Skip to content

feat(shared): Add oiat field to JwtHeader type - #8107

Merged
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type
Apr 3, 2026
Merged

feat(shared): Add oiat field to JwtHeader type#8107
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 18, 2026

Copy link
Copy Markdown
Member

Why

Session Minter uses oiat (original_issued_at) in the JWT header to track when token claims were last assembled from the DB. Edge re-mints copy this value forward, so consumers can determine claim freshness regardless of how many times the token was re-signed at the edge.

What

Add oiat?: number to the JwtHeader interface in jwtv2.ts. Marked @internal.

Test plan

  • Type-only change, no runtime behavior
  • Existing JWT parsing still works (oiat passes through via JSON.parse)

Summary by CodeRabbit

  • Chores
    • Internal improvements to JWT token handling infrastructure to support enhanced token management capabilities.

Session Minter uses oiat (original_issued_at) in the JWT header to
track when token claims were last assembled from the DB. Edge
re-mints copy this value forward, so consumers can determine claim
freshness regardless of how many times the token was re-signed.
Marked @internal so developers don't depend on this field.
@changeset-bot

changeset-botBot commented Mar 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ee6914d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 3, 2026 0:58am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8107

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8107

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8107

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8107

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8107

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8107

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8107

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8107

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8107

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8107

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8107

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8107

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8107

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8107

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8107

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8107

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8107

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8107

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8107

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8107

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8107

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8107

commit: ee6914d

@coderabbitai

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: faa483ba-a8c6-4e43-871f-67c368438f99

📥 Commits

Reviewing files that changed from the base of the PR and between abfd5ef and ee6914d.

📒 Files selected for processing (2)
  • .changeset/session-minter-oiat-type.md
  • packages/shared/src/types/jwtv2.ts

📝 Walkthrough

Walkthrough

This pull request adds a changeset entry for the @clerk/shared package indicating a patch-level release. The JwtHeader interface in packages/shared/src/types/jwtv2.ts is extended with a new optional field oiat?: number. The field, documented as @internal, represents the original\_issued\_at timestamp and is intended for Session Minter monotonic token freshness checks. External dependencies on this field are discouraged.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'feat(shared): Add oiat field to JwtHeader type' directly and clearly summarizes the main change in the pull request, which is adding the oiat field to the JwtHeader type.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@nikosdouvlis
nikosdouvlis merged commit 636b496 into mainApr 3, 2026
44 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/plat-2469-oiat-jwt-header-type branch April 3, 2026 13:15
nikosdouvlis added a commit that referenced this pull request May 12, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
nikosdouvlis added a commit that referenced this pull request May 13, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@bratsos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(shared): Add oiat field to JwtHeader type by nikosdouvlis · Pull Request #8107 · clerk/javascript · GitHub
Skip to content

feat(shared): Add oiat field to JwtHeader type - #8107

Merged
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type
Apr 3, 2026
Merged

feat(shared): Add oiat field to JwtHeader type#8107
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 18, 2026

Copy link
Copy Markdown
Member

Why

Session Minter uses oiat (original_issued_at) in the JWT header to track when token claims were last assembled from the DB. Edge re-mints copy this value forward, so consumers can determine claim freshness regardless of how many times the token was re-signed at the edge.

What

Add oiat?: number to the JwtHeader interface in jwtv2.ts. Marked @internal.

Test plan

  • Type-only change, no runtime behavior
  • Existing JWT parsing still works (oiat passes through via JSON.parse)

Summary by CodeRabbit

  • Chores
    • Internal improvements to JWT token handling infrastructure to support enhanced token management capabilities.

