Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

M2M Token only authentication in Clerk Middleware

Aperta
#9,981 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@wobsoriano ci sta già lavorando.

Dal 29/9/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

needs-triage
Preliminary Checks
Reproduction

https://github.com/x-delfino/clerk-fastify-issue-repro

Publishable key

pk_test_dG91Y2hlZC1mb3dsLTk5MDYuY2xlcmsuYWNjb3VudHMuZGV2JA

Description

I'm trying to use M2M tokens to authenticate one machine to another, without any subsequent backend API access. I'm testing this with the clerk fastify plugin, but I don't think the issue is necessarily specific to that package

Steps to reproduce:

  1. Create M2M Machines in Clerk:
  • MachineA: no scopes
  • MachineB: scope for MachineA
  1. Setup workspace (using MachineA secret key):
git clone https://github.com/x-delfino/clerk-fastify-issue-repro
cd clerk-fastify-issue-repro
pnpm install
export CLERK_MACHINE_SECRET_KEY="ak_XXXXXXXXX"
pnpm run serve
  1. Generate token for MachineB
  2. make HTTP request:
TOKEN="MACHINE_B_TOKEN"
curl -H "Authorization: Bearer $TOKEN" localhost:8080/protected

Expected behavior:

To receive response:

{"message":"Machine authenticated successfully","subject":"mch_XXXXXXXXX","scopes":["mch_XXXXXXXXX"]}

Actual behavior:

Response received:

{"statusCode":500,"error":"Internal Server Error","message":"Publishable key is missing.\n\nTo create a new Clerk app, run:\nnpx clerk@latest init\n\nTo use an existing Clerk app, run:\nnpx clerk@latest link\nnpx clerk@latest env pull\n\nFor production keys, run:\nnpx clerk@latest env pull --instance prod\n\nOr copy keys from https://dashboard.clerk.com/~/api-keys into your .env file."}

Providing CLERK_PUBLISHABLE_KEY changes the response to:

{"statusCode":500,"error":"Internal Server Error","message":"Missing Clerk Secret Key. Go to https://dashboard.clerk.com and get your key for your instance."}

Detail:

The clerk middleware for fastify hardcodes the acceptsToken to 'any':

https://github.com/clerk/javascript/blob/dfb620474e85fa36f8925e3f3091b5911c080492/packages/fastify/src/withClerkMiddleware.ts#L110-L116

When the token is then processed, as it's not explicitly M2MToken or ApiKey - it tries to load the publishable key:

https://github.com/clerk/javascript/blob/26feba7c666f48cc4f8d3ecf1ebfd3290cbdf679/packages/backend/src/tokens/authenticateContext.ts#L86-L98

I patched the fastify clerk middleware to allow the acceptsToken key to be provided:

    const requestState = await clerkClient.authenticateRequest(req, {
      ...clerkOptions,
      secretKey,
      publishableKey,
      proxyUrl: resolvedProxyUrl,
      // acceptsToken: 'any',
    });

Allowing me to update my sample code to:

fastify.register(clerkPlugin, { acceptsToken: "m2m_token" })

Allowing me to receive and validate M2M tokens using M2M tokens only

However, this isn't type correct. ClerkFastifyOptions, through a chain of intersections, doesn't pull in acceptsToken from AuthenticateRequestOptions

https://github.com/clerk/javascript/blob/2ee976bb66b7c112ae5bec5605a5bb42736c7e01/packages/backend/src/tokens/factory.ts#L8-L22

I'm not sure the best way to proceed from here as changes may affect more than fastify

Environment
System:
    OS: macOS 26.5
    CPU: (10) arm64 Apple M4
    Memory: 134.00 MB / 32.00 GB
    Shell: 5.9 - /bin/zsh
  Binaries:
    Node: 26.10.0 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/node
    npm: 11.19.1 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/npm
    pnpm: 11.27.0 - /nix/store/gjkd8wjh079v7i5j2rb8y0b5r19addpa-pnpm-11.27.0/bin/pnpm
  Browsers:
    Safari: 26.5
  npmPackages:
    @clerk/fastify: ^3.1.82 => 3.1.82 
    @types/node: ^26.6.3 => 26.6.3 
    fastify: ^5.12.5 => 5.12.5 
    typescript: ^7.0.2 => 7.0.2
Lingua principale
TypeScript
Stelle
1.8k
Fork
477
Merge medio
2g 3h
PR unite (30g)
269

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di clerk/javascript

Tutte le issue di clerk/javascript

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.