SYSTEM Cited by 1 source
Cloudflare Gateway¶
Overview¶
Cloudflare Gateway is the Cloudflare One secure web gateway (SWG) — traffic from managed devices and sites is sent through Gateway by the Cloudflare One Client, where it can be observed and controlled after it leaves the client but before it reaches its destination. With TLS decryption enabled, Gateway associates each request with a user + device, inspects the destination and protocol headers, and applies HTTP / network policy independent of any particular client application. (Source: sources/2026-08-14-cloudflare-how-cloudflare-detects-mcp-traffic-and-helps-secure-it)
Gateway is the network control point in the
three-control-points
framing (client / network / server): it has the widest lens for remote
traffic on managed paths, though it cannot see local stdio calls, off-network
connections, Do Not Inspect
traffic, or anything that never traverses it. Canonical wiki instance of
patterns/central-proxy-choke-point at the SWG altitude.
MCP traffic detection (2026-08-14)¶
Gateway classifies MCP traffic at the
protocol layer rather than by URL/host heuristics — a URL does not tell you
a request is MCP (an MCP server can live at an ordinary …/api path, and an
unrelated service can happen to use mcp in its host/path). For session-based
Streamable HTTP connections, MCP clients send an MCP-Protocol-Version header
after initialization; Gateway inspects that header on every TLS-inspected
request and classifies accordingly, using
detection built from patterns observed
across the millions of requests traversing the Cloudflare network so it
"identifies MCP negotiation and proxying to a hostname without relying on
knowing the specific host or URL ahead of time."
All Cloudflare Zero Trust customers see MCP indications in Gateway HTTP logs and can Allow/Block with a new boolean selector:
true when the MCP-Protocol-Version header is present on a TLS-inspected
request. Canonical wiki instance of
protocol-header-traffic-classification. (Selector is
experimental; detection-selector details will be documented as the signal
reaches GA.)
Portal-only enforcement¶
Gateway distinguishes governed MCP Portal traffic
from direct employee connections via a Traffic Source selector: Portal
traffic routed through Gateway carries an mcp_portal on-ramp tag. A baseline
enforcement rule blocks any detected MCP that did not arrive through a Portal:
This is the network half of preventing
shadow MCP and Portal bypass — canonical wiki instance
of portal-only-egress-enforcement. Portal bypass additionally
requires an origin that can reject direct requests (Access policy, source-IP
restriction, or an enterprise authorization mechanism the MCP server initiates).
Both experimental.is_mcp and Traffic Source exist in HTTP logs for decrypted
traffic, so administrators can observe before enforcing.
Where data loss prevention
is supported, Gateway can also inspect the JSON-RPC method and arguments (e.g.
DLP profiles for initialize, tools/call, resources/read).
Caveats¶
Network-layer inspection requires TLS decryption. Local stdio MCP servers,
off-network connections, Do Not Inspect traffic, and non-conforming/legacy
transports that omit MCP-Protocol-Version remain outside Gateway's view —
header absence does not prove non-MCP. The source does not disclose
detection latency/throughput or false-positive/negative rates.
Seen in¶
- sources/2026-08-14-cloudflare-how-cloudflare-detects-mcp-traffic-and-helps-secure-it
— protocol-layer MCP detection (
experimental.is_mcp), Portal-only enforcement via themcp_portalTraffic Source, DLP over JSON-RPC.
Related¶
- systems/cloudflare-one — the Zero Trust suite Gateway is part of.
- systems/mcp-server-portal — the governed MCP path Gateway enforces access to.
- systems/cloudflare-access — origin identity that makes Portal bypass rejectable.
- mcp-protocol-version-header — the wire signal Gateway keys on.
- shadow-mcp — the problem Gateway detection addresses.
- protocol-header-traffic-classification — classify by header, not URL.
- portal-only-egress-enforcement — allow only governed-on-ramp MCP traffic.
- patterns/central-proxy-choke-point — the SWG as single network vantage point.