Protected Quick Tunnels: simple accountless authentication for your next dev project
Curated from Cloudflare Blog
Most developers default to exposing local services via raw IP or insecure tunnels when testing in production-like environments. This update addresses a specific operational gap: secure access without the friction of provisioning accounts or managing complex identity providers. By leveraging email-based allowlists directly within the tunneling agent, you can enforce strict access controls on ephemeral dev setups instantly. This is particularly useful for shared team environments where trust models are informal but security requirements remain non-negotiable. The lack of dependency on a central identity broker reduces configuration drift and setup time. For working practitioners, the key takeaway is to treat local tunneling as a security boundary, not just a connectivity tool; implementing email-based restrictions now prevents accidental exposure of sensitive development endpoints to the public internet.
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
— Cloudflare Blog