SYSTEM Cited by 2 sources
Cloudflare MCP Server Portal¶
Cloudflare MCP Server Portal is the Cloudflare OS integration surface for existing Model Context Protocol servers. Cloudflare OS can use a portal to connect an organization’s existing MCP-tool servers while its Gatekeeper layer supplies resource-aware authorization beyond an MCP server's tool inventory. (Source: sources/2026-08-05-cloudflare-os-an-open-platform-for-agents-apps-and-work)
Governed path for MCP traffic (2026-08-14)¶
The 2026-08-14 MCP-security update positions the Portal as the governed path in Cloudflare One: it gives employees one managed endpoint and puts Access identity, a curated tool catalog, and logging in front of the upstream server. Administrators can route compatible upstream calls through Gateway for HTTP policy, predictable egress, and DLP (per-Portal or per-server), and export tool activity via Logpush. (Source: sources/2026-08-14-cloudflare-how-cloudflare-detects-mcp-traffic-and-helps-secure-it)
Three concrete additions in this update:
mcp_portalTraffic Source. When Portal traffic routes through Gateway it carries anmcp_portalon-ramp tag, so policy can distinguish Portal-proxied requests from direct employee connections — the basis of Portal-only egress enforcement.- Pre-registered OAuth clients. Because many providers require an admin to
register a fixed client ID/secret/callback/scopes (rather than
Dynamic Client Registration, which MCP
2026-07-28deprecated), Portals now support manual OAuth credentials — the admin registers the Portal's callback URL upstream and enters the credentials; the Portal discovers OAuth metadata when available or accepts explicit authorization/token/revocation/issuer endpoints. Each user still authorizes their own upstream data; the stored client secret is used only to fetch updated tool + prompt lists. - Private-server routing (in active development). Work to let Portals reach servers on private networks via Gateway routing + the Cloudflare One network — the private server keeps its private hostname, the Portal presents its tools beside public upstreams, and Access policy + Portal logging + tool controls still apply at the same front door.
Portal bypass¶
A Portal only helps if employees use it. Connecting directly to an approved server's upstream URL skips the Portal's Access policy, curated catalog, DLP, and audit trail — Portal bypass, distinct from shadow MCP. Preventing it requires the network control (Gateway) plus an origin that can reject direct requests.
Role in Cloudflare OS¶
The portal is an integration surface, not the complete authorization model. MCP can describe the tools available to an agent, but it does not identify the underlying resources actually observed through a permitted tool call. Cloudflare OS uses Gatekeepers to make those resource reads and their later sharing/egress effects policy-visible through observation-coupled authorization.
Caveats¶
The source does not specify portal deployment topology, authentication protocol, registry/discovery behavior, tool aggregation limits, transport, policy schema, or a relationship to the similarly named internal MCP surfaces mentioned in earlier wiki pages. This page records only the Cloudflare OS integration role disclosed in the 2026-08-05 article.
Seen in¶
- sources/2026-08-14-cloudflare-how-cloudflare-detects-mcp-traffic-and-helps-secure-it
— the Portal as the governed MCP path:
mcp_portalTraffic Source, pre-registered OAuth clients, private-server routing, Portal-bypass problem. - sources/2026-08-05-cloudflare-os-an-open-platform-for-agents-apps-and-work — supports existing organization MCP servers in Cloudflare OS.
Related¶
- systems/cloudflare-os — consuming agent-workspace platform.
- systems/model-context-protocol — the interoperable tool protocol.
- systems/cloudflare-os-gatekeeper — service-aware resource-policy boundary.
- systems/cloudflare-gateway — routes/enforces Portal traffic; stamps the
mcp_portalon-ramp. - systems/cloudflare-one — the Zero Trust suite the Portal sits in.
- systems/cloudflare-access — the identity layer in front of the upstream server.
- shadow-mcp — Portal bypass vs. shadow MCP.
- dynamic-client-registration — the deprecated OAuth path pre-registration replaces.
- portal-only-egress-enforcement — enforcing use of the Portal.