Cloudflare Protected Quick Tunnels: share localhost with a guest list
Cloudflare Protected Quick Tunnels add an --allowed-mail flag to cloudflared 2026.9.3. Share a local app by URL, but only verified emails get in. Free.
The fastest way to show a client a half-built app just stopped being public. Cloudflare Protected Quick Tunnels, announced October 2, add one flag to cloudflared that limits a throwaway trycloudflare.com URL to email addresses you name. No Cloudflare account on either side. Free.
What actually happened
Quick Tunnels have always worked like this: run cloudflared tunnel --url http://localhost:8080 and you get a random public URL pointing at your laptop. Anyone with the link gets in. Per Cloudflare's announcement, cloudflared 2026.9.3 adds --allowed-mail:
cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com
Repeat the flag for more people, or use a domain wildcard like '*@example.com'. A visitor enters their email, gets a one-time PIN, types it in, and is in. Cloudflare Access verifies the address; cloudflared checks it against your list locally, so Cloudflare says the guest list never leaves your machine. Sessions last up to four hours or until you stop the tunnel.
Why it matters for your business
We demo work in progress constantly. A new checkout flow, an internal dashboard, a webhook handler a vendor needs to hit. The honest options used to be a public URL and a prayer, a staging deploy that takes longer than the demo, or an account-backed tunnel with real config.
A random URL is not access control. Links get forwarded, pasted into Slack, and saved in browser history. A dev build often holds seed data copied from production and an admin route with no login. Gating it by verified email closes that hole for the cost of one flag.
Wildcards match how clients work. '*@clientco.com' lets their whole team review without you collecting names, and nobody else gets in.
Know what it isn't. Four-hour sessions and a laptop-bound tunnel make this a demo tool, not hosting. Anything that needs to stay up, or that a webhook must reach without a human, still belongs on a real deploy.
Key takeaways
- cloudflared 2026.9.3 adds
--allowed-mailto Quick Tunnels, gating the URL to verified email addresses - Supports multiple addresses and domain wildcards like
'*@example.com' - Visitors verify with an emailed one-time PIN; neither side needs a Cloudflare account; free
- Sessions last up to four hours or until the tunnel stops: built for demos, not hosting
- Upgrade cloudflared and make the flag the default in your team's demo script
Want to see real progress, not screenshots? We show clients working builds every week, behind access controls, on their own data. See how we ship, or start a project.
Sources: Cloudflare blog: Protected Quick Tunnels.
- #cloudflare
- #cloudflared
- #quick-tunnels
- #client-demos
- #dev-tools
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Perplexity Decisions API: $0.04 per million, open weights too
Perplexity launched a Decisions API on pplx-decider-v1-27b at $0.04 per million input tokens, with Apache 2.0 weights. Price your ticket routing again.
Read itStrands Decider 2B: AWS open-sources a 115ms decision model
AWS Strands Labs open-sourced Strands Decider 2B, a decision model that picks from fixed options with a confidence score. Use it to route tickets and gate tool calls.
Read it