Session Minter uses oiat (original_issued_at) in the JWT header to
track when token claims were last assembled from the DB. Edge
re-mints copy this value forward, so consumers can determine claim
freshness regardless of how many times the token was re-signed.
Marked @internal so developers don't depend on this field.
@changeset-bot

changeset-botBot commented Mar 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ee6914d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 3, 2026 0:58am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8107

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8107

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8107

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8107

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8107

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8107

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8107

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8107

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8107

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8107

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8107

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8107

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8107

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8107

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8107

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8107

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8107

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8107

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8107

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8107

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8107

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8107

commit: ee6914d

@coderabbitai

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: faa483ba-a8c6-4e43-871f-67c368438f99

📥 Commits

Reviewing files that changed from the base of the PR and between abfd5ef and ee6914d.

📒 Files selected for processing (2)
  • .changeset/session-minter-oiat-type.md
  • packages/shared/src/types/jwtv2.ts

📝 Walkthrough

Walkthrough

This pull request adds a changeset entry for the @clerk/shared package indicating a patch-level release. The JwtHeader interface in packages/shared/src/types/jwtv2.ts is extended with a new optional field oiat?: number. The field, documented as @internal, represents the original\_issued\_at timestamp and is intended for Session Minter monotonic token freshness checks. External dependencies on this field are discouraged.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'feat(shared): Add oiat field to JwtHeader type' directly and clearly summarizes the main change in the pull request, which is adding the oiat field to the JwtHeader type.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@nikosdouvlis
nikosdouvlis merged commit 636b496 into mainApr 3, 2026
44 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/plat-2469-oiat-jwt-header-type branch April 3, 2026 13:15
nikosdouvlis added a commit that referenced this pull request May 12, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
nikosdouvlis added a commit that referenced this pull request May 13, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@bratsos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(shared): Add oiat field to JwtHeader type by nikosdouvlis · Pull Request #8107 · clerk/javascript · GitHub
Skip to content

feat(shared): Add oiat field to JwtHeader type - #8107

Merged
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type
Apr 3, 2026
Merged

feat(shared): Add oiat field to JwtHeader type#8107
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 18, 2026

Copy link
Copy Markdown
Member

Why

Session Minter uses oiat (original_issued_at) in the JWT header to track when token claims were last assembled from the DB. Edge re-mints copy this value forward, so consumers can determine claim freshness regardless of how many times the token was re-signed at the edge.

What

Add oiat?: number to the JwtHeader interface in jwtv2.ts. Marked @internal.

Test plan

  • Type-only change, no runtime behavior
  • Existing JWT parsing still works (oiat passes through via JSON.parse)

Summary by CodeRabbit

  • Chores
    • Internal improvements to JWT token handling infrastructure to support enhanced token management capabilities.

Session Minter uses oiat (original_issued_at) in the JWT header to
track when token claims were last assembled from the DB. Edge
re-mints copy this value forward, so consumers can determine claim
freshness regardless of how many times the token was re-signed.
Marked @internal so developers don't depend on this field.
@changeset-bot

changeset-botBot commented Mar 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ee6914d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 3, 2026 0:58am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8107

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8107

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8107

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8107

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8107

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8107

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8107

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8107

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8107

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8107

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8107

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8107

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8107

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8107

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8107

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8107

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8107

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8107

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8107

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8107

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8107

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8107

commit: ee6914d

@coderabbitai

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: faa483ba-a8c6-4e43-871f-67c368438f99

📥 Commits

Reviewing files that changed from the base of the PR and between abfd5ef and ee6914d.

📒 Files selected for processing (2)
  • .changeset/session-minter-oiat-type.md
  • packages/shared/src/types/jwtv2.ts

📝 Walkthrough

Walkthrough

This pull request adds a changeset entry for the @clerk/shared package indicating a patch-level release. The JwtHeader interface in packages/shared/src/types/jwtv2.ts is extended with a new optional field oiat?: number. The field, documented as @internal, represents the original\_issued\_at timestamp and is intended for Session Minter monotonic token freshness checks. External dependencies on this field are discouraged.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'feat(shared): Add oiat field to JwtHeader type' directly and clearly summarizes the main change in the pull request, which is adding the oiat field to the JwtHeader type.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@nikosdouvlis
nikosdouvlis merged commit 636b496 into mainApr 3, 2026
44 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/plat-2469-oiat-jwt-header-type branch April 3, 2026 13:15
nikosdouvlis added a commit that referenced this pull request May 12, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
nikosdouvlis added a commit that referenced this pull request May 13, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@bratsos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(shared): Add oiat field to JwtHeader type by nikosdouvlis · Pull Request #8107 · clerk/javascript · GitHub
Skip to content

feat(shared): Add oiat field to JwtHeader type - #8107

Merged
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type
Apr 3, 2026
Merged

feat(shared): Add oiat field to JwtHeader type#8107
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 18, 2026

