Install
npm install @clerk/nextjsShowcase


Verified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agent auth — stories about agent auth in this arenaAgent authevidence →
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment controlevidence →
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise ssoevidence →
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooksevidence →
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integrationevidence →
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordlessevidence →
Stories about mfa passwordless in this arena
Oauth oidc — stories about oauth oidc in this arenaOauth oidcevidence →
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenantevidence →
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissionsevidence →
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession managementevidence →
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migrationevidence →
Stories about user migration in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 3 free · 1 paid · 0 enterprise · 33 not stated in evidence
Follow the green: where the map greys out is where Clerk stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agent auth — stories about agent auth in this arenaAgent auth
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Versioning policy · API sandbox · Full data export · Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM
Subscribe to events via webhooks
✓8/10
Build against official SDKs
✓8/10
Issue scoped/least-privilege API credentials for an agent
✓8/10
unlocks → Autonomous automations
Connect an agent via an official MCP server
✓9/10
Download a machine-readable API spec (OpenAPI or equivalent)
✓9/10
unlocks → Interactive API docs
Rely on versioned APIs with a documented deprecation policy
—–
Test against a sandbox environment without touching production data
—–
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓9/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—0/10
Operate the product with natural-language commands
~5/10
unlocks → Autonomous automations
Plug MCP servers into this product so it can use their tools
—0/10
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
—0/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment control
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise sso
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooks
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integration
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless
Stories about mfa passwordless in this arena
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
✓8/10
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
✓8/10
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
~6/10
Oauth oidc — stories about oauth oidc in this arenaOauth oidc
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissions
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession management
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migration
Stories about user migration in this arena
Sorted by importance (agentic first) (high → low) · 56/56 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none± | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full± | 8/10 | Tprobed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full±free | 8/10 | Cclaimed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none± | 0/10 | ||
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none± | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | untested | none yet | |
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 3 | full | 8/10 | Cclaimed | |
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box C Orgs | developer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 3 | full | 8/10 | Xcommunity | |
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed G Mfa | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 3 | full | 8/10 | Cclaimed | |
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks G Rbac | developer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 3 | partial | 7/10 | Xcommunity | |
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partialfree | 7/10 | Cclaimed | |
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | fullfree | 7/10 | Cclaimed | |
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 6/10 | Cclaimed | |
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details C Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 3 | partial | 6/10 | Cclaimed | |
Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 3 | partial | 6/10 | Xcommunity | |
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens C Mcp | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 6/10 | Cclaimed | |
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session C Sessions | developer | Session management — stories about session management in this arenaSession management | 3 | disputed | 5/10 | Dcontradicted | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 4/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 2 | full | 8/10 | Cclaimed | |
Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync C Webhooks | developer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | full | 7/10 | Cclaimed | |
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets C Device flow | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | partial | 6/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods G Passwordless | developer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 2 | partialpaid | 6/10 | Cclaimed | |
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code G Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | partial | 6/10 | Cclaimed | |
Give each customer organization its own SSO connection with verified domains and just-in-time provisioning G Orgs | security-engineer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 2 | partial | 5/10 | Cclaimed | |
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app") C Provider | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | partial | 5/10 | Cclaimed | |
Bulk-import existing users — including password hashes — and export them again, so I am never locked in C Migration | developer | User migration — stories about user migration in this arenaUser migration | 2 | partial | 4/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 4/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 4/10 | Cclaimed | |
Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM G Audit | security-engineer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | disputed | 3/10 | Dcontradicted | |
Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | partial | 3/10 | Cclaimed | |
Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app access G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control where the auth system and its user data run — self-managed deployment, private instance, or my own database C Deployment | security-engineer | Deployment control — stories about deployment control in this arenaDeployment control | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows C Hardening | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 1 | full | 8/10 | Cclaimed | |
Let users and admins see active sessions and devices and revoke them individually or all at once C Sessions | security-engineer | Session management — stories about session management in this arenaSession management | 1 | partial | 6/10 | Cclaimed | |
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets C Migration | founder | User migration — stories about user migration in this arenaUser migration | 1 | partial | 5/10 | Cclaimed | |
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles C Rbac | security-engineer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 1 | partial | 3/10 | Xcommunity | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 36 stories with headroom
What would move Clerk’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
Clerk's AI-related evidence is about enabling external AI coding agents (via an MCP server) to consume Clerk's docs/snippets, and about infrastructure ('eve') for authenticating and authorizing AI agents built by developers — not a built-in assistant inside Clerk's own product that an end-user could delegate tasks to.
