BetaWeekly digests are a beta — we're trying something new. Feedback welcome.
Enterprise SSO gets more flexible as middleware patches a credential leak
September 21–27, 2026
Multiple enterprise connections per Organization arrive in Clerk, alongside a cross-request credential leak fix in clerkMiddleware and a cleaner blocked-request experience across its SDKs. Better Auth lands captcha and banned-user messaging, while Supabase's auth server churns through release candidates.
Enterprise identity gets more flexible
The biggest shift this week is in how organizations model their identity providers. Clerk now lets an Organization hold more than one SAML or OIDC enterprise connection, retiring the organization_already_has_sso_connection error that blocked a second connection, and letting more than one directory provision the same user. Clerk tracks each directory's view of a user separately, so a user stays active as long as one enabled directory reports them active, and memberships are only removed when no directory grants them anymore. That matters for companies running parallel IdPs — mergers, regional divisions, or a migration in flight — where the old one-connection limit forced awkward workarounds.
Clerk also cleaned up the enterprise sign-in path. Enterprise SSO sign-ins that were erroring instead of prompting now raise a proper verification challenge across the localization packages, with the SignIn and SignUp components showing a dedicated screen when a request is blocked — complete with a trace ID and support reference the user can quote. The same blocked-request screen and SSO fix landed in the core JavaScript SDK and in the UI package, and custom flows calling authenticateWithRedirect() or authenticateWithPopup() with Clerk Protect enabled now get a ClerkRuntimeError with a resumable path in clerk-js.
A credential leak patched, and a rename
The security fix worth acting on is in Clerk's Next.js middleware: a cross-request credential leak in clerkMiddleware() meant that, when using dynamic secret keys resolved per request, a clerkClient() call inside the handler could be built with a concurrent request's secret key. Each request now gets its own isolated store. The same package also silenced a development-only React key warning in ClerkProvider under the App Router.
On the API surface, Clerk renamed the SSO fallback flow to SSO bypass to match the feature's shipping name — ssoFallbackFirstFactors becomes ssoBypassFirstFactors, localization keys and the card action id follow suit. Since the flow was never enabled on any instance, nothing breaks, but the new name also brings admin controls: organization admins can manage the SSO bypass allowlist from the OrganizationProfile security page, with custom flows reaching the same list through organization.ssoBypassAllowlist. The rest of the JavaScript SDK's week was routine alignment — a long tail of framework adapters picking up the shared package bumps.
Mobile, captcha, and a quiet auth server
Clerk's mobile SDKs saw smaller but practical fixes. The iOS SDK now requires the currently enrolled biometric set for reverification, so users who changed their fingerprints or Face ID must re-enroll with the new set, plus a layout tweak for iPhone Duo; a follow-up fixed Nuke package resolution under Xcode Cloud. On the Expo side, a cancelled biometric prompt no longer leaves useLocalCredentials() reporting stale credentials, and the offline resource cache no longer carries a previous Clerk instance's user and session across switches.
Better Auth's week centered on hardening: it added Vercel BotID as a captcha provider and a bannedUserMessage hook so sign-in errors can explain a ban reason, rejected over-length passwords before hashing, and fixed hydration mismatches, overlapping auth-query races, and adapter schema validation across Kysely, Prisma, D1, and SQLite. Supabase's auth server, meanwhile, kept to release candidates — a string of checksum-only builds with nothing user-facing to report yet.
Releases covered12
- Clerk allows multiple enterprise connections per Organization (opens in new tab)
- @clerk/localizations v4.20.0 fixes enterprise SSO verification challenge (opens in new tab)
- Clerk JavaScript SDK v4.36.0 adds blocked request screen and fixes enterprise SSO sign-in (opens in new tab)
- Clerk JavaScript SDK @clerk/ui@1.36.0 fixes enterprise SSO and verification challenges (opens in new tab)
- @clerk/clerk-js v6.34.1 fixes enterprise SSO sign-in verification challenge (opens in new tab)
- @clerk/nextjs@7.9.5 fixes credential leak in clerkMiddleware (opens in new tab)
- @clerk/react@6.17.0 renames SSO fallback to SSO bypass (opens in new tab)
- Clerk JavaScript SDK v6.33.0 renames SSO fallback to SSO bypass (opens in new tab)
- Clerk iOS SDK 1.5.6 requires current-set biometrics for reverification (opens in new tab)
- Clerk iOS SDK 1.5.7 drops .git suffix from Nuke package URL (opens in new tab)
- Clerk Expo v4.6.9 fixes biometric prompt and offline cache issues (opens in new tab)