we_are_coded.by CODE · The world, decoded
БГ
Cloudflare

Cloudflare added an optional email lock to Quick Tunnels and gave agents web search through three partners

Cloudflare · event date: 2 October 2026Builders

From cloudflared 2026.9.3 the --allowed-mail flag lets only chosen emails or domains through a Quick Tunnel, with a one-time PIN from Cloudflare Access and no account for anyone. Without the flag the tunnel stays public. The same day brought Web Search API through AI Gateway: search for agents from Ceramic.ai, Exa and Linkup, at the partners' own prices, no markup.

In short
  • Quick Tunnels date from 2021. Without the flag nothing changes: the tunnel is public. With --allowed-mail only the emails and domains you wrote down get in.
  • The guest list stays on your machine. Per Cloudflare, the company learns only that the tunnel requires email login, not whom you invited. A session lasts up to four hours.
  • Web Search API: Ceramic.ai, Exa and Linkup through AI Gateway, over REST and a Workers binding. The partners have committed to obey robots.txt and to identify themselves. The price is the partner's, no markup.
Checked on5 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The agent has finished the feature and asks if you want to try it on your phone. It runs one command and hands you a link. Anyone can open it.

The facts: on 2 October 2026 Cloudflare published two things for agents. First, Protected Quick Tunnels. Quick Tunnels have existed since 2021: the command cloudflared tunnel --url publishes your local service at a random address on trycloudflare.com, with no account, no domain and no cost. From cloudflared 2026.9.3 you can add --allowed-mail and the tunnel lets in only the email addresses and domains you choose, including a wildcard for a whole domain; the visitor proves the address with a one-time PIN from Cloudflare Access and nobody on either side needs an account. Without the flag the tunnel stays public as before. To change the list you stop cloudflared and start a new tunnel; access ends for everyone when the process exits. For agents there is --output json. As Cloudflare describes it, the email check is done by Cloudflare Access, while the decision who gets in is made by cloudflared itself on your machine against the rules you typed; a small broker on Workers issues a signed assertion and never sees the list. A visitor's session lasts up to four hours. If the service does not confirm the protected mode, cloudflared refuses to start rather than give you a public address by mistake. It also works through wrangler: npx wrangler tunnel quick-start. The protection is free, like Quick Tunnels themselves, and was shipped by two interns, Hugo Vicente and Alessandro Frigerio. Second, Web Search API through AI Gateway, in beta according to Cloudflare's changelog: the company announced a partnership with web search providers, starting with Ceramic.ai, Exa and Linkup. Requests show up in the usual AI Gateway logs and draw down from the credits in it; Cloudflare offers search at the partners' list pricing with no markup and will mark the partners that support zero data retention. It works through a REST call, through a Workers binding (env.AI.websearch) and with your own key for the provider. The partners have committed that their crawler meets Cloudflare's requirements for Verified bots and that every response includes a link to the location of the crawled content. Built-in server tools in AI Gateway are announced as coming soon.

The post answers a Hacker News question. On 18 September a link to Quick Tunnels gathered more than 800 points there, and one commenter asked how long until someone's agent opens a tunnel to their most private things. Cloudflare's answer is one flag, but the flag is off by default. An agent that leaves the flag out opens a public tunnel, exactly as before.

Cloudflare suggests one line in AGENTS.md and itself adds that agents do not always follow instructions: look at what they ran. cloudflared prints whether a tunnel uses email protection and how many rules it holds, without printing the addresses.

The flag protects only when it is written.

The search is the quieter of the two, and it is still in beta. Cloudflare says agents usually guess the address and sometimes get a 404; a search engine is a better starting point. The bigger part is the condition on the partners: the crawler identifies itself, obeys robots.txt and says where it took the content from. That is useful to whoever's site gets crawled. The post does not describe how this is checked, and on price it says only that it is the partners' list price, without markup.

If your agent opens tunnels, add the line to AGENTS.md today and watch cloudflared's output: that is where you see whether the link is for you or for everyone.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cloudflare - Protected Quick Tunnels, 02.10.2026→Cloudflare - Introducing Web Search API via AI Gateway, 02.10.2026→Cloudflare - Changelog: Introducing Web Search API, 02.10.2026
Original: https://wearecoded.com/en/articles/cloudflare-quick-tunnels-web-search-agenti.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news