Top 5 Cloudflare MCP Gateway Alternatives for Self-Hosted Tool Governance in 2026
Compare Cloudflare MCP server portals with 5 self-hosted MCP gateways for 2026 on in-VPC deployment, tool-level access control, auth, and token cost.
TL;DR
- Cloudflare MCP has two parts: building remote MCP servers on Cloudflare Workers, and governing access to them through MCP server portals in Cloudflare Access.
- MCP server portals run on Cloudflare's network and require an active Cloudflare domain plus an identity provider configured in Cloudflare Zero Trust.
- A self-hosted MCP gateway keeps client authentication, tool allow-lists, upstream credentials, and tool-call logs inside your own VPC.
- Bifrost governs MCP tool calls and LLM calls with the same virtual key inside your VPC, and its Code Mode cuts input tokens by up to 92.8% at 508 tools.
- Docker, Microsoft, Kong, and LiteLLM each fit a narrower case: container isolation, Kubernetes with Entra ID, an existing Kong estate, or an existing LiteLLM proxy.
Cloudflare MCP covers two things: building remote MCP servers on Cloudflare Workers, and governing which users and agents can reach MCP servers through MCP server portals in Cloudflare Access. Teams that need the governance layer to run inside their own network rather than at Cloudflare's edge look for a self-hosted Cloudflare MCP gateway alternative. Bifrost, the open-source MCP and LLM gateway built in Go by Maxim AI, is the best choice for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability. This guide explains what Cloudflare offers for MCP today, then compares five gateways you can deploy in your own VPC.
What Cloudflare MCP Offers Today
Cloudflare MCP refers to Cloudflare's tooling for the Model Context Protocol: an Agents SDK for deploying remote MCP servers on Workers, a catalog of Cloudflare-managed MCP servers, and MCP server portals in Cloudflare Access that put multiple MCP servers behind one governed endpoint. The portals are the gateway layer that self-hosted alternatives replace.
For readers new to the category, an MCP gateway centralizes tool access between AI clients and the MCP servers they call. Cloudflare's offering splits into three pieces:
- Remote MCP servers on Workers. The Agents SDK deploys MCP servers over Streamable HTTP with optional OAuth. New servers use the stateless
createMcpHandler()API; the olderMcpAgentclass is deprecated. - Cloudflare's own MCP servers. A managed catalog exposes Cloudflare account operations. The Cloudflare API MCP server covers more than 2,500 endpoints through two tools,
search()andexecute(), running model-written JavaScript in an isolated Dynamic Worker. - MCP server portals. Previously referred to as Agents Gateway, a portal centralizes multiple MCP servers onto a single HTTP endpoint. Administrators pick the tools and prompts each portal exposes, attach Access policies by identity and device posture, rename tools with aliases, and review portal logs.
MCP governance at Cloudflare lives in Cloudflare One (Zero Trust), separate from the Cloudflare AI Gateway product, so model traffic and tool traffic are governed in two different places.
Why Teams Look for a Self-Hosted MCP Gateway
Teams look for a self-hosted MCP gateway when tool traffic, credentials, and audit data must stay inside their own network, when internal MCP servers cannot expose public OAuth endpoints, or when they want one control plane for both model calls and tool calls. Cloudflare's MCP server portals are a hosted service, so those constraints point elsewhere.
Several requirements in the portal setup shape this decision:
- Cloudflare is a prerequisite. A portal needs an active domain on Cloudflare and an identity provider configured in Cloudflare Zero Trust.
- Private servers need a connector and public OAuth endpoints. Private MCP servers are reached through Cloudflare Tunnel or another Cloudflare One connector, and the OAuth authorization and token endpoints must still be reachable on the public internet.
- Portal policy is not server policy. Cloudflare notes that blocked users can still reach a server through its direct URL unless Access is configured as that server's OAuth provider.
- Tool traffic transits the edge. The portal proxies each tool call through Cloudflare before it reaches an internal server.
