How Cloudflare detects MCP traffic and helps secure it
- Source
- blog.cloudflare.com
- Date

- AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
- MCP — The Model Context Protocol — an open standard that lets any AI assistant plug into any tool or data source without custom integration code.
Teams running servers get a way to see shadow MCP traffic and force agents through an approved path, which is the first practical control over what an can reach at machine speed.
“The introduction of AI agents changes both thresholds. Their decisions are nondeterministic, and they can take the same action (or invoke the same tool) indefinitely, without getting tired or stopping for lunch. A plausible — but incorrect — decision can become thousands of incorrect actions before a human notices.”
“The Model Context Protocol does not use a guaranteed hostname or require /mcp in the path, so a direct connection can look like any other HTTPS API call.”
“Its presence is a strong positive indicator of MCP; its absence does not prove that a request is not MCP.”
“Shadow MCP is a connection to a server the organization has not approved. An employee finds the server in a repository, a product guide, or a message from a colleague and adds it directly to their MCP client. The security team has no idea which tools it exposes or what data employees send to it.”
“Starting today, all Cloudflare Zero Trust customers see indications of MCP traffic in their Gateway HTTP logs and can explicitly block or allow that traffic with a new Gateway selector: experimental.is_mcp == true”
Checking sign-in…
Loading comments…


