The Current State of Cloud MCP Servers
Zapier vs Make vs Gumloop vs Cloudflare... Who wins the MCP server race for AI? It's complicated. Our breakdown of the current players and why unification is the next big step
When we started building AI agents at Mazaal AI, we quickly realized that their usefulness depends entirely on their ability to actually do things in the world. The Model Context Protocol (MCP) has emerged as the best way to bridge this gap. We've been testing MCP since Anthropic introduced back in November and recent OpenAI's announcement that they'll be integrating with MCP, it was no brainer for us to start implementing. After weeks of testing different cloud MCP server providers, I've formed some opinions that might help others navigating this evolving landscape.
The Major Players
Zapier MCP
Zapier's approach is characterized by breadth and simplicity. Their library of 7,000+ integrations is impressive, but what's more valuable is the granular permission control. You can let your AI create a Google Doc without giving it access to your entire Google workspace.
The main drawback is architectural: one server URL encompasses all your tools. This forces each agent to wade through a crowded context window filled with tools it doesn't need. I'm also surprised they haven't enabled converting existing Zaps into MCP tools yet - seems like low-hanging fruit.
Make MCP
Make offers similar integration breadth but with a crucial advantage: existing Make scenarios automatically become available as MCP tools. This means complex workflows you've already built can immediately be accessed by your AI agents.
They suffer from the same limitation as Zapier - just one server per user. Different agents need different toolsets, and this architecture doesn't accommodate that well.
Composio MCP
Composio was early to market with hosted MCPs and has built a solid reputation. They've taken an interesting approach: you can have multiple servers, but each connects to just one integration (one for Gmail, another for Notion, etc.).
Initially, their integration library was smaller, but recent research shows they now support up to 250 tools. Their biggest weakness is in the permission model - it's all-or-nothing. Give your AI access to Notion, and it can do everything in Notion. This creates unnecessary security exposure. Their authentication also requires an extra "initiate connection" step that sometimes confuses the AI.
Emerging Contenders
Gumloop guMCP
Gumloop has taken the open-source route with guMCP. Their collection of MCP servers can run both remotely and locally, with support for both stdio and SSE transports. The unified backend architecture creates consistency across different services, and their full open-source approach is encouraging community contributions.
What's particularly interesting is their comprehensive server support across Google services, communication tools, productivity tools, and business tools - all with a consistent implementation pattern. It's just that the support for the tools is fairly limited at the moment - but that's the whole point of going all in as open source.
Cloudflare MCP
Cloudflare recently entered the space, enabling developers to build and deploy remote MCP servers on their platform. They've simplified the process considerably by handling much of the complexity, adding components like workers-oauth-provider for OAuth integration.
By making MCP servers accessible over the internet with familiar authorization flows, they're expanding the potential user base beyond technical users who can run local servers.
The tradeoff comes in platform dependency. Cloudflare's MCP toolchain relies on proprietary Workers KV storage and Durable Object orchestration, making migration to other providers technically challenging. Performance characteristics also differ from traditional serverful architectures - while Cloudflare's global network reduces latency for distributed users, complex workflows may encounter cold start delays in serverless environments
Auth0 MCP
Auth0 has partnered with Cloudflare to address the authentication challenges of remote MCP servers. They provide secure authentication flows that allow AI applications to access protected APIs through MCP servers. This collaboration aims to standardize the security aspects of MCP implementation, addressing one of the major hurdles in adoption.
Observations
The MCP server landscape reminds me of the early days of web frameworks. The approaches differ dramatically, suggesting we haven't converged on optimal patterns yet.
The ideal MCP server would combine Zapier's granular permissions, Make's workflow leverage, Composio's multi-server architecture, Cloudflare's deployment simplicity, and Gumloop's open-source flexibility. We're not there yet, but the pace of innovation suggests we might be soon.
The choice depends on three factors: your specific integration needs, desired level of control, and existing workflows. If you're already invested in Make scenarios, their automatic conversion to MCP tools provides immediate value. If security through granular permissions matters most, Zapier might be preferable. For those who value open-source flexibility, Gumloop offers an attractive alternative.
What strikes me most is how rapidly this space is evolving. Six months from now, this assessment will likely be obsolete. That's why I'm curious - what are your experiences with these or other MCP providers? Which have you found most effective for your AI agents?
Security Considerations in Modern MCP Architectures
The shift toward remote MCP servers introduces new attack vectors that original protocol designers didn't anticipate. Cloudflare's token indirection model - where MCP servers issue their own scoped tokens rather than passing through upstream credentials - reduces but doesn't eliminate risk. A compromised MCP server could still abuse its delegated permissions, albeit within narrower bounds than full API access. Researchers have demonstrated attack vectors where malformed tool descriptions trick agents into invoking dangerous operations - for example, a "file_compress" tool that actually exfiltrates data. Neither current MCP specifications nor major implementations include tool risk classification systems to prevent such exploits
Mazaal's Take on MCP and the Strategy.
The MCP ecosystem today feels like TCP/IP before routers—every network speaks the protocol, but they can’t find each other. Our insight at Mazaal is simple: tools should be discovered, not configured.
We're building three things that matter:
-
A dynamic registry where any MCP server—from your intern’s Raspberry Pi to Zapier or Compose IO cluster—advertises its capabilities (short term plan)
-
Policy envelopes that wrap every tool call with auth, rate limits, and cost controls (medium term)
-
A negotiation layer that translates between incompatible auth flows (OAuth here, session tokens there) (long term)
The magic isn’t technical—it’s social. The endgame? Agents that evolve. Yours starts using a new PDF parser because our registry shows it’s 30ms faster, then drops it when Cloudflare launches a better one. No rewiring.
We’re betting that in tools, as in markets, liquidity beats ownership. Let the protocols fight—we’ll be the exchange.
Keep reading
All articles →
AI
AI Agent Examples: How Businesses Leverage AI for Growth (2025)
AI agents are intelligent software programs capable of autonomously performing tasks, making decisions, and adapting to real-time data. Unlike traditional automation tools that operate on rigid rules, AI agents leverage machine learning and natural language processing to understand context and optimize outcomes.

AI agents
AI Agents: Your New Virtual Team Members for Smarter Business Automation
Imagine if you had a tireless assistant who could handle routine tasks, answer questions, and even make minor decisions for you—all without needing a coffee break. Sounds like science fiction, right? AI agents make this a reality. Read more on how AI agents are changing the world.

AI agents
What we shipped: May 2026
Agent Skills replace Prompts, the dashboard gets one consistent design with real metrics on workflow cards, and the agent builder and conversations dashboard now work properly on mobile.