Cloudflare MCP Server Portals put the MCP servers you already run behind one governed endpoint, inside the Cloudflare One estate you already pay for. Willow is a purpose-built agent governance and enablement platform that deploys anywhere, including on-premises and air-gapped. Compare where each one fits, and where running both makes sense.
Willow is a full-stack AI governance platform with shadow AI detection, unified build & runtime guards, infrastructure-as-code via GitHub, and a plugin marketplace for enterprise-wide governance. Cloudflare MCP Portals offers fast, cloud-only deployment with Zero Trust security for teams already in the Cloudflare ecosystem.
A purpose-built control plane for agent access and enablement across the organization. One product covering identity, a curated catalog, per-agent and per-action policy, endpoint discovery of unmanaged AI, employee self-service, and configuration as code. It deploys as SaaS, dedicated cloud, on-premises, hybrid, air-gapped, or with EU residency, and it is proven at Wix across roughly 5,000 weekly active users.
A centralizing endpoint inside Cloudflare One that centralizes multiple MCP servers onto a single HTTP endpoint, with per-tool enable and disable, tool aliases, automatic namespacing, and Access policy in front. It is one layer of a reference architecture that also uses Cloudflare Access for identity, Gateway and DLP for shadow-MCP detection, AI Gateway for spend limits, and Workers for hosting MCP servers you build.
Cloudflare leads on four of these. Willow leads on seven.
Cloudflare wins
Cloudflare has been ISO 27001 certified since 2019 and currently holds ISO 27001:2022, ISO 27018:2019 since 2022, and ISO 27701:2019 as both a PII Processor and PII Controller since 2021. Cloudflare for Government has held FedRAMP Moderate authorization since 2022. Willow holds SOC 2 Type II and GDPR with EU data residency, and does not hold ISO 27001 today. If your procurement requires ISO certification or FedRAMP authorization, Cloudflare clears bars Willow does not.
Cloudflare wins
Portals were announced as available in Open Beta for all Cloudflare One customers, with up to 50 free seats to start, riding spend you already have rather than a separate agent-governance line item. The network behind it is something no startup matches.
Cloudflare wins
AI Gateway spend limits let you set cost-based budgets, and when cumulative spend reaches the limit AI Gateway blocks further requests with a 429 response until the window resets, with the option to route to a cheaper fallback model instead of blocking. Budgets can be split by model, provider, or custom metadata such as a user or team. Willow reduces the tokens each call consumes but does not set hard spend stops. On enforcement, Cloudflare is ahead.
Cloudflare wins
You can build and deploy MCP servers on Cloudflare: you extend the McpAgent class and serve it as a Worker, and each instance has its own durable state backed by a Durable Object with its own SQL database. If your team is building MCP servers rather than only consuming them, that is a platform Willow does not compete with.
Willow wins
Portals are part of Cloudflare's cloud. Willow deploys on-premises on AWS, GCP, or Azure, hybrid, air-gapped, or with EU residency, delivered as a managed service. For a sovereign, regulated, or disconnected environment, this is the difference between a shortlist and a non-starter.
Willow wins
Cloudflare's shadow-MCP detection reads network traffic to find remote MCP servers outside of IT oversight. That is genuine discovery. What it cannot see is what never crosses the wire. Cloudflare's own documentation notes that MCP servers using stdio transport do not expose a remote HTTP endpoint and cannot be added to a portal, and those servers are equally invisible to network-based detection. Willow's endpoint scan agent finds local MCP servers, skill files, and agents on the device itself.
Willow wins
Adding a server to a portal means an administrator entering its URL. There is no catalog to pick from, no marketplace, and no vetting or risk scoring of the upstream server you point at. Willow ships 1,000+ pre-built, enterprise-vetted connectors and scores each server's security posture, so the question shifts from what URL do I trust to which approved tool does this team need.
Willow wins
Portals govern MCP servers and the tools they expose. Willow adds skills, plugins, toolkits, and commands on top, publishable and distributable to teams, which is a layer Cloudflare's MCP surface does not attempt.
Willow wins
Portals expect an administrator to register servers and a user to paste one URL into a client. Willow gives employees a Connect Panel and marketplace where they browse an approved, risk-scored catalog and connect any AI client in one click, with IT approving the catalog once.
Willow wins
Willow syncs toolkits, skills, commands, MCP servers, and clients to GitHub as version-controlled files with pull-request review and two-way sync. Cloudflare configures portals through the Cloudflare One dashboard and API.
Willow wins
Cloudflare's MCP governance is assembled from Access, Portals, Gateway and DLP, AI Gateway, and Workers. Each is strong. Together they are a reference architecture you wire up and maintain. Willow ships the equivalent scope as a single platform.
These are in Cloudflare's own documentation and they matter if you are scoping a portal deployment.
