Connections

Connect with Cloudflare Tunnel

Install cloudflared, create a named Cloudflare Tunnel, route a hostname to RepoTunnel’s local origin, and verify the managed connection.

Guides follow the current project source. Check the release notes for your installed version.

What this setup needs

The built-in Cloudflare provider uses a named tunnel, a tunnel token and a public hostname. RepoTunnel runs the local cloudflared worker and forwards to its reserved loopback origin.

  • A Cloudflare account and a domain managed through Cloudflare for the published hostname.
  • cloudflared installed on the same computer as RepoTunnel.
  • Permission to create a tunnel and publish its hostname.
  • RepoTunnel running with an approved project.

1 Install cloudflared

Open Cloudflare’s downloads page, select the correct operating system and CPU architecture, and follow its installation instructions. Install the executable on the computer where RepoTunnel runs.

Return to Connect, select Cloudflare and check for cloudflared detected on this computer. If detection still fails, check the installation location and restart RepoTunnel so it sees the updated environment.

Code
cloudflared --version

2 Create a named tunnel

In the current Cloudflare dashboard, open Networking, then Tunnels. Create a tunnel with a recognizable name such as repotunnel-desktop. Select the computer’s operating system and architecture under Setup Environment.

The dashboard’s connector instructions include the tunnel credential. Copy the token value from the installation/run command into RepoTunnel’s Cloudflare Tunnel token field. Use RepoTunnel to manage this connection’s worker after installing the executable.

  1. Open the Cloudflare dashboard and select the correct account.
  2. Go to Networking → Tunnels and choose Create Tunnel.
  3. Name the tunnel and create it.
  4. Find the tunnel token in the connector’s Install and Run instructions.
  5. Keep that token in the local app’s credential field; treat it as a secret.

3 Publish the localhost origin

Select the named tunnel, open Routes and choose Add route, then Published application. Pick a subdomain under a domain you administer.

Set Service URL to the HTTP localhost origin reported by RepoTunnel. The current reserved Cloudflare origin is port 43182. This service runs on the same computer as cloudflared; do not use the website preview port, a public hostname, or an arbitrary project development server.

Leave the optional Path field empty to forward all of RepoTunnel’s routes, then save the published route. The HTTP hop here is local to the computer; the client-facing hostname uses HTTPS through Cloudflare.

Code
http://localhost:43182
Cloudflare published application dialog with hostname and Service URL fields

Cloudflare’s official tutorial shows Routes → Add route → Published application. Its sample service and path are examples; for RepoTunnel use the localhost origin shown in Connect and leave Path empty. Screenshot from the public tutorial at 2:30, © Cloudflare.

4 Connect from RepoTunnel

  1. Open Connect and select Cloudflare.
  2. Paste only the named tunnel’s token into Cloudflare Tunnel token.
  3. Enter the public hostname as an HTTPS origin: https://YOUR_PUBLIC_HOST, replacing YOUR_PUBLIC_HOST with your published hostname. Do not include /mcp in this field.
  4. Choose Set up & connect and wait for the local gateway and public provider to become ready.
  5. Copy RepoTunnel’s displayed MCP endpoint for your AI client.

5 Verify and authorize

Check the named tunnel’s status in Cloudflare and the provider’s readiness in RepoTunnel. Open the hostname’s /health route, then finish RepoTunnel OAuth and request an approved workspace from the intended AI client.

Cloudflare routing and RepoTunnel project permissions are separate boundaries. A successful tunnel does not grant more file, terminal or device access.

Code
curl -i https://YOUR_PUBLIC_HOST/health
Note

Replace YOUR_PUBLIC_HOST with the hostname you published in Cloudflare.

Use a named tunnel for this provider

Cloudflare Quick Tunnels create temporary trycloudflare.com addresses. They are a testing path and differ from RepoTunnel’s configured named-tunnel flow.

Cloudflare documents changing hostnames, limited concurrent requests and no Server-Sent Events support for Quick Tunnels. Follow the named tunnel and stable hostname setup above for this managed provider.

Troubleshoot the failing layer

  • cloudflared not detected: verify the executable’s installation and restart the app after environment changes.
  • Tunnel disconnected: inspect the connector status, tunnel token and outbound network access using Cloudflare’s troubleshooting guide.
  • Origin unreachable or 502: check the Service URL, same-machine localhost origin and RepoTunnel gateway status.
  • Unexpected login page: inspect whether an additional Cloudflare Access browser policy is protecting this hostname and whether the MCP client supports it.
  • Health works but tools fail: verify OAuth discovery, authorization and the exact /mcp endpoint.
Start typing to search.