Agent skill

Clerk CLI

by geekskai in geekskai/blog

Operate the Clerk CLI (clerk binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any…

MITAuto-check: notesBackend & APIs

Install Clerk CLI

skills CLI
$ npx skills add geekskai/blog --skill clerk-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install geekskai/blog clerk-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/geekskai/blog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/clerk-cli .claude/skills/clerk-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clerk-cli
GitHub stars
103
Used in
2 other repos
Token cost
~8.8k tokens
SKILL.md length
2,944 words
Files
4 (incl. references)
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Operate the Clerk CLI (clerk binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any…

  • Works in 5 steps: Discover before acting: clerk api ls… → Preview mutations: --dry-run on every… → Target explicitly in production: pass… → …
  • The user mentions Clerk management tasks
  • SKILL.md covers Execution environment (prefer…, Invoking the CLI, Prerequisites (run at session… and The mental model, plus 8 more sections
  • Calls jq, bunx and python3; needs CLERK_PLATFORM_API_KEY

What it does

Clerk CLI is an agent skill from geekskai/blog. Operate the Clerk CLI (clerk binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any Clerk Backend, Platform, or Frontend API call. Use when the user mentions Clerk management tasks, "list clerk users", "impersonate a user", "test webhooks locally", "enable orgs", "enable billing", "clerk env pull", "clerk doctor", "clerk deploy", "clerk api", or any ad-hoc Clerk API request. Prefer the CLI over raw…

Its SKILL.md is about 8.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/agent-mode.md`, `references/auth.md` and `references/recipes.md`).

It sits in Backend & APIs, covering Webhooks and Authentication. The repository describes itself as: 🚀 2026 Most Popular FREE Blog Template! Next.js 14, Zero Code - Just Write & Deploy | 2026最火免费博客模板!支持Markdown,一键部署,极致性能!⚡️ ✨ Write in Markdown, get your professional blog in…. The licence is MIT.

When your agent uses it

  • The user mentions Clerk management tasks
  • List clerk users
  • Impersonate a user
  • Test webhooks locally

Example prompts

  • “list clerk users”
  • “impersonate a user”
  • “test webhooks locally”
  • “/clerk-cli”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Discover before acting: clerk api ls before clerk api .
  2. Preview mutations: --dry-run on every config patch, config put, api -X POST/PATCH/PUT/DELETE.
  3. Target explicitly in production: pass --instance prod rather than relying on defaults, and confirm with the user before any production…
  4. Never commit secrets: env pull writes to .env.local (which should be gitignored). Don't paste secret keys into code or chat.
  5. Use doctor --json to diagnose before assuming the CLI is broken.

What it can do on your machine

Read from SKILL.md and the folder at commit e5554c5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq
    • bunx
    • python3
    • node
    • npx
    • pnpm
    • yarn
    • npm
    • stripe

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use bunx, npx, pnpm, yarn and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLERK_PLATFORM_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clerk CLI loads about 8.8k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 155 tokens; SKILL.md has 2,944 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~8.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:37
    - **Local `.env*` files**: publishable and secret keys materialized by
  • NoteMentions a .env fileSKILL.md:213
    env file (merge, not clobber). Resolves `.env.development.local` → framework-preferred file → `.env.local`; override wit
  • NoteMentions a .env fileSKILL.md:272
    commit secrets:** `env pull` writes to `.env.local` (which should be gitignored). Don't paste secret keys into code or

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from geekskai/blog at commit e5554c5, republished under its MIT licence (© geekskai). 2,944 words, ~8,811 tokens.

Download SKILL.mdSave it as .claude/skills/clerk-cli/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
clerk-cli
description
Operate the Clerk CLI (`clerk` binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any Clerk Backend, Platform, or Frontend API call. Use when the user mentions Clerk management tasks, "list clerk users", "impersonate a user", "test webhooks locally", "enable orgs", "enable billing", "clerk env pull", "clerk doctor", "clerk deploy", "clerk api", or any ad-hoc Clerk API request. Prefer the CLI over raw HTTP: it handles auth, key resolution, app/instance targeting, and formatting automatically.
license
MIT

Clerk CLI

The clerk binary is a pre-authenticated gateway to Clerk's Backend API and Platform API, plus project-level tooling (auth, linking, env pulls, instance config). When the user asks anything that touches a Clerk resource, reach for clerk first instead of hand-rolling curl.

