---
collection: auth-identity
collection_name: Auth & Identity
week_start: 2026-09-21
title: Enterprise SSO gets more flexible as middleware patches a credential leak
release_count: 51
generated: 2026-09-28
canonical: https://releases.sh/collections/auth-identity/digest/2026-09-21
---

# Enterprise SSO gets more flexible as middleware patches a credential leak

Multiple enterprise connections per Organization arrive in Clerk, alongside a cross-request credential leak fix in clerkMiddleware and a cleaner blocked-request experience across its SDKs. Better Auth lands captcha and banned-user messaging, while Supabase's auth server churns through release candidates.

### Enterprise identity gets more flexible

The biggest shift this week is in how organizations model their identity providers. [Clerk now lets an Organization hold more than one SAML or OIDC enterprise connection](https://clerk.com/changelog/2026-09-24-multiple-enterprise-connections-per-organization), retiring the `organization_already_has_sso_connection` error that blocked a second connection, and letting more than one directory provision the same user. Clerk tracks each directory's view of a user separately, so a user stays active as long as one enabled directory reports them active, and memberships are only removed when no directory grants them anymore. That matters for companies running parallel IdPs — mergers, regional divisions, or a migration in flight — where the old one-connection limit forced awkward workarounds.

Clerk also cleaned up the enterprise sign-in path. Enterprise SSO sign-ins that were erroring instead of prompting now [raise a proper verification challenge](https://github.com/clerk/javascript/releases/tag/%40clerk/localizations%404.20.0) across the localization packages, with the SignIn and SignUp components showing a dedicated screen when a request is blocked — complete with a trace ID and support reference the user can quote. The same blocked-request screen and SSO fix [landed in the core JavaScript SDK](https://github.com/clerk/javascript/releases/tag/%40clerk/shared%404.36.0) and in [the UI package](https://github.com/clerk/javascript/releases/tag/%40clerk/ui%401.36.0), and custom flows calling `authenticateWithRedirect()` or `authenticateWithPopup()` with Clerk Protect enabled now get a `ClerkRuntimeError` with a resumable path [in `clerk-js`](https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.34.1).

### A credential leak patched, and a rename

The security fix worth acting on is in [Clerk's Next.js middleware](https://github.com/clerk/javascript/releases/tag/%40clerk/nextjs%407.9.5): a cross-request credential leak in `clerkMiddleware()` meant that, when using dynamic secret keys resolved per request, a `clerkClient()` call inside the handler could be built with a concurrent request's secret key. Each request now gets its own isolated store. The same package also silenced a development-only React key warning in `ClerkProvider` under the App Router.

On the API surface, Clerk [renamed the SSO fallback flow to SSO bypass](https://github.com/clerk/javascript/releases/tag/%40clerk/react%406.17.0) to match the feature's shipping name — `ssoFallbackFirstFactors` becomes `ssoBypassFirstFactors`, localization keys and the card action id follow suit. Since the flow was never enabled on any instance, nothing breaks, but the new name also brings admin controls: organization admins can [manage the SSO bypass allowlist from the OrganizationProfile security page](https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.33.0), with custom flows reaching the same list through `organization.ssoBypassAllowlist`. The rest of the JavaScript SDK's week was routine alignment — a long tail of framework adapters picking up the shared package bumps.

### Mobile, captcha, and a quiet auth server

Clerk's mobile SDKs saw smaller but practical fixes. The [iOS SDK now requires the currently enrolled biometric set for reverification](https://github.com/clerk/clerk-ios/releases/tag/1.5.6), so users who changed their fingerprints or Face ID must re-enroll with the new set, plus a layout tweak for iPhone Duo; a follow-up [fixed Nuke package resolution under Xcode Cloud](https://github.com/clerk/clerk-ios/releases/tag/1.5.7). On the Expo side, [a cancelled biometric prompt no longer leaves `useLocalCredentials()` reporting stale credentials](https://github.com/clerk/javascript/releases/tag/%40clerk/expo%404.6.9), and the offline resource cache no longer carries a previous Clerk instance's user and session across switches.

Better Auth's week centered on hardening: it [added Vercel BotID as a captcha provider and a `bannedUserMessage` hook](https://github.com/better-auth/better-auth/releases/tag/v1.7.6) so sign-in errors can explain a ban reason, rejected over-length passwords before hashing, and fixed hydration mismatches, overlapping auth-query races, and adapter schema validation across Kysely, Prisma, D1, and SQLite. Supabase's auth server, meanwhile, kept to release candidates — a string of checksum-only builds with nothing user-facing to report yet.

## Releases covered

### Better Auth

- [better-auth v1.7.6 adds Vercel BotID captcha and banned-user messages](https://github.com/better-auth/better-auth/releases/tag/v1.7.6)

### Clerk

- [Clerk allows multiple enterprise connections per Organization](https://clerk.com/changelog/2026-09-24-multiple-enterprise-connections-per-organization)
- [@clerk/localizations v4.20.0 fixes enterprise SSO verification challenge](https://github.com/clerk/javascript/releases/tag/%40clerk/localizations%404.20.0)
- [Clerk JavaScript SDK v4.36.0 adds blocked request screen and fixes enterprise SSO sign-in](https://github.com/clerk/javascript/releases/tag/%40clerk/shared%404.36.0)
- [Clerk JavaScript SDK @clerk/ui@1.36.0 fixes enterprise SSO and verification challenges](https://github.com/clerk/javascript/releases/tag/%40clerk/ui%401.36.0)
- [@clerk/clerk-js v6.34.1 fixes enterprise SSO sign-in verification challenge](https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.34.1)
- [@clerk/nextjs@7.9.5 fixes credential leak in clerkMiddleware](https://github.com/clerk/javascript/releases/tag/%40clerk/nextjs%407.9.5)
- [@clerk/react@6.17.0 renames SSO fallback to SSO bypass](https://github.com/clerk/javascript/releases/tag/%40clerk/react%406.17.0)
- [Clerk JavaScript SDK v6.33.0 renames SSO fallback to SSO bypass](https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.33.0)
- [Clerk iOS SDK 1.5.6 requires current-set biometrics for reverification](https://github.com/clerk/clerk-ios/releases/tag/1.5.6)
- [Clerk iOS SDK 1.5.7 drops .git suffix from Nuke package URL](https://github.com/clerk/clerk-ios/releases/tag/1.5.7)
- [Clerk Expo v4.6.9 fixes biometric prompt and offline cache issues](https://github.com/clerk/javascript/releases/tag/%40clerk/expo%404.6.9)
