Cloudflare's Quick Tunnels can now be locked to an email
A single flag on cloudflared now lets developers, and the coding agents working for them, restrict a public Quick Tunnel to chosen email addresses, checked with a one-time PIN and no Cloudflare account.

Cloudflare has given its Quick Tunnels an access control, so the free feature that publishes a service running on a developer's machine at a random public URL no longer has to be open to anyone holding the link.
One flag, one-time PIN
From cloudflared 2026.9.3, the command can take --allowed-mail, which limits a tunnel to the email addresses and domains you name. A visitor proves they own an allowed address with a one-time PIN issued through Cloudflare Access. Cloudflare says neither side needs an account: the person running the tunnel still does not create a DNS record, write a configuration file or open a dashboard.
The flag can be repeated for individuals or opened up to a whole domain, so an allowed list can read alice@example.com, bob@example.com and then *@example.com. Leave it out, Cloudflare notes, and public Quick Tunnels behave exactly as they have since 2021.
Built for agents as much as people
Cloudflare says coding agents have made Quick Tunnels more popular than ever. An agent that has just finished a feature needs somewhere to show the result, a machine at home needs to be reachable from a phone, and a Model Context Protocol server on a laptop needs a public endpoint before a hosted assistant can call it. A tunnel produces that URL from a single command, with no sign-up form for an agent to get stuck on, and a --output json mode turns every log line into an object so the agent can lift the URL out without scraping text. Cloudflare points to a Hacker News thread on 18 September 2026 that climbed past 800 points and 300 comments, and says adoption has grown exponentially since agents took off.
What changes, and what does not
Access ends for everyone the moment the cloudflared process exits, and changing who is allowed means stopping the tunnel and starting a new one. For a stable hostname or richer rules, such as identity provider groups, Cloudflare points to Tunnel paired with Access; for reaching a home agent with no public URL at all, it points to Cloudflare Mesh.
Our opinion
Quick Tunnels have always been a small, unglamorous feature, and the way agents found them says something about how software is now built: the tool that wins is the one an agent can run without asking a human to fill in a form. Adding protection through a single flag, rather than a dashboard and a setup step, is the right shape for that audience, because it is cheap enough for an agent to remember and to document in a file like AGENTS.md. The honest catch is that protection here is a habit, not a guarantee — this is a shareable link to a laptop, it disappears with the process, and it is not a substitute for a real tunnel when something has to stay up.