News · curated 16 Aug 2026
How Cloudflare detects MCP traffic and helps secure it
First reported · updated · 2 reports cloudflare.com
Coverage timeline
Why it matters
AI agents connecting to MCP servers can invoke sensitive tools at machine speed and volume without human judgment, and because MCP traffic looks like ordinary HTTPS, defenders need protocol-aware detection to find and control unsanctioned agent tool access.
Cloudflare announced new Cloudflare One / Gateway capabilities to detect inspected MCP (Model Context Protocol) traffic, attribute it to users and servers, and enforce MCP Portal-only access to trusted MCP servers. The post explains the anatomy of an MCP tool call — including JSON-RPC over HTTP signals like MCP-Method and Mcp-Name headers — and how those protocol signals let defenders surface 'shadow MCP' connections that agents make outside approved paths.