Copy link
Copy Markdown
Member

Why

Session Minter uses oiat (original_issued_at) in the JWT header to track when token claims were last assembled from the DB. Edge re-mints copy this value forward, so consumers can determine claim freshness regardless of how many times the token was re-signed at the edge.

What

Add oiat?: number to the JwtHeader interface in jwtv2.ts. Marked @internal.

Test plan

  • Type-only change, no runtime behavior
  • Existing JWT parsing still works (oiat passes through via JSON.parse)

Summary by CodeRabbit

  • Chores
    • Internal improvements to JWT token handling infrastructure to support enhanced token management capabilities.

Session Minter uses oiat (original_issued_at) in the JWT header to
track when token claims were last assembled from the DB. Edge
re-mints copy this value forward, so consumers can determine claim
freshness regardless of how many times the token was re-signed.
Marked @internal so developers don't depend on this field.
@changeset-bot

changeset-botBot commented Mar 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ee6914d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 3, 2026 0:58am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8107

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8107

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8107

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8107

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8107

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8107

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8107

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8107

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8107

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8107

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8107

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8107

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8107

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8107

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8107

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8107

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8107

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8107

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8107

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8107

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8107

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8107

commit: ee6914d

@coderabbitai

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: faa483ba-a8c6-4e43-871f-67c368438f99

📥 Commits

Reviewing files that changed from the base of the PR and between abfd5ef and ee6914d.

📒 Files selected for processing (2)
  • .changeset/session-minter-oiat-type.md
  • packages/shared/src/types/jwtv2.ts

📝 Walkthrough

Walkthrough

This pull request adds a changeset entry for the @clerk/shared package indicating a patch-level release. The JwtHeader interface in packages/shared/src/types/jwtv2.ts is extended with a new optional field oiat?: number. The field, documented as @internal, represents the original\_issued\_at timestamp and is intended for Session Minter monotonic token freshness checks. External dependencies on this field are discouraged.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'feat(shared): Add oiat field to JwtHeader type' directly and clearly summarizes the main change in the pull request, which is adding the oiat field to the JwtHeader type.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@nikosdouvlis
nikosdouvlis merged commit 636b496 into mainApr 3, 2026
44 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/plat-2469-oiat-jwt-header-type branch April 3, 2026 13:15
nikosdouvlis added a commit that referenced this pull request May 12, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
nikosdouvlis added a commit that referenced this pull request May 13, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@bratsos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(shared): Add oiat field to JwtHeader type by nikosdouvlis · Pull Request #8107 · clerk/javascript · GitHub
Skip to content

feat(shared): Add oiat field to JwtHeader type - #8107

Merged
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type
Apr 3, 2026
Merged

feat(shared): Add oiat field to JwtHeader type#8107
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 18, 2026

Copy link
Copy Markdown
Member

Why

Session Minter uses oiat (original_issued_at) in the JWT header to track when token claims were last assembled from the DB. Edge re-mints copy this value forward, so consumers can determine claim freshness regardless of how many times the token was re-signed at the edge.

What

Add oiat?: number to the JwtHeader interface in jwtv2.ts. Marked @internal.

Test plan

  • Type-only change, no runtime behavior
  • Existing JWT parsing still works (oiat passes through via JSON.parse)

Summary by CodeRabbit

  • Chores
    • Internal improvements to JWT token handling infrastructure to support enhanced token management capabilities.