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
nonemoves agent-readyimpact 45
Clerk's evidence only shows it publishing its own MCP server for other AI agents to consume Clerk's SDK docs (clerk-docs-2/26/-4), which is the opposite direction of the story — Clerk acting as an MCP client that plugs in external MCP servers to use their tools.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
Evidence only shows a migration tool for importing user data INTO Clerk (JSON/CSV via Backend API) and a general Backend/OpenAPI surface, but nothing documents a bulk data-export feature or open-format export path for users wanting to leave the platform.
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
Clerk is a hosted, closed-source authentication/user-management SaaS; there is no evidence of a self-hostable core product, on-prem deployment option, or open-source server.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence anywhere in the pack addresses AI training data usage or opt-out policies for Clerk; the evidence covers auth, RBAC, sessions, MCP tooling, and reliability complaints but nothing about data being used for AI training or a mechanism to prevent it.
Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background
nonemoves Built-in AIimpact 30
Missing: any documented automation/workflow builder, scheduling, or background task runner within Clerk itself.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Evidence shows Clerk publishes an OpenAPI JSON spec (clerk-probe-3) and various docs pages, but there is no evidence of an interactive API reference UI (e.g., a 'try it out' console or runnable code sandbox) that lets users execute API calls directly from the docs.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
The evidence pack shows an OpenAPI spec exists and extensive feature docs, but nowhere is there mention of API versioning scheme, version headers, or a documented deprecation policy for Clerk's APIs/SDKs.
Showing the top 8 of 36 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map11 surfaces · 39 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs36 stories
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets
- Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Subscribe to events via webhooks
- Operate the product with natural-language commands
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in
- Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM
- Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync
- Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")
- Do everything through the API that I can do in the UI
- Read the product's source under an open license
- Give each customer organization its own SSO connection with verified domains and just-in-time provisioning
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
- Let users and admins see active sessions and devices and revoke them individually or all at once
- Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session
- Bulk-import existing users — including password hashes — and export them again, so I am never locked in
- Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets
Changelog docs12 stories
- Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Issue scoped/least-privilege API credentials for an agent
- Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM
- Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
- Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details
- Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")
CLI docs9 stories
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- Subscribe to events via webhooks
- Operate the product with natural-language commands
- Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
Hacker News8 stories
- Build against official SDKs
- Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM
- Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
- Do everything through the API that I can do in the UI
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
- Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session
clerk.com7 stories
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Let users and admins see active sessions and devices and revoke them individually or all at once
- Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session
OpenAPI spec4 stories
GitHub README4 stories
- Build against official SDKs
- Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Read the product's source under an open license
Pricing docs4 stories
- Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Issue scoped/least-privilege API credentials for an agent
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
llms.txt3 stories
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
5 of 18 testable claims verified · 1 contradicted → integrity 17/100
25 distinct capability claims found in Clerk’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
5
Verified
12
Unverified
1
Contradicted
20
Undersold
Verified (8)
“Remote MCP server lets AI coding agents (Claude, Cursor, Copilot) pull Clerk SDK snippets and implementation patterns”
“Organizations feature groups users with roles/permissions for multi-tenant B2B apps (workspaces, teams, projects)”
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxfullproof ↗
“Default admin/member roles plus custom roles and fine-grained permissions for app-specific authorization”
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checkspartialproof ↗
“Default admin/member roles plus custom roles and fine-grained permissions for app-specific authorization”
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple rolespartialproof ↗
