← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Cloudflare Quick Tunnels Add Accountless Authentication for Local Development Sharing

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Quick Tunnels now support `--allowed-mail` for access control.
  • Users authenticate with a one-time PIN via Cloudflare Access.
  • No Cloudflare account is required for either party.
  • Addresses security concerns for sharing local dev environments.

New Authentication for Quick Tunnels

Cloudflare has introduced a new authentication feature for its Quick Tunnels, enabling developers to control who can access their locally running services shared via a `trycloudflare.com` URL. This update, available with `cloudflared` version 2026.9.3 and later, allows users to specify allowed email addresses or domains using the `--allowed-mail` flag.

How Accountless Authentication Works

When `--allowed-mail` is used, visitors attempting to access the Quick Tunnel must prove ownership of an allowed email address. This is done through a one-time PIN sent by Cloudflare Access. Neither the developer sharing the service nor the visitor accessing it needs a Cloudflare account to utilize this authentication method.

Addressing Security Concerns for Development Sharing

Quick Tunnels, launched in 2021, provide a way to expose local development environments to a public URL without requiring an account or domain. The primary security concern was that anyone with the link could access the service. This new authentication feature directly addresses that vulnerability, making it safer to share work-in-progress applications or sensitive information.

The adoption of Quick Tunnels has increased, partly due to AI agents using them to publish code or services they generate. The ability to restrict access is particularly relevant for these automated workflows, preventing unintended public exposure of development projects.

Impact on Developer Workflows

This update provides developers and AI agents with a more secure method for sharing local projects for testing or review. It maintains the simplicity of Quick Tunnels while adding a layer of access control, which is important for collaborative development and for scenarios where agents automatically publish content that might require restricted viewing.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cloudflare has updated its Quick Tunnels feature to include an accountless authentication option, allowing developers to restrict access to shared local services. This update addresses security concerns for sharing development projects, particularly with the rise of AI agents utilizing Quick Tunnels for publishing work.