This skill targets clerk latest. If clerk --version disagrees with the latest available CLI, refresh it with clerk update, or invoke the latest through a package runner such as bunx clerk@latest. The binary is always the source of truth, so run clerk <command> --help to verify anything this skill claims.

Execution environment (prefer the host, understand the sandbox warning)

Most AI coding agents default to running shell commands in a sandbox where the user's home directory, OS keychain, browser launch, localhost callback binding, or network access may be blocked. The Clerk CLI depends on all of those host capabilities:

  • OS credential store: clerk auth login stores the OAuth token in the system keychain. A sandbox without keychain access reports "not logged in" even when the host is authenticated.
  • Home-directory Clerk state: saved config, cached metadata, and fallback credentials live under the user's Clerk config/data directories.
  • Linked project metadata: resolved from the repo's git remote plus Clerk config. Sandboxes with stripped repo state or blocked home-dir reads can misreport "not linked".
  • Local .env* files: publishable and secret keys materialized by clerk env pull.
  • Outbound network access to Clerk: every Backend and Platform API call.
  • Browser + localhost OAuth callback: clerk auth login needs both.

In agent mode, the CLI now does a best-effort warn-once check at the host-sensitive library boundaries. When it detects that host-only Clerk state or system capabilities are unavailable, it emits:

text
Host-only Clerk state or system capabilities may be unavailable in agent mode. This may be a sandboxed run.
Re-run this command on the host shell before trusting auth, link, env, or API failures.

Treat that warning as authoritative. The command may continue, but any auth, link, env, config, API, browser, or OAuth callback failure from that invocation is untrusted until you rerun the same command on the host.

Prefer these commands on the user's host shell, not in a sandbox:

clerk doctor, clerk whoami, clerk auth login, clerk link, clerk env pull, clerk apps ..., clerk config ..., clerk api ....

If a command was accidentally run in a sandbox and it reports Not logged in, auth_required, not linked, missing env, keychain/file permission errors, or network failures, do not treat the result as authoritative. Rerun it on the host before acting on it or reporting it to the user.

Invoking the CLI

Before running any clerk command, figure out which binary to invoke and bind that choice for the rest of the session:

sh
# 1. Prefer a globally installed binary when it matches the skill's target version.
command -v clerk >/dev/null 2>&1 && clerk --version

If that prints latest or any version you trust, use bare clerk for the rest of the session.

Otherwise fall back to a package runner, in this order (matches the CLI's own preferredRunner logic, which prefers the runner that matches the project's lockfile):

Project package managerInvocation
bun (bun.lock*)bunx clerk@latest
npm (package-lock.json)npx -y clerk@latest
pnpm (pnpm-lock.yaml)pnpm dlx clerk@latest
yarn >= 2 (yarn.lock)yarn dlx clerk@latest

Yarn Classic (v1) has no dlx; treat those projects as "no preferred runner" and fall back to the first runner from the list above that's on PATH.

The published npm package is clerk, not @clerk/cli. Never teach npm install -g clerk as the primary path. If the global CLI is stale or behaves differently from this skill, either upgrade the global install or fall back to the latest runner form above.

Prerequisites (run at session start)

Before running any other Clerk command in a session, verify the CLI is authenticated, linked, and healthy:

sh
clerk --version               # confirm the binary is on PATH
clerk doctor --json           # structured health check; exit 1 if anything failed

Always run clerk doctor --json first. It catches the common setup failures (not logged in, project not linked, missing keys, stale CLI version) up front, so later commands don't fail with confusing errors. In agent mode it also includes a Host execution check that warns when Clerk's host-side config / credential directories are not writable, which is the canonical signal that the current invocation is likely sandboxed.

Each result has name, status (pass/warn/fail), message, optional detail, optional remedy (how to fix it), and optional fix (label for auto-fixable issues). Parse that and act on it, or surface it to the user. If Host execution warns, rerun the command on the host before trusting any auth/link/env/API failures from the same sandboxed run. Rerun clerk doctor --json whenever a later command starts misbehaving.

