Try Bifrost Enterprise free for 14 days. Request access

Top 5 Cloudflare MCP Gateway Alternatives for Self-Hosted Tool Governance in 2026

Compare Cloudflare MCP server portals with 5 self-hosted MCP gateways for 2026 on in-VPC deployment, tool-level access control, auth, and token cost.

Top 5 Cloudflare MCP Gateway Alternatives for Self-Hosted Tool Governance in 2026

TL;DR

  • Cloudflare MCP has two parts: building remote MCP servers on Cloudflare Workers, and governing access to them through MCP server portals in Cloudflare Access.
  • MCP server portals run on Cloudflare's network and require an active Cloudflare domain plus an identity provider configured in Cloudflare Zero Trust.
  • A self-hosted MCP gateway keeps client authentication, tool allow-lists, upstream credentials, and tool-call logs inside your own VPC.
  • Bifrost governs MCP tool calls and LLM calls with the same virtual key inside your VPC, and its Code Mode cuts input tokens by up to 92.8% at 508 tools.
  • Docker, Microsoft, Kong, and LiteLLM each fit a narrower case: container isolation, Kubernetes with Entra ID, an existing Kong estate, or an existing LiteLLM proxy.

Cloudflare MCP covers two things: building remote MCP servers on Cloudflare Workers, and governing which users and agents can reach MCP servers through MCP server portals in Cloudflare Access. Teams that need the governance layer to run inside their own network rather than at Cloudflare's edge look for a self-hosted Cloudflare MCP gateway alternative. Bifrost, the open-source MCP and LLM gateway built in Go by Maxim AI, is the best choice for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability. This guide explains what Cloudflare offers for MCP today, then compares five gateways you can deploy in your own VPC.

What Cloudflare MCP Offers Today

Cloudflare MCP refers to Cloudflare's tooling for the Model Context Protocol: an Agents SDK for deploying remote MCP servers on Workers, a catalog of Cloudflare-managed MCP servers, and MCP server portals in Cloudflare Access that put multiple MCP servers behind one governed endpoint. The portals are the gateway layer that self-hosted alternatives replace.

For readers new to the category, an MCP gateway centralizes tool access between AI clients and the MCP servers they call. Cloudflare's offering splits into three pieces:

  • Remote MCP servers on Workers. The Agents SDK deploys MCP servers over Streamable HTTP with optional OAuth. New servers use the stateless createMcpHandler() API; the older McpAgent class is deprecated.
  • Cloudflare's own MCP servers. A managed catalog exposes Cloudflare account operations. The Cloudflare API MCP server covers more than 2,500 endpoints through two tools, search() and execute(), running model-written JavaScript in an isolated Dynamic Worker.
  • MCP server portals. Previously referred to as Agents Gateway, a portal centralizes multiple MCP servers onto a single HTTP endpoint. Administrators pick the tools and prompts each portal exposes, attach Access policies by identity and device posture, rename tools with aliases, and review portal logs.

MCP governance at Cloudflare lives in Cloudflare One (Zero Trust), separate from the Cloudflare AI Gateway product, so model traffic and tool traffic are governed in two different places.

Why Teams Look for a Self-Hosted MCP Gateway

Teams look for a self-hosted MCP gateway when tool traffic, credentials, and audit data must stay inside their own network, when internal MCP servers cannot expose public OAuth endpoints, or when they want one control plane for both model calls and tool calls. Cloudflare's MCP server portals are a hosted service, so those constraints point elsewhere.

Several requirements in the portal setup shape this decision:

  • Cloudflare is a prerequisite. A portal needs an active domain on Cloudflare and an identity provider configured in Cloudflare Zero Trust.
  • Private servers need a connector and public OAuth endpoints. Private MCP servers are reached through Cloudflare Tunnel or another Cloudflare One connector, and the OAuth authorization and token endpoints must still be reachable on the public internet.
  • Portal policy is not server policy. Cloudflare notes that blocked users can still reach a server through its direct URL unless Access is configured as that server's OAuth provider.
  • Tool traffic transits the edge. The portal proxies each tool call through Cloudflare before it reaches an internal server.

