Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs Zenity

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

Zenity AI Agent Security & Governance Platform

Security and governance platform for AI agents, aimed at security teams

Short answer

Cloudflare MCP server portals put MCP servers behind one governed endpoint; Zenity is a security and governance platform that, it says, helps security teams discover agents and enforce policies.⁠Source 1, Source 2, Source 3, Source 4 A portal controls who can use its MCP tools; Zenity says it can block agent actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 1, Source 5

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both apply rules to agents’ tool use: a portal proxies and logs MCP tool calls, and Zenity says it logs agents’ tool calls and can check their actions against rules.⁠Source 1, Source 6, Source 7
Where they differ
A portal is one endpoint for MCP clients, in front of MCP servers added to Cloudflare Access.⁠Source 1 Zenity says it scans for agents, including in SaaS platforms or on laptops.⁠Source 6
Running both
Neither vendor publicly documents using the two together. Cloudflare documents Logpush of portal logs to a SIEM; Zenity says its audit log events stream to Splunk or Microsoft Sentinel.⁠Source 1, Source 8
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 1
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 1
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 1
  • Agents across organizations: Not publicly documented

Zenity

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: Not publicly documented
  • Registry and governance: OfferedAI Observability agent inventory⁠Source 6
  • Traffic between agents, tools, and models: OfferedTool-call blocking for coding agents⁠Source 9
  • Agents across organizations: Not publicly documented

At a glance

TopicCloudflare MCP server portalsZenity
What it isPuts multiple MCP servers behind one HTTP endpoint, governed through Cloudflare Access.⁠Source 1, Source 2 Cloudflare says portals are part of Cloudflare One.⁠Source 10A SaaS security and governance platform for AI agents, spanning SaaS, homegrown cloud platforms, and end-user devices.⁠Source 3
What it keeps a list ofMCP servers and their tools, up to 80 servers per portal.⁠Source 1 A registry of agents is not publicly documented.Agents, found by scanning, Zenity says: in platforms such as Microsoft Copilot Studio, ChatGPT Enterprise, and Salesforce Agentforce, in custom builds, and on laptops.⁠Source 6
How it sees agent activityIn the path: MCP clients connect to the portal’s URL, and it proxies each tool call to the right server.⁠Source 1Zenity says it connects through an Evaluate API and OpenTelemetry for custom agents, agent hooks for coding agents, and Claude’s Compliance API for Claude Enterprise.⁠Source 8, Source 9, Source 11
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 12 A separate price for portals is not publicly documented.Custom pricing by private offer on its main AWS Marketplace listing.⁠Source 3 A separate Security Hub Extended listing shows usage prices.⁠Source 13
Available sinceGenerally available since 24 September 2026, after an open beta announced in August 2025.⁠Source 12, Source 14Zenity announced Azure Marketplace availability in March 2025 (Microsoft has since unified it into Microsoft Marketplace) and AWS Marketplace availability in January 2026.⁠Source 15, Source 16, Source 17

What each one is

Cloudflare MCP server portals

Cloudflare says MCP server portals are part of Cloudflare One, its secure access service edge (SASE) platform.⁠Source 10 Admins add MCP servers to Cloudflare Access and build portals from them: each portal is one URL for MCP clients, with Access policies and request logs.⁠Source 1

Zenity AI Agent Security & Governance Platform

Zenity AI Agent Security & Governance Platform is delivered as SaaS; Zenity says it lets security teams discover and inventory agents and enforce policies.⁠Source 3, Source 4 Zenity’s listing says it spans SaaS, home-grown cloud platforms, and end-user devices.⁠Source 3 Zenity describes three layers: Surface, Enforce, and Protect.⁠Source 4

The differences that matter

  1. What each one keeps track of

    Cloudflare MCP server portals

    MCP servers and their tools: admins add servers to Cloudflare Access and choose which tools and prompt templates each portal exposes.⁠Source 1

    Zenity

    Agents: Zenity says AI Observability scans the environment and catalogs each agent with its configuration, permissions, and tool access.⁠Source 6

    Agents reach a portal as MCP clients, signed in with a user’s identity provider login or an Access service token.⁠Source 1, Source 18 Zenity says it flags agents outside sanctioned deployment channels.⁠Source 6

  2. Where each one sits

    Cloudflare MCP server portals

    In the path: MCP clients connect to the portal’s URL, and it attaches credentials and proxies each tool call to the right server.⁠Source 1