If clerk --version reports a newer CLI than this skill covers, trust clerk <command> --help first and refresh this skill bundle from its source.

The mental model

LayerWhat it doesCommands
Session / projectAuth, link a repo to a Clerk app, pull env keysauth login, link, unlink, whoami, env pull, doctor
Instance configManage the configuration (social providers, session lifetimes, etc.) for a specific instanceconfig pull, config schema, config patch, config put
Backend API (default)Runtime data: users, orgs, sessions, invitations, JWT templates, webhooksclerk api <path>
Platform API (--platform)Account-level: applications, instances, billingclerk api --platform <path>
Frontend API (--fapi)The instance's public client-facing API (what clerk-js calls)clerk api --fapi <path>

A project is "linked" to an application via clerk link. Once linked, most commands auto-resolve the target app and dev instance from the repo's git remote. To target something else, pass --app <id> and/or --instance dev|prod|<instance_id>. See references/auth.md for the full resolution order.

Discover endpoints - don't memorize them

The CLI ships with the Clerk OpenAPI catalog. Always discover endpoints dynamically instead of guessing paths:

sh
clerk api ls                  # list every Backend API endpoint
clerk api ls users            # filter by keyword (matches path, summary, tag, operationId)
clerk api ls --platform apps  # list Platform API endpoints

Use this before clerk api <path>. If you don't see the endpoint you expected, it probably isn't exposed.

The clerk api command (the workhorse)

clerk api makes authenticated HTTP calls. It auto-resolves keys, auto-detects method from body presence, supports stdin, and can preview mutations with --dry-run.

sh
# GET requests
clerk api /users                                  # list users
clerk api /users/user_abc123                      # fetch one
clerk api /users?limit=5&order_by=-created_at     # query params work inline

# Mutating requests
clerk api /users -d '{"email_address":["a@b.co"]}'          # POST (auto-detected from body)
clerk api /users/user_abc123 -X PATCH -d '{"first_name":"A"}'
clerk api /users/user_abc123 -X DELETE

# Body from file or stdin
clerk api /users --file payload.json
cat payload.json | clerk api /users

# Always preview mutations first
clerk api /users/user_abc123 -X DELETE --dry-run
clerk api /users/user_abc123 -X DELETE --yes      # skip confirmation once you've verified

# Target a specific app/instance
clerk api /users --app app_abc123 --instance prod

# Include response headers when debugging
clerk api /users --include

# Platform API (account-level, not tenant data)
clerk api /v1/platform/applications --platform

# Frontend API (the instance's public client-facing API — what clerk-js calls.
# Unauthenticated; --fapi and --platform cannot be combined, --secret-key is ignored)
clerk api --fapi /environment

In human mode, clerk api with no arguments opens an interactive request builder; in agent mode it prints usage guidance and exits 0 — always pass an endpoint (or ls) explicitly from scripts.

For instance config, prefer the dedicated clerk config ... commands over raw Platform API /config paths. They handle dry-run, diffing, and confirmation more cleanly than the raw endpoint form.

Always --dry-run a mutation before running it for real. Then re-run without --dry-run (add --yes if you're sure). In agent mode, interactive confirmation is bypassed, so --dry-run is the only safety net for destructive calls.

JSON bodies must be valid JSON. The CLI validates and rejects malformed payloads.

Endpoint paths may be given with or without /v1/ prefix - both work for Backend API calls. The CLI normalizes.

See references/recipes.md for concrete patterns: listing/filtering users, creating orgs, impersonation sessions, etc.

