BetaWeekly digests are a beta — we're trying something new. Feedback welcome.
Auth & Identity weekly digests
- Week of July 13, 2026Security hardening at the foundation
Clerk patched a stored XSS vector in SSR script tags, locked down IPC origin validation in Electron, and announced TLS cipher suite deprecation, while the Clerk JS SDK gained timeout-based failure recovery for slow Frontend API endpoints.
- Week of July 6, 2026Hardening access: enforcement, federation, and fraud prevention
Auth0’s third-party apps for Organizations reached GA, Clerk enforced a token claim bypass, and both platforms added new fraud and federation controls.
- Week of June 29, 2026Browsers, bots, and billing
WorkOS shipped a browser-facing GraphQL API and an MCP server for AI management, Auth0 pushed SCIM provisioning to downstream apps via Event Streams, and Clerk added account credits UI and OAuth token revocation.
- Week of June 22, 2026Self-serve SSO and multi-project orgs reshape enterprise auth
WorkOS launched multiple Projects, Clerk enabled self-serve SSO for customer IT admins, and better-auth shipped a major OAuth provider restructuring — enterprise-grade auth capabilities moved further into developer tooling this week.
- Week of June 15, 2026OAuth consent comes home and Clerk enforces auth at lint time
Clerk ships a hostable OAuth consent component, an experimental ESLint plugin that catches unprotected Next.js routes, and exclusive organization membership, while Better Auth fixes OIDC claim overrides and Auth0's Refresh Token Metadata reaches GA for Enterprise customers.
- Week of June 8, 2026Better Auth hardens concurrent flows while Clerk standardises metadata APIs
Better Auth shipped fixes for dozens of race conditions and replay vulnerabilities across authentication flows, while Clerk deprecated unsafeMetadata in favour of dedicated updateMetadata methods and added new metadata replacement APIs to its backend SDK.
- Week of June 1, 2026The week M2M went multi-tenant and SCIM closed the loop
Auth0 shipped machine-to-machine access for third-party applications and made Inbound SCIM Groups generally available, while Clerk rolled out prebuilt organization management UI across its native mobile SDKs and a major backend API update.
- Week of May 25, 2026Debugging emails, hardening auth, and SSO everywhere
Clerk launched Email Logs in public beta for debugging delivery issues, while Better Auth patched several high-severity security flaws. Auth0 shipped GA passkeys with cross-subdomain support and organization-scoped Token Vault, and Clerk added self-serve SSO configuration across its SDKs.
- Week of May 18, 2026Js-cookie security fix ripples across every Clerk SDK
Every Clerk JavaScript SDK patched this week to upgrade js-cookie to 3.0.7, addressing a cross-site scripting vulnerability. Meanwhile, a new UI helper fixes subscription button visibility for seat-based plans without a base fee.
- Week of May 11, 2026Clerk patches a Next.js bypass, ships SSO UI, and adds metadata updates
The week's biggest story is a high-severity Next.js App Router middleware bypass fixed in Clerk's Next.js SDK, while across the JavaScript monorepo the team shipped SAML SSO configuration steps, user metadata APIs, new UI customization options, and a WorkOS feature flags runtime client.