Cloudflare adds email checks to temporary developer tunnels
Cloudflare introduced Protected Quick Tunnels for developers sharing local applications over the Internet. Allowed visitors verify their email address with a one-time code, without creating a Cloudflare account. The allowed-address list stays on the developer's device. Sessions last at most four hours and end when the tunnel stops; changing the list requires a new tunnel.
Artificial Intelligence··Morning
An email code guards temporary previews
Cloudflare introduced Protected Quick Tunnels for developers exposing a local application to the Internet through a temporary address. They can choose allowed email addresses or domains. Visitors verify ownership of their email with a one-time code, and neither the developer nor the visitor needs a Cloudflare account.[1], [2]
The guest list stays on the developer's device
The allowed-mail option is available in cloudflared 2026.9.3, Cloudflare's connector for publishing local services. Without the option, a Quick Tunnel remains open to anyone with its URL. Changing the list requires stopping the process and creating a new tunnel. The list stays in the developer's process memory.[1]
Cloudflare Access authenticates the email address. A Worker relays short-lived, signed authentication data; the local connector then checks the visitor against the list. The assertion is tied to the tunnel hostname and a single-use browser state.[1]
Sessions end with the tunnel process
The browser state is valid for ten minutes. A session lasts at most four hours, ending sooner if the Access session expires or the tunnel stops. Authentication data travels in a POST request and is removed before reaching the local application. If the protected authentication mode cannot be confirmed, the tunnel closes access rather than becoming public.[1]