M2M Token only authentication in Clerk Middleware
Maintainer antworten meist innerhalb von 1 Tag
@wobsoriano arbeitet bereits daran.
Seit 29.9.2026.
Bewertung
Dieses Issue wurde noch nicht bewertet.
Beschreibung
Preliminary Checks
-
I have reviewed the documentation: https://clerk.com/docs
-
I have searched for existing issues: https://github.com/clerk/javascript/issues
-
I have not already reached out to Clerk support via email or Discord (if you have, no need to open an issue here)
-
This issue is not a question, general help request, or anything other than a bug report directly related to Clerk. Please ask questions in our Discord community: https://clerk.com/discord.
Reproduction
https://github.com/x-delfino/clerk-fastify-issue-repro
Publishable key
pk_test_dG91Y2hlZC1mb3dsLTk5MDYuY2xlcmsuYWNjb3VudHMuZGV2JA
Description
I'm trying to use M2M tokens to authenticate one machine to another, without any subsequent backend API access. I'm testing this with the clerk fastify plugin, but I don't think the issue is necessarily specific to that package
Steps to reproduce:
- Create M2M Machines in Clerk:
MachineA: no scopesMachineB: scope forMachineA
- Setup workspace (using
MachineAsecret key):
git clone https://github.com/x-delfino/clerk-fastify-issue-repro
cd clerk-fastify-issue-repro
pnpm install
export CLERK_MACHINE_SECRET_KEY="ak_XXXXXXXXX"
pnpm run serve
- Generate token for
MachineB - make HTTP request:
TOKEN="MACHINE_B_TOKEN"
curl -H "Authorization: Bearer $TOKEN" localhost:8080/protected
Expected behavior:
To receive response:
{"message":"Machine authenticated successfully","subject":"mch_XXXXXXXXX","scopes":["mch_XXXXXXXXX"]}
Actual behavior:
Response received:
{"statusCode":500,"error":"Internal Server Error","message":"Publishable key is missing.\n\nTo create a new Clerk app, run:\nnpx clerk@latest init\n\nTo use an existing Clerk app, run:\nnpx clerk@latest link\nnpx clerk@latest env pull\n\nFor production keys, run:\nnpx clerk@latest env pull --instance prod\n\nOr copy keys from https://dashboard.clerk.com/~/api-keys into your .env file."}
Providing CLERK_PUBLISHABLE_KEY changes the response to:
{"statusCode":500,"error":"Internal Server Error","message":"Missing Clerk Secret Key. Go to https://dashboard.clerk.com and get your key for your instance."}
Detail:
The clerk middleware for fastify hardcodes the acceptsToken to 'any':
When the token is then processed, as it's not explicitly M2MToken or ApiKey - it tries to load the publishable key:
I patched the fastify clerk middleware to allow the acceptsToken key to be provided:
const requestState = await clerkClient.authenticateRequest(req, {
...clerkOptions,
secretKey,
publishableKey,
proxyUrl: resolvedProxyUrl,
// acceptsToken: 'any',
});
Allowing me to update my sample code to:
fastify.register(clerkPlugin, { acceptsToken: "m2m_token" })
Allowing me to receive and validate M2M tokens using M2M tokens only
However, this isn't type correct. ClerkFastifyOptions, through a chain of intersections, doesn't pull in acceptsToken from AuthenticateRequestOptions
I'm not sure the best way to proceed from here as changes may affect more than fastify
Environment
System:
OS: macOS 26.5
CPU: (10) arm64 Apple M4
Memory: 134.00 MB / 32.00 GB
Shell: 5.9 - /bin/zsh
Binaries:
Node: 26.10.0 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/node
npm: 11.19.1 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/npm
pnpm: 11.27.0 - /nix/store/gjkd8wjh079v7i5j2rb8y0b5r19addpa-pnpm-11.27.0/bin/pnpm
Browsers:
Safari: 26.5
npmPackages:
@clerk/fastify: ^3.1.82 => 3.1.82
@types/node: ^26.6.3 => 26.6.3
fastify: ^5.12.5 => 5.12.5
typescript: ^7.0.2 => 7.0.2
- Vorherrschende Sprache
- TypeScript
- Sterne
- 1.8k
- Forks
- 477
- Ø Merge
- 2 T. 25 Min.
- Gemergte PRs (30 T.)
- 267
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus clerk/javascript
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
clerk/javascript#10026 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
@clerk/nextjs: onBeforeSetActive never settles when invalidateCacheAction rejects (e.g. after a redeploy), so setActive and signOut hang foreverEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
clerk/javascript#9987 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 65/100
clerk/javascript#10011 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 50/100
clerk/javascript#9984 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 72/100
clerk/javascript#9972 ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in clerk/javascript
Ähnliche Issues
-
Schwierigkeit 2/5 Unter einer Stunde Anfängerfreundlichkeit 85/100
capricorn86/happy-dom#2474 ·
Maintainer antworten meist innerhalb von 2 Tagen
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
JSerwatka/letterboxd-tweaks#81 · 1 Kommentar ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
siyuan-note/siyuan#20165 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
polkadot-js/phishing#5716 ·
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 90/100
juice-shop/juice-shop#3662 ·
Maintainer antworten meist innerhalb von 1 Tag