Agent skill

Clerk Auth

by LeoYeAI in LeoYeAI/openclaw-master-skills

Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP…

MITAuto-check: notesBackend & APIs

Install Clerk Auth

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill clerk-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills clerk-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/clerk-auth .claude/skills/clerk-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clerk-auth
GitHub stars
2.2k
Token cost
~6.1k tokens
SKILL.md length
1,736 words
Files
33 (incl. scripts, references, assets)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP…

  • Works in 9 steps: API Keys Beta (Dec 11, 2025) - NEW ✨ → Next.js 16: proxy.ts Middleware Filename… → Force Password Reset (Dec 19, 2025) → …
  • : API keys for users/orgs
  • SKILL.md covers What's New (Dec 2025 - Jan 2026), API Version 2025-11-10…, Critical Patterns & Error… and clerkMiddleware() Configuration, plus 4 more sections
  • Runs Shell and JavaScript scripts from its folder; calls node, npm and wrangler; needs CLERK_SECRET_KEY and CLERK_WEBHOOK_SIGNING_SECRET

What it does

Clerk Auth is an agent skill from LeoYeAI/openclaw-master-skills. Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference. Prevents 15 documented errors. Use when: API keys for users/orgs, Next.js 16 middleware filename, troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors, webhook verification, user type inconsistencies, or testing with 424242 OTP.

Its SKILL.md is about 6.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 39 other files, including scripts, reference files and assets (for example `.claude-plugin/plugin.json`, `README.md` and `_meta.json`).

It sits in Backend & APIs, covering Webhooks, Web application vulnerabilities and Vulnerability scanning. It works with Clerk, Next.js and Google Cloud. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • : API keys for users/orgs
  • Next.js 16 middleware filename
  • Troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors
  • Webhook verification

Example prompts

  • “/clerk-auth”

Requirements

  • Node.js
  • A Bash shell
  • A credential in CLERK_SECRET_KEY
  • A credential in CLERK_WEBHOOK_SIGNING_SECRET

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. API Keys Beta (Dec 11, 2025) - NEW ✨
  2. Next.js 16: proxy.ts Middleware Filename (Dec 2025)
  3. Force Password Reset (Dec 19, 2025)
  4. Organization Reports & Filters (Dec 15-17, 2025)
  5. API Version 2025-11-10 (Nov 10, 2025) - BREAKING CHANGES ⚠️
  6. Next.js v6 Async auth() (Oct 2024) - BREAKING CHANGE ⚠️
  7. PKCE Support for Custom OAuth (Nov 12, 2025)
  8. Client Trust: Credential Stuffing Defense (Nov 14, 2025)
  9. Next.js 16 Support (Nov 2025)

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell and JavaScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm
    • wrangler

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • clerk.com
    • github.com
    • stackoverflow.com
    • status.clerk.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLERK_SECRET_KEY
    • CLERK_WEBHOOK_SIGNING_SECRET
    • CLERK_JWT_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clerk Auth loads about 6.1k tokens when it runs, and up to ~18k if it reads all its reference files. Until then it costs about 119 tokens; SKILL.md has 1,736 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~6.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~18k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:519
    **Prevention**: Always set in `.env.local` or via `wrangler secret put`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,736 words, ~6,077 tokens.

Download SKILL.mdSave it as .claude/skills/clerk-auth/SKILL.md (or your agent's skills folder). This skill also uses 32 other files; get the full folder from GitHub.
name
clerk-auth
description
Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference. Prevents 15 documented errors. Use when: API keys for users/orgs, Next.js 16 middleware filename, troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors, webhook verification, user type inconsistencies, or testing with 424242 OTP.
user-invocable
true

Clerk Auth - Breaking Changes & Error Prevention Guide

Package Versions: @clerk/nextjs@6.36.7, @clerk/backend@2.29.2, @clerk/clerk-react@5.59.2, @clerk/testing@1.13.26 Breaking Changes: Nov 2025 - API version 2025-11-10, Oct 2024 - Next.js v6 async auth() Last Updated: 2026-01-09


What's New (Dec 2025 - Jan 2026)

1. API Keys Beta (Dec 11, 2025) - NEW ✨

User-scoped and organization-scoped API keys for your application. Zero-code UI component.

