M2M Token only authentication in Clerk Middleware
I maintainer di solito rispondono entro 1 giorno
@wobsoriano ci sta già lavorando.
Dal 29/9/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Preliminary Checks
-
I have reviewed the documentation: https://clerk.com/docs
-
I have searched for existing issues: https://github.com/clerk/javascript/issues
-
I have not already reached out to Clerk support via email or Discord (if you have, no need to open an issue here)
-
This issue is not a question, general help request, or anything other than a bug report directly related to Clerk. Please ask questions in our Discord community: https://clerk.com/discord.
Reproduction
https://github.com/x-delfino/clerk-fastify-issue-repro
Publishable key
pk_test_dG91Y2hlZC1mb3dsLTk5MDYuY2xlcmsuYWNjb3VudHMuZGV2JA
Description
I'm trying to use M2M tokens to authenticate one machine to another, without any subsequent backend API access. I'm testing this with the clerk fastify plugin, but I don't think the issue is necessarily specific to that package
Steps to reproduce:
- Create M2M Machines in Clerk:
MachineA: no scopesMachineB: scope forMachineA
- Setup workspace (using
MachineAsecret key):
git clone https://github.com/x-delfino/clerk-fastify-issue-repro
cd clerk-fastify-issue-repro
pnpm install
export CLERK_MACHINE_SECRET_KEY="ak_XXXXXXXXX"
pnpm run serve
- Generate token for
MachineB - make HTTP request:
TOKEN="MACHINE_B_TOKEN"
curl -H "Authorization: Bearer $TOKEN" localhost:8080/protected
Expected behavior:
To receive response:
{"message":"Machine authenticated successfully","subject":"mch_XXXXXXXXX","scopes":["mch_XXXXXXXXX"]}
Actual behavior:
Response received:
{"statusCode":500,"error":"Internal Server Error","message":"Publishable key is missing.\n\nTo create a new Clerk app, run:\nnpx clerk@latest init\n\nTo use an existing Clerk app, run:\nnpx clerk@latest link\nnpx clerk@latest env pull\n\nFor production keys, run:\nnpx clerk@latest env pull --instance prod\n\nOr copy keys from https://dashboard.clerk.com/~/api-keys into your .env file."}
Providing CLERK_PUBLISHABLE_KEY changes the response to:
{"statusCode":500,"error":"Internal Server Error","message":"Missing Clerk Secret Key. Go to https://dashboard.clerk.com and get your key for your instance."}
Detail:
The clerk middleware for fastify hardcodes the acceptsToken to 'any':
When the token is then processed, as it's not explicitly M2MToken or ApiKey - it tries to load the publishable key:
I patched the fastify clerk middleware to allow the acceptsToken key to be provided:
const requestState = await clerkClient.authenticateRequest(req, {
...clerkOptions,
secretKey,
publishableKey,
proxyUrl: resolvedProxyUrl,
// acceptsToken: 'any',
});
Allowing me to update my sample code to:
fastify.register(clerkPlugin, { acceptsToken: "m2m_token" })
Allowing me to receive and validate M2M tokens using M2M tokens only
However, this isn't type correct. ClerkFastifyOptions, through a chain of intersections, doesn't pull in acceptsToken from AuthenticateRequestOptions
I'm not sure the best way to proceed from here as changes may affect more than fastify
Environment
System:
OS: macOS 26.5
CPU: (10) arm64 Apple M4
Memory: 134.00 MB / 32.00 GB
Shell: 5.9 - /bin/zsh
Binaries:
Node: 26.10.0 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/node
npm: 11.19.1 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/npm
pnpm: 11.27.0 - /nix/store/gjkd8wjh079v7i5j2rb8y0b5r19addpa-pnpm-11.27.0/bin/pnpm
Browsers:
Safari: 26.5
npmPackages:
@clerk/fastify: ^3.1.82 => 3.1.82
@types/node: ^26.6.3 => 26.6.3
fastify: ^5.12.5 => 5.12.5
typescript: ^7.0.2 => 7.0.2
- Lingua principale
- TypeScript
- Stelle
- 1.8k
- Fork
- 477
- Merge medio
- 2g 3h
- PR unite (30g)
- 269
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di clerk/javascript
-
[expo] useLocalCredentials throws "Invalid key provided to SecureStore" during render when the publishable key has base64 padding (=)Forse già presa @RaphaelFakhri l’ha presa 3 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
clerk/javascript#10033 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
clerk/javascript#10026 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
clerk/javascript#9987 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 65/100
clerk/javascript#10011 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 50/100
clerk/javascript#9984 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di clerk/javascript
Issue simili
-
area/dashboard kind/bug QA/dev-automation
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
rancher/dashboard#19379 · 2 commenti ·
I maintainer di solito rispondono entro 5 giorni
-
perf(core): getComments() runs the approved count and the comment list as two sequential queriesApertaarea/core bot:bug bot:working
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
emdash-cms/emdash#3905 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
lingdojo/kana-dojo#31728 · 1 commento · 5 reazioni ·
I maintainer di solito rispondono entro 1 giorno
-
selective-claw: freshTailTurns=0 keeps ALL turns verbatim and summarizes none (slice(-0) === slice(0))Forse già presa @zjncs l’ha presa oggi. Apertacomponent:tokenless
Difficoltà 2/5 1-3 ore Idoneità per principianti 80/100
agentic-os-org/ANOLISA#6112 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug needs triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
rjsf-team/react-jsonschema-form#5439 ·
I maintainer di solito rispondono entro 1 giorno