Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
chore(ui,shared,localizations): Improve error handling when creating API keys by wobsoriano · Pull Request #8056 · clerk/javascript · GitHub
Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore(ui,shared,localizations): Improve error handling when creating API keys by wobsoriano · Pull Request #8056 · clerk/javascript · GitHub
Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore(ui,shared,localizations): Improve error handling when creating API keys by wobsoriano · Pull Request #8056 · clerk/javascript · GitHub
Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' chore(ui,shared,localizations): Improve error handling when creating API keys by wobsoriano · Pull Request #8056 · clerk/javascript · GitHub
Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore(ui,shared,localizations): Improve error handling when creating API keys by wobsoriano · Pull Request #8056 · clerk/javascript · GitHub
Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore(ui,shared,localizations): Improve error handling when creating API keys by wobsoriano · Pull Request #8056 · clerk/javascript · GitHub
Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); chore(ui,shared,localizations): Improve error handling when creating API keys by wobsoriano · Pull Request #8056 · clerk/javascript · GitHub
Skip to content

chore(ui,shared,localizations): Improve error handling when creating API keys - #8056

Merged
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded
Mar 30, 2026
Merged

chore(ui,shared,localizations): Improve error handling when creating API keys#8056
wobsoriano merged 9 commits into
mainfrom
rob/api-keys-usage-exceeded

Conversation

@wobsoriano

@wobsorianowobsoriano commented Mar 12, 2026

Copy link
Copy Markdown
Member

Description

  • Handles 403 (usage exceeded) and 409 (duplicate name) errors when creating API keys in the <APIKeys /> component
  • Add localized error messages for both cases

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Enhanced API key creation error handling with localized messages for duplicate names and usage limits.
    • Added Chrome extension support with Vite template and testing infrastructure.
    • Introduced staging environment support for integration testing.
  • Bug Fixes

    • Fixed token cache refresh timer cleanup to prevent accumulation across overwrites.
    • Improved satellite auto-sync defaulting behavior and request handling.
    • Corrected multiple localization strings across languages.
  • Documentation

    • Updated integration testing guides for staging environment configuration.

@vercel

vercelBot commented Mar 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMar 30, 2026 11:26pm

Request Review

@changeset-bot

changeset-botBot commented Mar 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2384233

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/localizationsPatch
@clerk/sharedPatch
@clerk/uiPatch
@clerk/reactPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@wobsorianowobsoriano changed the title chore(ui,shared,localization): Improve error handling when creating API keyschore(ui,shared,localizations): Improve error handling when creating API keysMar 12, 2026
@wobsoriano
wobsoriano marked this pull request as ready for review March 12, 2026 20:56
@coderabbitai

coderabbitaiBot commented Mar 12, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This pull request introduces API key error handling improvements, adds Chrome extension integration testing support, implements staging instance testing capabilities, reorganizes machine authentication tests, and performs widespread package version updates across the monorepo. Changes include new localization strings for API key conflicts and usage limits, updates to multiple frontend packages with bug fixes and feature improvements, enhancements to Clerk JS core functionality including session minting and token refresh behavior, updates to GitHub Actions workflows and Turbo configuration for CI/CD, and reorganization of integration tests to support both production and staging environments with new test fixtures and helpers.

Possibly related PRs

@pkg-pr-new

pkg-pr-newBot commented Mar 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8056

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8056

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8056

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8056

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8056

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8056

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8056

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8056

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8056

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8056

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8056

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8056

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8056

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8056

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8056

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8056

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8056

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8056

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8056

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8056

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8056

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8056

commit: 2384233

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@packages/ui/src/components/APIKeys/APIKeys.tsx`:
- Around line 123-126: The 403 branch in APIKeys.tsx currently maps all
forbidden responses to the "usage exceeded" message; update the handler in the
block that checks err.status === 403 to inspect the backend error code (e.g.,
err?.data?.code or err?.body?.code) and only call
card.setError(t(localizationKeys('unstable__errors.api_key_usage_exceeded')))
when that code equals "token_quota_exceeded"; for other 403s call a generic
forbidden message (or a fallback like t(localizationKeys('errors.forbidden')))
and ensure err is safely null-checked before reading the code to avoid runtime
errors.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0715d523-4e31-4d5b-8073-facaf725b8f5

📥 Commits

Reviewing files that changed from the base of the PR and between a5aa803 and 5b7dfa9.

📒 Files selected for processing (5)
  • .changeset/cyan-elephants-roll.md
  • integration/tests/machine-auth/component.test.ts
  • packages/localizations/src/en-US.ts
  • packages/shared/src/types/localization.ts
  • packages/ui/src/components/APIKeys/APIKeys.tsx

Comment threadpackages/ui/src/components/APIKeys/APIKeys.tsx Outdated
card.setError(undefined);
setIsCopyModalOpen(true);
setAPIKey(apiKey);
} catch (err: any) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pre-existing issue, but it seems like we are only handling Clerk errors here, but silently ignoring all other errors. Wouldn't this leave the component in a transient state on other errors?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated! It now matches on the actual error code instead of HTTP status, and falls back to handleError which handles all kind of errors so they don't get silently swallowed. This matches the pattern used in other components (UserMembershipList, InviteMembersForm, and ChooseOrganizationScreen.)

if (isClerkAPIResponseError(err)) {
if (err.status === 409) {
card.setError('API Key name already exists');
if (err.status === 403) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Out of curiosity, is 403 guaranteed to be a quota exceeded error?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this specific flow yes, it's guaranteed a quota error.

Match on error codes instead of status codes and add handleError
fallback for non-Clerk and unhandled Clerk errors to prevent the
component from getting stuck in a transient state.
@wobsoriano
wobsoriano merged commit 00715a6 into mainMar 30, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/api-keys-usage-exceeded branch March 30, 2026 23:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@jacekradko@brunol95