You can now restrict who can access a Quick Tunnel. Use the new --allowed-mail flag in cloudflared to require visitors to authenticate with a one-time PIN sent to their email before they reach your local service.
cloudflared tunnel --url http://localhost:8080 --allowed-mail [email protected]

Previously, anyone with a trycloudflare.com URL could access the service behind it. Protected Quick Tunnels let you share a local development server, webhook receiver, or demo with specific people without creating a Cloudflare account or configuring a domain.
You can allow:
- A single email address:
--allowed-mail [email protected] - Multiple email addresses, by repeating the flag or using a comma-separated list:
--allowed-mail '[email protected],[email protected]' - Every address on a domain:
--allowed-mail '*@example.com'
Visitors do not need a Cloudflare account. Access ends for everyone when you stop the cloudflared process.
To get started, update cloudflared to the latest version and refer to Restrict access by email.
Source: Cloudflare