Inspecting large outputs (do not flood your context)

users list, apps list, config pull, and most clerk api GETs return payloads that can be many kilobytes or megabytes. Production tenants commonly have thousands of users; an instance config can be hundreds of fields deep. Reading those responses into the conversation costs context window for no benefit. Save the response to a file first, then query just what you need with jq:

sh
# 1. Persist the response. Use --limit 250 to maximize page size for users list.
clerk users list --json --limit 250 > /tmp/users.json
clerk apps list --json                > /tmp/apps.json
clerk api /users/user_abc123          > /tmp/user.json

# 2. Inspect only what you need.
jq '.data | length'                       /tmp/users.json   # current page size
jq '.hasMore'                             /tmp/users.json   # are more pages available?
jq '.data[0] | keys'                      /tmp/users.json   # discover the user shape once
jq '.data[] | {id, email_addresses}'      /tmp/users.json   # project to a few fields
jq '[.data[] | select(.banned)] | length' /tmp/users.json   # aggregate without reading rows

If jq is not available, fall back to Python or Node - both can stream the file without printing it whole:

sh
python3 -c 'import json; d=json.load(open("/tmp/users.json")); print(len(d["data"]), d["hasMore"])'
node -e 'const d=require("/tmp/users.json"); console.log(d.data.length, d.hasMore)'

cat / head the file only when you genuinely need to see the raw structure for one-off debugging. When walking pages, write each page to its own file (e.g. page-${offset}.json) so individual pages stay independently inspectable.

Core commands at a glance

CommandPurposeKey flags
clerk initScaffold Clerk into a project. --starter only supports bootstrap for Next.js, React Router, Astro, Nuxt, TanStack Start, React, Vue, and JavaScript.--framework, --pm, --name (with --starter), --app, --starter, -y, --no-skills
clerk auth loginOAuth browser login (stores token). Agent mode: no-op if already logged in. With no stored session it still opens a browser and binds a localhost callback, so it is not unattended; prefer CLERK_PLATFORM_API_KEY for headless flows. Aliases: signup, signin, sign-in. Top-level shortcut: clerk login.-
clerk auth logoutClear stored credentials. Aliases: signout, sign-out. Top-level shortcut: clerk logout.-
clerk whoamiPrint the logged-in email.-
clerk link / clerk unlinkLink this repo to a Clerk app, or remove the link. unlink requires --yes in agent mode.(see --help)
clerk env pullWrite publishable + secret keys to the framework's env file (merge, not clobber). Resolves .env.development.local → framework-preferred file → .env.local; override with --file.(see --help)
clerk config {pull,schema}Fetch instance config JSON, or its JSON Schema.(see --help)
clerk config patchPartial update (PATCH) of instance config. Pass --destructive to actually delete sub-resources touched by the patch rather than resetting them to defaults.--app, --instance, --file, --json, --dry-run, --yes, --destructive
clerk config putFull replacement (PUT) of instance config. Pass --destructive to actually delete removed sub-resources rather than resetting them to defaults.--app, --instance, --file, --json, --dry-run, --yes, --destructive
clerk apps {list,create}List or create Clerk applications. Defaults to JSON in agent mode.(see --help)
clerk users (no subcommand)Interactive picker for users actions in human mode; in agent mode prints the action list and exits 2. Always pass an explicit subcommand from agents.--app, --instance, --secret-key
clerk users listList users via curated BAPI flags. JSON output (default when piped or in agent mode) is {data, hasMore} so callers can paginate without /users/count. --limit defaults to 100 (max 250).--limit, --offset, --query, --email-address, --phone-number, --username, --user-id, --external-id, --order-by, --json, --app, --instance, --secret-key
