# Protect MCP Endpoints at the Edge with Amazon CloudFront and AWS WAF

DevFeed: [Protect MCP Endpoints at the Edge with Amazon CloudFront and AWS WAF](<https://devfeed.tech/articles/protect-mcp-endpoints-at-the-edge-with-amazon-cloudfront-and-aws-waf-65227.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/networking-and-content-delivery/protect-mcp-endpoints-at-the-edge-with-amazon-cloudfront-and-aws-waf/>)

Author: Jaiganesh Girinathan

Published: 2026-10-05T18:25:14Z

Content type: tutorial

Language: en

Sources: [Networking & Content Delivery](<https://devfeed.tech/sources/networking-content-delivery.md>)

Topics: [MSP MCP](<https://devfeed.tech/topics/msp-mcp.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Cloudflare Workers](<https://devfeed.tech/topics/cloudflare-workers.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [amazon-cloudfront](<https://devfeed.tech/tags/amazon-cloudfront.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-waf](<https://devfeed.tech/tags/aws-waf.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [model-context-protocol-mcp](<https://devfeed.tech/tags/model-context-protocol-mcp.md>), [networking-content-delivery](<https://devfeed.tech/tags/networking-content-delivery.md>), [security](<https://devfeed.tech/tags/security.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>), [waf](<https://devfeed.tech/tags/waf.md>)

## AI overview

The article explains how to secure and monitor Model Context Protocol endpoints with AWS WAF at Amazon CloudFront or an Application Load Balancer. It presents nine controls, including protocol-version checks, caller labeling, request-size limits, tool allowlists, SQL and SSRF detection, and rate limits. It also describes observability and recommends testing rules in Count mode before blocking traffic. Per-user rate limits and token validation remain responsibilities of the origin server.

## Source excerpt

AWS WAF gives you a practical way to secure and observe Model Context Protocol (MCP) endpoints at the edge. MCP has quickly become the standard way AI agents communicate to tools and data. Originally, it was a stateful protocol built around long-running sessions, persistent connections, and client-to-server-instance binding. The 2026-07-28 MCP revision redesigned MCP as [...]