Cloudflare now fingerprints MCP traffic at the protocol level — the MCP-Protocol-Version header is the tell
Cloudflare Gateway detects Model Context Protocol traffic via HTTP headers rather than URL patterns, keying on the MCP-Protocol-Version header that conforming clients must send after initialization, plus Mcp-Method and Mcp-Name headers that expose which tool is being invoked without body inspection. Shipped alongside: an experimental.is_mcp policy selector, a dedicated MCP dashboard showing unique servers and users, a Traffic Source selector separating Portal-originated from direct connections, and Agents SDK v0.20.0 supporting the stateless MCP 2026-07-28 spec. Cloudflare is candid that absence of the header does not prove a request isn't MCP, and detection requires TLS decryption — so shadow-MCP discovery is best-effort, and they publish no numbers on how much of it exists.
↳ Follow the thread