Build1 publisher2 min readPublished
Cloudflare's cloudflared 2026.9.3 adds optional one-time-PIN email gating for Quick Tunnel links
Cloudflare's cloudflared 2026.9.3 adds an --allowed-mail flag that limits a Quick Tunnel to approved email addresses via a one-time PIN. Public stays the default, so the safeguard works only if whoever starts the tunnel, increasingly a coding agent, adds the flag.
The Engineer · Build desk

What happened
- Several people can be admitted by repeating the flag, or a whole domain with a wildcard entry such as '*@example.com'.
- The list is fixed for the life of the process: changing it means stopping cloudflared and starting a new tunnel, and access ends when the process exits.
- Cloudflare suggests one line in an agent's AGENTS.md file telling it to always add --allowed-mail with the user's own address when starting a Quick Tunnel.
- The latest Wrangler starts the same protected tunnel with 'wrangler tunnel quick-start' and strips --allowed-mail values from its debug logs.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Adding or removing a tester mid-session costs a restart, and because each Quick Tunnel gets a random URL, probably a fresh link to send round.
- exposure A wildcard such as '*@example.com' admits anyone who can read a PIN at that domain, so the rule is only as narrow as the domain's mailbox list.
- decision Previews that need a stable hostname or identity-provider groups still have to move to Cloudflare Tunnel with Access; the flag fits disposable links.
Cloudflare describes how the work is split in two lines: "Cloudflare verifies the email. Your machine decides who gets in." [19] The company also says outsiders are stopped before a request reaches the developer's machine [6]. Taken together, the rules come from the local cloudflared process and are enforced upstream, before traffic crosses the tunnel [4]. In my view that is the right lifetime for a preview link. Nothing outlives the process, so there is no grant to revoke a week later [9].
The tooling also keeps the list itself out of view. cloudflared reports whether a tunnel uses email authentication and how many rules it holds, without printing the addresses [13]. Teammates' addresses stay out of terminal scrollback and out of any agent transcript that records it [13].
The weak link is compliance. The AGENTS.md line only helps if the agent obeys it. The post concedes this in an unusually candid line for a launch post: "Agents don't always follow instructions." It tells users to check what the agent ran [12].
Checking by eye suits a person at a terminal. An agent opening tunnels unattended needs a mechanical check. With --output json, every cloudflared log line is a JSON object, so an agent can pick out the URL without scraping text [15]. The email-authentication status should arrive in that same stream [13]. A wrapper that already parses out the URL can then refuse to hand over a link from an unprotected tunnel [5].
Cloudflare says Tunnel and Quick Tunnels adoption has grown exponentially since agents took off, though the post does not include a figure [18]. On September 18, 2026, a link to the Quick Tunnels page reached the top of Hacker News with more than 800 points and 300 comments, the company wrote [16]. One commenter in that thread asked: "how long until someone's agent sets up a tunnel for the world to see one's most sensitive, private and embarrassing information or insecure work-in-progress app?" [17]
What to watch
- Whether cloudflared or Wrangler add a way to make --allowed-mail the default for every Quick Tunnel, so an agent cannot forget it.
- Whether agent tools that already start Quick Tunnels pass the flag by themselves and check the email-authentication status before sharing a link.