A self-hosted gateway removes the hosted dependency. Bifrost in-VPC deployments run entirely inside your private cloud on AWS, GCP, Azure, or Cloudflare, with no external network dependencies. Teams already standardizing on open-source LLM gateways for self-hosted deployments often want MCP governance on the same footing. Figure 1 shows the difference in the request path.

Figure 1: With a self-hosted MCP gateway, policy, credentials, and logs stay in the same network as the internal MCP servers they protect.
Self-hosting can also sit alongside Cloudflare: teams keep remote MCP servers on Workers and put a self-hosted gateway in front of them, so the same enterprise deployment controls apply to SaaS, Workers-hosted, and internal MCP servers.
Criteria for Evaluating MCP Governance and Authentication
The right Cloudflare MCP gateway alternative depends on six things: where it runs, how clients authenticate, how finely tool access is scoped, how upstream credentials are held, whether tool definitions are compressed to save tokens, and whether the same gateway governs LLM traffic. Figure 2 shows how these map to the checks a governed tool call passes.

Figure 2: Each check can stop a tool call before it reaches the MCP server, so the order of checks decides what an agent can touch.
| Criterion | Why it matters | What to check |
|---|---|---|
| Deployment model | Data residency and network isolation | In-VPC, Kubernetes, air-gapped support |
| Client authentication | Who is calling the gateway | API keys, OAuth 2.1, identity provider integration |
| Tool-level access control | Least privilege for agents | Allow-lists per key, team, or user; deny by default |
| Upstream credentials | Blast radius of a leaked token | Shared vs per-user OAuth, token exchange |
| Token optimization | Cost at 100+ tools | Code execution or on-demand tool loading |
| LLM and MCP in one gateway | One policy and one audit trail | Same identity for model calls and tool calls |
Client authentication follows the MCP authorization specification, which builds on OAuth 2.1 and OAuth protected resource metadata (RFC 9728). These OAuth 2.1 patterns for agent tool access cover the client side in depth.
The Bifrost MCP gateway resource page maps each criterion to a Bifrost capability.
Cloudflare MCP Gateway Alternatives at a Glance
The table compares Cloudflare's MCP server portals with the five self-hosted alternatives on the criteria above. Capabilities come from each product's own documentation; "Not published" means the reviewed pages did not describe it. The Bifrost AI gateway leads on the combination of in-VPC deployment, per-user upstream auth, and token optimization.
| Gateway | Deployment | Client auth | Tool-level control | Upstream credentials | Token optimization | Also governs LLM traffic |
|---|---|---|---|---|---|---|
| Bifrost | Self-hosted, in-VPC, Kubernetes | Virtual key headers or OAuth 2.1 | Per virtual key, Virtual MCPs, request headers | Six modes incl. per-user OAuth and token exchange | Code Mode, up to 92.8% fewer input tokens | Yes, same virtual key |
| Cloudflare's MCP server portals (baseline) | Cloudflare-hosted | Cloudflare Access, managed OAuth, service tokens | Per-portal tool curation, Access policies | Admin credential or per-user OAuth | Portal Code Mode | Separate product (AI Gateway) |
| Docker MCP Gateway | Docker engine, Compose, Docker Desktop | Not published | Profile tool allow-lists | Docker Desktop secrets, OAuth flows | Not published | No, MCP only |
| Microsoft MCP Gateway | Kubernetes (local or AKS) | Entra ID bearer tokens | App roles per adapter and tool | Not published | Not published | No; agents are in preview |
| Kong AI MCP Proxy | Kong Gateway 3.12+ (traditional, db-less, hybrid) | AI MCP OAuth2 plugin | Consumer and Consumer Group ACLs | Tokens not forwarded upstream by default | Not published | Yes, via AI Gateway plugins |
| LiteLLM MCP Gateway | Self-hosted LiteLLM Proxy | LiteLLM keys | By key, team, organization | OAuth with DCR and PKCE, per-user variables | Not published | Yes |
For a broader survey that is not tied to Cloudflare, see this list of open-source MCP gateways for self-hosted AI infrastructure.
