Releases Index

BetaWeekly digests are a beta — we're trying something new. Feedback welcome.

Auth SDKs ship a security-heavy week of account-takeover fixes and enterprise SSO controls

September 28 – October 4, 2026

Better AuthClerkAuth0
Better Auth, Clerk, Auth0

Better Auth patched a critical Magic Link account-takeover vulnerability, Clerk made Directory Sync self-serve for organization admins and added an SSO bypass for locked-out enterprise users, while Auth0 warned that refresh tokens are about to get longer and Clerk's JavaScript SDK rolled a Protect-challenge overhaul out across every framework package.

A critical fix lands in Better Auth

The week's most urgent item is Better Auth's patch for a Magic Link account-takeover vulnerability, which also covered an OAuth Proxy bug that accepted sign-in state as a provider profile. Anyone running Magic Link on shared verification storage needs to upgrade every server in the group together, request fresh Magic Links, and restart any OAuth or SAML sign-ins that were mid-flight — no database migration required, but the sequencing matters because a half-upgraded fleet is exactly the window an attacker wants. The same release tightened a handful of adjacent loose ends: ID-token sign-ins now respect the social provider's disableSignUp setting, concurrent PostgreSQL requests no longer slip past database-backed rate limits, and CAPTCHA and rate-limit errors finally carry proper JSON Content-Type headers.

Enterprise SSO gets more self-serve, and a pressure valve

Clerk spent the week making enterprise connections less dependent on support tickets. Self-serve Directory Sync lets a customer's own IT admins configure SCIM provisioning — including Google Workspace via the Google Admin SDK — from the Security tab inside <OrganizationProfile />, rather than waiting on a customer team to hand over a SCIM endpoint and bearer token. It's gated behind Organizations plus the Pro or Business plan with the B2B Authentication add-on, and stays off until you enable it under Organization permissions.

The counterpart is SSO bypass, which addresses the failure mode every enterprise deployment eventually hits: the IdP goes down or a certificate expires, and the very people who could fix it can't sign in. Allowlisted users can now fall back to a one-time email code through a "Can't use SSO?" link in the SignIn component, everyone else stays pinned to SSO, and each successful bypass is recorded as a sign_in.sso_bypass.succeeded event in Application Logs — so the escape hatch is auditable rather than invisible. The allowlist itself is manageable from the Dashboard, the Backend API, or by org members holding the org:sys_entconns_sso_bypass:manage permission.

Clerk's JavaScript SDK ships a broad release train

Clerk's JavaScript SDK cut a long series of coordinated packages, and the headline change is that custom flows built with useSignIn() and useSignUp() now handle Clerk Protect challenges automatically — the challenge surfaces in a modal and the method returns once the user passes it, with SSO challenges appearing back at <HandleSSOCallback />. That behavior propagated outward to Clerk UI, React, shared, the Electron and Chrome extension wrappers, plus the usual dependents. The same work shrank the Solana wallet picker from 306 KB to 2 KB, dropping React Native, Metro, and @solana/web3.js from the bundle.

Elsewhere in the train: Mosaic fixed menu popups animating closed and mouse-triggered focus rings, Next.js stopped ending error messages with a period because agents were fetching the trailing dot and 404ing, the backend JSDoc clarified Electron dev-server origins and linked the Protect rules page, and Expo bumped its bundled Android SDK. The rest of the wave — Fastify, Express, Nuxt, Hono, Vue, testing, React Router, TanStack Start, Astro, Expo Passkeys, and localizations — was routine dependency churn.

Breaking changes to plan for

Two smaller releases carry upgrade work. The Clerk iOS SDK simplified its Billing has() method and read API call shapes — a breaking change for existing callers — while also fixing refreshed tokens drifting out of sync with session state, non-idempotent requests being retried after a possible server-side effect, and a telemetry flush loop that kept the collector alive. And Auth0 is raising refresh token entropy, which means newly issued tokens will exceed the current ~45-character baseline. Existing sessions stay valid, but hardcoded length checks, fixed-width columns like VARCHAR(45), and maximum-length regexes will start failing — worth a grep before the change lands.

AI-generated digests may contain mistakes.
Releases covered26
Clerk