“Self-serve organization UI lets users create orgs, switch accounts, manage settings/billing, and view memberships/invites”
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxfullproof ↗
“First-party integration adds authentication to Next.js apps”
Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edgepartialproof ↗
“Session automatically carries organization context (memberships, roles, active organization) for authorization checks”
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxfullproof ↗
“Session automatically carries organization context (memberships, roles, active organization) for authorization checks”
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checkspartialproof ↗
Unverified (16)
“Prebuilt drop-in UI components for full user management (sign-up, sign-in, profile)”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Webhooks notify your backend of Clerk events like user creation or updates”
Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in syncfullproof ↗
“Open-source migration tool imports a JSON/CSV list of users into Clerk via the Backend API, respecting rate limits”
Bulk-import existing users — including password hashes — and export them again, so I am never locked inpartialproof ↗
“Open-source migration tool imports a JSON/CSV list of users into Clerk via the Backend API, respecting rate limits”
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resetspartialproof ↗
“Enterprise SSO lets users sign in with an Identity Provider (Azure AD, Okta, Google Workspace) with synced user data”
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-infullproof ↗
“Enterprise SSO supports multiple protocols including SAML and OIDC”
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-infullproof ↗
“Supports second-factor MFA strategies: SMS code, authenticator app, and backup codes”
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where neededfullproof ↗
“Sign-in attempts return a needs_second_factor status to enforce MFA step-up”
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where neededfullproof ↗
“OAuth implementation supports scoped access so third-party apps get limited access to user data via Clerk's API”
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")partialproof ↗
“Separate API keys (programmatic callers) and M2M tokens (agent-to-agent) provide machine authentication”
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loopfullproof ↗
“Account UI includes SignUp/SignIn components plus a dropdown for profile and security settings”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Can gate individual agent tool calls against caller's Clerk permissions/scopes and broker OAuth tokens on the caller's behalf”
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authoritypartialproof ↗
“UI components, email templates, and branding (custom CSS, custom domain) can be fully customized”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Passkey and device-biometric sign-in are supported as authentication methods”
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methodspartialproof ↗
“Built-in, continually updated ML-based bot detection reduces fraudulent sign-ups; brute-force-protected OTP delivery”
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flowsfullproof ↗
“Full session lifecycle management with active device monitoring and per-device sign-out/revocation in the user profile UI”
Let users and admins see active sessions and devices and revoke them individually or all at oncepartialproof ↗
Contradicted (2)
“Short-lived JWT session tokens are generated to authenticate requests to your backend”
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised sessiondisputedproof ↗
“Full session lifecycle management with active device monitoring and per-device sign-out/revocation in the user profile UI”
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised sessiondisputedproof ↗
Undersold (20)
Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transactionpartialproof ↗
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secretspartialproof ↗
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentialspartialproof ↗
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokenspartialproof ↗
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Drive the product through a documented public APIfullproof ↗
Issue scoped/least-privilege API credentials for an agentfullproof ↗
Operate the product with natural-language commandspartialproof ↗
Download a machine-readable API spec (OpenAPI or equivalent)fullproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailspartialproof ↗
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom codepartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Read the product's source under an open licensepartialproof ↗
Give each customer organization its own SSO connection with verified domains and just-in-time provisioningpartialproof ↗
Claims outside our story set (3)
Real capability claims found in Clerk’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Pricing table component displays plans with feature comparisons and subscription options”
source ↗“Waitlist feature collects signups and gates access to features/products before launch”
source ↗“Billing support for B2C/B2B apps including free trials, subscription plans, payments, and billing webhook events”
source ↗
Business model
Free tier up to a monthly-active-user allowance, then per-MAU usage pricing with paid add-ons for advanced MFA, organizations, and enterprise SSO connections; custom enterprise contracts above that.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime llms.txt 100% · openapi.json 100% (30d, checked every 6h since Sep 8 '26)
