AI NewsDev toolsAnnouncement

Cloudflare adds an email allow list to Quick Tunnels so an agent can share a preview with only the people you name

Cloudflare Quick Tunnels now take an --allowed-mail flag in cloudflared 2026.9.3 and in the latest wrangler, so a one-command preview URL only lets in the email addresses or domains you listed, and neither you nor the visitor needs a Cloudflare account.

AI News

Editorial2 min read

LinkedInX
Cloudflare blog social card for Protected Quick Tunnels

Image: Cloudflare

Why it mattersAn agent that shares a local dev server with the whole internet is now one flag away from sharing it only with you, which is the step most review workflows skipped because adding an account felt heavier than the preview itself.

A coding agent that finishes a feature and offers to let you try it on your phone has one short way to do it: run cloudflared tunnel --url http://localhost:5173 and hand over the trycloudflare.com link it prints. Nothing was wrong with the link except that anyone could open it. Cloudflare announced a change today that lets the same one-line command issue a URL only the people you name can reach, without either side signing in to Cloudflare.

Starting with cloudflared version 2026.9.3, the command takes a repeatable --allowed-mail flag that holds either an exact address or a wildcard such as *@example.com. A visitor arrives at the URL, enters their email address, types in the one-time PIN that Cloudflare Access sends to that inbox, and reaches the local app. Anyone whose address is not on the list is stopped before the request leaves Cloudflare. Cloudflare says the same flag works from the latest wrangler as npx wrangler tunnel quick-start --allowed-mail.

The guest list stays on your machine

Cloudflare describes a design where the authentication half of the job runs on its own infrastructure and the authorization half runs on yours. Cloudflare Access verifies that a visitor controls an email address. A short-lived signed assertion is handed to cloudflared, which checks the address against the rules you typed and decides whether to let the request through. Cloudflare says it learns that a tunnel requires email authentication, but never learns who was invited.

The reasoning Cloudflare gives for that split is that Quick Tunnels have no account, so there is no obvious place for a central policy to live. Keeping the list in the connector on the developer's machine avoids a per-request lookup, keeps the rules out of Cloudflare's view and lets a public Quick Tunnel keep working exactly as before when the flag is omitted.

Agents were the forcing function

Cloudflare says Quick Tunnels have grown faster since coding agents picked them up as a default way to share whatever they just finished. On 18 September 2026, Cloudflare says a link to the Quick Tunnels documentation reached the top of Hacker News and gathered more than 800 points and 300 comments, with one commenter asking how long until an agent sets up a tunnel exposing something embarrassing. The company presents this release as its answer.

To make the flag the default for a coding agent, Cloudflare suggests adding one sentence to the AGENTS.md file the agent reads, and checking what the agent ran afterwards: cloudflared prints whether a tunnel uses email authentication and how many rules it holds, but will not print the addresses themselves.

For a team that already uses Cloudflare Access with an identity provider, the full product is still the right tool and this is not a replacement for it. For a developer who wants to share a port with one person without opening a dashboard, the single flag is the whole fix.

Source

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX