Agent skill

Clerk Enterprise Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Configure enterprise SSO, role-based access control, and organization management.

MITAuto-check passedBackend & APIs

Install Clerk Enterprise Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill clerk-enterprise-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace clerk-enterprise-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/clerk-enterprise-rbac .claude/skills/clerk-enterprise-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clerk-enterprise-rbac
GitHub stars
2.8k
Token cost
~3k tokens
SKILL.md length
486 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Configure enterprise SSO, role-based access control, and organization management.

  • Works in 8 steps: Enable Organizations and Add UI Components → Define Custom Roles and Permissions → RBAC Middleware — Route Protection by Role → …
  • Implementing SSO integration
  • SKILL.md covers Overview, Prerequisites, Instructions and Error Handling, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Clerk Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure enterprise SSO, role-based access control, and organization management. Use when implementing SSO integration, configuring role-based permissions, or setting up organization-level controls. Trigger with phrases like "clerk SSO", "clerk RBAC", "clerk enterprise", "clerk roles", "clerk permissions", "clerk organizations".

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/implementation-guide.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authorization and RBAC and Authentication. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Implementing SSO integration
  • Configuring role-based permissions
  • Setting up organization-level controls
  • With phrases like clerk SSO

Example prompts

  • “clerk SSO”
  • “clerk RBAC”
  • “clerk enterprise”
  • “/clerk-enterprise-rbac”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Enable Organizations and Add UI Components
  2. Define Custom Roles and Permissions
  3. RBAC Middleware — Route Protection by Role
  4. Permission Checks in Server Components
  5. Permission Checks in Client Components
  6. Organization Member Management via Backend API
  7. Programmatic Role/Permission Management (Backend API)
  8. SAML SSO Configuration

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • clerk.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Clerk Enterprise Rbac loads about 3k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 486 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 486 words, ~2,954 tokens.

Download SKILL.mdSave it as .claude/skills/clerk-enterprise-rbac/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
clerk-enterprise-rbac
description
Configure enterprise SSO, role-based access control, and organization management. Use when implementing SSO integration, configuring role-based permissions, or setting up organization-level controls. Trigger with phrases like "clerk SSO", "clerk RBAC", "clerk enterprise", "clerk roles", "clerk permissions", "clerk organizations".
allowed-tools
Read, Write, Edit, Grep
compatibility
Designed for Claude Code
version
1.15.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, clerk, rbac, enterprise, organizations

Clerk Enterprise RBAC

Overview

Implement enterprise-grade role-based access control, organization management, and SSO with Clerk. Covers custom roles and permissions, organization lifecycle, multi-tenant access patterns, SAML/OIDC SSO, and the Backend API for programmatic role management (released Nov 2025).

Prerequisites

  • Clerk Pro or Enterprise plan (Organizations + SSO require paid plan)
  • Organizations feature enabled in Clerk Dashboard > Organizations > Settings
  • Next.js 14+ with App Router (examples use @clerk/nextjs)

Instructions

Step 1: Enable Organizations and Add UI Components
typescript
// app/org-selector/page.tsx
import { OrganizationSwitcher, OrganizationProfile } from '@clerk/nextjs'

export default function OrgPage() {
  return (
    <div className="p-8">
      <h1>Select Organization</h1>
      <OrganizationSwitcher
        hidePersonal={false}
        afterSelectOrganizationUrl="/dashboard"
        afterCreateOrganizationUrl="/dashboard"
      />
      <div className="mt-8">
        <OrganizationProfile />
      </div>
    </div>
  )
}
Step 2: Define Custom Roles and Permissions

Configure in Clerk Dashboard > Organizations > Roles and Permissions.

Default roles (built-in):

RoleKeyBuilt-in Permissions
Adminorg:adminFull org management (members, settings, billing)
Memberorg:memberView org, read-only access

Custom permissions (create in Dashboard > Organizations > Permissions):

PermissionKeyDescription
Read dataorg:data:readView organization resources
Write dataorg:data:writeCreate/update resources
Delete dataorg:data:deleteDelete resources
Manage billingorg:billing:manageAccess billing settings
View analyticsorg:analytics:readAccess analytics dashboard

Custom roles (create in Dashboard > Organizations > Roles):

