{"collection":{"slug":"auth-identity","name":"Auth & Identity"},"digest":{"id":"cwd_n_KxaZ6XyE4D-Hlmh1w_n","weekStart":"2026-09-21","title":"Enterprise SSO gets more flexible as middleware patches a credential leak","intro":"Multiple enterprise connections per Organization arrive in Clerk, alongside a cross-request credential leak fix in clerkMiddleware and a cleaner blocked-request experience across its SDKs. Better Auth lands captcha and banned-user messaging, while Supabase's auth server churns through release candidates.","body":"### Enterprise identity gets more flexible\n\nThe biggest shift this week is in how organizations model their identity providers. [Clerk now lets an Organization hold more than one SAML or OIDC enterprise connection](/release/rel_UCMjqIChLOICR6e91nLYm-clerk-allows-multiple-enterprise-connections-per-organization), retiring the `organization_already_has_sso_connection` error that blocked a second connection, and letting more than one directory provision the same user. Clerk tracks each directory's view of a user separately, so a user stays active as long as one enabled directory reports them active, and memberships are only removed when no directory grants them anymore. That matters for companies running parallel IdPs — mergers, regional divisions, or a migration in flight — where the old one-connection limit forced awkward workarounds.\n\nClerk also cleaned up the enterprise sign-in path. Enterprise SSO sign-ins that were erroring instead of prompting now [raise a proper verification challenge](/release/rel_47PiAqwMPzJigCicJt302-clerk-localizations-v4-20-0-fixes-enterprise-sso-verification-challenge) across the localization packages, with the SignIn and SignUp components showing a dedicated screen when a request is blocked — complete with a trace ID and support reference the user can quote. The same blocked-request screen and SSO fix [landed in the core JavaScript SDK](/release/rel_Pv-h9bOp6zwFXf20xuLAR-clerk-javascript-sdk-v4-36-0-adds-blocked-request-screen-and-fixes-enterprise) and in [the UI package](/release/rel_oxeuJyTd7K7r9RPLeY-x8-clerk-javascript-sdk-clerk-ui-1-36-0-fixes-enterprise-sso-and-verification), and custom flows calling `authenticateWithRedirect()` or `authenticateWithPopup()` with Clerk Protect enabled now get a `ClerkRuntimeError` with a resumable path [in `clerk-js`](/release/rel_nQ-WuDg6IGFVsWjDYcfzG-clerk-clerk-js-v6-34-1-fixes-enterprise-sso-sign-in-verification-challenge).\n\n### A credential leak patched, and a rename\n\nThe security fix worth acting on is in [Clerk's Next.js middleware](/release/rel_BXsCe1ZOnSgTaCt4_eMYB-clerk-nextjs-7-9-5-fixes-credential-leak-in-clerkmiddleware): a cross-request credential leak in `clerkMiddleware()` meant that, when using dynamic secret keys resolved per request, a `clerkClient()` call inside the handler could be built with a concurrent request's secret key. Each request now gets its own isolated store. The same package also silenced a development-only React key warning in `ClerkProvider` under the App Router.\n\nOn the API surface, Clerk [renamed the SSO fallback flow to SSO bypass](/release/rel_H8g7pIDBrABwmmWkSmjlK-clerk-react-6-17-0-renames-sso-fallback-to-sso-bypass) to match the feature's shipping name — `ssoFallbackFirstFactors` becomes `ssoBypassFirstFactors`, localization keys and the card action id follow suit. Since the flow was never enabled on any instance, nothing breaks, but the new name also brings admin controls: organization admins can [manage the SSO bypass allowlist from the OrganizationProfile security page](/release/rel_9Dz3H2zXwaBNTrr2kbJoW-clerk-javascript-sdk-v6-33-0-renames-sso-fallback-to-sso-bypass), with custom flows reaching the same list through `organization.ssoBypassAllowlist`. The rest of the JavaScript SDK's week was routine alignment — a long tail of framework adapters picking up the shared package bumps.