Trending:

Cloudflare adds accountless protection to Quick Tunnels with email-based authentication

Illustration of Cloudflare Quick Tunnels with email authentication
TechStaged-owned

Summary

  • Cloudflare launched Quick Tunnels in 2021 to share local development services, and the core use case remains.
  • Starting with cloudflared 2026.9.3, users can add --allowed-mail to enable accountless tunnels with email-based access control.
  • Protected Quick Tunnels authenticate visitors via Cloudflare Access by sending a one-time PIN to the visitor’s email.

Cloudflare has expanded Quick Tunnels with a protected mode that preserves the accountless ethos while enabling access control. The feature is introduced in tandem with cloudflared 2026.9.3, which adds a new --allowed-mail option to the one-command tunnel workflow.

Protected Quick Tunnels rely on email-based verification rather than a traditional Cloudflare account, aligning with the broader Quick Tunnels goal of providing a fast, public URL from a local service without setup friction.

HOW THE PROTECTION WORKS

When a visitor opens a protected Quick Tunnel, the request is redirected to login.trycloudflare.com where a random, single-use state is tied to the browser for 10 minutes. Cloudflare Access then sends a one-time PIN to the visitor’s email, and verification occurs through that channel. TechStaged has also covered Cloudflare Traces enters open beta, enabling end-to-end request tracing across the platform.

A short-lived, signed handoff is produced by a stateless authentication broker running on Cloudflare Workers. cloudflared validates the handoff and enforces the visitor rules on the developer’s machine, without sharing the guest list with Cloudflare.

  • Authentication confirms control over the email address.
  • Authorization decisions are made locally by cloudflared against user-specified rules.
  • The guest list never leaves the developer’s machine.

WHAT CHANGES FOR DEVELOPERS

Public Quick Tunnels remain unchanged if you do not supply --allowed-mail. To restrict access, you can repeat the flag or specify a domain, and the tunnel will only accept traffic from the verified addresses that match the rules.

If cloudflared is stopped or the session ends, access is terminated and must be re-established on the next run. The design avoids a central policy lookup on every request and keeps authentication local to the developer’s environment.

CONTEXT AND RECEPTION

The design emphasizes privacy: the guest list and the rules reside on the developer’s machine, while Cloudflare’s role verifies email ownership but does not host the tunnel’s policy. The system uses a one-time PIN flow and a non-persistent session.

The concept has gained visibility, including a Hacker News thread on September 18, 2026, which highlighted agent-based workflows and debates about exposure risks of public previews.

WHAT HAPPENS NEXT

Setup details, matching rules, and limits are documented in the Quick Tunnels documentation. Cloudflare notes that email-protected Quick Tunnels are free to use, continuing the cost-free nature of the feature.

In practice, switch to a protected tunnel by adding --allowed-mail and following the authentication flow; the system remains accountless and requires no DNS records, domains, or signup forms.

  • Public Quick Tunnels vs. protected mode: same command, with added access control.
  • Restarting with a different --allowed-mail updates who can access the tunnel.

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.