Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(nextjs): Deprecate createRouteMatcher by Ephem · Pull Request #8994 · clerk/javascript · GitHub
Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(nextjs): Deprecate createRouteMatcher by Ephem · Pull Request #8994 · clerk/javascript · GitHub
Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(nextjs): Deprecate createRouteMatcher by Ephem · Pull Request #8994 · clerk/javascript · GitHub
Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(nextjs): Deprecate createRouteMatcher by Ephem · Pull Request #8994 · clerk/javascript · GitHub
Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(nextjs): Deprecate createRouteMatcher by Ephem · Pull Request #8994 · clerk/javascript · GitHub
Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(nextjs): Deprecate createRouteMatcher by Ephem · Pull Request #8994 · clerk/javascript · GitHub
Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(nextjs): Deprecate createRouteMatcher by Ephem · Pull Request #8994 · clerk/javascript · GitHub
Skip to content

fix(nextjs): Deprecate createRouteMatcher - #8994

Merged
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher
Jul 6, 2026
Merged

fix(nextjs): Deprecate createRouteMatcher#8994
jacekradko merged 5 commits into
mainfrom
fredrik/nextjs-deprecate-create-route-matcher

Conversation

@Ephem

@EphemEphem commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Note

For any external folks that stumble across this:

We are about to deprecate createRouteMatcher and are recommending not doing auth gating at the Middleware level. Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

We are launching a lint rule to help you ensure you protect all relevant individual resources.

Full rationale and a migration guide will be available before we merge this.

Deprecates createRouteMatcher in @clerk/nextjs, including a runtime warning.

This PR is waiting for:

  • Release of the latest eslint-plugin changes
    • We should determine if we also want to release this as stable first - Should be in a good place
  • Doc changes to be finalized and released

Doc changes and this PR should go out at roughly the same time.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Deprecations
    • Marked createRouteMatcher() as deprecated and added a runtime warning with migration guidance toward resource-based authorization checks, including a Next.js TypeScript example using auth.protect() to protect pages and server components.
  • Tests
    • Added Vitest coverage to verify the deprecation warning is emitted with the expected message when createRouteMatcher() is invoked.

@vercel

vercelBot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 6, 2026 2:33pm
swingsetReadyReadyPreview, CommentJul 6, 2026 2:33pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8a2b818b-dc34-4d09-9bfc-5dc8102da8d3

📥 Commits

Reviewing files that changed from the base of the PR and between 938f7a5 and 151e46a.

📒 Files selected for processing (1)
  • packages/nextjs/src/server/routeMatcher.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/nextjs/src/server/routeMatcher.ts

📝 Walkthrough

Walkthrough

@clerk/nextjs now warns at runtime when createRouteMatcher() is used. A new changeset documents the deprecation and migration path, and a Vitest test checks the warning call.

Changes

Route matcher deprecation

Layer / File(s)Summary
Runtime deprecation warning
packages/nextjs/src/server/routeMatcher.ts, packages/nextjs/src/server/__tests__/routeMatcher.test.ts, .changeset/nextjs-deprecate-route-matcher.md
createRouteMatcher() now calls the shared deprecation helper with migration text; the new Vitest suite asserts the warning call, and the changeset records the patch deprecation note.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers:alexcarpenter

Poem

A bunny hopped by, ears up high,
to see a route matcher say goodbye.
“Protect the page!” the whiskers cheered,
as deprecation bells appeared.
🐇✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately and concisely summarizes the main change: deprecating createRouteMatcher in nextjs.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-newBot commented Jun 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8994

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8994

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8994

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8994

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@8994

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@8994

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@8994

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8994

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8994

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8994

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8994

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8994

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8994

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8994

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8994

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8994

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8994

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8994

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8994

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8994

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8994

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8994

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8994

commit: 151e46a

@github-actions

github-actionsBot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-06T14:34:49.123Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 151e46a.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
packages/nextjs/src/server/routeMatcher.ts (2)

32-32: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add an explicit return type to the exported factory.
This public API should declare its return type explicitly to match the TypeScript guidelines for exported functions and keep the surface stable for consumers. As per coding guidelines and the retrieved learning, exported TypeScript APIs should declare explicit return types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` at line 32, The exported factory
createRouteMatcher currently relies on type inference for its public API; add an
explicit return type annotation to the createRouteMatcher function signature so
the route matcher surface stays stable for consumers and matches the TypeScript
guideline for exported functions. Keep the implementation unchanged and ensure
the declared return type reflects the value returned by createRouteMatcher.

Sources: Coding guidelines, Learnings


23-31: 📐 Maintainability & Code Quality | 🔵 Trivial

Have Docs review the new deprecation copy.
This @deprecated block will render in generated Clerk Docs, so the migration wording should be reviewed before release. As per path instructions, public/reference-facing JSDoc is customer-facing documentation.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/nextjs/src/server/routeMatcher.ts` around lines 23 - 31, The
`@deprecated` JSDoc in routeMatcher is customer-facing and will be rendered in the
generated docs, so the migration copy needs a docs review before release. Have
Docs review and approve the wording in the routeMatcher deprecation block,
especially the guidance about moving auth checks into pages/layouts/API
routes/Server Functions and the migration guide link, and make any requested
copy edits without changing the API behavior.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/nextjs/src/server/routeMatcher.ts`:
- Line 32: The exported factory createRouteMatcher currently relies on type
inference for its public API; add an explicit return type annotation to the
createRouteMatcher function signature so the route matcher surface stays stable
for consumers and matches the TypeScript guideline for exported functions. Keep
the implementation unchanged and ensure the declared return type reflects the
value returned by createRouteMatcher.
- Around line 23-31: The `@deprecated` JSDoc in routeMatcher is customer-facing
and will be rendered in the generated docs, so the migration copy needs a docs
review before release. Have Docs review and approve the wording in the
routeMatcher deprecation block, especially the guidance about moving auth checks
into pages/layouts/API routes/Server Functions and the migration guide link, and
make any requested copy edits without changing the API behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0bf23da2-670c-48f3-a91c-8cb1a5356bbd

📥 Commits

Reviewing files that changed from the base of the PR and between cfd523d and 7f3bbbf.

📒 Files selected for processing (3)
  • .changeset/nextjs-deprecate-route-matcher.md
  • packages/nextjs/src/server/__tests__/routeMatcher.test.ts
  • packages/nextjs/src/server/routeMatcher.ts

Middleware-based auth checks rely on path matching, which can diverge from how Next.js routes requests and leave protected resources reachable.

For a migration guide, see:
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrating-from-create-route-matcher

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note: These links need updating if the migration guide moves or is renamed before releasing it

@changeset-bot

changeset-botBot commented Jun 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 151e46a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread.changeset/nextjs-deprecate-route-matcher.md Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/routeMatcher.ts Outdated
Comment threadpackages/nextjs/src/server/__tests__/routeMatcher.test.ts Outdated
Co-authored-by: Alexis Aguilar <98043211+alexisintech@users.noreply.github.com>
…ate-create-route-matcher
# Conflicts:
#	packages/nextjs/src/server/routeMatcher.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@jacekradko@alexisintech