\n\n### Mobile, captcha, and a quiet auth server\n\nClerk's mobile SDKs saw smaller but practical fixes. The [iOS SDK now requires the currently enrolled biometric set for reverification](/release/rel_YdOP7qx8xIegq9apCIcR--clerk-ios-sdk-1-5-6-requires-current-set-biometrics-for-reverification), so users who changed their fingerprints or Face ID must re-enroll with the new set, plus a layout tweak for iPhone Duo; a follow-up [fixed Nuke package resolution under Xcode Cloud](/release/rel_c5UAozcyr7xJui-7-UdNA-clerk-ios-sdk-1-5-7-drops-git-suffix-from-nuke-package-url). On the Expo side, [a cancelled biometric prompt no longer leaves `useLocalCredentials()` reporting stale credentials](/release/rel_JnrdWEJUQr9o2019W_rvI-clerk-expo-v4-6-9-fixes-biometric-prompt-and-offline-cache-issues), and the offline resource cache no longer carries a previous Clerk instance's user and session across switches.\n\nBetter Auth's week centered on hardening: it [added Vercel BotID as a captcha provider and a `bannedUserMessage` hook](/release/rel_HN7mv3NwZc5lIDte4Cu4j-better-auth-v1-7-6-adds-vercel-botid-captcha-and-banned-user-messages) so sign-in errors can explain a ban reason, rejected over-length passwords before hashing, and fixed hydration mismatches, overlapping auth-query races, and adapter schema validation across Kysely, Prisma, D1, and SQLite. Supabase's auth server, meanwhile, kept to release candidates — a string of checksum-only builds with nothing user-facing to report yet.","releaseIds":["rel_UCMjqIChLOICR6e91nLYm","rel_47PiAqwMPzJigCicJt302","rel_Pv-h9bOp6zwFXf20xuLAR","rel_oxeuJyTd7K7r9RPLeY-x8","rel_nQ-WuDg6IGFVsWjDYcfzG","rel_BXsCe1ZOnSgTaCt4_eMYB","rel_H8g7pIDBrABwmmWkSmjlK","rel_9Dz3H2zXwaBNTrr2kbJoW","rel_YdOP7qx8xIegq9apCIcR-","rel_c5UAozcyr7xJui-7-UdNA","rel_JnrdWEJUQr9o2019W_rvI","rel_HN7mv3NwZc5lIDte4Cu4j"],"releaseCount":51,"generatedAt":"2026-09-28T06:18:14.170Z","releases":[{"id":"rel_UCMjqIChLOICR6e91nLYm","title":"Clerk allows multiple enterprise connections per Organization","path":"/release/rel_UCMjqIChLOICR6e91nLYm-multiple-sso-connections-per-organization-multi-directory-provisioning","url":"https://clerk.com/changelog/2026-09-24-multiple-enterprise-connections-per-organization","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":3},{"id":"rel_47PiAqwMPzJigCicJt302","title":"@clerk/localizations v4.20.0 fixes enterprise SSO verification challenge","path":"/release/rel_47PiAqwMPzJigCicJt302-enterprise-sso-sign-in-verification-challenge-no-longer-errors","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/localizations%404.20.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_Pv-h9bOp6zwFXf20xuLAR","title":"Clerk JavaScript SDK v4.36.0 adds blocked request screen and fixes enterprise SSO sign-in","path":"/release/rel_Pv-h9bOp6zwFXf20xuLAR-blocked-requests-show-dedicated-screen-enterprise-sso-sign-in-fixed","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/shared%404.36.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_oxeuJyTd7K7r9RPLeY-x8","title":"Clerk JavaScript SDK @clerk/ui@1.36.0 fixes enterprise SSO and verification challenges","path":"/release/rel_oxeuJyTd7K7r9RPLeY-x8-enterprise-sso-verification-challenges-fixed-blocked-requests-show-trace-id","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/ui%401.36.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_nQ-WuDg6IGFVsWjDYcfzG","title":"@clerk/clerk-js v6.34.1 fixes enterprise SSO sign-in verification challenge","path":"/release/rel_nQ-WuDg6IGFVsWjDYcfzG-enterprise-sso-sign-ins-now-show-verification-challenge","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.34.1","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_BXsCe1ZOnSgTaCt4_eMYB","title":"@clerk/nextjs@7.9.5 fixes credential leak in clerkMiddleware","path":"/release/rel_BXsCe1ZOnSgTaCt4_eMYB-cross-request-credential-leak-in-clerkmiddleware-fixed","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/nextjs%407.9.5","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_H8g7pIDBrABwmmWkSmjlK","title":"@clerk/react@6.17.0 renames SSO fallback to SSO bypass","path":"/release/rel_H8g7pIDBrABwmmWkSmjlK-sso-fallback-renamed-to-sso-bypass","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/react%406.17.