Cloudflare Zero Trust and Tunnels on your phone.
See who can reach your internal tools, which devices are enrolled and where each tunnel sends its traffic. Put a hostname behind Access with a swipe.
plan Zero Trust and Tunnels are part of Clouder Pro.
Tunnel info
Ingress rules
http://localhost:3000
http://localhost:8080
http://localhost:8081
http_status:404
Swipe a hostname to protect it with Cloudflare Access.
The admin side, not the client
Clouder works on the admin side of Cloudflare Zero Trust. It shows the devices your team enrolled and the posture rules they have to meet, and it manages Access applications, Gateway rules and tunnels. It is not the device client people install to connect through Zero Trust; that is Cloudflare's WARP client.
Tunnels and routes
Cloudflare Tunnel connects a server to Cloudflare through the cloudflared connector, without opening inbound ports. In Clouder you can create a tunnel, manage its routes and handle the token a connector uses to join it.
Each tunnel lists its public hostnames and routes, so you can check which services it publishes and which private ranges it carries without opening a terminal on the server.
Whatever you create in Clouder is created in your Cloudflare account through the Cloudflare API, so a tunnel you set up on your phone is there in the dashboard when you sit down at a laptop.
Put a hostname behind Access
Swipe a tunnel's public hostname to put it behind Cloudflare Access, then choose who may open it: individual email addresses, or everyone at a domain. Protected hostnames carry a lock, so you can tell which services are still open to the internet without opening each one.
From then on, Cloudflare asks visitors to prove who they are before a request reaches the tunnel, and anyone not on the list never gets as far as your server.
Added in Clouder 3.2.10 for iPhone and iPad, released on September 30, 2026.
Access applications and Gateway rules
Your Access applications sit next to the Gateway rules that filter your team's traffic. When someone asks why a site is blocked or why an internal app keeps asking them to sign in, the answer is usually in one of these two lists.
Devices and posture
Connected devices and posture policies show which machines are enrolled and which checks your policies require. When an application depends on a posture check, this is the first place to look if someone suddenly cannot reach it.
What your token needs
If you sign in with an API token you created yourself, it needs the Zero Trust and Cloudflare Tunnel permissions for these screens. The token permissions checklist in Clouder shows whether your token reaches them and what to add. The security page explains how Clouder signs in and which tokens it uses.
When a phone is the right tool
A teammate messages that they cannot open the wiki. From your phone you can check whether the hostname sits behind Access and for whom, whether their device is enrolled, and whether the hostname is still on the tunnel.
Or you have just put a new internal tool on a tunnel and want it locked before anyone shares the link. Swipe its hostname behind Access, limit it to your company's domain, and it is protected before you are back at your desk.
Free and Pro
Zero Trust and Tunnels are Clouder Pro features, on iPhone, iPad and Android. On the free tier, Clouder shows your zones, DNS, Workers and Pages read-only. Compare Free and Pro for the full list.