RolePermissionsUse Case
org:managerdata:read, data:write, analytics:readContent managers
org:viewerdata:readRead-only stakeholders
org:billing_admindata:read, billing:manageFinance team
Step 3: RBAC Middleware — Route Protection by Role
typescript
// middleware.ts
import { clerkMiddleware, createRouteMatcher } from '@clerk/nextjs/server'

const isPublicRoute = createRouteMatcher([
  '/',
  '/sign-in(.*)',
  '/sign-up(.*)',
  '/api/webhooks(.*)',
])
const isAdminRoute = createRouteMatcher(['/admin(.*)'])
const isManagerRoute = createRouteMatcher(['/manage(.*)'])

export default clerkMiddleware(async (auth, req) => {
  if (isPublicRoute(req)) return

  if (isAdminRoute(req)) {
    // Only org:admin can access /admin/*
    await auth.protect({ role: 'org:admin' })
  } else if (isManagerRoute(req)) {
    // org:admin OR org:manager can access /manage/*
    await auth.protect((has) =>
      has({ role: 'org:admin' }) || has({ role: 'org:manager' })
    )
  } else {
    // All other routes just require authentication
    await auth.protect()
  }
})
Step 4: Permission Checks in Server Components
typescript
// app/admin/page.tsx
import { auth } from '@clerk/nextjs/server'
import { redirect } from 'next/navigation'

export default async function AdminPage() {
  const { userId, orgId, orgRole, has } = await auth()

  if (!userId) redirect('/sign-in')
  if (!orgId) redirect('/org-selector')

  // Permission-based checks (preferred over role-based)
  const canManageMembers = has({ permission: 'org:sys_memberships:manage' })
  const canWriteData = has({ permission: 'org:data:write' })
  const canDeleteData = has({ permission: 'org:data:delete' })
  const canViewAnalytics = has({ permission: 'org:analytics:read' })

  return (
    <div>
      <h1>Admin Panel</h1>
      <p>Current role: {orgRole}</p>

      <nav>
        {canManageMembers && <a href="/admin/members">Manage Members</a>}
        {canWriteData && <a href="/admin/content">Content Management</a>}
        {canDeleteData && <a href="/admin/danger-zone">Danger Zone</a>}
        {canViewAnalytics && <a href="/admin/analytics">Analytics</a>}
      </nav>
    </div>
  )
}
Step 5: Permission Checks in Client Components
typescript
'use client'
import { Protect, useOrganization, useAuth } from '@clerk/nextjs'

export function AdminSection() {
  const { organization } = useOrganization()
  const { has } = useAuth()

  return (
    <div>
      <h2>{organization?.name}</h2>

      {/* Declarative: Protect component with fallback */}
      <Protect
        role="org:admin"
        fallback={<p>You need admin access to view this section.</p>}
      >
        <DangerZone />
      </Protect>

      {/* Permission-based rendering */}
      <Protect permission="org:data:write">
        <EditForm />
      </Protect>

      {/* Imperative: has() for conditional logic */}
      {has?.({ permission: 'org:analytics:read' }) && (
        <AnalyticsDashboard />
      )}
    </div>
  )
}
Step 6: Organization Member Management via Backend API
typescript
// app/api/org/members/route.ts
import { auth, clerkClient } from '@clerk/nextjs/server'

export async function GET() {
  const { orgId, has } = await auth()
  if (!orgId) return Response.json({ error: 'No org selected' }, { status: 400 })
  if (!has({ permission: 'org:sys_memberships:read' })) {
    return Response.json({ error: 'Forbidden' }, { status: 403 })
  }

  const client = await clerkClient()
  const members = await client.organizations.getOrganizationMembershipList({
    organizationId: orgId,
  })

  return Response.json({
    members: members.data.map(m => ({
      userId: m.publicUserData?.userId,
      name: `${m.publicUserData?.firstName} ${m.publicUserData?.lastName}`,
      email: m.publicUserData?.identifier,
      role: m.role,
      joinedAt: m.createdAt,
    })),
  })
}

export async function POST(req: Request) {
  const { orgId, userId, has } = await auth()
  if (!orgId || !has({ permission: 'org:sys_memberships:manage' })) {
    return Response.json({ error: 'Forbidden' }, { status: 403 })
  }

  const { emailAddress, role } = await req.json()
  const client = await clerkClient()

  const invitation = await client.organizations.createOrganizationInvitation({
    organizationId: orgId,
    emailAddress,
    role: role || 'org:member',
    inviterUserId: userId!,
  })

  return Response.json({ invitation: { id: invitation.id, emailAddress, role } })
}
Step 7: Programmatic Role/Permission Management (Backend API)
typescript
// lib/org-roles.ts — manage roles and permissions via API (released Nov 2025)
import { clerkClient } from '@clerk/nextjs/server'

export async function createCustomRole(orgId: string) {
  const client = await clerkClient()

  // Create a custom permission
  await client.organizations.createOrganizationPermission({
    organizationId: orgId,
    name: 'Manage reports',
    key: 'org:reports:manage',
    description: 'Create, edit, and delete reports',
  })

  // Create a custom role with that permission
  await client.organizations.createOrganizationRole({
    organizationId: orgId,
    name: 'Report Manager',
    key: 'org:report_manager',
    description: 'Can manage all reports',
    permissions: ['org:reports:manage', 'org:data:read'],
  })
}

