Cloudflare Adds Accountless Email Auth to Quick Tunnels for Agent-Shared Links

Cloudflare Blog · rss · 2026-10-02

Cloudflare's Quick Tunnels have become the shortest path for developers — and increasingly coding agents — to expose a local service at a public trycloudflare.com URL, but anyone with the link could open it. Starting with cloudflared 2026.9.3, a new --allowed-mail flag restricts access to chosen emails or domains; visitors verify ownership via a one-time PIN from Cloudflare Access, with no account needed on either side.

Design: Access handles authentication (proving email control), while cloudflared on your machine makes the authorization decision against in-memory rules — your guest list never leaves your machine. Constraints included staying accountless, not touching public tunnel paths, avoiding central policy lookups per request, and protecting typed email addresses. Intermediate designs (per-tunnel Access apps, or a fully self-built flow) were rejected for scale or security reasons; a stateless broker on Workers issues short-lived signed handoffs.

Usage: add one line to AGENTS.md to make agent previews protected by default; --output lets agents parse the URL; the latest wrangler also supports the flag (including wildcard domains) and strips emails from debug logs. Quick Tunnel adoption has grown exponentially with agents; a related HN thread drew 800+ points.

Original post →

More from coding & agent

coding & agent channel →