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_9Dz3H2zXwaBNTrr2kbJoW","title":"Clerk JavaScript SDK v6.33.0 renames SSO fallback to SSO bypass","path":"/release/rel_9Dz3H2zXwaBNTrr2kbJoW-sso-fallback-renamed-to-sso-bypass-admins-can-manage-allowlist","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.33.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_YdOP7qx8xIegq9apCIcR-","title":"Clerk iOS SDK 1.5.6 requires current-set biometrics for reverification","path":"/release/rel_YdOP7qx8xIegq9apCIcR--reverification-now-requires-current-set-biometrics","url":"https://github.com/clerk/clerk-ios/releases/tag/1.5.6","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":2},{"id":"rel_c5UAozcyr7xJui-7-UdNA","title":"Clerk iOS SDK 1.5.7 drops .git suffix from Nuke package URL","path":"/release/rel_c5UAozcyr7xJui-7-UdNA-nuke-package-url-drops-git-suffix-for-xcode-cloud","url":"https://github.com/clerk/clerk-ios/releases/tag/1.5.7","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":1},{"id":"rel_JnrdWEJUQr9o2019W_rvI","title":"Clerk Expo v4.6.9 fixes biometric prompt and offline cache issues","path":"/release/rel_JnrdWEJUQr9o2019W_rvI-biometric-prompt-cancellation-handled-offline-cache-cleared-on-instance-switch","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/expo%404.6.9","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_HN7mv3NwZc5lIDte4Cu4j","title":"better-auth v1.7.6 adds Vercel BotID captcha and banned-user messages","path":"/release/rel_HN7mv3NwZc5lIDte4Cu4j-vercel-botid-captcha-over-length-passwords-now-rejected","url":"https://github.com/better-auth/better-auth/releases/tag/v1.7.6","org":{"slug":"better-auth","name":"Better Auth","avatarUrl":"https://media.releases.sh/orgs/better-auth.png","githubHandle":"better-auth"},"product":null,"importance":3}],"sections":[{"heading":"Enterprise identity gets more flexible","anchor":"enterprise-identity-gets-more-flexible","lede":"The biggest shift this week is in how organizations model their identity providers.","releaseIds":["rel_UCMjqIChLOICR6e91nLYm","rel_47PiAqwMPzJigCicJt302","rel_Pv-h9bOp6zwFXf20xuLAR","rel_oxeuJyTd7K7r9RPLeY-x8","rel_nQ-WuDg6IGFVsWjDYcfzG"],"releases":[{"id":"rel_UCMjqIChLOICR6e91nLYm","title":"Clerk allows multiple enterprise connections per Organization","path":"/release/rel_UCMjqIChLOICR6e91nLYm-multiple-sso-connections-per-organization-multi-directory-provisioning","url":"https://clerk.com/changelog/2026-09-24-multiple-enterprise-connections-per-organization","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":3},{"id":"rel_47PiAqwMPzJigCicJt302","title":"@clerk/localizations v4.20.0 fixes enterprise SSO verification challenge","path":"/release/rel_47PiAqwMPzJigCicJt302-enterprise-sso-sign-in-verification-challenge-no-longer-errors","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/localizations%404.20.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_Pv-h9bOp6zwFXf20xuLAR","title":"Clerk JavaScript SDK v4.36.0 adds blocked request screen and fixes enterprise SSO sign-in","path":"/release/rel_Pv-h9bOp6zwFXf20xuLAR-blocked-requests-show-dedicated-screen-enterprise-sso-sign-in-fixed","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/shared%404.36.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_oxeuJyTd7K7r9RPLeY-x8","title":"Clerk JavaScript SDK @clerk/ui@1.36.0 fixes enterprise SSO and verification challenges","path":"/release/rel_oxeuJyTd7K7r9RPLeY-x8-enterprise-sso-verification-challenges-fixed-blocked-requests-show-trace-id","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/ui%401.36.