Quick Tunnels Adds Email Authentication for Local Development
This simple mechanism replaces the need for complex authentication setups or shared passwords
Quick Tunnels, a tool that lets developers expose local servers to the internet, has introduced email authentication. The update, announced this week, allows users to restrict access to their tunnels by specifying approved email addresses. This change makes it easier to share work with teammates while keeping it secure. The new feature builds on the core idea that developers should be able to share their projects quickly and safely. By adding the —allowed-mail flag to the cloudflared command, you can list one or more email addresses that are permitted to connect through the tunnel. When a visitor opens the tunnel URL, they must provide a valid email that matches the list. If the address is not on the list, access is denied.
Breaking news:
This simple mechanism replaces the need for complex authentication setups or shared passwords. How the New Feature Works When you start a tunnel, you now include the flag like this: cloudflared tunnel —allowed-mail user@example.com. The tool then generates a unique URL that points to your local service. The email verification step is handled by Cloudflare’s authentication system, which sends a one‑time link to the user’s inbox. The user clicks the link, and the tunnel grants access. If the email is not on the list, the user receives a clear error message. This process is fully automated and requires no additional software on the developer’s machine. Because the verification happens on Cloudflare’s edge, the local server remains hidden behind a secure tunnel. The authentication data never touches the developer’s machine, reducing the risk of credential leakage.
The approach also scales: you can add or remove allowed emails on the fly by restarting the tunnel with a new list
The approach also scales: you can add or remove allowed emails on the fly by restarting the tunnel with a new list. This flexibility is ideal for teams that need to share prototypes or beta features with a small group of stakeholders. Will This Change My Workflow? Yes, but in a helpful way. Developers who previously shared tunnels with temporary passwords or shared secrets will now use email verification instead. The process requires only a single command line change, and the authentication flow is invisible to the end user. For teams that already use email for collaboration, this aligns with existing workflows and improves security. The update also enhances visibility. Cloudflare logs record which email addresses accessed the tunnel and when, giving developers insight into who is testing their work. This audit trail can be useful for compliance or debugging purposes.
The introduction of email authentication is part of a broader trend toward accountless, easy‑to‑use security for development tools. By eliminating the need for separate login portals, Quick Tunnels keeps the focus on coding while still protecting against unauthorized access. Developers can now share their work more confidently, knowing only the intended recipients can view it. Frequently Asked Questions Q: Can I use multiple email addresses with a single tunnel? A: Yes. Separate the addresses with commas when you run the command. The tunnel will accept any of the listed emails. Q: What happens if an email user does not receive the verification link? A: The user can request a new link by clicking the resend button on the verification page. If the issue persists, check the email address for typos. Q: Does this feature affect the tunnel’s performance? A: No.
The authentication check occurs at Cloudflare’s edge, adding negligible latency to the connection.
More stories: