How Cloudflare detects MCP traffic and helps secure it Cloudflare announced new Cloudflare One capabilities to identify inspected Model Context Protocol (MCP) traffic, show which users and servers generate it, and control direct connections on managed network paths, helping administrators see whether AI agents use approved paths or bypass them. The controls, combined with MCP Server Portals, address risks from AI agents that can act at machine speed and make nondeterministic decisions, potentially causing thousands of incorrect actions before a human notices. How Cloudflare detects MCP traffic and helps secure it Most companies designed their resource permissions with a human user in mind. A senior engineer may be able to deploy to production, query a sensitive database, or revoke another user's access. Those privileges come with risk, but that risk has traditionally been bounded by two assumptions: the engineer will use human judgment, and the engineer can only act at human speed. An engineer who sees an unexpected result will usually stop and reconsider their actions. Any human being can only click, type, and review so much in a single day. The introduction of AI agents changes both thresholds. Their decisions are nondeterministic, and they can take the same action or invoke the same tool indefinitely, without getting tired or stopping for lunch. A plausible — but incorrect — decision can become thousands of incorrect actions before a human notices. Today, we're announcing new Cloudflare One https://developers.cloudflare.com/cloudflare-one/ capabilities to identify inspected MCP traffic, show which users and servers are generating it, and control direct connections on managed network paths. Combined with , these controls help administrators see whether agents are using an approved path, or somehow bypassing it. https://developers.cloudflare.com/cloudflare-one/access-controls/ai-controls/mcp-portals/ MCP Server Portals Model Context Protocol https://www.cloudflare.com/learning/ai/what-is-model-context-protocol-mcp/ MCP servers give agents a common way to discover and invoke tools backed by third-party SaaS products, internal applications, and APIs. The underlying permissions are likely familiar; what changes is who makes each decision, and how quickly a bad decision can spread. Connecting an agent to one of these tools can take a single line of configuration. An employee can point Claude Code, Codex, Cursor, OpenCode, VS Code, or any AI harness at an MCP server without checking whether it is approved. The resulting traffic has no obvious shape. The Model Context Protocol does not use a guaranteed hostname or require /mcp in the path, so a direct connection can look like any other HTTPS API call. To explain how these controls fit together, we'll start with the anatomy of a tool call and the information it exposes. We'll then compare the three places a security team can act: inside the client, on the network, and at the MCP server. From there, we'll show how Cloudflare Gateway https://developers.cloudflare.com/cloudflare-one/traffic-policies/ uses protocol signals to find shadow MCP traffic and enforce MCP Portal-only access to trusted MCP servers. The anatomy of an MCP tool call The same MCP tool call has three forms as it moves through a system. Inside the client it is a decision to invoke a tool with a set of arguments. On the network it is an HTTP transaction carrying a JSON-RPC https://www.jsonrpc.org/specification message. At the server it becomes a call to a tool handler that may read data, change state, or complete some other action. Consider an agent that wants to know the weather in Austin. A remote MCP request can look like this: POST /mcp HTTP/1.1 Host: tools.example.com Authorization: Bearer