Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

How Cloudflare detects MCP traffic and helps secure it

Blog post from Cloudflare

Post Details
Company
Date Published
Author
-
Word Count
3,491
Company Posts That Month
44
Language
English
Hacker News Points
-
Post removed?
No
Summary

Cloudflare announces Cloudflare One capabilities for identifying, monitoring, and controlling Model Context Protocol (MCP) traffic, addressing the heightened risk of AI agents that can make nondeterministic decisions and execute actions at machine speed using existing organizational permissions. MCP tool calls can be governed at the client, network, and server layers, each offering different visibility and enforcement capabilities, while network inspection provides broad coverage of remote traffic but cannot observe local, off-network, or undecrypted connections. Gateway can now classify TLS-inspected MCP requests using protocol headers, expose related users, hosts, and traffic sources in logs and a dedicated dashboard, and enable policies that allow or block detected traffic, including direct connections that bypass approved Cloudflare MCP Portals. MCP Portals provide managed endpoints with identity controls, curated tool catalogs, logging, data-loss-prevention routing, and support for pre-registered OAuth clients, helping organizations distinguish and address both unapproved “shadow MCP” servers and direct bypasses of approved services. The update also notes planned private-network connectivity for Portal-managed MCP servers and adds support for the newer stateless MCP protocol in Cloudflare’s Agents SDK while retaining compatibility with legacy implementations.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 118 8,729 854 211 -20%
Zero Trust 2 201 62 27 -20%
AI Agents 1 5,780 1,243 245 -15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.