typescript
// 1. Add the component for self-service API key management
import { APIKeys } from '@clerk/nextjs'

export default function SettingsPage() {
  return (
    <div>
      <h2>API Keys</h2>
      <APIKeys />  {/* Full CRUD UI for user's API keys */}
    </div>
  )
}

Backend Verification:

typescript
import { verifyToken } from '@clerk/backend'

// API keys are verified like session tokens
const { data, error } = await verifyToken(apiKey, {
  secretKey: process.env.CLERK_SECRET_KEY,
  authorizedParties: ['https://yourdomain.com'],
})

// Check token type
if (data?.tokenType === 'api_key') {
  // Handle API key auth
}

clerkMiddleware Token Types:

typescript
// v6.36.0+: Middleware can distinguish token types
clerkMiddleware((auth, req) => {
  const { userId, tokenType } = auth()

  if (tokenType === 'api_key') {
    // API key auth - programmatic access
  } else if (tokenType === 'session_token') {
    // Regular session - web UI access
  }
})

Pricing (Beta = Free):

  • Creation: $0.001/key
  • Verification: $0.0001/verification
2. Next.js 16: proxy.ts Middleware Filename (Dec 2025)

⚠️ BREAKING: Next.js 16 changed middleware filename due to critical security vulnerability (CVE disclosed March 2025).

Background: The March 2025 vulnerability (affecting Next.js 11.1.4-15.2.2) allowed attackers to completely bypass middleware-based authorization by adding a single HTTP header: x-middleware-subrequest: true. This affected all auth libraries (NextAuth, Clerk, custom solutions).

Why the Rename: The middleware.ts → proxy.ts change isn't just cosmetic - it's Next.js signaling that middleware-first security patterns are dangerous. Future auth implementations should not rely solely on middleware for authorization.

Next.js 15 and earlier: middleware.ts
Next.js 16+:            proxy.ts

Correct Setup for Next.js 16:

typescript
// src/proxy.ts (NOT middleware.ts!)
import { clerkMiddleware } from '@clerk/nextjs/server'

export default clerkMiddleware()

export const config = {
  matcher: [
    '/((?!_next|[^?]*\\.(?:html?|css|js(?!on)|jpe?g|webp|png|gif|svg|ttf|woff2?|ico|csv|docx?|xlsx?|zip|webmanifest)).*)',
    '/(api|trpc)(.*)',
  ],
}

Minimum Version: @clerk/nextjs@6.35.0+ required for Next.js 16 (fixes Turbopack build errors and cache invalidation on sign-out).

3. Force Password Reset (Dec 19, 2025)

Administrators can mark passwords as compromised and force reset:

typescript
import { clerkClient } from '@clerk/backend'

// Force password reset for a user
await clerkClient.users.updateUser(userId, {
  passwordDigest: 'compromised',  // Triggers reset on next sign-in
})
4. Organization Reports & Filters (Dec 15-17, 2025)

Dashboard now includes org creation metrics and filtering by name/slug/date.


API Version 2025-11-10 Breaking Changes

1. API Version 2025-11-10 (Nov 10, 2025) - BREAKING CHANGES ⚠️

Affects: Applications using Clerk Billing/Commerce APIs

Critical Changes:

  • Endpoint URLs: /commerce/ → /billing/ (30+ endpoints)

    GET /v1/commerce/plans → GET /v1/billing/plans
    GET /v1/commerce/statements → GET /v1/billing/statements
    POST /v1/me/commerce/checkouts → POST /v1/me/billing/checkouts
  • Field Terminology: payment_source → payment_method

    typescript
    // OLD (deprecated)
    { payment_source_id: "...", payment_source: {...} }
    
    // NEW (required)
    { payment_method_id: "...", payment_method: {...} }
  • Removed Fields: Plans responses no longer include:

    • amount, amount_formatted (use fee.amount instead)
    • currency, currency_symbol (use fee objects)
    • payer_type (use for_payer_type)
    • annual_monthly_amount, annual_amount
  • Removed Endpoints:

    • Invoices endpoint (use statements)
    • Products endpoint
  • Null Handling: Explicit rules - null means "doesn't exist", omitted means "not asserting existence"

Migration: Update SDK to v6.35.0+ which includes support for API version 2025-11-10.