    Zenity

    Zenity says it connects through an Evaluate API and OpenTelemetry for custom agents, agent hooks for coding agents, and Claude’s Compliance API for Claude Enterprise.⁠Source 8, Source 9, Source 11

    Private MCP servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.⁠Source 1, Source 19 Network requirements for Zenity’s integrations aren’t in its public docs; its product docs require a login.⁠Source 20

  3. How actions are controlled

    Cloudflare MCP server portals

    By access: Access policies decide who can connect to a portal, and tools an admin turns off can’t be called through it.⁠Source 1

    Zenity

    By action: Zenity says Boundaries can check agent actions in real time and can block actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 5, Source 7

    Portals can be managed with the Cloudflare Terraform provider, and Zenity says Boundaries policies can be managed as version-controlled files through a command-line interface.⁠Source 1, Source 8

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsZenity
Network exposureMCP clients reach the portal’s HTTPS URL; private MCP servers connect through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 21Delivered as SaaS.⁠Source 3 Network requirements for connected agents aren’t in Zenity’s public docs; its product docs require a login.⁠Source 20
IdentityAccess sign-in with your identity provider, or an Access service token for agents; independent MFA isn’t enforced for portal-authorized servers.⁠Source 1, Source 18Zenity says Boundaries rules can reference Okta attributes, such as role.⁠Source 7 Issuing agent identities isn’t in its public docs.
Access changes and revocationDeleting a service token revokes access; blocked users can reach a server’s direct URL; Cloudflare advises Access as OAuth provider.⁠Source 1, Source 22Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 7 It says Prevent-mode rules hard-stop actions.⁠Source 7
Audit trailAccess logs each request made with a portal’s tools; Logpush export to a SIEM is on Enterprise plans only.⁠Source 1Zenity says it logs agent messages and tool calls, and can stream audit log events to Splunk or Microsoft Sentinel.⁠Source 6, Source 8
ComplianceSuper Administrators can get Cloudflare’s PCI, SOC 2, and ISO documents.⁠Source 23 Their scope for portals is not publicly documented.Zenity says it holds SOC 2 Type II and ISO 27001 compliance; FedRAMP “In Process” was announced in March 2026.⁠Source 24, Source 25

