Cloudflare has introduced a major security enhancement to its popular Quick Tunnels service, addressing a long-standing vulnerability that made temporary local development previews accessible to anyone with a link. Beginning with version 2026.9.3 of the cloudflared connector, developers and their automated coding agents can enforce strict email-based access controls without requiring a Cloudflare account, a custom domain, or any upfront configuration costs.
Launched initially in 2021, Quick Tunnels quickly became a favorite tool among developers looking for an effortless way to share local services, applications, or projects running in development environments. By running a single command, developers could publish a local port—such as a dev server running on localhost:5173—to a random, publicly accessible trycloudflare.com URL. The utility of the service meant that anyone could instantly bridge their machine to the wider internet with zero friction.
However, that exact convenience always carried a persistent catch: anyone who managed to obtain the link could open it. While acceptable for casual sharing, this open-door policy became a pressing concern as the development ecosystem shifted dramatically toward autonomous coding agents.
The rise of AI-driven coding agents has made Quick Tunnels more popular than ever. Modern development workflows frequently involve coding agents that autonomously write code, spin up local development servers, and offer to let developers test features directly on their mobile devices. Similarly, agents running on home hardware or Model Context Protocol servers running on local laptops require public endpoints so that hosted assistants can interact with them.
Because Quick Tunnels provide the shortest path from a local port to a public URL without getting stuck behind signup forms or complex dashboards, agents have eagerly adopted them. This surge in automated usage drove a massive wave of adoption. On September 18, 2026, a link to the Quick Tunnels documentation climbed to the top of Hacker News, gathering more than 800 points and 300 comments. The ensuing online discussion functioned as a comprehensive catalog of modern agent workflows, with users praising how helpful the capability is for agentic work on the go.
Yet, the Hacker News discussion also highlighted the exact risks associated with ubiquitous, unauthenticated tunnels. Commentators immediately raised security concerns, questioning how long it would be before an automated agent inadvertently set up an unprotected tunnel exposing sensitive, private, or embarrassing information, or insecure work-in-progress applications to the entire world.
The new update directly solves this dilemma by allowing developers to pass specific email addresses or entire domains into the cloudflared command using the --allowed-mail flag. When a visitor attempts to open a protected Quick Tunnel URL, they are directed to a Cloudflare Access sign-in page where they enter their email address and complete a verification step using a one-time PIN sent to their inbox.

Crucially, this authentication step only verifies that the visitor controls the designated email address. The actual authorization decision is made locally on the developer’s machine by cloudflared, which compares the verified address against the rules provided by the user when launching the tunnel. If an unauthorized user attempts to visit the link, they are stopped entirely before a single request can reach the local machine. Developers can invite specific individuals or permit entire domains using wildcards, maintaining granular control without ever needing to touch a DNS record, write a configuration file, or open a browser dashboard. If no email restrictions are specified, Quick Tunnels continue to function exactly as they always have, remaining fully public.
Integrating this security measure into existing workflows is designed to be frictionless for both humans and machines. Because the protection relies on a single command-line flag, developers can easily bake the requirement into instructions files read by their coding agents, such as AGENTS.md, ensuring that any preview links generated automatically are restricted to authorized personnel by default. Furthermore, developers building applications using Cloudflare Workers can leverage the same functionality directly through the latest version of the wrangler command-line tool.
Designing an authentication and authorization framework for an accountless service presented a unique architectural challenge for Cloudflare’s engineering team. Traditional Cloudflare products enforce access rules by tying policies to a centralized Cloudflare account. Because Quick Tunnels operate entirely without accounts, establishing where the guest list should reside required a novel design approach.
The engineering team considered several alternatives before arriving at their final solution. An initial proposal involved provisioning a dynamic Cloudflare Access application for every active Quick Tunnel. However, with hundreds of thousands of ephemeral tunnels running simultaneously—many lasting only a few minutes—creating and routing temporary applications for short-lived guest lists proved impractical. A second proposal involved housing both the authentication mechanisms and the authorization rules directly within the cloudflared connector. While keeping rules on the developer’s machine made sense for authorization, handling global email delivery, abuse prevention, session management, and translated sign-in pages locally was not viable.
The resulting architecture successfully divides responsibilities by leveraging Cloudflare Access strictly for identity verification, while leaving authorization entirely in the hands of the local machine. When a visitor attempts to access a protected tunnel, Cloudflare Access verifies email ownership via a lightweight authentication broker running on Cloudflare Workers. This broker is entirely stateless, storing no tunnel policies, visitor sessions, or identity records, and it never has visibility into the tunnel’s guest list. Instead, it passes a short-lived, signed handoff to cloudflared, which evaluates the credentials in memory against the developer’s predefined rules. Consequently, the guest list never leaves the local machine, preserving user privacy while securing the endpoint.
Significantly, this security feature was entirely conceptualized, engineered, and brought to production by two Cloudflare interns, Hugo Vicente handling product requirements and Alessandro Frigerio leading engineering. Their work underscores Cloudflare’s longstanding internship philosophy of entrusting real-world challenges to interns and deploying their solutions directly into production environments.
Email protection for Quick Tunnels is available free of charge alongside the standard Quick Tunnels service. Developers can utilize the new functionality by updating their cloudflared connector and appending the allowed mail parameters to their local execution commands, ensuring that future previews shared by developers or their autonomous agents remain accessible exclusively to invited guests.
Leave a Reply