Where the control plane runs, and who holds the data.
This is the cleanest split on the page. If your security team requires the control plane inside your own environment, Cloudflare is not a candidate and Willow is. If you want someone else's global network doing the work, that is exactly what Cloudflare is for.
Finding what employees are already running.
Both discover unmanaged MCP. The difference is the vantage point. Cloudflare sees the wire, which is powerful for remote servers and blind to anything local. Willow sees the device, which is where stdio servers and skill files live. If your risk is a developer wiring a local MCP into a coding agent, that is an endpoint problem.
Getting approved tools into people's hands without a ticket queue.
Cloudflare's per-tool curation is genuinely good. What Portals do not attempt is the enablement half: there is no catalog to browse, nothing to request, and no self-service path. That is a deliberate scope choice on their side, and it is the largest altitude gap between the two products.
Two different answers to the same bill.
Cloudflare wins this one. It enforces, and Willow does not. Willow's contribution is on the other side of the equation, reducing what each call costs in the first place. If a hard budget ceiling is the requirement, that is AI Gateway.
How much assembly the answer requires.
If you already run Cloudflare One and have a platform team comfortable wiring products together, the assembly is a reasonable trade for bundled pricing and a network you trust. If you want agent governance to arrive as a product rather than a project, that is the case for Willow.
We are six to ten months ahead of most companies in AI adoption. More code to production, fewer incidents, real outcomes. Willow is what made it possible to move that fast without slowing down our security posture.
Asaf Yonay, Head of AI Core, Wix
Wix needed a secure, governed way to connect employees and agents to internal tools, documentation, and workflows. With Willow, the AI Core team built the enterprise MCP infrastructure that now supports nearly 600 tools and 300,000+ weekly tool calls across engineering, product, design, HR, finance, legal, and business teams.
Common questions from teams weighing Willow against Cloudflare MCP Server Portals.
Portals centralize the MCP servers your organization already runs onto a single HTTP endpoint inside Cloudflare One, with per-tool curation and Access policy in front. Willow is a purpose-built agent governance and enablement platform: a curated catalog with risk scoring, employee self-service, per-agent and per-action policy, endpoint discovery of unmanaged AI, configuration as code in GitHub, and deployment anywhere including on-premises and air-gapped. They sit at different layers, and the overlap is the govern-MCP-access slice.
Sometimes, and this is the honest cross-shop. If you are already on Cloudflare One, your MCP servers are remote HTTP endpoints, you need curation and access policy rather than employee enablement, and cloud-only deployment is fine, Portals may be all you need. If you need on-premises or air-gapped deployment, discovery of local MCP servers and skill files, a self-service catalog for non-technical employees, or GitOps governance, those are outside what Portals set out to do.
Yes. Cloudflare Gateway and DLP detect shadow MCP by scanning network traffic, matching MCP hostname and URL patterns and inspecting POST bodies for JSON-RPC methods, which surfaces remote MCP servers outside IT oversight. Any claim that Cloudflare has no shadow-AI detection is incorrect. The scope difference is that network-based detection cannot see MCP servers using stdio transport or skill files that stay on the device, which is what Willow's endpoint scan agent covers.
Cloudflare does, clearly. It has been ISO 27001 certified since 2019 and currently holds ISO 27001:2022, ISO 27018:2019 since 2022, and ISO 27701:2019 as both PII Processor and PII Controller since 2021, and Cloudflare for Government has held FedRAMP Moderate authorization since 2022. Willow holds SOC 2 Type II and GDPR, offers EU data residency, and does not hold ISO 27001 today. Where Willow adds compliance value is deployment, because an on-premises or air-gapped deployment keeps regulated data inside your own environment.
Cloudflare, if you need enforcement. AI Gateway spend limits set cost-based budgets and block requests with a 429 when the budget is exhausted, or reroute to a cheaper fallback model, and budgets can be split by model, provider, or custom metadata such as a user or team. Willow does not set hard spend stops. What Willow does is reduce the tokens each call consumes, through tool-response format optimization and usage analytics by team and tool.
Portals run on Cloudflare's global network as part of Cloudflare One, with no self-hosted or air-gapped option, and were announced as available to Cloudflare One customers with up to 50 free seats to start. Willow deploys as SaaS, dedicated cloud, on-premises on AWS, GCP, or Azure, hybrid, and air-gapped, with EU residency, all delivered as a managed service, and it typically goes live in about ten days.
Yes, and for many teams that is the right answer. They operate at different layers. You can host remote MCP servers on Cloudflare Workers, keep Cloudflare Access and Gateway doing network and identity work, and run Willow as the agent governance and enablement layer that decides which employees and agents reach which tools, with endpoint discovery covering what the network cannot see.
Give them a Basecamp. Go from AI chaos to AI work, in minutes.