Session Minter uses oiat (original_issued_at) in the JWT header to
track when token claims were last assembled from the DB. Edge
re-mints copy this value forward, so consumers can determine claim
freshness regardless of how many times the token was re-signed.
Marked @internal so developers don't depend on this field.
@changeset-bot

changeset-botBot commented Mar 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ee6914d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 3, 2026 0:58am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8107

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8107

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8107

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8107

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8107

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8107

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8107

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8107

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8107

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8107

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8107

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8107

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8107

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8107

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8107

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8107

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8107

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8107

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8107

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8107

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8107

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8107

commit: ee6914d

@coderabbitai

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: faa483ba-a8c6-4e43-871f-67c368438f99

📥 Commits

Reviewing files that changed from the base of the PR and between abfd5ef and ee6914d.

📒 Files selected for processing (2)
  • .changeset/session-minter-oiat-type.md
  • packages/shared/src/types/jwtv2.ts

📝 Walkthrough

Walkthrough

This pull request adds a changeset entry for the @clerk/shared package indicating a patch-level release. The JwtHeader interface in packages/shared/src/types/jwtv2.ts is extended with a new optional field oiat?: number. The field, documented as @internal, represents the original\_issued\_at timestamp and is intended for Session Minter monotonic token freshness checks. External dependencies on this field are discouraged.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'feat(shared): Add oiat field to JwtHeader type' directly and clearly summarizes the main change in the pull request, which is adding the oiat field to the JwtHeader type.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@nikosdouvlis
nikosdouvlis merged commit 636b496 into mainApr 3, 2026
44 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/plat-2469-oiat-jwt-header-type branch April 3, 2026 13:15
nikosdouvlis added a commit that referenced this pull request May 12, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
nikosdouvlis added a commit that referenced this pull request May 13, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@bratsos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(shared): Add oiat field to JwtHeader type by nikosdouvlis · Pull Request #8107 · clerk/javascript · GitHub
Skip to content

feat(shared): Add oiat field to JwtHeader type - #8107

Merged
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type
Apr 3, 2026
Merged

feat(shared): Add oiat field to JwtHeader type#8107
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 18, 2026

Copy link
Copy Markdown
Member

Why

Session Minter uses oiat (original_issued_at) in the JWT header to track when token claims were last assembled from the DB. Edge re-mints copy this value forward, so consumers can determine claim freshness regardless of how many times the token was re-signed at the edge.

What

Add oiat?: number to the JwtHeader interface in jwtv2.ts. Marked @internal.

Test plan

  • Type-only change, no runtime behavior
  • Existing JWT parsing still works (oiat passes through via JSON.parse)

Summary by CodeRabbit

  • Chores
    • Internal improvements to JWT token handling infrastructure to support enhanced token management capabilities.

Session Minter uses oiat (original_issued_at) in the JWT header to
track when token claims were last assembled from the DB. Edge
re-mints copy this value forward, so consumers can determine claim
freshness regardless of how many times the token was re-signed.
Marked @internal so developers don't depend on this field.
@changeset-bot

changeset-botBot commented Mar 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ee6914d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 3, 2026 0:58am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8107

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8107

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8107

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8107

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8107

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8107

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8107

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8107

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8107

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8107

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8107

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8107

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8107

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8107

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8107

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8107

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8107

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8107

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8107

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8107

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8107

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8107

commit: ee6914d

@coderabbitai

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: faa483ba-a8c6-4e43-871f-67c368438f99

📥 Commits

Reviewing files that changed from the base of the PR and between abfd5ef and ee6914d.