Official Guide: https://clerk.com/docs/guides/development/upgrading/upgrade-guides/2025-11-10

2. Next.js v6 Async auth() (Oct 2024) - BREAKING CHANGE ⚠️

Affects: All Next.js Server Components using auth()

typescript
// ❌ OLD (v5 - synchronous)
const { userId } = auth()

// ✅ NEW (v6 - asynchronous)
const { userId } = await auth()

Also affects: auth.protect() is now async in middleware

typescript
// ❌ OLD (v5)
auth.protect()

// ✅ NEW (v6)
await auth.protect()

Compatibility: Next.js 15, 16 supported. Static rendering by default.

3. PKCE Support for Custom OAuth (Nov 12, 2025)

Custom OIDC providers and social connections now support PKCE (Proof Key for Code Exchange) for enhanced security in native/mobile applications where client secrets cannot be safely stored.

Use case: Mobile apps, native apps, public clients that can't securely store secrets.

4. Client Trust: Credential Stuffing Defense (Nov 14, 2025)

Automatic secondary authentication when users sign in from unrecognized devices:

  • Activates for users with valid passwords but no 2FA
  • No configuration required
  • Included in all Clerk plans

How it works: Clerk automatically prompts for additional verification (email code, backup code) when detecting sign-in from new device.

5. Next.js 16 Support (Nov 2025)

@clerk/nextjs v6.35.2+ includes cache invalidation improvements for Next.js 16 during sign-out.


Critical Patterns & Error Prevention

Next.js v6: Async auth() Helper

Pattern:

typescript
import { auth } from '@clerk/nextjs/server'

export default async function Page() {
  const { userId } = await auth()  // ← Must await

  if (!userId) {
    return <div>Unauthorized</div>
  }

  return <div>User ID: {userId}</div>
}
Cloudflare Workers: authorizedParties (CSRF Prevention)

CRITICAL: Always set authorizedParties to prevent CSRF attacks

typescript
import { verifyToken } from '@clerk/backend'

const { data, error } = await verifyToken(token, {
  secretKey: c.env.CLERK_SECRET_KEY,
  // REQUIRED: Prevent CSRF attacks
  authorizedParties: ['https://yourdomain.com'],
})

Why: Without authorizedParties, attackers can use valid tokens from other domains.

Source: https://clerk.com/docs/reference/backend/verify-token


clerkMiddleware() Configuration

Route Protection Patterns
typescript
import { clerkMiddleware, createRouteMatcher } from '@clerk/nextjs/server'

// Define protected routes
const isProtectedRoute = createRouteMatcher([
  '/dashboard(.*)',
  '/api/private(.*)',
])

const isAdminRoute = createRouteMatcher(['/admin(.*)'])

export default clerkMiddleware(async (auth, req) => {
  // Protect routes
  if (isProtectedRoute(req)) {
    await auth.protect()  // Redirects unauthenticated users
  }

  // Require specific permissions
  if (isAdminRoute(req)) {
    await auth.protect({
      role: 'org:admin',  // Requires organization admin role
    })
  }
})
All Middleware Options
OptionTypeDescription
debugbooleanEnable debug logging
jwtKeystringJWKS public key for networkless verification
clockSkewInMsnumberToken time variance (default: 5000ms)
organizationSyncOptionsobjectURL-based org activation
signInUrlstringCustom sign-in URL
signUpUrlstringCustom sign-up URL
Organization Sync (URL-based Org Activation)

⚠️ Next.js Only: This feature currently only works with clerkMiddleware() in Next.js. It does NOT work with authenticateRequest() in other runtimes (Cloudflare Workers, Express, etc.) due to Sec-Fetch-Dest header checks.

Source: GitHub Issue #7178

typescript
clerkMiddleware({
  organizationSyncOptions: {
    organizationPatterns: ['/orgs/:slug', '/orgs/:slug/(.*)'],
    personalAccountPatterns: ['/personal', '/personal/(.*)'],
  },
})

Webhooks

Webhook Verification
typescript
import { Webhook } from 'svix'

export async function POST(req: Request) {
  const payload = await req.text()
  const headers = {
    'svix-id': req.headers.get('svix-id')!,
    'svix-timestamp': req.headers.get('svix-timestamp')!,
    'svix-signature': req.headers.get('svix-signature')!,
  }

  const wh = new Webhook(process.env.CLERK_WEBHOOK_SIGNING_SECRET!)

  try {
    const event = wh.verify(payload, headers)
    // Process event
    return Response.json({ success: true })
  } catch (err) {
    return Response.json({ error: 'Invalid signature' }, { status: 400 })
  }
}
Common Event Types
EventTrigger
user.createdNew user signs up
user.updatedUser profile changes
user.deletedUser account deleted
session.createdNew sign-in
session.endedSign-out
organization.createdNew org created
organization.membership.createdUser joins org

