Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(backend,nextjs): Add support for M2M JWT creation and verification by wobsoriano · Pull Request #7955 · clerk/javascript · GitHub
Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(backend,nextjs): Add support for M2M JWT creation and verification by wobsoriano · Pull Request #7955 · clerk/javascript · GitHub
Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(backend,nextjs): Add support for M2M JWT creation and verification by wobsoriano · Pull Request #7955 · clerk/javascript · GitHub
Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(backend,nextjs): Add support for M2M JWT creation and verification by wobsoriano · Pull Request #7955 · clerk/javascript · GitHub
Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(backend,nextjs): Add support for M2M JWT creation and verification by wobsoriano · Pull Request #7955 · clerk/javascript · GitHub
Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(backend,nextjs): Add support for M2M JWT creation and verification by wobsoriano · Pull Request #7955 · clerk/javascript · GitHub
Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat(backend,nextjs): Add support for M2M JWT creation and verification by wobsoriano · Pull Request #7955 · clerk/javascript · GitHub
Skip to content

feat(backend,nextjs): Add support for M2M JWT creation and verification - #7955

Merged
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3
Mar 2, 2026
Merged

feat(backend,nextjs): Add support for M2M JWT creation and verification#7955
wobsoriano merged 2 commits into
mainfrom
rob/m2m-jwts-core3

Conversation

@wobsoriano

@wobsorianowobsoriano commented Feb 28, 2026

Copy link
Copy Markdown
Member

Description

Cherry-picked from Core 2 PR #7883

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Added JWT-format support for machine-to-machine (M2M) tokens with local verification and custom claims.
  • Bug Fixes / Behavior

    • Endpoints now reject machine tokens when only session tokens are accepted, preventing token-type misclassification.
    • Improved JWT-based machine token detection and routing for verification.
  • Tests

    • Expanded test coverage for M2M creation, JWT verification, routing, and edge/error cases.

@changeset-bot

changeset-botBot commented Feb 28, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 13609a6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Feb 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentFeb 28, 2026 2:10am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Feb 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7955

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7955

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7955

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7955

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7955

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7955

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@7955

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7955

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7955

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7955

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@7955

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7955

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7955

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7955

@clerk/react

npm i https://pkg.pr.new/@clerk/react@7955

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7955

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7955

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7955

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7955

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@7955

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7955

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7955

commit: 13609a6

@coderabbitai

coderabbitaiBot commented Feb 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds JWT-format support for M2M tokens alongside opaque tokens: new M2MTokenFormat, token creation now accepts tokenFormat, and M2MToken.fromJwtPayload constructs tokens from JWT claims. Introduces local JWT verification utilities (verifyMachineJwt.ts) and routes verification via verifyM2MJwt/verifyOAuthJwt. Token detection expanded with isM2MJwt and isMachineJwt. Backend factory and M2MTokenApi constructor signatures updated to accept JWT-related options. Removes two internal exports, changes M2M id prefixes from m2m_ to mt_, tightens session-only endpoint handling for machine tokens, and adds extensive tests.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 54.55% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding M2M JWT creation and verification support across backend and nextjs packages.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/backend/src/jwt/verifyMachineJwt.ts`:
- Line 89: The JWT header's `kid` must be validated before calling
resolveKeyAndVerifyJwt to avoid using undefined keys; in both verifyM2MJwt and
verifyOAuthJwt check that decoded.header.kid is a non-empty string and
throw/return a clear error (e.g., "missing JWT kid in header") if absent,
preventing downstream cache lookups like
loadClerkJwkFromPem/loadClerkJWKFromRemote from receiving `undefined`; update
the call sites that currently pass decoded.header.kid to first validate and fail
fast with a descriptive error when the kid is missing.
In `@packages/backend/src/tokens/verify.ts`:
- Around line 264-266: The code calls decodedResult.payload.sub.startsWith(...)
which can throw if sub is undefined or not a string; update the conditional in
the verify flow (the branch that currently checks M2M_SUBJECT_PREFIX) to first
ensure typeof decodedResult.payload.sub === 'string' (or use the existing
isM2MJwt type guard from machine.ts) before calling startsWith, and only call
verifyM2MJwt(token, decodedResult, options) when that guard passes; otherwise
fall through to the non-M2M verification path.

ℹ️ Review info

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 21c96e8 and 50e64c0.

📒 Files selected for processing (25)
  • .changeset/clever-ways-raise.md
  • integration/tests/machine-auth/m2m.test.ts
  • packages/backend/src/__tests__/exports.test.ts
  • packages/backend/src/api/__tests__/M2MTokenApi.test.ts
  • packages/backend/src/api/endpoints/M2MTokenApi.ts
  • packages/backend/src/api/factory.ts
  • packages/backend/src/api/resources/M2MToken.ts
  • packages/backend/src/api/resources/__tests__/M2MToken.test.ts
  • packages/backend/src/errors.ts
  • packages/backend/src/fixtures/index.ts
  • packages/backend/src/fixtures/machine.ts
  • packages/backend/src/internal.ts
  • packages/backend/src/jwt/verifyMachineJwt.ts
  • packages/backend/src/tokens/__tests__/authObjects.test.ts
  • packages/backend/src/tokens/__tests__/machine.test.ts
  • packages/backend/src/tokens/__tests__/verify.test.ts
  • packages/backend/src/tokens/machine.ts
  • packages/backend/src/tokens/request.ts
  • packages/backend/src/tokens/verify.ts
  • packages/express/src/__tests__/getAuth.test.ts
  • packages/fastify/src/__tests__/getAuth.test.ts
  • packages/nextjs/src/server/__tests__/clerkMiddleware.test.ts
  • packages/nextjs/src/server/__tests__/getAuthDataFromRequest.test.ts
  • packages/nextjs/src/server/data/getAuthDataFromRequest.ts
  • packages/nextjs/src/server/protect.ts
💤 Files with no reviewable changes (1)
  • packages/backend/src/tests/exports.test.ts

Comment threadpackages/backend/src/jwt/verifyMachineJwt.ts
Comment threadpackages/backend/src/tokens/verify.ts

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changeset available in core 2

@wobsoriano
wobsoriano merged commit cd1973e into mainMar 2, 2026
43 checks passed
@wobsoriano
wobsoriano deleted the rob/m2m-jwts-core3 branch March 2, 2026 16:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@jacekradko