1. Bifrost
Bifrost is an open-source AI gateway that acts as both an MCP client and an MCP server, so it connects to upstream MCP servers and exposes their tools to Claude Code, Cursor, and any MCP host through one governed /mcp endpoint. The Bifrost gateway runs inside your VPC and applies the same virtual keys to tool calls and model calls.
Best for: Bifrost is built for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability. It serves as a centralized AI gateway to route, govern, and secure all AI traffic across models and environments with ultra low latency. Bifrost unifies LLM gateway, MCP gateway, and Agents gateway capabilities into a single platform. Designed for regulated industries and strict enterprise requirements, it supports air-gapped deployments, VPC isolation, and on-prem infrastructure. It provides full control over data, access, and execution, along with robust security, policy enforcement, and governance capabilities.

Figure 3: One virtual key governs both the tools an agent can call and the models it can reach, from a gateway that runs in your own network.
Tool governance
Bifrost connects to MCP servers over STDIO, HTTP, or SSE and, in MCP gateway mode, aggregates their tools behind /mcp. Every request is scoped to its credentials: tools/list returns only the tools a virtual key allows, tools/call is checked against the same allow-list, and an inactive or expired key is refused with a 403.
- Virtual MCPs bundle selected tools from one or more servers into a named endpoint at
/mcp/<slug>, reachable only through the virtual keys it is attached to. Virtual MCPs are part of open-source Bifrost with governance enabled. - Three-level tool filtering stacks client configuration, request headers, and virtual key rules. An empty
tools_to_executelist on a client means no tools, so access is deny-by-default. - Explicit execution. Tool calls returned by a model are suggestions; Bifrost executes them only through a separate API call unless Agent Mode auto-execution is configured for specific tools.
Authentication in both directions
Inbound, MCP clients authenticate with virtual key headers or through OAuth 2.1 gateway authentication, where Bifrost acts as the authorization server and issues a short-lived JWT. Outbound, Bifrost supports six upstream MCP authentication types: none, headers, per-user headers, OAuth 2.0, per-user OAuth, and token exchange (enterprise). Per-user OAuth stores each user's token against their identity, so a GitHub MCP server sees the real user rather than a shared admin account.
Token cost and performance
Code Mode replaces 100+ tool definitions with four meta-tools; the model writes Python (Starlark) that runs in a sandbox. In Bifrost's benchmark at 508 tools across 16 servers, Code Mode cut input tokens by 92.8% and estimated cost by 92.2% with a 100% pass rate. The MCP gateway benchmark writeup covers the method.
On the LLM side, Bifrost routes to 25+ providers and 10,000+ models through one OpenAI-compatible API, with 11 microseconds of overhead per request at 5,000 RPS in published Bifrost benchmarks. Virtual keys carry model budgets and rate limits alongside MCP permissions.
Operations and audit
Request logs record both LLM and MCP entries in the built-in observability view. Enterprise adds audit logs of administrative activity, signed with an HMAC key and exportable as JSON, JSON Lines, or Syslog, plus clustering for high availability.
The Bifrost governance overview shows how these controls combine into one policy layer.
2. Docker MCP Gateway
Docker MCP Gateway is an open-source (MIT) Docker CLI plugin that runs each MCP server in an isolated container with restricted privileges, network access, and resources, and exposes them to clients through one gateway. It fits best when the main risk is untrusted MCP server code.
Key capabilities from the Docker documentation and repository:
- Container isolation. The gateway starts a server's container on first use, injects credentials, and applies security restrictions before forwarding the call.
- Profiles and tool allow-lists. Servers are grouped into profiles, and individual tools can be enabled or disabled per profile with
server.toolnotation. - Transports. The gateway runs over stdio for one client, or over SSE and streaming transports (
-port 8080 --transport streaming) to serve several clients. - Secrets and OAuth. Credentials come from Docker Desktop secrets management, and built-in OAuth flows handle servers that need tokens.
