Solutions  ·  2026-08-16

Cloudflare Gateway adds MCP traffic detection and Portal-only enforcement controls

SolutionsHigh impactGlobal
Cloudflare announced (Aug 14, 2026) new Cloudflare One capabilities: Gateway now natively detects MCP traffic via protocol headers (Mcp-Protocol-Version, Mcp-Method, Mcp-Name), exposes an experimental.is_mcp policy selector, and adds an AI Security dashboard showing MCP server/user discovery, plus Access for Workers to enforce identity-aware auth on self-hosted MCP endpoints.
Shadow MCP connections bypass approved enterprise tool governance; this closes the visibility gap for remote/managed-path MCP traffic (though not local stdio), directly addressing a widely-cited agentic attack surface (21,000+ exposed MCP servers, ~92% lacking OAuth per third-party research cited alongside the launch).
Enterprise security/network teams using Cloudflare One should inventory MCP traffic and move to Portal-only enforcement within 30 days; complements existing MCP Server Portals feature.
Cloudflare BlogCloudflare Changelog
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →