Cloud Computing and Data Centers

Cloudflare Adds Email Authentication to Quick Tunnels Without an Account

Cloudflare has added the --allowed-mail option to Quick Tunnels, allowing access to local applications to be restricted by specific email addresses or domains without requiring the owner or visitor to have a Cloudflare account.

2026-10-02
4 min read
3 views
certi.news Editorial Team
Cloudflare Adds Email Authentication to Quick Tunnels Without an Account

Cloudflare announced the addition of email authentication to its Quick Tunnels service, allowing developers to specify the email addresses or domains permitted to access an application running locally. The feature is available starting with cloudflared 2026.9.3 and does not require either party to create a Cloudflare account.

Quick Tunnels are used to publish a service running on a developer’s device through a random address under the trycloudflare.com domain, without configuring DNS, opening a dashboard, or paying fees. The main drawback was that anyone with the link could open the service. To address this, the developer adds the following option to the command:

cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com

When the link is opened, the visitor is asked to enter their email address and then a one-time code sent to their inbox. After verifying ownership of the email address, cloudflared compares it with the access rules defined locally by the developer. The option can be repeated for multiple addresses, or a wildcard domain such as *@example.com can be used. If the option is not used, Quick Tunnels remain public as before.

What Changes in Practice?

The update gives developers a quick way to protect previews of local applications, particularly when an agent creates a service on a personal device and its owner wants to preview it from a phone or share it with specific people. The invite list remains on the developer’s device and is not sent to Cloudflare; Cloudflare Access verifies control of the email address, while cloudflared makes the allow decision locally.

According to Cloudflare, the design uses a stateless authentication intermediary running on Cloudflare Workers to issue short-lived, signed authorization. The intermediary does not store tunnel policies, visitor sessions, or identity logs. After successful verification, the tool creates a local session that lasts up to four hours, or for a shorter period if the login session expires, and ends immediately when the cloudflared process is stopped.

Feature Limitations and Alternatives

This authentication is intended for browser-based access. It verifies email ownership but does not itself provide an advanced permissions system. For a stable hostname or more detailed rules, such as identity-provider groups, Cloudflare recommends using Cloudflare Tunnel with Cloudflare Access. For private, bidirectional connections without a public address, the company points to Cloudflare Mesh.

The protected tunnel can also be run through the latest version of Wrangler using the command npx wrangler tunnel quick-start. Cloudflare says the feature is free, like Quick Tunnels, and that the tool does not print email addresses in debug logs. However, developers still need to restart the tunnel to change the list of allowed users, since there is no centralized account dashboard for managing the policy.

Why Does This News Matter?

The change does not turn Quick Tunnels into a complete replacement for enterprise identity-management infrastructure, but it addresses a clear practical risk: publishing a local test application through a public link that anyone can discover or share. Combining Cloudflare’s email verification with the tool making the decision on the developer’s device preserves operational simplicity while reducing exposure of unfinished applications. Protection remains tied to the security of the device and the email rules defined by the developer, and stopping the process cuts off access for everyone.

News source
Cloudflare Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news