⚠️ Important: Webhook routes must be PUBLIC (no auth). Add to middleware exclude list:

typescript
const isPublicRoute = createRouteMatcher([
  '/api/webhooks/clerk(.*)',  // Clerk webhooks are public
])

clerkMiddleware((auth, req) => {
  if (!isPublicRoute(req)) {
    auth.protect()
  }
})

UI Components Quick Reference

ComponentPurpose
<SignIn />Full sign-in flow
<SignUp />Full sign-up flow
<SignInButton />Trigger sign-in modal
<SignUpButton />Trigger sign-up modal
<SignedIn>Render only when authenticated
<SignedOut>Render only when unauthenticated
<UserButton />User menu with sign-out
<UserProfile />Full profile management
<OrganizationSwitcher />Switch between orgs
<OrganizationProfile />Org settings
<CreateOrganization />Create new org
<APIKeys />API key management (NEW)
React Hooks
HookReturns
useAuth(){ userId, sessionId, isLoaded, isSignedIn, getToken }
useUser(){ user, isLoaded, isSignedIn }
useClerk()Clerk instance with methods
useSession()Current session object
useOrganization()Current org context
useOrganizationList()All user's orgs

JWT Templates - Size Limits & Shortcodes

JWT Size Limitation: 1.2KB for Custom Claims ⚠️

Problem: Browser cookies limited to 4KB. Clerk's default claims consume ~2.8KB, leaving 1.2KB for custom claims.

⚠️ Development Note: When testing custom JWT claims in Vite dev mode, you may encounter "431 Request Header Fields Too Large" error. This is caused by Clerk's handshake token in the URL exceeding Vite's 8KB limit. See Issue #11 for solution.

Solution:

json
// ✅ GOOD: Minimal claims
{
  "user_id": "{{user.id}}",
  "email": "{{user.primary_email_address}}",
  "role": "{{user.public_metadata.role}}"
}

// ❌ BAD: Exceeds limit
{
  "bio": "{{user.public_metadata.bio}}",  // 6KB field
  "all_metadata": "{{user.public_metadata}}"  // Entire object
}

Best Practice: Store large data in database, include only identifiers/roles in JWT.

Available Shortcodes Reference
CategoryShortcodesExample
User ID & Name{{user.id}}, {{user.first_name}}, {{user.last_name}}, {{user.full_name}}"John Doe"
Contact{{user.primary_email_address}}, {{user.primary_phone_address}}"john@example.com"
Profile{{user.image_url}}, {{user.username}}, {{user.created_at}}"https://..."
Verification{{user.email_verified}}, {{user.phone_number_verified}}true
Metadata{{user.public_metadata}}, {{user.public_metadata.FIELD}}{"role": "admin"}
Organizationorg_id, org_slug, org_role (in sessionClaims)"org:admin"

Advanced Features:

  • String Interpolation: "{{user.last_name}} {{user.first_name}}"
  • Conditional Fallbacks: "{{user.public_metadata.role || 'user'}}"
  • Nested Metadata: "{{user.public_metadata.profile.interests}}"

Official Docs: https://clerk.com/docs/guides/sessions/jwt-templates


Testing with Clerk

Test Credentials (Fixed OTP: 424242)

Test Emails (no emails sent, fixed OTP):

john+clerk_test@example.com
jane+clerk_test@gmail.com

Test Phone Numbers (no SMS sent, fixed OTP):

+12015550100
+19735550133

Fixed OTP Code: 424242 (works for all test credentials)

Generate Session Tokens (60-second lifetime)

Script (scripts/generate-session-token.js):

bash
# Generate token
CLERK_SECRET_KEY=sk_test_... node scripts/generate-session-token.js

# Create new test user
CLERK_SECRET_KEY=sk_test_... node scripts/generate-session-token.js --create-user

# Auto-refresh token every 50 seconds
CLERK_SECRET_KEY=sk_test_... node scripts/generate-session-token.js --refresh

Manual Flow:

  1. Create user: POST /v1/users
  2. Create session: POST /v1/sessions
  3. Generate token: POST /v1/sessions/{session_id}/tokens
  4. Use in header: Authorization: Bearer <token>
E2E Testing with Playwright

