---
collection: auth-identity
collection_name: Auth & Identity
week_start: 2026-09-28
title: Auth SDKs ship a security-heavy week of account-takeover fixes and enterprise SSO controls
release_count: 26
generated: 2026-10-05
canonical: https://releases.sh/collections/auth-identity/digest/2026-09-28
---

# Auth SDKs ship a security-heavy week of account-takeover fixes and enterprise SSO controls

Better Auth patched a critical Magic Link account-takeover vulnerability, Clerk made Directory Sync self-serve for organization admins and added an SSO bypass for locked-out enterprise users, while Auth0 warned that refresh tokens are about to get longer and Clerk's JavaScript SDK rolled a Protect-challenge overhaul out across every framework package.

### A critical fix lands in Better Auth

The week's most urgent item is [Better Auth's patch for a Magic Link account-takeover vulnerability](https://github.com/better-auth/better-auth/releases/tag/v1.7.7), which also covered an OAuth Proxy bug that accepted sign-in state as a provider profile. Anyone running Magic Link on shared verification storage needs to upgrade every server in the group together, request fresh Magic Links, and restart any OAuth or SAML sign-ins that were mid-flight — no database migration required, but the sequencing matters because a half-upgraded fleet is exactly the window an attacker wants. The same release tightened a handful of adjacent loose ends: ID-token sign-ins now respect the social provider's `disableSignUp` setting, concurrent PostgreSQL requests no longer slip past database-backed rate limits, and CAPTCHA and rate-limit errors finally carry proper JSON Content-Type headers.

### Enterprise SSO gets more self-serve, and a pressure valve

Clerk spent the week making enterprise connections less dependent on support tickets. [Self-serve Directory Sync](https://clerk.com/changelog/2026-09-30-self-serve-directory-sync) lets a customer's own IT admins configure SCIM provisioning — including Google Workspace via the Google Admin SDK — from the Security tab inside `<OrganizationProfile />`, rather than waiting on a customer team to hand over a SCIM endpoint and bearer token. It's gated behind Organizations plus the Pro or Business plan with the B2B Authentication add-on, and stays off until you enable it under Organization permissions.

The counterpart is [SSO bypass](https://clerk.com/changelog/2026-09-29-sso-bypass), which addresses the failure mode every enterprise deployment eventually hits: the IdP goes down or a certificate expires, and the very people who could fix it can't sign in. Allowlisted users can now fall back to a one-time email code through a "Can't use SSO?" link in the `SignIn` component, everyone else stays pinned to SSO, and each successful bypass is recorded as a `sign_in.sso_bypass.succeeded` event in Application Logs — so the escape hatch is auditable rather than invisible. The allowlist itself is manageable from the Dashboard, the Backend API, or by org members holding the `org:sys_entconns_sso_bypass:manage` permission.

### Clerk's JavaScript SDK ships a broad release train

Clerk's JavaScript SDK cut a long series of coordinated packages, and the headline change is that [custom flows built with `useSignIn()` and `useSignUp()` now handle Clerk Protect challenges automatically](https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.36.0) — the challenge surfaces in a modal and the method returns once the user passes it, with SSO challenges appearing back at `<HandleSSOCallback />`. That behavior propagated outward to [Clerk UI](https://github.com/clerk/javascript/releases/tag/%40clerk/ui%401.38.0), [React](https://github.com/clerk/javascript/releases/tag/%40clerk/react%406.17.4), [shared](https://github.com/clerk/javascript/releases/tag/%40clerk/shared%404.37.1), the [Electron](https://github.com/clerk/javascript/releases/tag/%40clerk/electron%400.0.49) and [Chrome extension](https://github.com/clerk/javascript/releases/tag/%40clerk/chrome-extension%403.1.89) wrappers, plus the usual dependents. The same work shrank the Solana wallet picker from 306 KB to 2 KB, dropping React Native, Metro, and `@solana/web3.js` from the bundle.

Elsewhere in the train: [Mosaic fixed menu popups animating closed and mouse-triggered focus rings](https://github.com/clerk/javascript/releases/tag/%40clerk/mosaic%400.1.4), [Next.js stopped ending error messages with a period](https://github.com/clerk/javascript/releases/tag/%40clerk/nextjs%407.9.9) because agents were fetching the trailing dot and 404ing, [the backend JSDoc clarified Electron dev-server origins and linked the Protect rules page](https://github.com/clerk/javascript/releases/tag/%40clerk/backend%403.21.1), and [Expo bumped its bundled Android SDK](https://github.com/clerk/javascript/releases/tag/%40clerk/expo%404.7.3). The rest of the wave — [Fastify](https://github.com/clerk/javascript/releases/tag/%40clerk/fastify%403.1.84), [Express](https://github.com/clerk/javascript/releases/tag/%40clerk/express%402.1.74), [Nuxt](https://github.com/clerk/javascript/releases/tag/%40clerk/nuxt%403.1.8), [Hono](https://github.com/clerk/javascript/releases/tag/%40clerk/hono%400.1.84), [Vue](https://github.com/clerk/javascript/releases/tag/%40clerk/vue%402.5.8), [testing](https://github.com/clerk/javascript/releases/tag/%40clerk/testing%402.2.41), [React Router](https://github.com/clerk/javascript/releases/tag/%40clerk/react-router%403.6.29), [TanStack Start](https://github.com/clerk/javascript/releases/tag/%40clerk/tanstack-react-start%401.6.3), [Astro](https://github.com/clerk/javascript/releases/tag/%40clerk/astro%404.1.8), [Expo Passkeys](https://github.com/clerk/javascript/releases/tag/%40clerk/expo-passkeys%402.0.25), and [localizations](https://github.com/clerk/javascript/releases/tag/%40clerk/localizations%404.21.1) — was routine dependency churn.

