- Cloudflare's cloudflared 2026.9.3 lets Quick Tunnels admit only chosen email addresses through the --allowed-mail flag. Without the flag, tunnels stay public.
- Coding agents can start tunnels on their own, so a public default becomes a decision nobody made. A safe option is not a safe default.
- Ask teams where agents use tunnels, whether cloudflared is current, and whether anyone checks the tool's output for email protection.
A coding agent finishes a feature and offers to show it on your phone. With a single command, it starts a tunnel and gives you a web address. Nobody decided who else may open that address. That small moment carries the argument of this story: when software acts for you, the default setting becomes your decision.
What Cloudflare changed
Cloudflare launched Quick Tunnels in 2021. The cloudflared connector publishes a service running on your own machine at a random trycloudflare.com address. It needs no account, no domain and no cost. Until now, as Cloudflare puts it, anyone with the link could open it.
Starting with cloudflared 2026.9.3, a developer can add a flag, --allowed-mail, followed by an email address or a whole domain. Visitors enter their address and then a one-time PIN that Cloudflare Access sends to that inbox. Everyone else is stopped before a request reaches the developer's machine. Cloudflare says the feature is free.
There is a catch. If the flag is left out, Cloudflare says public tunnels behave exactly as before. The protection exists, but it is opt-in.
How agents changed who creates links
Cloudflare says Tunnel and Quick Tunnels adoption has grown exponentially since agents took off, but gives no figures. It does point to one public signal. A link to the Quick Tunnels page reached the top of Hacker News on September 18, 2026, with more than 800 points and 300 comments.
One commenter asked how long until someone's agent publishes sensitive or insecure work for the world to see. Cloudflare quotes the question and wrote its post as the answer. The worry fits the mechanism. A tunnel needs no signup form, so an agent can create one alone. The same ease that helps the developer removes the pause where a person would ask who should see this.
This is one vendor's fix for one tool. It is not proof of a wider pattern. But it shows where risk sits when agents act. The risk here is not a clever exploit. It is a convenient shortcut taken at machine speed, with a public default.
How the design keeps the guest list private
Cloudflare separates two questions. Authentication asks whether the visitor controls an email address. Authorization asks whether that person is welcome. Cloudflare Access answers the first. The developer's own machine answers the second.
A Quick Tunnel has no Cloudflare account to hold a guest list. Cloudflare considered placing an Access application in front of every tunnel. It dropped the idea because hundreds of thousands of tunnels can run at once, many for minutes. It also declined to build the whole email login itself. Email delivery, abuse control and session handling are hard to run safely.
The chosen path has four steps. First, a visitor arrives without a session, and cloudflared redirects them to a Cloudflare sign-in address. The redirect carries a random one-use token that expires after 10 minutes. Second, Access emails the PIN and verifies it. Third, a small stateless broker on Cloudflare Workers returns a short-lived signed assertion tied to that tunnel. Fourth, cloudflared checks the assertion and compares the email with the rules typed on the command line.
As a result, Cloudflare says, it learns that a tunnel requires email sign-in but not who was invited. A signed-in visitor gets a session of up to four hours, or until cloudflared stops. If a check fails, the request does not reach the local service. Cloudflare also says cloudflared refuses to start if the service does not confirm the authentication mode. A protected tunnel therefore does not quietly turn public.
A safe option is not a safe default
Cloudflare made the safe choice one flag away. It did not make it the starting point. Someone must still choose the flag, and someone must confirm it was used.
Cloudflare itself suggests a reminder: one line in the instructions file an agent reads, such as AGENTS.md, so previews open only for you. Then it adds a caution. Agents do not always follow instructions. The check it offers is the tool's own output, which states whether email protection is on and how many rules are loaded. The addresses stay hidden.
Questions to put to your engineering team:
Do our developers and agents use Quick Tunnels or similar tools, and on which machines? Is cloudflared at 2026.9.3 or later where they do? Do agent instruction files require the email flag, and does anyone read the output? Where a hosted assistant must reach a tunnelled service, how will it authenticate? Cloudflare says the sign-in page assumes a person at a browser. The post does not explain how automated clients fit, so ask.
Note the limits too. Access ends when the process exits, and changing who can get in means starting a new tunnel. For a stable hostname or group-based rules, Cloudflare points to Cloudflare Tunnel with Access.
When an agent can open a door with one command, someone has to decide who walks through. A lock that exists is not a lock that was fitted. Until the default changes, a person has to choose it and check it.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cloudflare.





