
How Cloudflare detects MCP traffic and helps secure it
Cloudflare introduced new Cloudflare One capabilities to detect, monitor, and control Model Context Protocol (MCP) traffic used by AI agents.
Why it matters
Since AI agents can execute thousands of incorrect actions faster than humans, these controls allow administrators to block unapproved tools and ensure secure usage paths.
The details
- Introduced experimental.is_mcp == true selector for MCP traffic detection in Gateway.
- Launched an MCP traffic dashboard to monitor users and identify shadow servers.
- Cloudflare Agents SDK v0.20.0 supports the stateless MCP 2026-07-28 specification.
Show entities and relationshipsHide entities and relationships
In this article
Products
Companies
Key connections
Cloudflare owns Cloudflare One
Cloudflare One is Cloudflare's zero-trust network platform.
Cloudflare owns Cloudflare Gateway
Cloudflare Gateway is a component of Cloudflare One.
Cloudflare owns MCP Server Portals
Cloudflare announced MCP Server Portals for governing MCP traffic.
Cloudflare owns Cloudflare Agents SDK
Cloudflare maintains the Agents SDK for building MCP clients and servers.
Cloudflare owns WriteGuard
WriteGuard is Cloudflare's internal MCP server middleware.
Cloudflare owns Cloudflare One Client
Cloudflare One Client is the endpoint agent for routing managed device traffic.
Show 11 more connectionsShow fewer connections
Cloudflare owns Logpush
Logpush is used to export MCP tool activity logs.
Cloudflare Gateway uses Model Context Protocol
Gateway classifies MCP traffic using protocol header signals from the MCP specification.
Cloudflare Gateway uses TLS Inspection
Gateway requires TLS decryption to inspect MCP-Protocol-Version headers.
Cloudflare Gateway uses Data Loss Prevention
Gateway can apply DLP scanning to MCP JSON-RPC method bodies.
Cloudflare Gateway uses JSON-RPC
Gateway inspects JSON-RPC method and argument fields for MCP policy enforcement.
MCP Server Portals uses OAuth
MCP Server Portals now support pre-registered OAuth clients for upstream authorization.
Cloudflare Agents SDK is built with Model Context Protocol
Cloudflare Agents SDK v0.20.0 implements both client and server sides of MCP 2026-07-28.
WriteGuard uses Model Context Protocol
WriteGuard operates at the MCP server layer to enforce risk tiers and block critical actions.
MCP Server Portals uses Cloudflare Gateway
Portal traffic can be routed through Gateway for HTTP policy, DLP, and predictable egress.
Cloudflare One Client uses Cloudflare Gateway
The Cloudflare One Client routes managed device traffic through Gateway for inspection.
Cloudflare One is related to Model Context Protocol
Cloudflare One is being extended with new capabilities to identify, inspect, and control MCP traffic.
Related events
Cloudflare launches MCP traffic detection, dashboard, and Portal-only enforcement in Cloudflare One
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.