feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(backend,nextjs): Introduce machine authentication - #5689

Merged
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m
May 30, 2025
Merged

feat(backend,nextjs): Introduce machine authentication#5689
wobsoriano merged 60 commits into
mainfrom
rob/robo-36-sdk-m2m

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 22, 2025

Copy link
Copy Markdown
Member

Description

This PR adds machine authentication support by introducing support for 4 token types: api_key, oauth_token, machine_token, and session_token. To maintain backwards compatibility, session_token remains the default authentication method when no specific token type is specified. This ensures existing apps continue to work without modification while allowing new applications to opt-in to machine authentication methods through the acceptsToken option.

Key changes:

  • Deprecated SignedInState and SignedOutState in favor of AuthenticatedState and UnauthenticatedState to better represent both session and machine authentication states. They still return the same properties, with an added tokenType and isAuthenticated properties (deprecating isSignedIn).
  • The toAuth() method now returns a different value if the tokenType is not a session_token. For now, we landed on the id, name, subject, claims and scopes property for machine auth tokens.
  • Added two new internal functions in authenticateRequest: authenticateAnyRequestWithTokenInHeader and authenticateMachineRequestWithTokenInHeader to handle machine authentication.
  • The internal signedIn and signedOut functions have been updated to accommodate machine auth.
  • Added new error types and codes specific to machine token verification (MachineTokenVerificationErrorCode)
  • Added new APIs (APIKeysApi, IdPOAuthAccessTokenApi, and MachineTokensApi) used inside a new verifyMachineAuthToken function to validate tokens against their respective endpoints
  • Added test for various scenarios for token validation, handling different token types, token mismatch, and proper error responses when verification fails

Here's an example usage pattern with API key:

Say C1 wants to protect their endpoints in a Hono app:

import{serve}from'@hono/node-server'import{createMiddleware}from'hono/factory'import{Hono}from'hono'import{clerkClient}from'./client'import{HTTPException}from'hono/http-exception'constapp=newHono()constclerkMiddleware=createMiddleware(async(c,next)=>{constauthReq=awaitclerkClient.authenticateRequest(c.req.raw,{acceptsToken: 'api_key'})if(!authReq.isAuthenticated){thrownewHTTPException(401,{message: 'Unauthorized'})}awaitnext()})app.post('/api/protected',clerkMiddleware,async(c,next)=>{returnc.text('Hello from /api/protected')})

Then C2 can access it by passing the api_key:

constresp=awaitfetch('http://localhost:3000/api/protected',{method: 'POST',headers: {'Content-Type': 'application/json','Authorization': `Bearer ${process.env.API_KEY}`},})constdata=awaitresp.text()

P.S. I attempted to break this down into smaller PRs but the changes are tightly coupled 😞. So sorry and thank you in advance reviewer! I believe 30-40% of the total changes are from the test files.

Resolves ROBO-36

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercelBot commented Apr 22, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox⬜️ Skipped (Inspect)May 30, 2025 2:23pm

@changeset-bot

changeset-botBot commented Apr 22, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ca83aff

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMajor
@clerk/tanstack-react-startMinor
@clerk/agent-toolkitMinor
@clerk/react-routerMinor
@clerk/expressMinor
@clerk/fastifyMinor
@clerk/astroMinor
@clerk/remixMinor
@clerk/nuxtMinor
@clerk/nextjsMinor
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jescalanjescalan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great so far!

Comment threadpackages/backend/src/jwt/types.ts Outdated
});

it('returns false for tokens without a recognized prefix', () => {
expect(isMachineToken('unknown_prefix_token')).toBe(false);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wanna note that we do plan to allow custom prefixes in the future - likely these end up being prepended to the token type prefix so i think it should be a fairly straightforward change

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a note to cover this in the future.

});

// Test each token type with parameterized tests
const tokenTypes = ['api_key', 'oauth_token', 'machine_token'] as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm mildly confused by the typecasting here

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah the as const is needed here so TS knows these are literal types that match the keys in our mock objects, otherwise it would just see it as string[]

const { sessionTokenInHeader } = authenticateContext;
if (!sessionTokenInHeader) {
return handleError(new Error('No token in header'), 'header');
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Something seems weird about this logic...

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe in practice this shouldn't be hit, as we check the existence of the header token before calling this method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah either that or we remove and do non-null assertions

Comment threadpackages/backend/src/fixtures/machine.ts Fixed

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need a minor update for these packages since we changed the auth type from AuthObject to SignedInAuthObject | SignedOutAuthObject for backwards compat

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though this is a major update, the only public API that is breaking is AuthObject. Previously, it's a union of SignedInAuthObject | SignedOutAuthObject but now it's

exporttypeAuthObject=|SignedInAuthObject|SignedOutAuthObject|AuthenticatedMachineObject|UnauthenticatedMachineObject;

