Choose who can enter
Password, expiring-link, email-code, and IP policy are distinct controls with different recovery and audit requirements.
Route access
Access policy belongs to tunnel creation. A protected route must remain closed until its policy is committed and verified.
See how it worksPassword, expiring-link, email-code, and IP policy are distinct controls with different recovery and audit requirements.
A route cannot become externally reachable while its intended protection is absent, stale, or only partially written.
Generated tunnel traffic uses a separate registrable domain so it cannot inherit control-plane authentication cookies.