A self-hosted gateway removes the hosted dependency. Bifrost in-VPC deployments run entirely inside your private cloud on AWS, GCP, Azure, or Cloudflare, with no external network dependencies. Teams already standardizing on open-source LLM gateways for self-hosted deployments often want MCP governance on the same footing. Figure 1 shows the difference in the request path.

Top lane routes MCP clients through a Cloudflare-hosted MCP server portal and Cloudflare Tunnel to private MCP servers; bottom lane routes clients through a self-hosted MCP gateway inside the VPC

Figure 1: With a self-hosted MCP gateway, policy, credentials, and logs stay in the same network as the internal MCP servers they protect.

Self-hosting can also sit alongside Cloudflare: teams keep remote MCP servers on Workers and put a self-hosted gateway in front of them, so the same enterprise deployment controls apply to SaaS, Workers-hosted, and internal MCP servers.

Criteria for Evaluating MCP Governance and Authentication

The right Cloudflare MCP gateway alternative depends on six things: where it runs, how clients authenticate, how finely tool access is scoped, how upstream credentials are held, whether tool definitions are compressed to save tokens, and whether the same gateway governs LLM traffic. Figure 2 shows how these map to the checks a governed tool call passes.

An MCP tool call passes through client authentication, a tool allow-list, and upstream credential injection before reaching the MCP server, with denied calls rejected and calls logged

Figure 2: Each check can stop a tool call before it reaches the MCP server, so the order of checks decides what an agent can touch.

Criterion Why it matters What to check
Deployment model Data residency and network isolation In-VPC, Kubernetes, air-gapped support
Client authentication Who is calling the gateway API keys, OAuth 2.1, identity provider integration
Tool-level access control Least privilege for agents Allow-lists per key, team, or user; deny by default
Upstream credentials Blast radius of a leaked token Shared vs per-user OAuth, token exchange
Token optimization Cost at 100+ tools Code execution or on-demand tool loading
LLM and MCP in one gateway One policy and one audit trail Same identity for model calls and tool calls

Client authentication follows the MCP authorization specification, which builds on OAuth 2.1 and OAuth protected resource metadata (RFC 9728). These OAuth 2.1 patterns for agent tool access cover the client side in depth.

The Bifrost MCP gateway resource page maps each criterion to a Bifrost capability.

Cloudflare MCP Gateway Alternatives at a Glance

The table compares Cloudflare's MCP server portals with the five self-hosted alternatives on the criteria above. Capabilities come from each product's own documentation; "Not published" means the reviewed pages did not describe it. The Bifrost AI gateway leads on the combination of in-VPC deployment, per-user upstream auth, and token optimization.

Gateway Deployment Client auth Tool-level control Upstream credentials Token optimization Also governs LLM traffic
Bifrost Self-hosted, in-VPC, Kubernetes Virtual key headers or OAuth 2.1 Per virtual key, Virtual MCPs, request headers Six modes incl. per-user OAuth and token exchange Code Mode, up to 92.8% fewer input tokens Yes, same virtual key
Cloudflare's MCP server portals (baseline) Cloudflare-hosted Cloudflare Access, managed OAuth, service tokens Per-portal tool curation, Access policies Admin credential or per-user OAuth Portal Code Mode Separate product (AI Gateway)
Docker MCP Gateway Docker engine, Compose, Docker Desktop Not published Profile tool allow-lists Docker Desktop secrets, OAuth flows Not published No, MCP only
Microsoft MCP Gateway Kubernetes (local or AKS) Entra ID bearer tokens App roles per adapter and tool Not published Not published No; agents are in preview
Kong AI MCP Proxy Kong Gateway 3.12+ (traditional, db-less, hybrid) AI MCP OAuth2 plugin Consumer and Consumer Group ACLs Tokens not forwarded upstream by default Not published Yes, via AI Gateway plugins
LiteLLM MCP Gateway Self-hosted LiteLLM Proxy LiteLLM keys By key, team, organization OAuth with DCR and PKCE, per-user variables Not published Yes

For a broader survey that is not tied to Cloudflare, see this list of open-source MCP gateways for self-hosted AI infrastructure.