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and Zenity compared on 18 criteria
Cloudflare MCP server portalsZenity
What it is
What it is and who it’s forCloudflare says portals are part of Cloudflare One, its SASE platform.⁠Source 10 A portal puts multiple MCP servers behind one endpoint, governed through Access.⁠Source 1, Source 2Zenity’s listing: a security and governance platform for AI agents across SaaS, cloud, and endpoints.⁠Source 3 Zenity says it lets security teams inventory agents.⁠Source 4
MaturityGA since 24 September 2026, after an open beta announced 26 August 2025.⁠Source 12, Source 14 Previously called Agents Gateway in some contexts.⁠Source 1Zenity announced AWS Marketplace availability in January 2026.⁠Source 17 It says GitHub Copilot and OpenAI Codex coverage reached GA in August 2026.⁠Source 8
Control
Agent registry and discoveryAdmins add third-party and internal MCP servers to Cloudflare Access, up to 80 per portal.⁠Source 1, Source 2 A registry of agents is not publicly documented.Zenity says AI Observability scans and catalogs agents in SaaS platforms, custom builds, and on laptops, with their permissions and tool access.⁠Source 6
Identity and access controlSign-in through Access with an identity provider, or an Access service token.⁠Source 1, Source 18 Policies can match emails, groups, country, and device posture checks.⁠Source 1Zenity says Boundaries rules can reference Okta attributes such as role and department.⁠Source 7 Issuing agent identities isn’t in its public docs.
Ownership, policy, and revocationAdmins choose which tools and prompt templates each portal exposes; turned-off tools can’t be called through it.⁠Source 1 Service tokens can be turned off or deleted.⁠Source 22Zenity says it can block actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 5 It says posture policies can alert, block, or remediate.⁠Source 26
Audit log and observabilityAccess logs each tool request, viewable per portal or per server.⁠Source 1 Exported logs record the user’s email and the tool called; Logpush is Enterprise-only.⁠Source 1, Source 27Zenity says it logs agent messages, tool calls, retrievals, and handoffs.⁠Source 6 It says audit log events can stream to Splunk or Microsoft Sentinel.⁠Source 8
Connection
How agents connectMCP clients use the portal’s HTTPS URL; it proxies tool calls.⁠Source 1 Private servers join via Cloudflare Tunnel with Gateway routing on.⁠Source 1, Source 19Zenity says OpenTelemetry agents can connect, with an Evaluate API for enforcement; coding agents use agent hooks.⁠Source 8, Source 9 Network needs aren’t in Zenity’s public docs.
Agents across organizationsPortals can include third-party MCP servers.⁠Source 2 Several identity providers can run at once for partners’ staff.⁠Source 28 Partner-controlled agents: not publicly documented.Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 20
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 1 A2A support is not publicly documented.Zenity says custom agents use OpenTelemetry and AIDR shows agent-to-agent requests and responses.⁠Source 8, Source 29 Whether Zenity supports A2A isn’t publicly documented.
Frameworks, models, and clouds supportedWorks with MCP clients that support remote servers.⁠Source 1 Stdio-only servers can’t be added, and some servers reject proxy-based clients like portals.⁠Source 1Zenity says discovery covers homegrown agents built on Azure AI Foundry, AWS Bedrock, or Google Vertex AI, and OpenTelemetry agents can connect.⁠Source 6, Source 8
Operations
Deployment options and data residencyA portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.⁠Source 1 Self-hosting a portal is not publicly documented.Software as a service, deployed on AWS per its AWS Marketplace listing.⁠Source 3 Hosting regions and self-hosting aren’t in Zenity’s public docs.
Compliance attestationsCompany-wide, Super Administrators can get PCI, SOC 2, ISO, and other documents in the dashboard.⁠Source 23 Portal-specific scope is not publicly documented.Zenity says it holds SOC 2 Type II and is ISO 27001 compliant.⁠Source 24 It announced FedRAMP “In Process” status in March 2026; authorization is pending.⁠Source 25
Support and SLASupport options vary by Zero Trust plan; professional services are Contract add-ons.⁠Source 30 Cloudflare advertises SLAs for paid Zero Trust plans with 100% uptime.⁠Source 30Zenity’s subscription terms commit to at least 99.9% monthly uptime, on a commercially reasonable efforts basis.⁠Source 31 Requests go via Zendesk in business hours.⁠Source 31
Time and effort to get runningNeeds a domain on Cloudflare and an identity provider in Zero Trust.⁠Source 1 Then add MCP servers, create a portal with tools and policies, and connect clients.⁠Source 1Zenity describes step-by-step guides for connecting custom agents via Cribl, LiteLLM, and Kong; its Cursor plugin installs in Cursor desktop.⁠Source 8, Source 32
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 12 A separate price for portals is not publicly documented.Main AWS Marketplace listing: custom pricing by private offer.⁠Source 3 Security Hub Extended listing: $130 per resource a month for Observability.⁠Source 13
Building
Agent building toolsSeparately from portals, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Workers.⁠Source 2, Source 33Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 20
Model accessNot publicly documented for portals. Cloudflare says its separate AI Gateway manages model traffic across AI providers.⁠Source 34Zenity says AIDR pairs rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.⁠Source 29 The models it uses aren’t in Zenity’s public docs.
Integrations and ecosystemPortals can be managed with Terraform; Cloudflare One supports social, open source, and corporate identity providers.⁠Source 1, Source 28Zenity says it integrates with Microsoft Agent 365 and AWS Security Hub Extended and is on the Cursor Marketplace.⁠Source 32, Source 35, Source 36 It announced a ServiceNow SecOps partnership.⁠Source 37

Which to choose

Choose Cloudflare MCP server portals if

  • You want multiple MCP servers behind one endpoint that MCP clients such as Claude Desktop or Windsurf can connect to.⁠Source 1
  • You already use Cloudflare One, which Cloudflare says includes portals, available to all Cloudflare customers.⁠Source 10, Source 12
  • You want MCP access set by identity: Access policies on emails, groups, country, and device posture, plus per-portal tool choice.⁠Source 1
  • Your MCP servers sit only on a private network: a portal can reach them through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 19, Source 21

Choose Zenity if

  • You want what Zenity says it offers: agents found by scanning, including on laptops, with flags for agents outside sanctioned channels.⁠Source 6
  • You want what Zenity says it offers: posture policies that alert, block, or remediate automatically, and ownership shown for every discovered agent.⁠Source 26
  • You need coding agents such as Claude Code and Cursor covered; Zenity says it covers them and can block dangerous tool calls.⁠Source 9
  • You want what Zenity says it offers: rules mapped to OWASP LLM and MITRE ATLAS, and audit events in Splunk or Sentinel.⁠Source 8, Source 29

Questions buyers ask

Does either one keep a registry of agents?