clerk users createCreate a user from curated flags or a raw BAPI body. No confirmation prompt in any mode - it writes immediately. --yes is accepted but has no effect. --dry-run is the only safety net; preview with it first.--email, --phone, --username, --password, --first-name, --last-name, --external-id, -d, --data, --file, --dry-run, --yes, --json
clerk users open [user-id]Open a user's dashboard page. Agent mode requires user-id and prints a JSON descriptor instead of launching a browser.(see --help)
clerk impersonate [user]Sign in as a user for debugging: creates a short-lived actor token and prints the sign-in URL. Alias: clerk imp. Requires clerk auth login (no --secret-key-only bypass) — every token is stamped cli:<email> for auditability. [user] accepts a user_... ID, exact email, or fuzzy search term. On production it bypasses the user's MFA and may count against the impersonation quota — confirm with the user first.--print, --open, --yes, --expires-in <seconds> (default 3600), --actor <context>, --app, --instance
clerk impersonate revoke <actor-token-id>Revoke a pending actor token. The token id is printed only at creation (the Backend API has no actor-token list endpoint), so capture it then.--app, --instance
clerk open [subpath]Open the linked app's dashboard in a browser. Agent mode: prints a JSON descriptor instead of opening.(see --help)
clerk deployHuman-mode production deploy wizard. Agent mode: emits a read-only JSON handoff and tells the agent whether to ask the human to run the wizard, wait for provisioning, finish OAuth, or do nothing.--mode agent, --mode human, --verbose
clerk deploy statusRead-only deploy verification. Triggers a DNS check, reports aggregate domain and OAuth readiness, and exits 0 only when complete. Agent mode does one quick check by default; pass --wait to keep waiting.--mode agent, --wait, --verbose
clerk webhooks listenFirst-party local webhook tunnel (like stripe listen): opens a Svix relay inbox URL and forwards each delivery to your local handler. No auth, no linked project, no Clerk API. Full flow in references/recipes.md.--forward-to <url> (required), --token <c_token>, -H, --header <k:v> (repeatable), --json (NDJSON)
clerk webhooks tokenMint a relay token (c_ + 10 base62 chars) to pin a stable listen inbox URL across machines: clerk webhooks listen --token "$(clerk webhooks token)" --forward-to ....--json
clerk webhooks verifyVerify a webhook signature offline (pure local HMAC, no auth): from a saved listen event line (--delivery @event.json) or from the four raw values.--secret <whsec> (required), --delivery @file, --payload @file, --id, --timestamp, --signature, --json
clerk enable orgs / clerk disable orgsToggle Organizations on the instance. For org features, components, and API usage, see the clerk-orgs skill.--force-selection, --auto-create, --max-members <n>, --domains, --dry-run, --yes, --app, --instance
clerk enable billing / clerk disable billingToggle billing for users and/or orgs (defaults to both). For plans, pricing components, and entitlements, see the clerk-billing skill.--for <orgs|users>, --dry-run, --yes, --no-skills (enable only), --app, --instance
clerk doctorHealth check (CLI version, login, link, env, config, completion; plus host-execution probe in agent mode).--json, --spotlight, --verbose, --fix
clerk api [path]Authenticated HTTP to Backend/Platform API.-X, -d, --file, --dry-run, --yes, --include, --app, --secret-key, --instance, --platform
clerk api ls [filter]Discover endpoints from the bundled OpenAPI catalog.(see --help)
clerk completion [shell]Print a shell completion script (bash, zsh, fish, powershell).-
clerk updateUpdate the CLI to the latest version.--channel, -y, --all