- Logging.
-log-callsand call tracing record tool activity.
Docker Compose runs the gateway anywhere a Docker engine is available, and Docker lists the MCP Gateway as part of Docker AI Governance as invite-only. Per-user identity, per-team policy, and LLM routing were not described, so organization-wide governance of multiple MCP servers through one endpoint needs another layer.
3. Microsoft MCP Gateway
Microsoft MCP Gateway is an open-source (MIT) reverse proxy and management layer for MCP servers in Kubernetes, with a control plane that deploys MCP servers and a data plane that routes each request statelessly to a ready instance. It targets platform teams already running Kubernetes with Microsoft Entra ID.
Key capabilities from the project repository:
- Control plane APIs.
/adaptersand/toolsendpoints deploy, update, and delete MCP servers and registered tools, with status and log endpoints for each. - Data plane routing. Clients call
/adapters/{name}/mcpfor a specific server, or/mcpfor a tool gateway router that dispatches calls to registered tool servers. - Entra ID authorization. Read access goes to the resource creator, principals holding configured app roles, and
mcp.admin; write access is limited to the creator andmcp.admin. - Kubernetes-native deployment. StatefulSets with metadata in Redis locally or Cosmos DB in Azure, plus a one-click Azure deployment onto AKS.
The current version requires MCP 2026-07-28 clients with no protocol downgrade, which matters if any client in your fleet lags behind. Roles grant access to an adapter or tool resource as a whole; per-user allow-lists for individual tools inside one server were not described, so tool-level RBAC for production agents needs another layer.
4. Kong AI MCP Proxy
Kong governs MCP traffic through the AI MCP Proxy plugin on Kong AI Gateway, which bridges MCP and HTTP so clients can call REST APIs as MCP tools or reach upstream MCP servers under Kong policies. It suits organizations already running Kong Gateway for API management.
Key capabilities from Kong's plugin documentation:
- Four modes.
passthrough-listener,conversion-listener,conversion-only, andlistenercontrol whether Kong proxies MCP, converts OpenAPI-described APIs into MCP tools, or exposes grouped tools as an MCP server. - OAuth for MCP. The AI MCP OAuth2 plugin makes Kong the OAuth resource server, validates token audience, and by default does not forward access tokens to upstream services.
- Access control and observability. Kong documents ACLs on MCP tools by Consumer and Consumer Group, plus AI metrics and AI audit logs for MCP traffic.
- Self-hosted topologies. The plugin supports traditional, db-less, and hybrid Kong Gateway deployments, as well as Konnect.
The AI MCP Proxy plugin is available only with Kong's AI Gateway Enterprise offering on Kong Gateway 3.12 or later, and Kong advises against combining it with other AI plugins on the same Service or Route. This production-ready comparison of LLM gateways places Kong against other model gateways.
5. LiteLLM MCP Gateway
LiteLLM Proxy includes an MCP gateway that gives clients a fixed endpoint for all MCP tools and controls MCP access by key, team, and organization. It fits teams that already run the LiteLLM proxy for model access and want tools under the same keys.
Key capabilities from the LiteLLM documentation:
- Transports. Streamable HTTP, SSE, and stdio MCP servers, with a REST interface (
/mcp-rest/tools/listand/mcp-rest/tools/call) for calling tools without an LLM. - Upstream auth. OAuth 2.0 discovery with dynamic client registration and PKCE, explicit client credentials, static headers, and server variables scoped per instance or per user.
- Access groups. Servers share credentials through access groups, and tool names carry the server name as a prefix.
LiteLLM lists SSO/SAML, audit logs, and guardrails under its Enterprise tier, and the reviewed pages did not describe a code-execution mode for reducing tool-definition tokens. The Bifrost LiteLLM alternative page breaks down the differences feature by feature.