Zenity says it keeps an inventory: AI Observability scans an organization’s environment and catalogs agents with their configuration, permissions, and tool access.⁠Source 6 Portals list MCP servers and their tools, which admins add to Cloudflare Access.⁠Source 1 A registry of agents in portals is not publicly documented.

Do they support MCP and A2A?

Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.⁠Source 1 Zenity says its Cursor plugin maps each agent to the MCP endpoints it uses.⁠Source 32 Portal A2A support is not publicly documented. Whether Zenity supports A2A isn’t publicly documented.

How is each one priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 12 A separate price for portals is not publicly documented. Zenity’s main AWS Marketplace listing is by private offer; its Security Hub Extended listing shows usage prices.⁠Source 3, Source 13

How do you cut off an agent in each one?

Deleting an agent’s service token revokes its access; turning it off stops it authenticating until turned back on.⁠Source 18, Source 22 Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 7

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

42 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344

  2. Source 2: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcdef

  3. Source 3: AWS Marketplace: Zenity Zenity · checked Back:abcdefghij

  4. Source 4: Platform | AI Agent Security & Governance Platform | Zenity Zenity · checked Back:abcd

  5. Source 5: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Zenity · checked Back:abc

  6. Source 6: AI Observability | See Every Agent, Know What it Touches | Zenity Zenity · checked Back:abcdefghijkl

  7. Source 7: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Zenity · checked Back:abcdefg

  8. Source 8: From Triage to Full Coverage: The Shift AI Agent Security Took in August Zenity · checked Back:abcdefghijkl

  9. Source 9: Coding and Personal Agents | Zenity Zenity · checked Back:abcde

  10. Source 10: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abcd

  11. Source 11: Claude's Agents Are Already Running Across Your Enterprise. Now Security Teams Can Catch Up. Zenity · checked Back:ab

  12. Source 12: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcdef

  13. Source 13: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Zenity · checked Back:abc

  14. Source 14: MCP server portals · Changelog Cloudflare · checked Back:ab

  15. Source 15: Zenity Now Available in the Microsoft Azure Marketplace Zenity · checked Back to text

  16. Source 16: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Zenity · checked Back to text

  17. Source 17: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Zenity · checked Back:ab

  18. Source 18: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abcd

  19. Source 19: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:abc

  20. Source 20: Zenity Documentation (login) Zenity · checked Back:abcd

  21. Source 21: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:ab

  22. Source 22: Service tokens · Cloudflare One docs Cloudflare · checked Back:abc

  23. Source 23: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  24. Source 24: Zenity Trust Center Zenity · checked Back:ab

  25. Source 25: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Zenity · checked Back:ab

  26. Source 26: AI Security Posture Management (AISPM) | Stop Agent Risk Before Deployment | Zenity Zenity · checked Back:ab

  27. Source 27: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back to text

  28. Source 28: Identity providers · Cloudflare One docs Cloudflare · checked Back:ab

  29. Source 29: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Zenity · checked Back:abc

  30. Source 30: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  31. Source 31: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Zenity · checked Back:ab

  32. Source 32: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Zenity · checked Back:abc

  33. Source 33: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back to text

  34. Source 34: AI Security | Cloudflare Cloudflare · checked Back to text

  35. Source 35: Zenity Now Integrates with Microsoft Agent 365 Zenity · checked Back to text

  36. Source 36: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Zenity · checked Back to text

  37. Source 37: Zenity Announces Partnership with ServiceNow to Operationalize AI Agent Risk Reduction in SecOps Zenity · checked Back to text

  38. Source 38: Your company's private network Blocks.ai · checked Back to text

  39. Source 39: Network requirements Blocks.ai · checked Back to text

  40. Source 40: Solutions: Agent sprawl Blocks.ai · checked Back to text

  41. Source 41: Solutions: Partner networks Blocks.ai · checked Back to text

  42. Source 42: Pricing Blocks.ai · checked Back to text