Cloudflare Quick Tunnels Add Accountless Authentication for Secure Local Development Sharing
Cloudflare's Quick Tunnels now supports accountless, email-based authentication, enhancing security for developers and AI agents sharing local projects.

Cloudflare has enhanced its Quick Tunnels service with a new accountless authentication feature, designed to provide secure access to locally hosted development projects. Introduced in cloudflared version 2026.9.3, the --allowed-mail flag allows users to restrict access to specific email addresses or domains. This move addresses a long-standing concern about the public nature of Quick Tunnels, which previously allowed anyone with a link to access a shared local service.
The new authentication mechanism leverages Cloudflare Access's one-time PIN (OTP) system. When a user attempts to access a protected Quick Tunnel, they are prompted to enter their email address. Cloudflare then sends an OTP to that address, which the user must provide to gain access. Crucially, neither the tunnel owner nor the visitor needs a Cloudflare account, preserving the simplicity and immediacy that made Quick Tunnels popular.
This update comes as AI agents increasingly utilize Quick Tunnels for tasks such as previewing newly built websites or providing remote access to local development environments. The ease of use of a single command makes it ideal for agentic workflows, but also raised concerns about potential exposure of sensitive work-in-progress applications. The --allowed-mail flag directly tackles this by enabling developers to control who can view their local projects.
Users can specify individual email addresses or entire domains using the --allowed-mail flag. For instance, running cloudflared tunnel --url http://localhost:5173 --allowed-mail [email protected] will ensure only Alice can access the tunnel after verifying her email. The flag can be repeated for multiple addresses or used with wildcard domains for broader, yet controlled, access.
For developers using Cloudflare Workers, the wrangler CLI also supports this new authentication feature. This integration allows for seamless creation of protected tunnels directly from the Workers development workflow. Similar to the cloudflared command, wrangler supports repeated flags, comma-separated values, and wildcard domains, while also omitting sensitive email addresses from debug logs.
The design carefully separates authentication (proving identity via email OTP) from authorization (deciding who is allowed in). The authorization rules are enforced locally by cloudflared on the user's machine, ensuring that no central policy lookup is required for each request and maintaining the accountless nature of the service. This approach avoids the complexity of managing individual Cloudflare Access applications for potentially short-lived tunnels.
While protected tunnels require restarting cloudflared to change access rules, and access is terminated when the process stops, Cloudflare offers more robust solutions like Cloudflare Tunnel with Cloudflare Access for stable hostnames and richer authorization policies. For scenarios requiring bidirectional connectivity without a public URL, Cloudflare Mesh is recommended. This layered approach allows developers to choose the right tool for their specific needs, from quick, temporary sharing to more permanent, secure deployments.