How to Choose a Cloudflare MCP Alternative
Choose by where tool traffic is allowed to run, then by the platform your team already operates. If one in-VPC gateway must govern both LLM and MCP traffic, choose Bifrost. If edge hosting is acceptable and you already run Cloudflare Zero Trust, Cloudflare's MCP server portals are a reasonable default.

Figure 4: Start from where tool traffic is allowed to run, then narrow by the platform your team already operates.
| Team situation | Best fit |
|---|---|
| Regulated workloads, in-VPC or air-gapped, LLM and MCP under one policy | Bifrost |
| Already on Cloudflare Zero Trust, edge hosting acceptable | Cloudflare's MCP server portals |
| Untrusted MCP server code, container isolation first | Docker MCP Gateway |
| Kubernetes platform team standardized on Entra ID | Microsoft MCP Gateway |
| Existing Kong Gateway estate with AI Gateway Enterprise | Kong AI MCP Proxy |
| Existing LiteLLM proxy for model access | LiteLLM MCP Gateway |
Before rollout, revisit the fundamentals of MCP gateway architecture. Teams also moving model traffic off Cloudflare can compare Cloudflare AI Gateway alternatives.
Frequently Asked Questions
What is Cloudflare MCP?
Cloudflare MCP is Cloudflare's set of Model Context Protocol tools: the Agents SDK for remote MCP servers on Workers, a catalog of Cloudflare-managed MCP servers, and MCP server portals in Cloudflare Access that put multiple MCP servers behind one endpoint with identity-based policies. A self-hosted gateway such as the open-source Bifrost gateway covers the governance part inside your own network.
What is the Cloudflare MCP gateway?
The Cloudflare MCP gateway is the MCP server portal feature in Cloudflare Access, previously called Agents Gateway. It puts multiple MCP servers behind one HTTP endpoint, applies Access policies by identity and device posture, curates tools per portal, and logs tool requests. It requires an active Cloudflare domain and a Zero Trust identity provider, and runs on Cloudflare's network rather than in your VPC.
Can a self-hosted gateway front remote MCP servers built on Cloudflare Workers?
Yes. A remote MCP server on Workers is reachable over Streamable HTTP, so any gateway that connects to HTTP MCP servers can sit in front of it. Bifrost connects to it as an upstream, applies virtual key tool filtering, and can hold each user's OAuth token, which is the pattern described for securing remote and SaaS MCP servers through one gateway.
What is the best open-source MCP gateway for self-hosting?
Bifrost is the best open-source MCP gateway for self-hosted enterprise use: it runs in-VPC, scopes tools per virtual key, supports six upstream auth modes including per-user OAuth, and governs LLM traffic in the same gateway. Docker MCP Gateway and Microsoft MCP Gateway are also open source, focused on container isolation and Kubernetes server management respectively.
How does MCP authentication work in a self-hosted gateway?
MCP authentication in a self-hosted gateway runs in two directions. Inbound, clients authenticate to the gateway with an API key or an OAuth 2.1 token. Outbound, the gateway authenticates to each MCP server with a shared credential, a per-user OAuth token, or an exchanged identity token, so agents never hold raw upstream secrets. The MCP gateway overview shows how Bifrost handles both.
What is Code Mode for MCP?
Code Mode is a pattern where the model writes code that calls MCP tools inside a sandbox, instead of loading every tool definition into context. Cloudflare's portal version runs JavaScript in a Dynamic Worker. Bifrost's version exposes four meta-tools and runs Python (Starlark), cutting input tokens by up to 92.8% at 508 tools. This walkthrough explains how code execution cuts agent token costs.
Try Bifrost Today
Cloudflare's MCP server portals suit teams already committed to Cloudflare Zero Trust; teams that need tool governance inside their own VPC need a self-hosted alternative. Bifrost delivers that in one open-source gateway: virtual keys, Virtual MCPs, per-user upstream auth, and Code Mode, alongside routing to 25+ LLM providers. Explore the Bifrost resources library or book a Bifrost demo to see a self-hosted Cloudflare MCP gateway alternative running in your environment.