chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(express,react,shared): Support dynamic options callback in clerkMiddleware - #8398

Merged
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys
Apr 24, 2026
Merged

chore(express,react,shared): Support dynamic options callback in clerkMiddleware#8398
wobsoriano merged 21 commits into
mainfrom
rob/express-sdk-dynamic-keys

Conversation

@wobsoriano

@wobsorianowobsoriano commented Apr 24, 2026

Copy link
Copy Markdown
Member

Description

app.use(clerkMiddleware((req)=>({publishableKey: req.hostname==='domain-a.com' ? PK_A : PK_B,})));

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Add ClerkMiddlewareOptionsCallback type so multi-domain/multi-tenant
apps can resolve publishableKey and secretKey per request:
app.use(clerkMiddleware((req) => ({
publishableKey: req.hostname === 'a.com' ? PK_A : PK_B,
secretKey: req.hostname === 'a.com' ? SK_A : SK_B,
})));
Static options path is unchanged. Callback path awaits the function
result and creates the auth handler per request.
@vercel

vercelBot commented Apr 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedApr 24, 2026 9:47pm

Request Review

@changeset-bot

changeset-botBot commented Apr 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f48bd81

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 20 packages
NameType
@clerk/sharedPatch
@clerk/reactPatch
@clerk/expressPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Apr 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR enhances the Express middleware to support dynamic, request-based configuration through a callback pattern while introducing a cross-package utility for multi-domain setups. The clerkMiddleware function now accepts either static options or an async-capable callback that derives options from the incoming request. A new publishableKeyFromHost utility is added to the shared package and re-exported through internal entry points in both React and Express packages. Build configuration is extended to support the new internal export path, and comprehensive tests validate the callback behavior including Promise handling and request properties.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately describes the main change: adding support for dynamic options callback in clerkMiddleware across express, react, and shared packages.
Docstring Coverage✅ PassedDocstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description provides a clear example of the new feature: a callback function passed to clerkMiddleware that dynamically selects configuration based on request hostname.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Apr 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8398

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8398

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8398

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8398

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8398

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8398

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8398

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8398

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8398

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8398

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8398

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8398

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8398

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8398

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8398

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8398

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8398

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8398

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8398

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8398

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8398

commit: f48bd81

Derives a production publishable key from the current request hostname,
falling back to the configured key for development instances (pk_test_).
Built on the existing buildPublishableKey and isDevelopmentFromPublishableKey
helpers.
Re-exported from @clerk/react/internal so Replit and other multi-domain
apps can use it without additional dependencies:
import { publishableKeyFromHost } from '@clerk/react/internal'
// React
<ClerkProvider publishableKey={publishableKeyFromHost(window.location.host, process.env.VITE_CLERK_PUBLISHABLE_KEY)}>
// Express (with the new clerkMiddleware callback)
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname, process.env.CLERK_PUBLISHABLE_KEY),
}))
Add @clerk/express/internal re-exporting publishableKeyFromHost from
@clerk/shared/keys. Mirrors the @clerk/react/internal pattern.
Also simplifies publishableKeyFromHost to take only host — buildPublishableKey
already handles dev vs prod detection via FAPI host patterns, so no
fallback key parameter is needed.
Usage:
import { publishableKeyFromHost } from '@clerk/express/internal'
clerkMiddleware((req) => ({
publishableKey: publishableKeyFromHost(req.hostname),
}))
Without it, dev instances on localhost produce an incorrect pk_live_ key.
If fallbackKey is a pk_test_ key it is returned as-is; otherwise the key
is derived from the host for production multi-domain setups.
Comment threadpackages/shared/src/keys.ts Outdated
if (fallbackKey && isDevelopmentFromPublishableKey(fallbackKey)) {
return fallbackKey;
}
return buildPublishableKey(`clerk.${host.toLowerCase()}`);

@wobsorianowobsorianoApr 24, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

existing helper that converts a FAPI URL into a base64-encoded publishable key

https://github.com/clerk/javascript/blob/70bd92ba85539aefb880f33e5fcd8cc1f1199756/packages/shared/src/keys.ts#L38,L44

Comment thread.changeset/new-kangaroos-search.md Outdated
@wobsorianowobsoriano changed the title feat(express): Support dynamic options callback in clerkMiddlewarechore(express,react,shared): Support dynamic options callback in clerkMiddlewareApr 24, 2026
Comment thread.changeset/brave-lions-fly.md Outdated
Comment threadpackages/express/src/internal.ts Outdated
@@ -0,0 +1 @@
export { publishableKeyFromHost } from '@clerk/shared/keys';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤔 I am a little hesitant to add a whole new entrypoint to a package in a hotfix.. just seems a bit early for this

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you saying we should just export from @clerk/express or let them import as-is from @clerk/shared/keys?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now I think I would suggest they import from @clerk/shared/keys until we are sure this is something we want to re-export from an SDK package.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gotcha

Comment threadpackages/shared/src/keys.ts
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts Outdated
Comment threadpackages/shared/src/keys.ts
@wobsoriano
wobsoriano merged commit 083c4c5 into mainApr 24, 2026
42 checks passed
@wobsoriano
wobsoriano deleted the rob/express-sdk-dynamic-keys branch April 24, 2026 21:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wobsoriano@jacekradko@nikosdouvlis@thiskevinwang