1. Bifrost

Bifrost is an open-source AI gateway that acts as both an MCP client and an MCP server, so it connects to upstream MCP servers and exposes their tools to Claude Code, Cursor, and any MCP host through one governed /mcp endpoint. The Bifrost gateway runs inside your VPC and applies the same virtual keys to tool calls and model calls.

Best for: Bifrost is built for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability. It serves as a centralized AI gateway to route, govern, and secure all AI traffic across models and environments with ultra low latency. Bifrost unifies LLM gateway, MCP gateway, and Agents gateway capabilities into a single platform. Designed for regulated industries and strict enterprise requirements, it supports air-gapped deployments, VPC isolation, and on-prem infrastructure. It provides full control over data, access, and execution, along with robust security, policy enforcement, and governance capabilities.

Coding agents, agent applications, and custom MCP hosts connect to Bifrost inside the VPC, which governs access to internal MCP servers, SaaS MCP servers, and LLM providers

Figure 3: One virtual key governs both the tools an agent can call and the models it can reach, from a gateway that runs in your own network.

Tool governance

Bifrost connects to MCP servers over STDIO, HTTP, or SSE and, in MCP gateway mode, aggregates their tools behind /mcp. Every request is scoped to its credentials: tools/list returns only the tools a virtual key allows, tools/call is checked against the same allow-list, and an inactive or expired key is refused with a 403.

  • Virtual MCPs bundle selected tools from one or more servers into a named endpoint at /mcp/<slug>, reachable only through the virtual keys it is attached to. Virtual MCPs are part of open-source Bifrost with governance enabled.
  • Three-level tool filtering stacks client configuration, request headers, and virtual key rules. An empty tools_to_execute list on a client means no tools, so access is deny-by-default.
  • Explicit execution. Tool calls returned by a model are suggestions; Bifrost executes them only through a separate API call unless Agent Mode auto-execution is configured for specific tools.

Authentication in both directions

Inbound, MCP clients authenticate with virtual key headers or through OAuth 2.1 gateway authentication, where Bifrost acts as the authorization server and issues a short-lived JWT. Outbound, Bifrost supports six upstream MCP authentication types: none, headers, per-user headers, OAuth 2.0, per-user OAuth, and token exchange (enterprise). Per-user OAuth stores each user's token against their identity, so a GitHub MCP server sees the real user rather than a shared admin account.

Token cost and performance

Code Mode replaces 100+ tool definitions with four meta-tools; the model writes Python (Starlark) that runs in a sandbox. In Bifrost's benchmark at 508 tools across 16 servers, Code Mode cut input tokens by 92.8% and estimated cost by 92.2% with a 100% pass rate. The MCP gateway benchmark writeup covers the method.

On the LLM side, Bifrost routes to 25+ providers and 10,000+ models through one OpenAI-compatible API, with 11 microseconds of overhead per request at 5,000 RPS in published Bifrost benchmarks. Virtual keys carry model budgets and rate limits alongside MCP permissions.

Operations and audit

Request logs record both LLM and MCP entries in the built-in observability view. Enterprise adds audit logs of administrative activity, signed with an HMAC key and exportable as JSON, JSON Lines, or Syslog, plus clustering for high availability.

The Bifrost governance overview shows how these controls combine into one policy layer.

2. Docker MCP Gateway

Docker MCP Gateway is an open-source (MIT) Docker CLI plugin that runs each MCP server in an isolated container with restricted privileges, network access, and resources, and exposes them to clients through one gateway. It fits best when the main risk is untrusted MCP server code.

Key capabilities from the Docker documentation and repository:

  • Container isolation. The gateway starts a server's container on first use, injects credentials, and applies security restrictions before forwarding the call.
  • Profiles and tool allow-lists. Servers are grouped into profiles, and individual tools can be enabled or disabled per profile with server.tool notation.
  • Transports. The gateway runs over stdio for one client, or over SSE and streaming transports (-port 8080 --transport streaming) to serve several clients.
  • Secrets and OAuth. Credentials come from Docker Desktop secrets management, and built-in OAuth flows handle servers that need tokens.
  • Logging. -log-calls and call tracing record tool activity.