Install @clerk/testing for automatic Testing Token management:

bash
npm install -D @clerk/testing

Global Setup (global.setup.ts):

typescript
import { clerkSetup } from '@clerk/testing/playwright'
import { test as setup } from '@playwright/test'

setup('global setup', async ({}) => {
  await clerkSetup()
})

Test File (auth.spec.ts):

typescript
import { setupClerkTestingToken } from '@clerk/testing/playwright'
import { test } from '@playwright/test'

test('sign up', async ({ page }) => {
  await setupClerkTestingToken({ page })

  await page.goto('/sign-up')
  await page.fill('input[name="emailAddress"]', 'test+clerk_test@example.com')
  await page.fill('input[name="password"]', 'TestPassword123!')
  await page.click('button[type="submit"]')

  // Verify with fixed OTP
  await page.fill('input[name="code"]', '424242')
  await page.click('button[type="submit"]')

  await expect(page).toHaveURL('/dashboard')
})

Official Docs: https://clerk.com/docs/guides/development/testing/overview


Known Issues Prevention

This skill prevents 15 documented issues:

Issue #1: Missing Clerk Secret Key

Error: "Missing Clerk Secret Key or API Key" Source: https://stackoverflow.com/questions/77620604 Prevention: Always set in .env.local or via wrangler secret put

Issue #2: API Key → Secret Key Migration

Error: "apiKey is deprecated, use secretKey" Source: https://clerk.com/docs/upgrade-guides/core-2/backend Prevention: Replace apiKey with secretKey in all calls

Issue #3: JWKS Cache Race Condition

Error: "No JWK available" Source: https://github.com/clerk/javascript/blob/main/packages/backend/CHANGELOG.md Prevention: Use @clerk/backend@2.17.2 or later (fixed)

Issue #4: Missing authorizedParties (CSRF)

Error: No error, but CSRF vulnerability Source: https://clerk.com/docs/reference/backend/verify-token Prevention: Always set authorizedParties: ['https://yourdomain.com']

Issue #5: Import Path Changes (Core 2)

Error: "Cannot find module" Source: https://clerk.com/docs/upgrade-guides/core-2/backend Prevention: Update import paths for Core 2

Show full SKILL.md (698 more words)Show less
Issue #6: JWT Size Limit Exceeded

Error: Token exceeds size limit Source: https://clerk.com/docs/backend-requests/making/custom-session-token Prevention: Keep custom claims under 1.2KB

Issue #7: Deprecated API Version v1

Error: "API version v1 is deprecated" Source: https://clerk.com/docs/upgrade-guides/core-2/backend Prevention: Use latest SDK versions (API v2025-11-10)

Issue #8: ClerkProvider JSX Component Error

Error: "cannot be used as a JSX component" Source: https://stackoverflow.com/questions/79265537 Prevention: Ensure React 19 compatibility with @clerk/clerk-react@5.59.2+

Issue #9: Async auth() Helper Confusion

Error: "auth() is not a function" Source: https://clerk.com/changelog/2024-10-22-clerk-nextjs-v6 Prevention: Always await: const { userId } = await auth()

Issue #10: Environment Variable Misconfiguration

Error: "Missing Publishable Key" or secret leaked Prevention: Use correct prefixes (NEXT_PUBLIC_, VITE_), never commit secrets

Issue #11: 431 Request Header Fields Too Large (Vite Dev Mode)

Error: "431 Request Header Fields Too Large" when signing in Source: Common in Vite dev mode when testing custom JWT claims Cause: Clerk's __clerk_handshake token in URL exceeds Vite's 8KB header limit Prevention:

Add to package.json:

json
{
  "scripts": {
    "dev": "NODE_OPTIONS='--max-http-header-size=32768' vite"
  }
}

Temporary Workaround: Clear browser cache, sign out, sign back in

Why: Clerk dev tokens are larger than production; custom JWT claims increase handshake token size

Note: This is different from Issue #6 (session token size). Issue #6 is about cookies (1.2KB), this is about URL parameters in dev mode (8KB → 32KB).

