megachangelog
Feature

Private MCP server support for Access portals

MCP server portals can now connect to private MCP servers on your network via Cloudflare Gateway without exposing them publicly. Set up a connection using Cloudflare Tunnel or Mesh, configure a private hostname or CIDR route, and enable Gateway traffic routing.

MCP server portals can now connect to MCP servers available only on your private network. The portal uses Cloudflare Gateway to reach private hostnames and IP addresses without exposing the MCP server to the public Internet.

Connect the server network to Cloudflare with Cloudflare Tunnel, Cloudflare Mesh, or another Cloudflare One connector. Configure a private hostname or CIDR route, then turn on Route traffic through Cloudflare Gateway when you add the server. OAuth authorization server endpoints, such as the authorization and token endpoints, must be accessible on the public Internet. If Cloudflare automatically registers the OAuth client through Dynamic Client Registration (DCR), the registration endpoint must also be accessible on the public Internet.

For setup instructions, refer to Connect a private MCP server.

accessmcpsecuritynetworkinggateway

Source: original entry ↗