Cloudflare on August 14 released a set of Cloudflare One capabilities that let enterprise network administrators detect Model Context Protocol traffic inside encrypted sessions, visualize which users and servers generate it, and block connections that skip an approved path1,2.
The release, authored by AJ Gerstenhaber and Kenny Johnson on the Cloudflare blog, spans three connected components.
First, Cloudflare Gateway now includes a detection heuristic that classifies TLS-inspected requests as MCP or non-MCP at the protocol layer. All Cloudflare Zero Trust customers can see MCP traffic indicators in their Gateway HTTP logs and can explicitly block or allow MCP requests using the boolean policy selector `experimental.is_mcp == true`.
Second, Cloudflare is introducing a dedicated MCP traffic dashboard. The dashboard surfaces total MCP requests, unique users, and unique servers over a configurable time window. It displays MCP servers over time with per-server request counts, breaks traffic down by on-ramp — separating MCP Server Portals traffic from direct device-client connections — and highlights top MCP servers seen outside portals, which Cloudflare labels "shadow MCP traffic". Administrators can filter by specific servers, users, or on-ramp types and navigate directly to Gateway HTTP logs filtered by the relevant host or user.
Third, Cloudflare is adding Traffic Source selectors to Gateway Network and HTTP policies, enabling administrators to write rules that distinguish requests routed through a Cloudflare MCP Portal from those connecting straight to an upstream server.
The framing in the announcement centers on a permissions argument rather than a threat-actor scenario. Corporate access models, Cloudflare argues, were designed around a human operator whose risk is bounded by two assumptions: the person exercises judgment, and the person can only work at human speed3. AI agents are constrained by neither — their decisions are nondeterministic, and they can invoke the same tool indefinitely without fatigue. "A plausible — but incorrect — decision can become thousands of incorrect actions before a human notices," the post states.
MCP Server Portals now support pre-registered OAuth clients. Cloudflare is also working to let MCP Server Portals connect to private servers through Cloudflare Gateway routing and the Cloudflare One network.
Separately, the Agents SDK reached v0.20.0 with support for MCP 2026-07-28 as both a client and a server. The SDK client first probes for the new stateless protocol with `server/discover` and falls back to the legacy `initialize` handshake if the server does not support it. The SDK's `createMcpHandler` can serve stateless tools, prompts, resources, and elicitation from a Worker without creating a transport session or Durable Object.
Vector Wire covered the initial announcement earlier on August 14, noting the Gateway classification capability and Zero Trust log integration[3].
ANALYSIS The release addresses a gap that emerges as enterprises adopt agentic workflows: existing network-security tooling was not designed to distinguish agent-initiated API calls from human-initiated ones, making it difficult to enforce least-privilege policies on autonomous tool use. By tagging MCP traffic at the proxy layer and surfacing shadow connections, Cloudflare is positioning Cloudflare One as the control plane through which enterprises govern agent access to internal and third-party services.