SLACloudflare lists a 100% uptime SLA for paid Zero Trust plans.⁠Source 35 Support varies by plan; professional services are Contract add-ons.⁠Source 35Okta suites include online support 24 hours a day, five days a week; Premier Success Plans are sold separately.⁠Source 15
Time and effort to get runningAn active domain on Cloudflare and an identity provider on Zero Trust; then add servers, create a portal, and connect an MCP client.⁠Source 1An Okta org with the product.⁠Source 12 Okta says it has prebuilt integrations for Salesforce Agentforce, Amazon Bedrock AgentCore, and ServiceNow AI Platform.⁠Source 17
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 14 A separate price for portals is not publicly documented.Okta says it is a separate subscription.⁠Source 3 Its pricing page lists it as an add-on to Okta suite plans.⁠Source 15 A list price is not publicly documented.
Building
Agent building toolsCloudflare’s separate Agents SDK is for building and hosting agents; MCP servers can be built on Workers.⁠Source 2, Source 36 A no-code builder is not publicly documented.Not publicly documented (checked 2 October 2026)
Model accessModels for portals: not publicly documented. Cloudflare’s separate Agents SDK works with Workers AI, OpenAI, Anthropic, and Google Gemini.⁠Source 37Not publicly documented (checked 2 October 2026)
Integrations and ecosystemPortals can be managed with Terraform.⁠Source 1 Logpush exports portal logs on Enterprise plans.⁠Source 1, Source 38 Social, open-source, and corporate identity providers work.⁠Source 33Okta’s imports include Salesforce Agentforce, Amazon Bedrock AgentCore, and Microsoft Copilot Studio.⁠Source 34 Okta says Slack and Notion support Cross App Access.⁠Source 3

Which to choose

Choose Cloudflare MCP server portals if

  • You want many MCP servers behind one endpoint, with admins choosing which tools each portal exposes.⁠Source 1
  • You want each user shown only the MCP servers their Access policy allows, with group, country, and device posture checks.⁠Source 1
  • Some MCP servers run only on your private network, and you want them reached through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 11, Source 25
  • You use Cloudflare One, which Cloudflare says includes portals, and want portal traffic in your Gateway HTTP logs with your other traffic.⁠Source 1, Source 20

Choose Okta for AI Agents if

  • You want agents registered alongside workforce users in Universal Directory, which Okta says assigns owners, with owners optional for hand-added agents.⁠Source 8, Source 10
  • Your agents come from builder platforms such as Salesforce Agentforce or Amazon Bedrock AgentCore, and you want them imported into Okta.⁠Source 7, Source 34
  • You want to control which agents may call other agents, with Okta issuing resource-scoped tokens that expire, Okta says.⁠Source 18, Source 26
  • You run HIPAA or other regulated environments, where Okta says its Core SKU registers agents inside your org’s regulated cell.⁠Source 29

Questions buyers ask

Does Okta offer an MCP gateway like Cloudflare’s portals?

Okta’s Agent Gateway, in preview, aggregates tools from multiple remote MCP servers behind one Okta-secured endpoint and enforces identity and policy on every tool call.⁠Source 6 On 22 September 2026, Okta said general availability was planned for Q3.⁠Source 19

Do they support MCP and A2A?

Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; their A2A support is not publicly documented.⁠Source 1 Okta says its Cross App Access protocol is the official Enterprise-Managed Authorization extension for MCP.⁠Source 3 Okta for AI Agents’ docs don’t mention the A2A protocol.

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 14 A separate price for portals is not publicly documented. Okta says Okta for AI Agents is a separate subscription.⁠Source 3 An Okta list price is not publicly documented.

Can either one connect agents across organizations?

Bringing in agents that another organization owns and controls is not publicly documented for either one. Cloudflare documents a setup for MCP servers that a third-party provider hosts, and Cloudflare One can use several identity providers at once for partners and contractors.⁠Source 33, Source 39

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

44 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546

  2. Source 2: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcd

  3. Source 3: Okta brings first-class identity to AI agents with Agent SSO Okta · checked Back:abcdefgh

  4. Source 4: Okta for AI Agents (Okta Help Center) Okta · checked Back:abcde

  5. Source 5: AI agent resource connections (Okta Help Center) Okta · checked Back:abcdefg

  6. Source 6: Agent Gateway (Okta Help Center) Okta · checked Back:abcde

  7. Source 7: Add and register AI agents (Okta Help Center) Okta · checked Back:abcd

  8. Source 8: Add AI agents manually (Okta Help Center) Okta · checked Back:abcdefghij

  9. Source 9: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcde

  10. Source 10: Okta for AI Agents (product page) Okta · checked Back:abcd

  11. Source 11: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:abcd

  12. Source 12: Set up AI agent token exchange (Okta Developer) Okta · checked Back:abcd

  13. Source 13: Add an Agent Gateway (Okta Help Center) Okta · checked Back:abcd

  14. Source 14: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcde

  15. Source 15: Plans & pricing (Okta) Okta · checked Back:abc

  16. Source 16: MCP server portals · Changelog Cloudflare · checked Back:ab

  17. Source 17: Okta for AI Agents is now generally available Okta · checked Back:abcde

  18. Source 18: Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance Okta · checked Back:abcde

  19. Source 19: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance Okta · checked Back:abcdef

  20. Source 20: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abc

  21. Source 21: Okta Identity Security Posture Management (ISPM) release announcements Okta · checked Back:ab

  22. Source 22: Discover and assess AI agents (Okta Help Center) Okta · checked Back to text

  23. Source 23: Service tokens · Cloudflare One docs Cloudflare · checked Back:abc

  24. Source 24: Connect AI agents to resources (Okta Help Center) Okta · checked Back to text

  25. Source 25: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:abc

  26. Source 26: Agent-to-agent connections (Okta Help Center) Okta · checked Back:abc

  27. Source 27: Log streaming (Okta Help Center) Okta · checked Back:ab

  28. Source 28: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  29. Source 29: Okta is the first independent and neutral identity platform to bring AI agent governance to highly regulated environments Okta · checked Back:abcd

  30. Source 30: Okta Security Trust Center | Powered by SafeBase Okta · checked Back:ab

  31. Source 31: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back to text

  32. Source 32: View Agent Gateway activity (Okta Help Center) Okta · checked Back to text

  33. Source 33: Identity providers · Cloudflare One docs Cloudflare · checked Back:abc

  34. Source 34: Apps that support AI agent imports (Okta Help Center) Okta · checked Back:abc

  35. Source 35: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  36. Source 36: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back to text

  37. Source 37: Using AI Models · Cloudflare Agents docs Cloudflare · checked Back to text

  38. Source 38: Logpush integration · Cloudflare One docs Cloudflare · checked Back to text

  39. Source 39: Secure MCP servers · Cloudflare One docs Cloudflare · checked Back to text

  40. Source 40: Your company's private network Blocks.ai · checked Back to text

  41. Source 41: Network requirements Blocks.ai · checked Back to text

  42. Source 42: Solutions: Agent sprawl Blocks.ai · checked Back to text

  43. Source 43: Solutions: Partner networks Blocks.ai · checked Back to text

  44. Source 44: Pricing Blocks.ai · checked Back to text