Skip to content

SYSTEM Cited by 1 source

Cloudflare Gateway

Overview

Cloudflare Gateway is the Cloudflare One secure web gateway (SWG) — traffic from managed devices and sites is sent through Gateway by the Cloudflare One Client, where it can be observed and controlled after it leaves the client but before it reaches its destination. With TLS decryption enabled, Gateway associates each request with a user + device, inspects the destination and protocol headers, and applies HTTP / network policy independent of any particular client application. (Source: sources/2026-08-14-cloudflare-how-cloudflare-detects-mcp-traffic-and-helps-secure-it)

Gateway is the network control point in the three-control-points framing (client / network / server): it has the widest lens for remote traffic on managed paths, though it cannot see local stdio calls, off-network connections, Do Not Inspect traffic, or anything that never traverses it. Canonical wiki instance of patterns/central-proxy-choke-point at the SWG altitude.

MCP traffic detection (2026-08-14)

Gateway classifies MCP traffic at the protocol layer rather than by URL/host heuristics — a URL does not tell you a request is MCP (an MCP server can live at an ordinary …/api path, and an unrelated service can happen to use mcp in its host/path). For session-based Streamable HTTP connections, MCP clients send an MCP-Protocol-Version header after initialization; Gateway inspects that header on every TLS-inspected request and classifies accordingly, using detection built from patterns observed across the millions of requests traversing the Cloudflare network so it "identifies MCP negotiation and proxying to a hostname without relying on knowing the specific host or URL ahead of time."

All Cloudflare Zero Trust customers see MCP indications in Gateway HTTP logs and can Allow/Block with a new boolean selector:

experimental.is_mcp == true

true when the MCP-Protocol-Version header is present on a TLS-inspected request. Canonical wiki instance of protocol-header-traffic-classification. (Selector is experimental; detection-selector details will be documented as the signal reaches GA.)

Portal-only enforcement

Gateway distinguishes governed MCP Portal traffic from direct employee connections via a Traffic Source selector: Portal traffic routed through Gateway carries an mcp_portal on-ramp tag. A baseline enforcement rule blocks any detected MCP that did not arrive through a Portal:

experimental.is_mcp == true and not traffic.onramp in ("mcp_portal")
Action: Block

This is the network half of preventing shadow MCP and Portal bypass — canonical wiki instance of portal-only-egress-enforcement. Portal bypass additionally requires an origin that can reject direct requests (Access policy, source-IP restriction, or an enterprise authorization mechanism the MCP server initiates). Both experimental.is_mcp and Traffic Source exist in HTTP logs for decrypted traffic, so administrators can observe before enforcing.

Where data loss prevention is supported, Gateway can also inspect the JSON-RPC method and arguments (e.g. DLP profiles for initialize, tools/call, resources/read).

Caveats

Network-layer inspection requires TLS decryption. Local stdio MCP servers, off-network connections, Do Not Inspect traffic, and non-conforming/legacy transports that omit MCP-Protocol-Version remain outside Gateway's view — header absence does not prove non-MCP. The source does not disclose detection latency/throughput or false-positive/negative rates.

Seen in

  • systems/cloudflare-one — the Zero Trust suite Gateway is part of.
  • systems/mcp-server-portal — the governed MCP path Gateway enforces access to.
  • systems/cloudflare-access — origin identity that makes Portal bypass rejectable.
  • mcp-protocol-version-header — the wire signal Gateway keys on.
  • shadow-mcp — the problem Gateway detection addresses.
  • protocol-header-traffic-classification — classify by header, not URL.
  • portal-only-egress-enforcement — allow only governed-on-ramp MCP traffic.
  • patterns/central-proxy-choke-point — the SWG as single network vantage point.
Last updated · 766 distilled / 2,225 read