A temporary preview URL is still an access decision. Cloudflare now lets you restrict a Quick Tunnel to invited email addresses without setting up an account.
Invite a reviewer without making the preview public
Cloudflare announced protected Quick Tunnels on October 2. With cloudflared 2026.9.3 or later, --allowed-mail it restricts access to selected email addresses. An invited visitor signs in with an emailed one-time PIN. Neither person needs a Cloudflare account.
A basic Quick Tunnel remains public if you omit the flag. Protection is an explicit launch choice, not a new default that secures existing preview commands.
Start with one named reviewer.
After starting your local HTTP service, adapt this documented command to its port and the reviewer’s real email address:
cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com
The Quick Tunnels documentation also supports repeated flags for several visitors and quoted domain wildcards. Prefer named addresses for an initial review. Allowing a whole domain broadens the invitation to everyone with an address there.
Test the denied path before sharing.
- Use a preview dataset without production credentials or customer records.
- Inspect the exact command and terminal output. Confirm the intended address is in the allowlist.
- Open a fresh browser session as the invited reviewer and complete the PIN flow.
- Use a separate fresh session with an uninvited address. Confirm it cannot reach the application.
- Stop the process when the review ends and confirm the preview is no longer reachable.
These are recommended checks; we have not run them against your local service. A successful login test covers only the allowed path. Testing rejection confirms that the invitation boundary behaves as intended.
Browser previews are not unattended agent credentials
Email authentication needs an interactive browser and does not support non-interactive clients. Quick Tunnels also lack an uptime guarantee and Server-Sent Events support. Those limits matter before you use one for a streaming application or an unattended MCP connection.
Stopping cloudflared ends access. Changing the allowlist requires a restart with a new temporary hostname. Use a production Tunnel when you need stable hosting; do not make a temporary review link part of a durable integration.
An instruction telling an AI agent to keep a preview private is useful, but it cannot replace access control. The effective command and denied-path test are the evidence. Our production AI controls guide and private MCP guide cover related boundaries for longer-lived systems.
Checked October 3, 2026, against Cloudflare’s announcement and documentation. The verification checklist is MustHave.ai guidance, not a live test report.