clerk <command> --help is the source of truth for flags. This table is a hint, not a spec. Before running an unfamiliar command or flag combination, run clerk <command> --help once per session. Every command also defines setExamples([...]) in source, which --help renders as a copy-pasteable Examples block, so you rarely need to guess syntax.

Show full SKILL.md (831 more words)Show less

Agent-mode behavior (important)

The CLI auto-detects agent mode when stdout is not a TTY, or when --mode agent / CLERK_MODE=agent is set. In agent mode:

  • Interactive prompts are disabled. Commands that would normally show pickers (link without --app, unlink without --yes, users without a subcommand) either auto-resolve or exit with a usage error. clerk api with no args prints usage guidance and exits 0; pass an endpoint (or ls) explicitly. Always pass explicit flags (--app, --yes) in scripted calls.
  • Host-sensitive operations emit a sandbox warning once per invocation. Home-directory Clerk state, keychain access, networked Clerk calls, browser launch, and localhost OAuth callback setup can trigger the warning shown above. If it appears, rerun the same command on the host before trusting the result.
  • If your harness does not clearly present as agent mode, force it. Use --mode agent or CLERK_MODE=agent when you want the CLI's non-interactive behavior and sandbox warning path to apply deterministically.
  • link supports deterministic agent flows. In agent mode, clerk link --app <id> links directly. Without --app, the CLI will try silent key-based autolink first; if it cannot determine the app unambiguously, it exits and tells you to pass --app.
  • init never selects or creates a real Clerk app for you in agent mode unless authenticated or given a target. Pass --app <id> (or pre-link the project) to authenticate and link a real app, or pass --keyless to use auto-generated temporary development keys when bootstrapping a new project on a keyless-capable framework. Without either, agent mode prints manual setup guidance and exits cleanly.
  • unlink requires --yes in agent mode. It gates on isAgent() && !options.yes and exits with a usage error without it. This is the exception, not the pattern - see the next bullet.
  • Only unlink actually requires --yes. Every other confirmation gate is written as isHuman() && !options.yes, so agent mode skips it outright: the mutation executes with no prompt and no error. Passing --yes is harmless but changes nothing. Do not treat it as a safety gate - --dry-run is the real one.
  • impersonate requires the [user] positional in agent mode. If a search term matches multiple users, it exits 2 listing candidate user IDs — retry with a specific user_... ID. Output is a JSON object ({url, id, userId, actor, ...}); surface url to the user and capture id — it is the only chance to record the revoke handle.
  • webhooks listen is long-running. Run it in the background. In agent mode (or with --json) it emits NDJSON: one ready line ({type:"ready", relay_url, forward_to}), then one event line per delivery — each event line can be fed back to clerk webhooks verify --delivery.
  • doctor --fix is ignored. Parse doctor --json output's remedy field and act on it yourself.
  • apps list and apps create default to JSON when piped.
  • users defaults to JSON when piped, like apps. clerk users list and clerk users create emit JSON in agent mode. Bare clerk users (no subcommand) is a usage error in agent mode - pass list, create, or open explicitly. clerk users open requires the user-id positional in agent mode and prints a JSON descriptor instead of launching a browser.
  • deploy has an agent handoff plus a verification gate. In agent mode, bare clerk deploy is read-only and emits a JSON handoff. It never drives the interactive wizard. Do not tell Claude or another agent to run ! clerk deploy, because the wizard needs interactive stdin prompts. Ask the human to run clerk deploy in a new terminal window when needed, then run clerk deploy status --mode agent to verify completion. See references/agent-mode.md.
  • --input-json <json|@file|-> expands JSON into flags on any command (e.g. clerk init --input-json '{"framework":"next","yes":true}'). Stdin needs the explicit - marker (echo '{"yes":true}' | clerk init --input-json -); bare piped stdin is not auto-detected, so shell loops and self-reading commands (cat body.json | clerk api …) are untouched. Place --input-json after the leaf subcommand. Full rules in references/agent-mode.md.

Full matrix and sandbox details in references/agent-mode.md.

Output format and errors

  • JSON output: --json on apps list and doctor. For clerk api, the response body is the raw API JSON, so pipe into jq freely.
  • Exit codes: 0 success, 1 runtime error, 2 usage/validation error. doctor returns 1 if any check failed.
  • Error format: User-facing errors print a single line to stderr and set a non-zero exit code. Use --verbose for stack traces when debugging.

Safety rules for autonomous use

  1. Discover before acting: clerk api ls <keyword> before clerk api <path>.
  2. Preview mutations: --dry-run on every config patch, config put, api -X POST/PATCH/PUT/DELETE.
  3. Target explicitly in production: pass --instance prod rather than relying on defaults, and confirm with the user before any production mutation.
  4. Never commit secrets: env pull writes to .env.local (which should be gitignored). Don't paste secret keys into code or chat.
  5. Use doctor --json to diagnose before assuming the CLI is broken.

References

© geekskai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .agents/skills/clerk-cli of geekskai/blog.

  • SKILL.md
  • references/agent-mode.md
  • references/auth.md
  • references/recipes.md

Open the folder on GitHubat commit e5554c5

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in geekskai/blog, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Clerk CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clerk CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clerk CLI this skillgeekskai/blog1032 repos~8.8kAutomated safety check: NotesMIT
API Patternsdilolabs/nosia2131 repos~2.5kAutomated safety check: PassMIT
GitHub OAuth Nango IntegrationAgentWorkforce/relay8661 repos~3.4kAutomated safety check: PassApache-2.0
Pii DetectorgoSprinto/compliance-skills133—~1.6kAutomated safety check: PassMIT
Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~3.2kAutomated safety check: PassMIT
Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~4kAutomated safety check: PassMIT

Similar skills

  • API Patterns

    dilolabs/nosia

    Builds REST APIs using respondto blocks with Jbuilder templates following the 37signals same-controllers-different-formats philosophy.

