Cloudflare has moved MCP server portals from beta to general availability, and the changelog entry is short enough to quote almost whole. In MCP server portals are now generally available, the product is one sentence: “A portal gives users one endpoint for approved Model Context Protocol (MCP) servers.” Behind that endpoint, “Cloudflare Access logs tool, prompt, and resource activity.” It is the enterprise answer to the question every MCP gateway post has circled, how a company lets its people and its agents reach many servers through one governed door, and it ships inside the Zero Trust product Cloudflare already sells rather than as a new one.
There are no figures, so there is nothing to discount, and the list of what landed since the beta is the substance. Gateway routing with HTTP logging and data loss prevention scanning. Code Mode policies “that control how portals reduce tool definitions and token use,” which is the context-cost problem Crawlbase and Postman described from the consumer side, solved at the edge. Static OAuth client credentials “for providers that do not support Dynamic Client Registration,” an admission that the MCP authorization story is uneven across servers and the portal has to paper over it. Session management for reconnecting servers and changing authorizations. Service token authentication “for autonomous agents and machine-to-machine access,” which is the first time a portal release has said plainly that the client may not have a human behind it. And Logpush, so the activity goes to a SIEM.
The catalog can check whether the company selling the governed front door walks through one itself. The Cloudflare provider page lists 650 API pages, and the portal’s controls live on the Cloudflare Zero Trust API, with the agents the service tokens are for on the Cloudflare Agents API. The agentic access profile maps 3,118 operations, 1,576 of them acting and 52 flagged human-in-the-loop, more than twice the next widest surface in today’s five.
The Kin Score is 80.6, exemplar band, carried by developer ergonomics at 91.1 and access clarity at 84.2, with contract quality at 68.9 and contract governance at 45.5. The Agent Readiness score is 72.5, agent-native, and the lit list is nearly the whole rubric: the MCP server, agent skills, an agent card, dry-run mode, idempotency, reversibility, delegated identity, protected resource metadata, and dynamic client registration. Only the well-known catalog, consent identity, and agentic commerce are dark. This is a post where the claim checks out. The vendor that just shipped service-token access for autonomous agents is, by the catalog’s reading, the most agent-ready provider profiled this week, and the one of the five whose own API an agent can find, register against, rehearse, and retry. The portal is for everyone else’s servers. Cloudflare’s own door was already built.