📒 Files selected for processing (2)
  • .changeset/session-minter-oiat-type.md
  • packages/shared/src/types/jwtv2.ts

📝 Walkthrough

Walkthrough

This pull request adds a changeset entry for the @clerk/shared package indicating a patch-level release. The JwtHeader interface in packages/shared/src/types/jwtv2.ts is extended with a new optional field oiat?: number. The field, documented as @internal, represents the original\_issued\_at timestamp and is intended for Session Minter monotonic token freshness checks. External dependencies on this field are discouraged.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'feat(shared): Add oiat field to JwtHeader type' directly and clearly summarizes the main change in the pull request, which is adding the oiat field to the JwtHeader type.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@nikosdouvlis
nikosdouvlis merged commit 636b496 into mainApr 3, 2026
44 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/plat-2469-oiat-jwt-header-type branch April 3, 2026 13:15
nikosdouvlis added a commit that referenced this pull request May 12, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
nikosdouvlis added a commit that referenced this pull request May 13, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@bratsos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); feat(shared): Add oiat field to JwtHeader type by nikosdouvlis · Pull Request #8107 · clerk/javascript · GitHub
Skip to content

feat(shared): Add oiat field to JwtHeader type - #8107

Merged
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type
Apr 3, 2026
Merged

feat(shared): Add oiat field to JwtHeader type#8107
nikosdouvlis merged 2 commits into
mainfrom
nikos/plat-2469-oiat-jwt-header-type

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 18, 2026

Copy link
Copy Markdown
Member

Why

Session Minter uses oiat (original_issued_at) in the JWT header to track when token claims were last assembled from the DB. Edge re-mints copy this value forward, so consumers can determine claim freshness regardless of how many times the token was re-signed at the edge.

What

Add oiat?: number to the JwtHeader interface in jwtv2.ts. Marked @internal.

Test plan

  • Type-only change, no runtime behavior
  • Existing JWT parsing still works (oiat passes through via JSON.parse)

Summary by CodeRabbit

  • Chores
    • Internal improvements to JWT token handling infrastructure to support enhanced token management capabilities.

Session Minter uses oiat (original_issued_at) in the JWT header to
track when token claims were last assembled from the DB. Edge
re-mints copy this value forward, so consumers can determine claim
freshness regardless of how many times the token was re-signed.
Marked @internal so developers don't depend on this field.
@changeset-bot

changeset-botBot commented Mar 18, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ee6914d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 3, 2026 0:58am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8107

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8107

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8107

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8107

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8107

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8107

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8107

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8107

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8107

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8107

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8107

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8107

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8107

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8107

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8107

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8107

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8107

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8107

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8107

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8107

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8107

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8107

commit: ee6914d

@coderabbitai

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro

Run ID: faa483ba-a8c6-4e43-871f-67c368438f99

📥 Commits

Reviewing files that changed from the base of the PR and between abfd5ef and ee6914d.

📒 Files selected for processing (2)
  • .changeset/session-minter-oiat-type.md
  • packages/shared/src/types/jwtv2.ts

📝 Walkthrough

Walkthrough

This pull request adds a changeset entry for the @clerk/shared package indicating a patch-level release. The JwtHeader interface in packages/shared/src/types/jwtv2.ts is extended with a new optional field oiat?: number. The field, documented as @internal, represents the original\_issued\_at timestamp and is intended for Session Minter monotonic token freshness checks. External dependencies on this field are discouraged.

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title 'feat(shared): Add oiat field to JwtHeader type' directly and clearly summarizes the main change in the pull request, which is adding the oiat field to the JwtHeader type.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@nikosdouvlis
nikosdouvlis merged commit 636b496 into mainApr 3, 2026
44 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/plat-2469-oiat-jwt-header-type branch April 3, 2026 13:15
nikosdouvlis added a commit that referenced this pull request May 12, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
nikosdouvlis added a commit that referenced this pull request May 13, 2026
Resolve tokenCache.ts conflict by adopting main's orphan guard
(cache.get(key) !== value short-circuit from #8098); drop the PR's
redundant compare-and-swap. Monotonic enforcement remains at the
broadcast handler, cookie write path, and Session resource where
user-visible state lives.
Drop stale changesets that were superseded by merged work:
- session-minter-oiat-type.md (oiat field shipped via #8107)
- session-minter-sdk-params.md (previous-token + force_origin shipped
via #8105 + #8106 + #8107)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@bratsos