    213 GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check passed
  • GitHub OAuth Nango Integration

    AgentWorkforce/relay

    A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling

    866 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • Pii Detector

    goSprinto/compliance-skills

    Proactive PII add-on — augments the main response with PII guidance.

    133 GitHub stars~1.6k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Frappe Core API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.

    187 GitHub starsUsed in 1 repo~3.2k tokens
    Backend & APIsAuto-check passed
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    187 GitHub starsUsed in 1 repo~4k tokens
    Backend & APIsAuto-check passed
  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    256 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed

More from geekskai/blog

All 20 skills in this repo
  • Clerk Android

    geekskai/blog

    Implement Clerk authentication for native Android apps using Kotlin and Jetpack Compose with clerk-android source-guided patterns.

    103 GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • React SPA auth patterns with @clerk/react for Vite/CRA - ClerkProvider setup, useAuth/useUser/useClerk hooks, React Router protected routes, custom sign-in flows.

    103 GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • React Router v7/v8 patterns with Clerk — rootAuthLoader, getAuth in loaders, clerkMiddleware, protected routes, SSR user data, org switching.

    103 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • TanStack React Start auth patterns with @clerk/tanstack-react-start - createServerFn, beforeLoad guards, loaders, Vinxi server.

    103 GitHub starsUsed in 1 repo~875 tokens
    Auto-check: notes
  • Astro patterns with Clerk — middleware, SSR pages, island components, API routes, static vs SSR rendering.

    103 GitHub stars~822 tokensUpdated yesterday
    Auto-check: notes
  • Clerk Billing

    geekskai/blog

    Clerk Billing for subscription management - render Clerk's PricingTable and in-app checkout drawer, configure subscription plans, seat-limit plans for B2B, feature entitlements with has(), and…

    103 GitHub stars~5.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Clerk CLI

What does Clerk CLI do?

Operate the Clerk CLI (clerk binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any…. Clerk CLI is an agent skill from geekskai/blog. Operate the Clerk CLI (clerk binary) for authentication, user/org/session management, impersonation, local webhook testing, deploy verification, instance config, env keys, feature toggles, and any Clerk Backend, Platform, or Frontend API call.

When should I use Clerk CLI?

Clerk CLI fits situations like: the user mentions Clerk management tasks; list clerk users; impersonate a user; test webhooks locally.

How do I install Clerk CLI in Claude Code?

Run `npx skills add geekskai/blog --skill clerk-cli -a claude-code`. Or copy the skill folder (.agents/skills/clerk-cli in geekskai/blog) into .claude/skills/clerk-cli in your project. Claude Code loads it when a task matches its description.

How do I install Clerk CLI in Codex?

Run `npx skills add geekskai/blog --skill clerk-cli -a codex`. Or copy the skill folder (.agents/skills/clerk-cli in geekskai/blog) into .agents/skills/clerk-cli in your project. Codex loads it when a task matches its description.

Can I use Clerk CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add geekskai/blog --skill clerk-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clerk-cli, .gemini/skills/clerk-cli, .github/skills/clerk-cli and .opencode/skills/clerk-cli in your project.

What does Clerk CLI need to run?

Going by SKILL.md and its folder, Clerk CLI needs the command-line tools its instructions call (jq, bunx, python3, node, npx and pnpm) and credentials named CLERK_PLATFORM_API_KEY. Our summary lists: Python 3; Node.js.

Does Clerk CLI access the network?

SKILL.md contains no URLs. Its commands use npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Clerk CLI safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Clerk CLI use?

Clerk CLI is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clerk CLI use?

About 8.8k tokens (SKILL.md is roughly 35k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Clerk CLI?

Skills that share tags, products or a category with Clerk CLI: API Patterns (dilolabs/nosia, 213 stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 866 stars), Pii Detector (goSprinto/compliance-skills, 133 stars) and Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clerk CLI?

geekskai (a GitHub user) maintains it in geekskai/blog, which has 103 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 7, 2026.

Source: geekskai/blog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.