Developers can now restrict access to their local applications shared via Cloudflare Quick Tunnels by specifying allowed email addresses or domains, using a simple command-line flag. This introduces one-time PIN authentication without requiring Cloudflare accounts for either party, enhancing security while maintaining ease of use.
- Email-based one-time PIN authentication added to Quick Tunnels
- No Cloudflare accounts needed for either tunnel host or visitor
- Simple command flag controls access to local dev services
Infrastructure signal
Cloudflare’s Quick Tunnels now include built-in email authentication without requiring user accounts, marking a significant step in secure ephemeral tunneling infrastructure. This feature disables open public access unless explicitly authorized by email, limiting exposure risk while preserving the zero-configuration paradigm that powered adoption since 2021. Cloudflared versions 2026.9.3 and later support the --allowed-mail flag, enabling targeted access rules.
The authentication relies on Cloudflare Access issuing one-time PIN codes to verify email ownership outside the local environment, while access rules are enforced client-side within the cloudflared process. This enforces control at the tunnel client endpoint, simplifying backend complexity and minimizing additional infrastructure or cost impact. The short-lived tunnel lifespan and ephemeral URLs complement this layered access method, addressing concerns over accidental data exposure that arose from completely open tunnels.
Developer impact
Developers benefit from a lightweight mechanism to safeguard local environments exposed via Quick Tunnels without sacrificing the ease and speed of sharing dev endpoints. Adding email whitelisting is achieved by appending a single flag in the tunnel command line, preserving existing workflows and tooling compatibility, including integration with worker deployments through wrangler. The output logs JSON formatting support aids automation agents in capturing URLs and states cleanly.
With no requirement to sign in to Cloudflare on either side, developers and stakeholders gain a frictionless, secure access experience through email verification. Authentication predominantly targets browser users and is optimized for granting temporary preview access, suitable for demos, remote testing, or agent-based workflows. While public tunnels remain unchanged without this flag, re-launching with --allowed-mail offers immediate access control, reducing operational overhead in managing tunnel exposure.
What teams should watch
Engineering teams operating developer tools, AI agent workflows, and local service previews should evaluate integrating this email-based authentication to mitigate risks linked to accidental public exposure. Security and platform teams must review tunnels launched with --allowed-mail to verify adherence to access policies and audit usage patterns since the client-side enforcement hides email details from logs but reports rule counts.
Teams deploying automated pipelines or shared development environments can embed these flags in instruction files (e.g., AGENTS.md) to ensure secure defaults. Observability on authentication events lives upstream at Cloudflare Access, while tunnel session lifetime remains tied to client process uptime. For scenarios requiring stable hostnames or richer authentication, teams should combine this feature with Cloudflare Tunnel and Access or Cloudflare Mesh for private connectivity and persistent endpoints.