cloudflared quick tunnels, wrapped in a small PowerShell script (run-tunnel.ps1) that starts the local server, opens the tunnel, and prints the URL.
Browsers only grant microphone access over a secure context — a trusted HTTPS certificate, not a bare local IP. Tailscale solved that, but it needs an account, a device enrolled, and DNS configured on every machine before a phone can reach it.
A Cloudflare quick tunnel needs no account and no DNS. One command forwards a local port to a live, browser-trusted *.trycloudflare.com HTTPS URL in seconds. Folding the UI and WebSocket onto one port means one tunnel covers the whole app.
The URL is ephemeral and unauthenticated by design — anyone holding the link can reach the local server until you close it. That's the right trade for a 10-minute phone demo, and the wrong one for anything persistent or sensitive. Pick per job: quick tunnel for throwaway, Tailscale for a stable private mesh with access control.