Cloudflare has expanded Quick Tunnels with a protected mode that preserves the accountless ethos while enabling access control. The feature is introduced in tandem with cloudflared 2026.9.3, which adds a new --allowed-mail option to the one-command tunnel workflow.
Protected Quick Tunnels rely on email-based verification rather than a traditional Cloudflare account, aligning with the broader Quick Tunnels goal of providing a fast, public URL from a local service without setup friction.
HOW THE PROTECTION WORKS
When a visitor opens a protected Quick Tunnel, the request is redirected to login.trycloudflare.com where a random, single-use state is tied to the browser for 10 minutes. Cloudflare Access then sends a one-time PIN to the visitor’s email, and verification occurs through that channel. TechStaged has also covered Cloudflare Traces enters open beta, enabling end-to-end request tracing across the platform.
A short-lived, signed handoff is produced by a stateless authentication broker running on Cloudflare Workers. cloudflared validates the handoff and enforces the visitor rules on the developer’s machine, without sharing the guest list with Cloudflare.
- Authentication confirms control over the email address.
- Authorization decisions are made locally by cloudflared against user-specified rules.
- The guest list never leaves the developer’s machine.
WHAT CHANGES FOR DEVELOPERS
Public Quick Tunnels remain unchanged if you do not supply --allowed-mail. To restrict access, you can repeat the flag or specify a domain, and the tunnel will only accept traffic from the verified addresses that match the rules.
If cloudflared is stopped or the session ends, access is terminated and must be re-established on the next run. The design avoids a central policy lookup on every request and keeps authentication local to the developer’s environment.
CONTEXT AND RECEPTION
The design emphasizes privacy: the guest list and the rules reside on the developer’s machine, while Cloudflare’s role verifies email ownership but does not host the tunnel’s policy. The system uses a one-time PIN flow and a non-persistent session.
The concept has gained visibility, including a Hacker News thread on September 18, 2026, which highlighted agent-based workflows and debates about exposure risks of public previews.
WHAT HAPPENS NEXT
Setup details, matching rules, and limits are documented in the Quick Tunnels documentation. Cloudflare notes that email-protected Quick Tunnels are free to use, continuing the cost-free nature of the feature.
In practice, switch to a protected tunnel by adding --allowed-mail and following the authentication flow; the system remains accountless and requires no DNS records, domains, or signup forms.
- Public Quick Tunnels vs. protected mode: same command, with added access control.
- Restarting with a different --allowed-mail updates who can access the tunnel.
RELATED COVERAGE
- Cloudflare Traces enters open beta, enabling end-to-end request tracing across the platform
- GitHub Copilot code review gains API access and a new default effort level
- GitHub posits AI is reshaping developer work, urges three skills to sharpen
- Cloudflare advances pledge to make features accessible to all, rolling out enterprise-grade tools to pay-as-you-go and free plans
- Developer Tools articles
SOURCES
- Cloudflare Blog: Protected Quick Tunnels: simple accountless authentication for your next dev project Published · Primary source