### Breaking changes to plan for

Two smaller releases carry upgrade work. The [Clerk iOS SDK simplified its Billing `has()` method and read API call shapes](https://github.com/clerk/clerk-ios/releases/tag/1.5.8) — a breaking change for existing callers — while also fixing refreshed tokens drifting out of sync with session state, non-idempotent requests being retried after a possible server-side effect, and a telemetry flush loop that kept the collector alive. And [Auth0 is raising refresh token entropy](https://auth0.com/changelog#5rn5HfDjtV2Hx80c3u9dBg), which means newly issued tokens will exceed the current ~45-character baseline. Existing sessions stay valid, but hardcoded length checks, fixed-width columns like `VARCHAR(45)`, and maximum-length regexes will start failing — worth a grep before the change lands.

## Releases covered

### Auth0

- [Auth0 to lengthen refresh tokens beyond 45 characters](https://auth0.com/changelog#5rn5HfDjtV2Hx80c3u9dBg)

### Better Auth

- [better-auth v1.7.7 patches critical Magic Link account-takeover vulnerability](https://github.com/better-auth/better-auth/releases/tag/v1.7.7)

### Clerk

- [Clerk launches self-serve Directory Sync for Organization admins](https://clerk.com/changelog/2026-09-30-self-serve-directory-sync)
- [Clerk adds SSO bypass so allowlisted users can sign in by email code](https://clerk.com/changelog/2026-09-29-sso-bypass)
- [@clerk/clerk-js@6.36.0 handles Clerk Protect challenges in custom flows](https://github.com/clerk/javascript/releases/tag/%40clerk/clerk-js%406.36.0)
- [Clerk UI v1.38.0 handles Protect challenges in custom sign-in and sign-up flows](https://github.com/clerk/javascript/releases/tag/%40clerk/ui%401.38.0)
- [@clerk/react@6.17.4 handles Clerk Protect challenges in custom flows](https://github.com/clerk/javascript/releases/tag/%40clerk/react%406.17.4)
- [@clerk/shared@4.37.1 handles Clerk Protect challenges in custom flows](https://github.com/clerk/javascript/releases/tag/%40clerk/shared%404.37.1)
- [Clerk JavaScript SDK @clerk/electron@0.0.49 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/electron%400.0.49)
- [Clerk JavaScript SDK @clerk/chrome-extension@3.1.89 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/chrome-extension%403.1.89)
- [Clerk Mosaic v0.1.4 fixes menu animation and focus ring display](https://github.com/clerk/javascript/releases/tag/%40clerk/mosaic%400.1.4)
- [@clerk/nextjs v7.9.9 removes period from error messages to fix broken URLs](https://github.com/clerk/javascript/releases/tag/%40clerk/nextjs%407.9.9)
- [Clerk JavaScript SDK v3.21.1 clarifies Electron and Protect documentation](https://github.com/clerk/javascript/releases/tag/%40clerk/backend%403.21.1)
- [Clerk Expo SDK v4.7.3 bumps bundled Android SDK to 1.1.10](https://github.com/clerk/javascript/releases/tag/%40clerk/expo%404.7.3)
- [Clerk JavaScript SDK @clerk/fastify@3.1.84 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/fastify%403.1.84)
- [@clerk/express v2.1.74 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/express%402.1.74)
- [Clerk JavaScript SDK @clerk/nuxt@3.1.8 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/nuxt%403.1.8)
- [Clerk JavaScript SDK @clerk/hono@0.1.84 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/hono%400.1.84)
- [@clerk/vue v2.5.8 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/vue%402.5.8)
- [@clerk/testing v2.2.41 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/testing%402.2.41)
- [Clerk JavaScript SDK @clerk/react-router@3.6.29 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/react-router%403.6.29)
- [Clerk JavaScript SDK @clerk/tanstack-react-start@1.6.3 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/tanstack-react-start%401.6.3)
- [Clerk JavaScript SDK @clerk/astro@4.1.8 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/astro%404.1.8)
- [Clerk Expo Passkeys @2.0.25 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/expo-passkeys%402.0.25)
- [@clerk/localizations@4.21.1 dependency update](https://github.com/clerk/javascript/releases/tag/%40clerk/localizations%404.21.1)
- [Clerk iOS SDK 1.5.8 breaks Billing has() and read API call shapes](https://github.com/clerk/clerk-ios/releases/tag/1.5.8)
