{"collection":{"slug":"auth-identity","name":"Auth & Identity"},"digests":[{"id":"cwd_srTZwAHk2PlYXpwHSDiTA","weekStart":"2026-07-13","title":"Security hardening at the foundation","intro":"Clerk patched a stored XSS vector in SSR script tags, locked down IPC origin validation in Electron, and announced TLS cipher suite deprecation, while the Clerk JS SDK gained timeout-based failure recovery for slow Frontend API endpoints.","releaseCount":94,"generatedAt":"2026-07-20T06:17:57.607Z"},{"id":"cwd_NCgHe0hDpcUCcJXhWTN0g","weekStart":"2026-07-06","title":"Hardening access: enforcement, federation, and fraud prevention","intro":"Auth0’s third-party apps for Organizations reached GA, Clerk enforced a token claim bypass, and both platforms added new fraud and federation controls.","releaseCount":90,"generatedAt":"2026-07-13T06:18:04.884Z"},{"id":"cwd_ufGALVDVps2X7f6Ju185q","weekStart":"2026-06-29","title":"Browsers, bots, and billing","intro":"WorkOS shipped a browser-facing GraphQL API and an MCP server for AI management, Auth0 pushed SCIM provisioning to downstream apps via Event Streams, and Clerk added account credits UI and OAuth token revocation.","releaseCount":50,"generatedAt":"2026-07-11T16:59:51.999Z"},{"id":"cwd_VfQ_gB9LlRgSa4dJi1cBu","weekStart":"2026-06-22","title":"Self-serve SSO and multi-project orgs reshape enterprise auth","intro":"WorkOS launched multiple Projects, Clerk enabled self-serve SSO for customer IT admins, and better-auth shipped a major OAuth provider restructuring — enterprise-grade auth capabilities moved further into developer tooling this week.","releaseCount":67,"generatedAt":"2026-07-11T17:05:52.601Z"},{"id":"cwd_JNlt8myJ0FhfF8G37HBH_","weekStart":"2026-06-15","title":"OAuth consent comes home and Clerk enforces auth at lint time","intro":"Clerk ships a hostable OAuth consent component, an experimental ESLint plugin that catches unprotected Next.js routes, and exclusive organization membership, while Better Auth fixes OIDC claim overrides and Auth0's Refresh Token Metadata reaches GA for Enterprise customers.","releaseCount":68,"generatedAt":"2026-07-11T17:00:41.503Z"},{"id":"cwd_nMl9HKqNHdSiO5cGJYpJs","weekStart":"2026-06-08","title":"Better Auth hardens concurrent flows while Clerk standardises metadata APIs","intro":"Better Auth shipped fixes for dozens of race conditions and replay vulnerabilities across authentication flows, while Clerk deprecated unsafeMetadata in favour of dedicated updateMetadata methods and added new metadata replacement APIs to its backend SDK.","releaseCount":75,"generatedAt":"2026-07-11T17:01:05.626Z"},{"id":"cwd_uhlAdTRHfuCqPvuv8pG_1","weekStart":"2026-06-01","title":"The week M2M went multi-tenant and SCIM closed the loop","intro":"Auth0 shipped machine-to-machine access for third-party applications and made Inbound SCIM Groups generally available, while Clerk rolled out prebuilt organization management UI across its native mobile SDKs and a major backend API update.","releaseCount":41,"generatedAt":"2026-07-11T17:04:58.668Z"},{"id":"cwd_j-hTDOXgbNKPsG-1rkzMi","weekStart":"2026-05-25","title":"Debugging emails, hardening auth, and SSO everywhere","intro":"Clerk launched Email Logs in public beta for debugging delivery issues, while Better Auth patched several high-severity security flaws. Auth0 shipped GA passkeys with cross-subdomain support and organization-scoped Token Vault, and Clerk added self-serve SSO configuration across its SDKs.","releaseCount":59,"generatedAt":"2026-07-11T17:02:28.721Z"},{"id":"cwd_V2C2moT8giZ_ElebNrZtU","weekStart":"2026-05-18","title":"Js-cookie security fix ripples across every Clerk SDK","intro":"Every Clerk JavaScript SDK patched this week to upgrade js-cookie to 3.0.7, addressing a cross-site scripting vulnerability. Meanwhile, a new UI helper fixes subscription button visibility for seat-based plans without a base fee.","releaseCount":87,"generatedAt":"2026-07-11T17:03:12.931Z"},{"id":"cwd_Jllw9iGvIsX8CAWmadk2v","weekStart":"2026-05-11","title":"Clerk patches a Next.js bypass, ships SSO UI, and adds metadata updates","intro":"The week's biggest story is a high-severity Next.js App Router middleware bypass fixed in Clerk's Next.js SDK, while across the JavaScript monorepo the team shipped SAML SSO configuration steps, user metadata APIs, new UI customization options, and a WorkOS feature flags runtime client.","releaseCount":48,"generatedAt":"2026-07-11T17:03:32.001Z"}],"pagination":{"nextCursor":null,"limit":50}}