AI Briefing
KOSign in

Cloudflare Adds Accountless Email Authentication to Quick Tunnels

·2026.10.02 22:00

Key point

Starting with cloudflared 2026.9.3, developers can restrict access to local services via Quick Tunnels using a single flag without creating a Cloudflare account.

Details

Cloudflare has introduced Protected Quick Tunnels, a feature allowing developers to restrict access to local development services using email authentication without requiring a Cloudflare account. Starting with cloudflared 2026.9.3, users can add the --allowed-mail flag to their command, limiting access to specific email addresses or domains. This update addresses a long-standing limitation where anyone with the random trycloudflare.com URL could view the hosted service.

Agent-Driven Adoption

The demand for this security feature has been driven largely by AI coding agents, which frequently use Quick Tunnels to expose local ports for testing. Agents prefer Quick Tunnels because they require no signup and can parse JSON output easily. However, this convenience raised security concerns, with community discussions highlighting the risk of agents accidentally exposing sensitive or insecure work-in-progress applications to the public internet.

How It Works

The system separates authentication from authorization to maintain the accountless nature of Quick Tunnels:

  • Authentication: Cloudflare Access verifies that a visitor controls the email address they enter by sending a one-time PIN.
  • Authorization: The cloudflared connector on the developer's machine checks the verified email against the local rules defined by the --allowed-mail flag.
  • Privacy: A stateless Cloudflare Workers broker handles the identity handoff, ensuring that the specific list of allowed emails never leaves the developer's machine. Cloudflare only knows that a tunnel requires email authentication, not who is on the list.

Implementation and Limits

Developers can protect tunnels by passing email addresses or domains to the --allowed-mail flag, which can be repeated for multiple entries. The feature is also supported in Wrangler for Workers projects. Once a visitor is authenticated, they receive a session cookie valid for up to four hours. If the cloudflared process stops, access ends immediately. This feature is free and integrates with existing workflows, including those using Cloudflare Mesh for private connectivity.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.