Cloudflare has introduced a new authentication feature for its Quick Tunnels, enabling developers to control who can access their locally running services shared via a `trycloudflare.com` URL. This update, available with `cloudflared` version 2026.9.3 and later, allows users to specify allowed email addresses or domains using the `--allowed-mail` flag.
When `--allowed-mail` is used, visitors attempting to access the Quick Tunnel must prove ownership of an allowed email address. This is done through a one-time PIN sent by Cloudflare Access. Neither the developer sharing the service nor the visitor accessing it needs a Cloudflare account to utilize this authentication method.
Quick Tunnels, launched in 2021, provide a way to expose local development environments to a public URL without requiring an account or domain. The primary security concern was that anyone with the link could access the service. This new authentication feature directly addresses that vulnerability, making it safer to share work-in-progress applications or sensitive information.
The adoption of Quick Tunnels has increased, partly due to AI agents using them to publish code or services they generate. The ability to restrict access is particularly relevant for these automated workflows, preventing unintended public exposure of development projects.
This update provides developers and AI agents with a more secure method for sharing local projects for testing or review. It maintains the simplicity of Quick Tunnels while adding a layer of access control, which is important for collaborative development and for scenarios where agents automatically publish content that might require restricted viewing.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cloudflare has updated its Quick Tunnels feature to include an accountless authentication option, allowing developers to restrict access to shared local services. This update addresses security concerns for sharing development projects, particularly with the rise of AI agents utilizing Quick Tunnels for publishing work.