SNACK: 3-line summary
- Cloudflare has added optional email PIN access to Quick Tunnels, letting you restrict local preview links to chosen email addresses.
- Email protection is free with cloudflared 2026.9.3 or later, with no Cloudflare account or domain required.
- Sign-in requires an interactive browser, and Quick Tunnels remains a tool for testing and development—not production traffic.
Cloudflare’s new Protected Quick Tunnels lets you share a local app preview with chosen testers, who sign in using an emailed PIN. You enable the restriction with –allowed-mail; neither you nor your visitors need to create a Cloudflare account.

Snackgirls react
Red: I’d like to try an unfinished game’s menus on my phone without opening the preview to everyone with the link.
Nea: For an early prototype, I’d pick a few people whose feedback I trust. A whole email domain feels like too many voices at that stage.
Who can open the preview?
Quick Tunnels gives a local HTTP service a temporary, random trycloudflare.com address. Without –allowed-mail , anyone with that URL can open it. Adding the flag restricts access to the email addresses or email domains you specify.
Visitors enter their email address on the Cloudflare Access sign-in page, then type in the one-time PIN sent to their inbox. An address outside your allowed list cannot reach the local app. If a check fails, the protected tunnel does not fall back to public access.

Set up a link for your testers
Install or update cloudflared to version 2026.9.3 or later, and start your local HTTP server. For a service running at http://localhost:8080 , use:
cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com
Replace the placeholder alice@example.com with your tester’s email address. Repeat –allowed-mail to add more individuals. To allow every address at a domain, use –allowed-mail ‘*@example.com’ ; the quotes prevent shell expansion.
To change the allowed visitors, stop cloudflared and start a new Quick Tunnel. Stopping the process ends access for everyone, and each new tunnel gets a different hostname.
Your machine keeps the guest list
Cloudflare Access verifies that a visitor controls the email address they enter. On your machine, cloudflared checks that verified address against an allowlist held in process memory and decides whether to let the request through.
Cloudflare does not receive the list of email addresses you invited. Access does process the visitor’s email during sign-in, however: keeping the guest list local does not mean Cloudflare never sees an email address.
Keep it for browser-based testing
Email authentication requires an interactive browser session and does not support non-interactive clients. An unattended AI tool, MCP client or webhook cannot use this email PIN sign-in flow.
Quick Tunnels has no uptime guarantee and does not support Server-Sent Events (SSE). Each tunnel supports up to 200 concurrent in-flight requests; additional requests receive HTTP 429. This is a limit on requests still being handled, not a daily allowance or a user count.
For production traffic or a stable hostname, Cloudflare points to an account-based Cloudflare Tunnel with Cloudflare Access. The temporary link is intended for testing and development.
Sources and checked date: October 3, 2026
