Skip to content
Rush Commerce
Tools & Teardowns2 min read

Cloudflare Protected Quick Tunnels: share localhost with a guest list

Cloudflare Protected Quick Tunnels add an --allowed-mail flag to cloudflared 2026.9.3. Share a local app by URL, but only verified emails get in. Free.

The fastest way to show a client a half-built app just stopped being public. Cloudflare Protected Quick Tunnels, announced October 2, add one flag to cloudflared that limits a throwaway trycloudflare.com URL to email addresses you name. No Cloudflare account on either side. Free.

What actually happened

Quick Tunnels have always worked like this: run cloudflared tunnel --url http://localhost:8080 and you get a random public URL pointing at your laptop. Anyone with the link gets in. Per Cloudflare's announcement, cloudflared 2026.9.3 adds --allowed-mail:

cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com

Repeat the flag for more people, or use a domain wildcard like '*@example.com'. A visitor enters their email, gets a one-time PIN, types it in, and is in. Cloudflare Access verifies the address; cloudflared checks it against your list locally, so Cloudflare says the guest list never leaves your machine. Sessions last up to four hours or until you stop the tunnel.

Why it matters for your business

We demo work in progress constantly. A new checkout flow, an internal dashboard, a webhook handler a vendor needs to hit. The honest options used to be a public URL and a prayer, a staging deploy that takes longer than the demo, or an account-backed tunnel with real config.

A random URL is not access control. Links get forwarded, pasted into Slack, and saved in browser history. A dev build often holds seed data copied from production and an admin route with no login. Gating it by verified email closes that hole for the cost of one flag.

Wildcards match how clients work. '*@clientco.com' lets their whole team review without you collecting names, and nobody else gets in.

Know what it isn't. Four-hour sessions and a laptop-bound tunnel make this a demo tool, not hosting. Anything that needs to stay up, or that a webhook must reach without a human, still belongs on a real deploy.

Key takeaways

  • cloudflared 2026.9.3 adds --allowed-mail to Quick Tunnels, gating the URL to verified email addresses
  • Supports multiple addresses and domain wildcards like '*@example.com'
  • Visitors verify with an emailed one-time PIN; neither side needs a Cloudflare account; free
  • Sessions last up to four hours or until the tunnel stops: built for demos, not hosting
  • Upgrade cloudflared and make the flag the default in your team's demo script

Want to see real progress, not screenshots? We show clients working builds every week, behind access controls, on their own data. See how we ship, or start a project.

Sources: Cloudflare blog: Protected Quick Tunnels.

  • #cloudflare
  • #cloudflared
  • #quick-tunnels
  • #client-demos
  • #dev-tools
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.