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250514155045
@clerk/astro2.8.0-snapshot.v20250514155045
@clerk/backend2.0.0-snapshot.v20250514155045
@clerk/chrome-extension2.4.4-snapshot.v20250514155045
@clerk/clerk-js5.65.1-snapshot.v20250514155045
@clerk/elements0.23.26-snapshot.v20250514155045
@clerk/clerk-expo2.11.4-snapshot.v20250514155045
@clerk/expo-passkeys0.3.3-snapshot.v20250514155045
@clerk/express1.5.0-snapshot.v20250514155045
@clerk/fastify2.3.0-snapshot.v20250514155045
@clerk/localizations3.15.3-snapshot.v20250514155045
@clerk/nextjs6.20.0-snapshot.v20250514155045
@clerk/nuxt1.7.0-snapshot.v20250514155045
@clerk/clerk-react5.31.3-snapshot.v20250514155045
@clerk/react-router1.5.0-snapshot.v20250514155045
@clerk/remix4.8.0-snapshot.v20250514155045
@clerk/shared3.8.3-snapshot.v20250514155045
@clerk/tanstack-react-start0.16.0-snapshot.v20250514155045
@clerk/testing1.7.0-snapshot.v20250514155045
@clerk/themes2.2.44-snapshot.v20250514155045
@clerk/types4.58.1-snapshot.v20250514155045
@clerk/vue1.8.1-snapshot.v20250514155045

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250514155045 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250514155045 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250514155045 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.4-snapshot.v20250514155045 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.65.1-snapshot.v20250514155045 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.26-snapshot.v20250514155045 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.4-snapshot.v20250514155045 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.3-snapshot.v20250514155045 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250514155045 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.15.3-snapshot.v20250514155045 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250514155045 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.3-snapshot.v20250514155045 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250514155045 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250514155045 --save-exact

@clerk/shared

npm i @clerk/shared@3.8.3-snapshot.v20250514155045 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250514155045 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.0-snapshot.v20250514155045 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.44-snapshot.v20250514155045 --save-exact

@clerk/types

npm i @clerk/types@4.58.1-snapshot.v20250514155045 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.1-snapshot.v20250514155045 --save-exact

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.1.0-snapshot.v20250515163910
@clerk/astro2.8.0-snapshot.v20250515163910
@clerk/backend2.0.0-snapshot.v20250515163910
@clerk/chrome-extension2.4.5-snapshot.v20250515163910
@clerk/clerk-js5.67.0-snapshot.v20250515163910
@clerk/elements0.23.27-snapshot.v20250515163910
@clerk/clerk-expo2.11.5-snapshot.v20250515163910
@clerk/expo-passkeys0.3.4-snapshot.v20250515163910
@clerk/express1.5.0-snapshot.v20250515163910
@clerk/fastify2.3.0-snapshot.v20250515163910
@clerk/localizations3.16.0-snapshot.v20250515163910
@clerk/nextjs6.20.0-snapshot.v20250515163910
@clerk/nuxt1.7.0-snapshot.v20250515163910
@clerk/clerk-react5.31.4-snapshot.v20250515163910
@clerk/react-router1.5.0-snapshot.v20250515163910
@clerk/remix4.8.0-snapshot.v20250515163910
@clerk/shared3.9.1-snapshot.v20250515163910
@clerk/tanstack-react-start0.16.0-snapshot.v20250515163910
@clerk/testing1.7.1-snapshot.v20250515163910
@clerk/themes2.2.45-snapshot.v20250515163910
@clerk/types4.59.0-snapshot.v20250515163910
@clerk/vue1.8.2-snapshot.v20250515163910

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.1.0-snapshot.v20250515163910 --save-exact

@clerk/astro

npm i @clerk/astro@2.8.0-snapshot.v20250515163910 --save-exact

@clerk/backend

npm i @clerk/backend@2.0.0-snapshot.v20250515163910 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.4.5-snapshot.v20250515163910 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.67.0-snapshot.v20250515163910 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.27-snapshot.v20250515163910 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.11.5-snapshot.v20250515163910 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.3.4-snapshot.v20250515163910 --save-exact

@clerk/express

npm i @clerk/express@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.3.0-snapshot.v20250515163910 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.16.0-snapshot.v20250515163910 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.20.0-snapshot.v20250515163910 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.7.0-snapshot.v20250515163910 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.31.4-snapshot.v20250515163910 --save-exact

@clerk/react-router

npm i @clerk/react-router@1.5.0-snapshot.v20250515163910 --save-exact

@clerk/remix

npm i @clerk/remix@4.8.0-snapshot.v20250515163910 --save-exact

@clerk/shared

npm i @clerk/shared@3.9.1-snapshot.v20250515163910 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.16.0-snapshot.v20250515163910 --save-exact

@clerk/testing

npm i @clerk/testing@1.7.1-snapshot.v20250515163910 --save-exact

@clerk/themes

npm i @clerk/themes@2.2.45-snapshot.v20250515163910 --save-exact

@clerk/types

npm i @clerk/types@4.59.0-snapshot.v20250515163910 --save-exact

@clerk/vue

npm i @clerk/vue@1.8.2-snapshot.v20250515163910 --save-exact

@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5689

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5689

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5689

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5689

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5689

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5689

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5689

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5689

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5689

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5689

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5689

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5689

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5689

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5689

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5689

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5689

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5689

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5689

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5689

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5689

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5689

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5689

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5689

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5689

commit: ca83aff

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!allow-major

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wobsoriano@clerk-cookie@jescalan@brkalow@LekoArts@github-advanced-security