Vibeleaderboard
← All Intel
Intel / blog

Protected Quick Tunnels: simple accountless authentication for your next dev project

Source
blog.cloudflare.com
Date
Key takeaways · AI-distilled
  • Cloudflare Access only proves the visitor controls the email address; cloudflared makes the allow or deny decision locally against the rules typed on the command line, so the guest list never leaves the developer's machine.
  • A stateless broker on Workers turns the Access identity into a short-lived signed assertion bound to the tunnel hostname and a single-use, 10-minute state, sent by form POST so it never lands in URLs, history or logs.
  • Visitor sessions last up to four hours, or less if the Access sign-in expires sooner, and end when cloudflared stops. cloudflared strips auth credentials before forwarding, so the local app needs no login code.
  • If the service does not confirm the authentication mode, cloudflared refuses to start instead of handing out a public URL, and a protected tunnel never falls back to public. Changing the means starting a new tunnel.
  • Cloudflare suggests adding the flag to an instructions file such as AGENTS.md, then checking cloudflared's output, which reports whether email auth is on and how many rules it holds without printing the addresses.
Terms in this piece · Glossary
  • AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
  • tool permissions — The rules governing which tools an agent may call and which need confirmation — the boundary between a mistake and an incident.
Why it matters

Coding agents often publish a local dev server through a Quick Tunnel, which anyone with the link could open. Adding --allowed-mail in cloudflared 2026.9.3 restricts access to chosen emails via one-time PIN, with no Cloudflare account needed.

Read the source blog.cloudflare.com
Recommended reads
Comments

Checking sign-in…

Loading comments…