OFICIAL Cloudflare Blog

How Cloudflare detects MCP traffic and helps secure it

What happened
Based on Cloudflare Blog · Aug 14, 2026

Cloudflare has introduced new controls in Cloudflare One to detect and secure Model Context Protocol (MCP) traffic, addressing risks posed by AI agents that can execute actions rapidly and nondeterministically.

How Cloudflare detects MCP traffic and helps secure it
Cloudflare Blog — Cloudflare
Key points
·
Most companies designed their resource permissions with a human user in mind.
·
A senior engineer may be able to deploy to production, query a sensitive database, or revoke another user's access.
·
Those privileges come with risk, but that risk has traditionally been bounded by two assumptions: the engineer will use human judgment, and the engineer can only act at human speed.
·
An engineer who sees an unexpected result will usually stop and reconsider their actions.

Cloudflare’s new capabilities in Cloudflare One aim to identify and manage MCP traffic, which is used by AI agents to invoke tools via third-party SaaS, internal applications, or APIs. These agents can act faster and with less oversight than human users, increasing the risk of unintended or harmful actions. The announcement highlights the need for visibility and control over MCP traffic, which may bypass traditional security measures due to its lack of standardized identifiers like hostnames or paths.

The MCP protocol enables AI agents to make tool calls through HTTP requests carrying JSON-RPC messages, exposing details such as the tool name, arguments, and authentication credentials. Security teams can intervene at three stages: within the client, on the network, or at the MCP server. Client-side controls require standardization across all devices, while network-level controls can inspect and block MCP traffic but may miss local or off-network calls. Server-side controls offer the deepest inspection but only protect servers that implement them.

Cloudflare Gateway uses protocol signals to detect MCP traffic, distinguishing between approved MCP Portal connections and unauthorized direct connections. Administrators can now report or block MCP traffic that does not follow approved paths, leveraging Cloudflare’s network infrastructure to enforce these policies. The detection relies on identifying MCP-specific headers and JSON-RPC methods within HTTPS traffic, which may otherwise appear as standard API calls.

The new controls complement existing security measures by providing a layered approach to MCP traffic management. Cloudflare’s WriteGuard, used internally, demonstrates server-side enforcement by assigning risk tiers to tools and blocking critical actions before execution. Combined with client and network controls, these measures aim to prevent data exposure, unauthorized actions, and shadow MCP usage across managed environments.

Original source → Deals on Clipraptor.com →