How Cloudflare Detects MCP Traffic and Enhances Security
Key point
Cloudflare announced new Cloudflare One security features that allow it to identify and control MCP traffic from AI agents.
Details
Existing resource permission designs assumed the judgment and speed of human users. However, AI agents make nondeterministic decisions and perform tasks at speeds far exceeding human capabilities, meaning incorrect decisions can lead to large-scale damage in an instant.
Model Context Protocol (MCP) servers allow agents to call external tools and APIs, but this traffic is difficult to distinguish from standard HTTPS API calls, making security management challenging. This is because MCP does not use fixed hostnames and does not require a specific path (/mcp).
To address this, Cloudflare announced new features in Cloudflare One. Key features include:
- Identifying inspected MCP traffic and tracking generated users/servers
- Controlling direct connections on managed network paths
- Verifying the use of approved paths via MCP Server Portals
Security teams can intervene at three points to control MCP requests:
- Inside the client: Immediately after the model selects a tool, destination, tool name, and arguments can be verified without decrypting network traffic. This is the fastest control stage, allowing the blocking of unauthorized servers or the removal of sensitive data.
- On the network: Cloudflare Gateway uses protocol signals to detect 'shadow MCP' traffic.
- At the MCP server: Tool calls are managed directly on the server side.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.