// Update a member's role
export async function updateMemberRole(
  orgId: string,
  userId: string,
  newRole: string
) {
  const client = await clerkClient()
  const memberships = await client.organizations.getOrganizationMembershipList({
    organizationId: orgId,
  })

  const membership = memberships.data.find(
    m => m.publicUserData?.userId === userId
  )
  if (!membership) throw new Error('User is not a member of this organization')

  await client.organizations.updateOrganizationMembership({
    organizationId: orgId,
    userId,
    role: newRole,
  })
}
Step 8: SAML SSO Configuration

Configure in Clerk Dashboard > SSO Connections > Add SAML Connection:

  1. ACS URL: https://<your-clerk-frontend-api>.clerk.accounts.dev/v1/saml/acs
  2. Entity ID: https://<your-clerk-frontend-api>.clerk.accounts.dev/v1/saml/metadata
  3. Upload IdP metadata XML from your provider (Okta, Azure AD, Google Workspace)
  4. Map SAML attributes: email, firstName, lastName
typescript
// Enforce SSO for specific email domains
// Clerk Dashboard > Organizations > Settings > "Verified domains"
// Add your company domain (e.g., acme.com)
// Users with @acme.com emails will be forced through SSO
Show full SKILL.md (233 more words)Show less

Error Handling

ErrorCauseSolution
orgId is nullNo active organizationRedirect to org selector, show <OrganizationSwitcher />
has() returns falseRole/permission not assignedCheck assignment in Dashboard > Organizations > Members
Permission denied on middlewareUser lacks required roleVerify route matcher maps to correct role
SSO login failsMisconfigured IdP metadataVerify ACS URL and Entity ID in IdP settings
Invitation failsEmail already a memberCheck membership before inviting
Custom role not visibleCreated via API, not DashboardRoles created via API are org-scoped, not instance-wide

Enterprise Considerations

  • Roles and permissions are embedded in the session JWT -- no extra network requests needed for authorization checks
  • Custom roles created in the Dashboard are instance-wide; roles created via Backend API are organization-scoped
  • For multi-tenant SaaS, combine Organizations with tenant-scoped database queries (WHERE org_id = :orgId)
  • Session claims include org_id, org_role, and org_permissions -- available in middleware without API calls
  • Verified domains + SAML SSO enable "just-in-time provisioning" -- users auto-join the org on first SSO sign-in
  • Consider the org:sys_* system permissions (sys_memberships:manage, sys_memberships:read, sys_domains:manage) for built-in org management actions

Resources

Next Steps

Proceed to clerk-migration-deep-dive for auth provider migration.

Output

  • RBAC model mapping Clerk orgs/roles/permissions to app authorization checks
  • Code or config for role gates (middleware, server actions, or API guards)
  • Escalation notes for SSO/SAML enterprise setups when in scope

Examples

Map org roles to feature access
User: Only org:billing can open the invoices page.
Skill: implements role check on the server and fails closed when claims missing.
Audit permission matrix
User: Produce a role × capability matrix for our Clerk org roles.
Skill: enumerates Clerk roles/permissions and maps them to app routes/actions.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/clerk-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/implementation-guide.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Clerk Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clerk Enterprise Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clerk Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61810 repos~4.4kAutomated safety check: PassNone
Configuration Cryptogreenpau/caddy-security2.3k—~3.5kAutomated safety check: PassApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Bkend Authww-w-ai/bkit-claude-code601—~937Automated safety check: NotesApache-2.0

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    618 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Bkend Auth

    ww-w-ai/bkit-claude-code

    bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

    601 GitHub stars~937 tokensUpdated 14 days ago
    Backend & APIsAuto-check: notes
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    756 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Clerk Enterprise Rbac

What does Clerk Enterprise Rbac do?

Configure enterprise SSO, role-based access control, and organization management. Clerk Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure enterprise SSO, role-based access control, and organization management.

When should I use Clerk Enterprise Rbac?

Clerk Enterprise Rbac fits situations like: implementing SSO integration; configuring role-based permissions; setting up organization-level controls; with phrases like clerk SSO.

How do I install Clerk Enterprise Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill clerk-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/clerk-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/clerk-enterprise-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Clerk Enterprise Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill clerk-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/clerk-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/clerk-enterprise-rbac in your project. Codex loads it when a task matches its description.

Can I use Clerk Enterprise Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill clerk-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clerk-enterprise-rbac, .gemini/skills/clerk-enterprise-rbac, .github/skills/clerk-enterprise-rbac and .opencode/skills/clerk-enterprise-rbac in your project.

What does Clerk Enterprise Rbac need to run?

SKILL.md names no scripts, command-line tools or credentials: Clerk Enterprise Rbac is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Clerk Enterprise Rbac access the network?

SKILL.md names 1 domain. As links in the text: clerk.com. This is read from the text; nothing was executed.

Is Clerk Enterprise Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clerk Enterprise Rbac use?

Clerk Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clerk Enterprise Rbac use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Clerk Enterprise Rbac?

Skills that share tags, products or a category with Clerk Enterprise Rbac: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 618 stars), Configuration Crypto (greenpau/caddy-security, 2.3k stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clerk Enterprise Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.