Docker Compose runs the gateway anywhere a Docker engine is available, and Docker lists the MCP Gateway as part of Docker AI Governance as invite-only. Per-user identity, per-team policy, and LLM routing were not described, so organization-wide governance of multiple MCP servers through one endpoint needs another layer.

3. Microsoft MCP Gateway

Microsoft MCP Gateway is an open-source (MIT) reverse proxy and management layer for MCP servers in Kubernetes, with a control plane that deploys MCP servers and a data plane that routes each request statelessly to a ready instance. It targets platform teams already running Kubernetes with Microsoft Entra ID.

Key capabilities from the project repository:

  • Control plane APIs. /adapters and /tools endpoints deploy, update, and delete MCP servers and registered tools, with status and log endpoints for each.
  • Data plane routing. Clients call /adapters/{name}/mcp for a specific server, or /mcp for a tool gateway router that dispatches calls to registered tool servers.
  • Entra ID authorization. Read access goes to the resource creator, principals holding configured app roles, and mcp.admin; write access is limited to the creator and mcp.admin.
  • Kubernetes-native deployment. StatefulSets with metadata in Redis locally or Cosmos DB in Azure, plus a one-click Azure deployment onto AKS.

The current version requires MCP 2026-07-28 clients with no protocol downgrade, which matters if any client in your fleet lags behind. Roles grant access to an adapter or tool resource as a whole; per-user allow-lists for individual tools inside one server were not described, so tool-level RBAC for production agents needs another layer.

4. Kong AI MCP Proxy

Kong governs MCP traffic through the AI MCP Proxy plugin on Kong AI Gateway, which bridges MCP and HTTP so clients can call REST APIs as MCP tools or reach upstream MCP servers under Kong policies. It suits organizations already running Kong Gateway for API management.

Key capabilities from Kong's plugin documentation:

  • Four modes. passthrough-listener, conversion-listener, conversion-only, and listener control whether Kong proxies MCP, converts OpenAPI-described APIs into MCP tools, or exposes grouped tools as an MCP server.
  • OAuth for MCP. The AI MCP OAuth2 plugin makes Kong the OAuth resource server, validates token audience, and by default does not forward access tokens to upstream services.
  • Access control and observability. Kong documents ACLs on MCP tools by Consumer and Consumer Group, plus AI metrics and AI audit logs for MCP traffic.
  • Self-hosted topologies. The plugin supports traditional, db-less, and hybrid Kong Gateway deployments, as well as Konnect.

The AI MCP Proxy plugin is available only with Kong's AI Gateway Enterprise offering on Kong Gateway 3.12 or later, and Kong advises against combining it with other AI plugins on the same Service or Route. This production-ready comparison of LLM gateways places Kong against other model gateways.

5. LiteLLM MCP Gateway

LiteLLM Proxy includes an MCP gateway that gives clients a fixed endpoint for all MCP tools and controls MCP access by key, team, and organization. It fits teams that already run the LiteLLM proxy for model access and want tools under the same keys.

Key capabilities from the LiteLLM documentation:

  • Transports. Streamable HTTP, SSE, and stdio MCP servers, with a REST interface (/mcp-rest/tools/list and /mcp-rest/tools/call) for calling tools without an LLM.
  • Upstream auth. OAuth 2.0 discovery with dynamic client registration and PKCE, explicit client credentials, static headers, and server variables scoped per instance or per user.
  • Access groups. Servers share credentials through access groups, and tool names carry the server name as a prefix.

LiteLLM lists SSO/SAML, audit logs, and guardrails under its Enterprise tier, and the reviewed pages did not describe a code-execution mode for reducing tool-definition tokens. The Bifrost LiteLLM alternative page breaks down the differences feature by feature.