Issue #12: User Type Mismatch (useUser vs currentUser)

Error: TypeScript errors when sharing user utilities across client/server Source: GitHub Issue #2176 Why It Happens: useUser() returns UserResource (client-side) with different properties than currentUser() returns User (server-side). Client has fullName, primaryEmailAddress object; server has primaryEmailAddressId and privateMetadata instead. Prevention: Use shared properties only, or create separate utility functions for client vs server contexts.

typescript
// ✅ CORRECT: Use properties that exist in both
const primaryEmailAddress = user.emailAddresses.find(
  ({ id }) => id === user.primaryEmailAddressId
)

// ✅ CORRECT: Separate types
type ClientUser = ReturnType<typeof useUser>['user']
type ServerUser = Awaited<ReturnType<typeof currentUser>>
Issue #13: Multiple acceptsToken Types Causes token-type-mismatch

Error: "token-type-mismatch" when using authenticateRequest() with multiple token types Source: GitHub Issue #7520 Why It Happens: When using authenticateRequest() with multiple acceptsToken values (e.g., ['session_token', 'api_key']), Clerk incorrectly throws token-type-mismatch error. Prevention: Upgrade to @clerk/backend@2.29.2+ (fix available in snapshot, releasing soon).

typescript
// This now works in @clerk/backend@2.29.2+
const result = await authenticateRequest(request, {
  acceptsToken: ['session_token', 'api_key'],  // Fixed!
})
Issue #14: deriveUrlFromHeaders Server Crash on Malformed URLs

Error: Server crashes with URL parsing error Source: GitHub Issue #7275 Why It Happens: Internal deriveUrlFromHeaders() function performs unsafe URL parsing and crashes the entire server when receiving malformed URLs in headers (e.g., x-forwarded-host: 'example.com[invalid]'). This is a denial-of-service vulnerability. Prevention: Upgrade to @clerk/backend@2.29.0+ (fixed).

Issue #15: treatPendingAsSignedOut Option for Pending Sessions

Error: None - optional parameter for edge case handling Source: Changelog @clerk/nextjs@6.32.0 Why It Exists: Sessions can have a pending status during certain flows (e.g., credential stuffing defense secondary auth). By default, pending sessions are treated as signed-out (user is null). Usage: Set treatPendingAsSignedOut: false to treat pending as signed-in (available in @clerk/nextjs@6.32.0+).

typescript
// Default: pending = signed out
const user = await currentUser()  // null if status is 'pending'

// Treat pending as signed in
const user = await currentUser({ treatPendingAsSignedOut: false })  // defined if pending

Production Considerations

Service Availability & Reliability

Context: Clerk experienced 3 major service disruptions in May-June 2025 attributed to Google Cloud Platform (GCP) outages. The June 26, 2025 outage lasted 45 minutes (6:16-7:01 UTC) and affected all Clerk customers.

Source: Clerk Postmortem: June 26, 2025

Mitigation Strategies:

  • Monitor Clerk Status for real-time updates
  • Implement graceful degradation when Clerk API is unavailable
  • Cache auth tokens locally where possible
  • For existing sessions, use jwtKey option for networkless verification:
typescript
clerkMiddleware({
  jwtKey: process.env.CLERK_JWT_KEY,  // Allows offline token verification
})

Note: During total outage, no new sessions can be created (auth requires Clerk API). However, existing sessions can continue working if you verify JWTs locally with jwtKey. Clerk committed to exploring multi-cloud redundancy to reduce single-vendor dependency risk.


Official Documentation


Package Versions

Latest (Nov 22, 2025):

json
{
  "dependencies": {
    "@clerk/nextjs": "^6.36.7",
    "@clerk/clerk-react": "^5.59.2",
    "@clerk/backend": "^2.29.2",
    "@clerk/testing": "^1.13.26"
  }
}

Token Efficiency:

  • Without skill: ~6,500 tokens (setup tutorials, JWT templates, testing setup, webhooks, production considerations)
  • With skill: ~3,200 tokens (breaking changes + critical patterns + error prevention + production guidance)
  • Savings: ~51% (~3,300 tokens)

Errors prevented: 15 documented issues with exact solutions Key value: API Keys beta, Next.js 16 proxy.ts (with March 2025 CVE context), clerkMiddleware() options, webhooks, component reference, API 2025-11-10 breaking changes, JWT size limits, user type mismatches, production considerations (GCP outages, jwtKey offline verification)


Last verified: 2026-01-20 | Skill version: 3.1.0 | Changes: Added 4 new Known Issues (#12-15: user type mismatch, acceptsToken type mismatch, deriveUrlFromHeaders crash, treatPendingAsSignedOut option), expanded proxy.ts section with March 2025 CVE security context, added Production Considerations section (GCP outages + mitigation), added organizationSyncOptions Next.js-only limitation note, updated minimum version requirements for Next.js 16 (6.35.0+).