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_nQ-WuDg6IGFVsWjDYcfzG","title":"@clerk/clerk-js v6.34.1 fixes enterprise SSO sign-in verification challenge","path":"/release/rel_nQ-WuDg6IGFVsWjDYcfzG-enterprise-sso-sign-ins-now-show-verification-challenge","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.34.1","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null}]},{"heading":"A credential leak patched, and a rename","anchor":"a-credential-leak-patched-and-a-rename","lede":"The security fix worth acting on is in Clerk's Next.js middleware: a cross-request credential leak in clerkMiddleware() meant that, when using dynamic secret keys resolved per request, a clerkClient() call inside the handler could be built with a concurrent request's secret key.","releaseIds":["rel_BXsCe1ZOnSgTaCt4_eMYB","rel_H8g7pIDBrABwmmWkSmjlK","rel_9Dz3H2zXwaBNTrr2kbJoW"],"releases":[{"id":"rel_BXsCe1ZOnSgTaCt4_eMYB","title":"@clerk/nextjs@7.9.5 fixes credential leak in clerkMiddleware","path":"/release/rel_BXsCe1ZOnSgTaCt4_eMYB-cross-request-credential-leak-in-clerkmiddleware-fixed","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/nextjs%407.9.5","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_H8g7pIDBrABwmmWkSmjlK","title":"@clerk/react@6.17.0 renames SSO fallback to SSO bypass","path":"/release/rel_H8g7pIDBrABwmmWkSmjlK-sso-fallback-renamed-to-sso-bypass","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/react%406.17.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_9Dz3H2zXwaBNTrr2kbJoW","title":"Clerk JavaScript SDK v6.33.0 renames SSO fallback to SSO bypass","path":"/release/rel_9Dz3H2zXwaBNTrr2kbJoW-sso-fallback-renamed-to-sso-bypass-admins-can-manage-allowlist","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.33.0","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null}]},{"heading":"Mobile, captcha, and a quiet auth server","anchor":"mobile-captcha-and-a-quiet-auth-server","lede":"Clerk's mobile SDKs saw smaller but practical fixes.","releaseIds":["rel_YdOP7qx8xIegq9apCIcR-","rel_c5UAozcyr7xJui-7-UdNA","rel_JnrdWEJUQr9o2019W_rvI","rel_HN7mv3NwZc5lIDte4Cu4j"],"releases":[{"id":"rel_YdOP7qx8xIegq9apCIcR-","title":"Clerk iOS SDK 1.5.6 requires current-set biometrics for reverification","path":"/release/rel_YdOP7qx8xIegq9apCIcR--reverification-now-requires-current-set-biometrics","url":"https://github.com/clerk/clerk-ios/releases/tag/1.5.6","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":2},{"id":"rel_c5UAozcyr7xJui-7-UdNA","title":"Clerk iOS SDK 1.5.7 drops .git suffix from Nuke package URL","path":"/release/rel_c5UAozcyr7xJui-7-UdNA-nuke-package-url-drops-git-suffix-for-xcode-cloud","url":"https://github.com/clerk/clerk-ios/releases/tag/1.5.7","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":1},{"id":"rel_JnrdWEJUQr9o2019W_rvI","title":"Clerk Expo v4.6.9 fixes biometric prompt and offline cache issues","path":"/release/rel_JnrdWEJUQr9o2019W_rvI-biometric-prompt-cancellation-handled-offline-cache-cleared-on-instance-switch","url":"https://github.com/clerk/javascript/releases/tag/%40clerk/expo%404.6.9","org":{"slug":"clerk","name":"Clerk","avatarUrl":"https://media.releases.sh/orgs/clerk.png","githubHandle":"clerk"},"product":null,"importance":null},{"id":"rel_HN7mv3NwZc5lIDte4Cu4j","title":"better-auth v1.7.6 adds Vercel BotID captcha and banned-user messages","path":"/release/rel_HN7mv3NwZc5lIDte4Cu4j-vercel-botid-captcha-over-length-passwords-now-rejected","url":"https://github.com/better-auth/better-auth/releases/tag/v1.7.6","org":{"slug":"better-auth","name":"Better Auth","avatarUrl":"https://media.releases.sh/orgs/better-auth.png","githubHandle":"better-auth"},"product":null,"importance":3}]}]}}