News

Cloudflare adds email-based protection to Quick Tunnels: enter --allowed-mail

From cloudflared 2026.9.3, Quick Tunnels can be restricted to chosen email addresses, with one-time PINs via Cloudflare Access, and no account required.

UptimeMag editorial team · 2 October 2026 · 2 min read

Cloudflare mette una password email ai Quick Tunnel: arriva --allowed-mail

Anyone who uses cloudflared tunnel --url to quickly showcase a local project already knows the problem: the link generated on trycloudflare.com is public, so anyone who finds it can open it. From cloudflared 2026.9.3 this changes, with an extra flag on the command line.

What --allowed-mail does

Starting with cloudflared 2026.9.3, you can add --allowed-mail to the command, and the Quick Tunnel will only let in the chosen email addresses and domains. Visitors prove they own one of those addresses with a one-time PIN sent by Cloudflare Access. Neither party needs a Cloudflare account.

The basic command, documented in the official changelog: cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com requires visitors to authenticate with a one-time PIN sent to their email before they can reach the local service.

For multiple people, you repeat the flag or use a comma-separated list; for an entire domain, a wildcard is enough: Multiple email addresses, by repeating the flag or using a comma-separated list: --allowed-mail 'alice@example.com,bob@example.com'. Every address on a domain: --allowed-mail '*@example.com'.

Without the flag, nothing changes: if --allowed-mail is omitted, public Quick Tunnels behave exactly as before. To revoke access, simply stop the process: access ends for everyone when the cloudflared process is stopped.

Where the address list lives

The interesting technical point for anyone who needs to trust this mechanism is that Cloudflare verifies the email, but it's the local machine that decides who gets in: a visitor opens the link, Cloudflare Access verifies their email with a one-time PIN, cloudflared on the local machine checks the address against the configured list, and only invited visitors reach the app. The list of authorised addresses is never sent to Cloudflare.

Also available via Wrangler and for AI agents

Those working on Workers can get the same behaviour via npx wrangler tunnel quick-start http://localhost:8080 --allowed-mail alice@example.com. The flag can also be added to instruction files read by coding agents, such as AGENTS.md, so that automatically shared previews stay protected.

Limitations to bear in mind

According to the official documentation, Quick Tunnels do not support Server-Sent Events (SSE), and email authentication requires an interactive browser session: it does not work with non-interactive clients. The feature is free, like Quick Tunnels themselves, and is available immediately by updating cloudflared to version 2026.9.3 or later.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50).