Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs Zenity
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Zenity AI Agent Security & Governance Platform
Security and governance platform for AI agents, aimed at security teams
Short answer
Cloudflare MCP server portals put MCP servers behind one governed endpoint; Zenity is a security and governance platform that, it says, helps security teams discover agents and enforce policies.Source 1, Source 2, Source 3, Source 4 A portal controls who can use its MCP tools; Zenity says it can block agent actions on Copilot Studio, Microsoft Foundry, and coding agents.Source 1, Source 5
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Zenity
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Identity and access: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says MCP server portals are part of Cloudflare One, its secure access service edge (SASE) platform.Source 10 Admins add MCP servers to Cloudflare Access and build portals from them: each portal is one URL for MCP clients, with Access policies and request logs.Source 1
Zenity AI Agent Security & Governance Platform
Zenity AI Agent Security & Governance Platform is delivered as SaaS; Zenity says it lets security teams discover and inventory agents and enforce policies.Source 3, Source 4 Zenity’s listing says it spans SaaS, home-grown cloud platforms, and end-user devices.Source 3 Zenity describes three layers: Surface, Enforce, and Protect.Source 4
The differences that matter
What each one keeps track of
Cloudflare MCP server portalsMCP servers and their tools: admins add servers to Cloudflare Access and choose which tools and prompt templates each portal exposes.Source 1
ZenityAgents: Zenity says AI Observability scans the environment and catalogs each agent with its configuration, permissions, and tool access.Source 6
Agents reach a portal as MCP clients, signed in with a user’s identity provider login or an Access service token.Source 1, Source 18 Zenity says it flags agents outside sanctioned deployment channels.Source 6
Where each one sits
Cloudflare MCP server portalsIn the path: MCP clients connect to the portal’s URL, and it attaches credentials and proxies each tool call to the right server.Source 1
ZenityZenity says it connects through an Evaluate API and OpenTelemetry for custom agents, agent hooks for coding agents, and Claude’s Compliance API for Claude Enterprise.Source 8, Source 9, Source 11
Private MCP servers connect through Cloudflare Tunnel or another connector, with Gateway routing on.Source 1, Source 19 Network requirements for Zenity’s integrations aren’t in its public docs; its product docs require a login.Source 20
How actions are controlled
Cloudflare MCP server portalsBy access: Access policies decide who can connect to a portal, and tools an admin turns off can’t be called through it.Source 1
ZenityBy action: Zenity says Boundaries can check agent actions in real time and can block actions on Copilot Studio, Microsoft Foundry, and coding agents.Source 5, Source 7
Portals can be managed with the Cloudflare Terraform provider, and Zenity says Boundaries policies can be managed as version-controlled files through a command-line interface.Source 1, Source 8
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | Zenity | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals are part of Cloudflare One, its SASE platform.Source 10 A portal puts multiple MCP servers behind one endpoint, governed through Access.Source 1, Source 2 | Zenity’s listing: a security and governance platform for AI agents across SaaS, cloud, and endpoints.Source 3 Zenity says it lets security teams inventory agents.Source 4 |
| Maturity | GA since 24 September 2026, after an open beta announced 26 August 2025.Source 12, Source 14 Previously called Agents Gateway in some contexts.Source 1 | Zenity announced AWS Marketplace availability in January 2026.Source 17 It says GitHub Copilot and OpenAI Codex coverage reached GA in August 2026.Source 8 |
| Control | ||
| Agent registry and discovery | Admins add third-party and internal MCP servers to Cloudflare Access, up to 80 per portal.Source 1, Source 2 A registry of agents is not publicly documented. | Zenity says AI Observability scans and catalogs agents in SaaS platforms, custom builds, and on laptops, with their permissions and tool access.Source 6 |
| Identity and access control | Sign-in through Access with an identity provider, or an Access service token.Source 1, Source 18 Policies can match emails, groups, country, and device posture checks.Source 1 | Zenity says Boundaries rules can reference Okta attributes such as role and department.Source 7 Issuing agent identities isn’t in its public docs. |
| Ownership, policy, and revocation | Admins choose which tools and prompt templates each portal exposes; turned-off tools can’t be called through it.Source 1 Service tokens can be turned off or deleted.Source 22 | Zenity says it can block actions on Copilot Studio, Microsoft Foundry, and coding agents.Source 5 It says posture policies can alert, block, or remediate.Source 26 |
| Audit log and observability | Access logs each tool request, viewable per portal or per server.Source 1 Exported logs record the user’s email and the tool called; Logpush is Enterprise-only.Source 1, Source 27 | Zenity says it logs agent messages, tool calls, retrievals, and handoffs.Source 6 It says audit log events can stream to Splunk or Microsoft Sentinel.Source 8 |
| Connection | ||
| How agents connect | MCP clients use the portal’s HTTPS URL; it proxies tool calls.Source 1 Private servers join via Cloudflare Tunnel with Gateway routing on.Source 1, Source 19 | Zenity says OpenTelemetry agents can connect, with an Evaluate API for enforcement; coding agents use agent hooks.Source 8, Source 9 Network needs aren’t in Zenity’s public docs. |
| Agents across organizations | Portals can include third-party MCP servers.Source 2 Several identity providers can run at once for partners’ staff.Source 28 Partner-controlled agents: not publicly documented. | Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)Source 20 |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 1 A2A support is not publicly documented. | Zenity says custom agents use OpenTelemetry and AIDR shows agent-to-agent requests and responses.Source 8, Source 29 Whether Zenity supports A2A isn’t publicly documented. |
| Frameworks, models, and clouds supported | Works with MCP clients that support remote servers.Source 1 Stdio-only servers can’t be added, and some servers reject proxy-based clients like portals.Source 1 | Zenity says discovery covers homegrown agents built on Azure AI Foundry, AWS Bedrock, or Google Vertex AI, and OpenTelemetry agents can connect.Source 6, Source 8 |
| Operations | ||
| Deployment options and data residency | A portal’s hostname is a proxied CNAME record pointing to gateway.agents.cloudflare.com.Source 1 Self-hosting a portal is not publicly documented. | Software as a service, deployed on AWS per its AWS Marketplace listing.Source 3 Hosting regions and self-hosting aren’t in Zenity’s public docs. |
| Compliance attestations | Company-wide, Super Administrators can get PCI, SOC 2, ISO, and other documents in the dashboard.Source 23 Portal-specific scope is not publicly documented. | Zenity says it holds SOC 2 Type II and is ISO 27001 compliant.Source 24 It announced FedRAMP “In Process” status in March 2026; authorization is pending.Source 25 |
| Support and SLA | Support options vary by Zero Trust plan; professional services are Contract add-ons.Source 30 Cloudflare advertises SLAs for paid Zero Trust plans with 100% uptime.Source 30 | Zenity’s subscription terms commit to at least 99.9% monthly uptime, on a commercially reasonable efforts basis.Source 31 Requests go via Zendesk in business hours.Source 31 |
| Time and effort to get running | Needs a domain on Cloudflare and an identity provider in Zero Trust.Source 1 Then add MCP servers, create a portal with tools and policies, and connect clients.Source 1 | Zenity describes step-by-step guides for connecting custom agents via Cribl, LiteLLM, and Kong; its Cursor plugin installs in Cursor desktop.Source 8, Source 32 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 12 A separate price for portals is not publicly documented. | Main AWS Marketplace listing: custom pricing by private offer.Source 3 Security Hub Extended listing: $130 per resource a month for Observability.Source 13 |
| Building | ||
| Agent building tools | Separately from portals, Cloudflare’s Agents docs cover building and hosting agents on Cloudflare, and remote MCP servers can be built on Workers.Source 2, Source 33 | Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)Source 20 |
| Model access | Not publicly documented for portals. Cloudflare says its separate AI Gateway manages model traffic across AI providers.Source 34 | Zenity says AIDR pairs rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.Source 29 The models it uses aren’t in Zenity’s public docs. |
| Integrations and ecosystem | Portals can be managed with Terraform; Cloudflare One supports social, open source, and corporate identity providers.Source 1, Source 28 | Zenity says it integrates with Microsoft Agent 365 and AWS Security Hub Extended and is on the Cursor Marketplace.Source 32, Source 35, Source 36 It announced a ServiceNow SecOps partnership.Source 37 |
Which to choose
Choose Cloudflare MCP server portals if
- You want multiple MCP servers behind one endpoint that MCP clients such as Claude Desktop or Windsurf can connect to.Source 1
- You already use Cloudflare One, which Cloudflare says includes portals, available to all Cloudflare customers.Source 10, Source 12
- You want MCP access set by identity: Access policies on emails, groups, country, and device posture, plus per-portal tool choice.Source 1
- Your MCP servers sit only on a private network: a portal can reach them through outbound-only Cloudflare Tunnel, with Gateway routing on.Source 1, Source 19, Source 21
Choose Zenity if
- You want what Zenity says it offers: agents found by scanning, including on laptops, with flags for agents outside sanctioned channels.Source 6
- You want what Zenity says it offers: posture policies that alert, block, or remediate automatically, and ownership shown for every discovered agent.Source 26
- You need coding agents such as Claude Code and Cursor covered; Zenity says it covers them and can block dangerous tool calls.Source 9
- You want what Zenity says it offers: rules mapped to OWASP LLM and MITRE ATLAS, and audit events in Splunk or Sentinel.Source 8, Source 29
Questions buyers ask
Does either one keep a registry of agents?
Zenity says it keeps an inventory: AI Observability scans an organization’s environment and catalogs agents with their configuration, permissions, and tool access.Source 6 Portals list MCP servers and their tools, which admins add to Cloudflare Access.Source 1 A registry of agents in portals is not publicly documented.
Do they support MCP and A2A?
How is each one priced?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
42 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz272829303132333435363738394041424344
Source 2: MCP governance · Cloudflare Agents docs Back:abcdef
Source 4: Platform | AI Agent Security & Governance Platform | Zenity Back:abcd
Source 5: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Back:abc
Source 6: AI Observability | See Every Agent, Know What it Touches | Zenity Back:abcdefghijkl
Source 7: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Back:abcdefg
Source 8: From Triage to Full Coverage: The Shift AI Agent Security Took in August Back:abcdefghijkl
Source 10: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abcd
Source 11: Claude's Agents Are Already Running Across Your Enterprise. Now Security Teams Can Catch Up. Back:ab
Source 12: MCP server portals are now generally available · Changelog Back:abcdef
Source 13: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Back:abc
Source 15: Zenity Now Available in the Microsoft Azure Marketplace Back to text
Source 16: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Back to text
Source 17: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Back:ab
Source 18: Service token support for MCP server portals · Changelog Back:abcd
Source 19: Private MCP server support for MCP server portals · Changelog Back:abc
Source 23: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 25: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Back:ab
Source 26: AI Security Posture Management (AISPM) | Stop Agent Risk Before Deployment | Zenity Back:ab
Source 27: MCP Portal Logs · Cloudflare Logs docs Back to text
Source 29: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Back:abc
Source 30: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 31: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Back:ab
Source 32: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Back:abc
Source 33: Build Agents on Cloudflare · Cloudflare Agents docs Back to text
Source 35: Zenity Now Integrates with Microsoft Agent 365 Back to text
Source 36: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Back to text
Source 37: Zenity Announces Partnership with ServiceNow to Operationalize AI Agent Risk Reduction in SecOps Back to text