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 32 other files (scripts, references, assets) in skills/clerk-auth of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • .claude-plugin/plugin.json
  • README.md
  • _meta.json
  • agents/clerk-setup.md
  • assets/example-template.txt
  • commands/setup.md
  • references/common-errors.md
  • references/example-reference.md
  • references/jwt-claims-guide.md
  • references/testing-guide.md
  • rules/clerk-auth.md
  • scripts/example-script.sh
  • scripts/generate-session-token.js
  • … and 19 more

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Clerk Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clerk Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clerk Auth this skillLeoYeAI/openclaw-master-skills2.2k—~6.1kAutomated safety check: NotesMIT
Web Ssrfs0ld13rr/pentestcode828—~660Automated safety check: WarnMIT
Clerk Authdavila7/claude-code-templates33k5 repos~376Automated safety check: PassMIT
Clerkgeekskai/blog1033 repos~1.5kAutomated safety check: PassMIT
Clerk Nextjs Patternsgeekskai/blog1032 repos~2.1kAutomated safety check: PassMIT
Sign In With Google Webgoogle/skills21k—~4.1kAutomated safety check: PassApache-2.0

Similar skills

  • Web Ssrf

    s0ld13rr/pentestcode

    Server-Side Request Forgery detection→internal-access→proof for web apps.

    828 GitHub stars~660 tokensUpdated 8 days ago
    Backend & APIsAuto-check: warnings
  • Clerk Auth

    davila7/claude-code-templates

    Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.

    33k GitHub starsUsed in 5 repos~376 tokens
    Backend & APIsAuto-check passed
  • Clerk

    geekskai/blog

    Clerk authentication router. An agent skill from geekskai/blog.

    103 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Advanced Next.js patterns - middleware, Server Actions, caching with Clerk.

    103 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Official

    Implement, configure, and secure Sign In With Google (SiwG) using Google Identity Services (GIS / https://accounts.google.com/gsi/client) across web architectures.

    21k GitHub stars~4.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Defending Applications

    telagod/code-abyss

    Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

    244 GitHub stars~777 tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Clerk Auth

What does Clerk Auth do?

Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP…. Clerk Auth is an agent skill from LeoYeAI/openclaw-master-skills.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference.

When should I use Clerk Auth?

Clerk Auth fits situations like: : API keys for users/orgs; Next.js 16 middleware filename; troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors; webhook verification.

How do I install Clerk Auth in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill clerk-auth -a claude-code`. Or copy the skill folder (skills/clerk-auth in LeoYeAI/openclaw-master-skills) into .claude/skills/clerk-auth in your project. Claude Code loads it when a task matches its description.

How do I install Clerk Auth in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill clerk-auth -a codex`. Or copy the skill folder (skills/clerk-auth in LeoYeAI/openclaw-master-skills) into .agents/skills/clerk-auth in your project. Codex loads it when a task matches its description.

Can I use Clerk Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill clerk-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clerk-auth, .gemini/skills/clerk-auth, .github/skills/clerk-auth and .opencode/skills/clerk-auth in your project.

What does Clerk Auth need to run?

Going by SKILL.md and its folder, Clerk Auth needs a shell and JavaScript for the scripts in its folder, the command-line tools its instructions call (node, npm and wrangler) and credentials named CLERK_SECRET_KEY, CLERK_WEBHOOK_SIGNING_SECRET and CLERK_JWT_KEY. Our summary lists: Node.js; A Bash shell; A credential in CLERK_SECRET_KEY; A credential in CLERK_WEBHOOK_SIGNING_SECRET.

Does Clerk Auth access the network?

SKILL.md names 4 domains. As links in the text: clerk.com, github.com, stackoverflow.com and status.clerk.com. This is read from the text; nothing was executed.

Is Clerk Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Clerk Auth use?

Clerk Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clerk Auth use?

About 6.1k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Clerk Auth?

Skills that share tags, products or a category with Clerk Auth: Web Ssrf (s0ld13rr/pentestcode, 828 stars), Clerk Auth (davila7/claude-code-templates, 33k stars), Clerk (geekskai/blog, 103 stars) and Clerk Nextjs Patterns (geekskai/blog, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clerk Auth?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.