How to Choose a Cloudflare MCP Alternative

Choose by where tool traffic is allowed to run, then by the platform your team already operates. If one in-VPC gateway must govern both LLM and MCP traffic, choose Bifrost. If edge hosting is acceptable and you already run Cloudflare Zero Trust, Cloudflare's MCP server portals are a reasonable default.

Decision flow for choosing between Bifrost, Cloudflare's MCP server portals, Docker MCP Gateway, Microsoft MCP Gateway, Kong, and LiteLLM based on network, governance, and platform questions

Figure 4: Start from where tool traffic is allowed to run, then narrow by the platform your team already operates.

Team situation Best fit
Regulated workloads, in-VPC or air-gapped, LLM and MCP under one policy Bifrost
Already on Cloudflare Zero Trust, edge hosting acceptable Cloudflare's MCP server portals
Untrusted MCP server code, container isolation first Docker MCP Gateway
Kubernetes platform team standardized on Entra ID Microsoft MCP Gateway
Existing Kong Gateway estate with AI Gateway Enterprise Kong AI MCP Proxy
Existing LiteLLM proxy for model access LiteLLM MCP Gateway

Before rollout, revisit the fundamentals of MCP gateway architecture. Teams also moving model traffic off Cloudflare can compare Cloudflare AI Gateway alternatives.

Frequently Asked Questions

What is Cloudflare MCP?

Cloudflare MCP is Cloudflare's set of Model Context Protocol tools: the Agents SDK for remote MCP servers on Workers, a catalog of Cloudflare-managed MCP servers, and MCP server portals in Cloudflare Access that put multiple MCP servers behind one endpoint with identity-based policies. A self-hosted gateway such as the open-source Bifrost gateway covers the governance part inside your own network.

What is the Cloudflare MCP gateway?

The Cloudflare MCP gateway is the MCP server portal feature in Cloudflare Access, previously called Agents Gateway. It puts multiple MCP servers behind one HTTP endpoint, applies Access policies by identity and device posture, curates tools per portal, and logs tool requests. It requires an active Cloudflare domain and a Zero Trust identity provider, and runs on Cloudflare's network rather than in your VPC.

Can a self-hosted gateway front remote MCP servers built on Cloudflare Workers?

Yes. A remote MCP server on Workers is reachable over Streamable HTTP, so any gateway that connects to HTTP MCP servers can sit in front of it. Bifrost connects to it as an upstream, applies virtual key tool filtering, and can hold each user's OAuth token, which is the pattern described for securing remote and SaaS MCP servers through one gateway.

What is the best open-source MCP gateway for self-hosting?

Bifrost is the best open-source MCP gateway for self-hosted enterprise use: it runs in-VPC, scopes tools per virtual key, supports six upstream auth modes including per-user OAuth, and governs LLM traffic in the same gateway. Docker MCP Gateway and Microsoft MCP Gateway are also open source, focused on container isolation and Kubernetes server management respectively.

How does MCP authentication work in a self-hosted gateway?

MCP authentication in a self-hosted gateway runs in two directions. Inbound, clients authenticate to the gateway with an API key or an OAuth 2.1 token. Outbound, the gateway authenticates to each MCP server with a shared credential, a per-user OAuth token, or an exchanged identity token, so agents never hold raw upstream secrets. The MCP gateway overview shows how Bifrost handles both.

What is Code Mode for MCP?

Code Mode is a pattern where the model writes code that calls MCP tools inside a sandbox, instead of loading every tool definition into context. Cloudflare's portal version runs JavaScript in a Dynamic Worker. Bifrost's version exposes four meta-tools and runs Python (Starlark), cutting input tokens by up to 92.8% at 508 tools. This walkthrough explains how code execution cuts agent token costs.

Try Bifrost Today

Cloudflare's MCP server portals suit teams already committed to Cloudflare Zero Trust; teams that need tool governance inside their own VPC need a self-hosted alternative. Bifrost delivers that in one open-source gateway: virtual keys, Virtual MCPs, per-user upstream auth, and Code Mode, alongside routing to 25+ LLM providers. Explore the Bifrost resources library or book a Bifrost demo to see a self-hosted Cloudflare MCP gateway alternative running in your environment.