Cloudflare on Friday gave developers a way to lock down Quick Tunnels, its one-command shortcut for putting a local server on the open web, without creating an account, a domain name or a bill.

The new option is a flag, --allowed-mail, in version 2026.9.3 of cloudflared, the company’s connector software. Pass it an email address, repeat it for more addresses or point it at a whole domain, and only visitors who prove control of a matching address get through. The proof is a one-time PIN sent by Cloudflare Access. Nobody on either side needs a Cloudflare account.

Quick Tunnels appeared in 2021. One typed command, cloudflared tunnel --url http://localhost:5173, publishes a local service at a random trycloudflare.com address. The catch has always been the same: anyone who finds the link can open it.

What changed is who types the command. Coding agents that finish a feature need a place to show the result, and agents running Model Context Protocol servers need a public endpoint a hosted assistant can call. The company said adoption of Cloudflare Tunnel and Quick Tunnels has grown exponentially since agents took off; it had already found that machines passed people on the web in May. On Sept. 18, a link to the Quick Tunnels page reached the top of Hacker News, drawing more than 800 points and 300 comments, many of them catalogs of agent workflows. One user wrote that his AI had found Quick Tunnels on its own to publish a site it had built. Another called them “insanely helpful when doing agentic work on the go.”

The same thread carried the question the new release answers: “how long until someone’s agent sets up a tunnel for the world to see one’s most sensitive, private and embarrassing information or insecure work-in-progress app?”

A visitor to a protected URL lands on a Cloudflare Access sign-in page, enters an email address and types the PIN sent to that inbox. Cloudflare verifies only that the person controls the address. The admission decision happens on the developer’s own machine, where cloudflared checks the verified address against the typed rules. A mismatch returns a generic page that reveals nothing about the list.

Cloudflare said the hard part was deciding where the guest list should live when no account exists. Its answer is a small, stateless authentication broker running on Cloudflare Workers: it delivers a signed, short-lived handoff from Access to cloudflared but stores no policies, sessions or identity records. “Cloudflare learns that a tunnel requires email authentication,” the company’s post said. “It doesn’t learn who you invited.”

Sessions last up to four hours, less if the Access sign-in expires sooner, and end for everyone the moment cloudflared exits. Without the flag, nothing changes; public Quick Tunnels behave exactly as they always have.

Cloudflare is also pitching the flag as a default for agents. The company’s post suggests adding one line to the instructions file a coding agent reads, such as AGENTS.md, telling it to always pass the owner’s address. Because agents do not always follow instructions, cloudflared prints whether a tunnel uses email authentication and how many rules it holds, without printing the addresses. The same option works through the Workers command-line tool with npx wrangler tunnel quick-start, which strips the addresses from its debug logs.

For a stable hostname or rules tied to identity provider groups, Cloudflare points developers to its full Tunnel product paired with Access. For reaching an agent at home from one’s own devices with no public URL at all, it offers a newer tool called Cloudflare Mesh.