Skip to content

M2M Token only authentication in Clerk Middleware #9981

Description

@x-delfino

Preliminary Checks

Reproduction

https://github.com/x-delfino/clerk-fastify-issue-repro

Publishable key

pk_test_dG91Y2hlZC1mb3dsLTk5MDYuY2xlcmsuYWNjb3VudHMuZGV2JA

Description

I'm trying to use M2M tokens to authenticate one machine to another, without any subsequent backend API access. I'm testing this with the clerk fastify plugin, but I don't think the issue is necessarily specific to that package

Steps to reproduce:

  1. Create M2M Machines in Clerk:
  • MachineA: no scopes
  • MachineB: scope for MachineA
  1. Setup workspace (using MachineA secret key):
git clone https://github.com/x-delfino/clerk-fastify-issue-repro
cd clerk-fastify-issue-repro
pnpm install
export CLERK_MACHINE_SECRET_KEY="ak_XXXXXXXXX"
pnpm run serve
  1. Generate token for MachineB
  2. make HTTP request:
TOKEN="MACHINE_B_TOKEN"
curl -H "Authorization: Bearer $TOKEN" localhost:8080/protected

Expected behavior:

To receive response:

{"message":"Machine authenticated successfully","subject":"mch_XXXXXXXXX","scopes":["mch_XXXXXXXXX"]}

Actual behavior:

Response received:

{"statusCode":500,"error":"Internal Server Error","message":"Publishable key is missing.\n\nTo create a new Clerk app, run:\nnpx clerk@latest init\n\nTo use an existing Clerk app, run:\nnpx clerk@latest link\nnpx clerk@latest env pull\n\nFor production keys, run:\nnpx clerk@latest env pull --instance prod\n\nOr copy keys from https://dashboard.clerk.com/~/api-keys into your .env file."}

Providing CLERK_PUBLISHABLE_KEY changes the response to:

{"statusCode":500,"error":"Internal Server Error","message":"Missing Clerk Secret Key. Go to https://dashboard.clerk.com and get your key for your instance."}

Detail:

The clerk middleware for fastify hardcodes the acceptsToken to 'any':

const requestState = await clerkClient.authenticateRequest(req, {
...clerkOptions,
secretKey,
publishableKey,
proxyUrl: resolvedProxyUrl,
acceptsToken: 'any',
});

When the token is then processed, as it's not explicitly M2MToken or ApiKey - it tries to load the publishable key:

if (options.acceptsToken === TokenType.M2MToken || options.acceptsToken === TokenType.ApiKey) {
// For non-session tokens, we only want to set the header values.
this.initHeaderValues();
} else {
// Even though the options are assigned to this later in this function
// we set the publishableKey here because it is being used in cookies/headers/handshake-values
// as part of getMultipleAppsCookie.
this.initPublishableKeyValues(options);
this.initHeaderValues();
// initCookieValues should be used before initHandshakeValues because it depends on suffixedCookies
this.initCookieValues();
this.initHandshakeValues();
}

I patched the fastify clerk middleware to allow the acceptsToken key to be provided:

    const requestState = await clerkClient.authenticateRequest(req, {
      ...clerkOptions,
      secretKey,
      publishableKey,
      proxyUrl: resolvedProxyUrl,
      // acceptsToken: 'any',
    });

Allowing me to update my sample code to:

fastify.register(clerkPlugin, { acceptsToken: "m2m_token" })

Allowing me to receive and validate M2M tokens using M2M tokens only

However, this isn't type correct. ClerkFastifyOptions, through a chain of intersections, doesn't pull in acceptsToken from AuthenticateRequestOptions

type BuildTimeOptions = Partial<
Pick<
AuthenticateRequestOptions,
| 'apiUrl'
| 'apiVersion'
| 'audience'
| 'domain'
| 'isSatellite'
| 'jwtKey'
| 'proxyUrl'
| 'publishableKey'
| 'secretKey'
| 'machineSecretKey'
>
>;

I'm not sure the best way to proceed from here as changes may affect more than fastify

Environment

System:
    OS: macOS 26.5
    CPU: (10) arm64 Apple M4
    Memory: 134.00 MB / 32.00 GB
    Shell: 5.9 - /bin/zsh
  Binaries:
    Node: 26.10.0 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/node
    npm: 11.19.1 - /nix/store/xs1l2nzllqp7imnhpd2n6cm0m70yzp10-nodejs-26.10.0/bin/npm
    pnpm: 11.27.0 - /nix/store/gjkd8wjh079v7i5j2rb8y0b5r19addpa-pnpm-11.27.0/bin/pnpm
  Browsers:
    Safari: 26.5
  npmPackages:
    @clerk/fastify: ^3.1.82 => 3.1.82 
    @types/node: ^26.6.3 => 26.6.3 
    fastify: ^5.12.5 => 5.12.5 
    typescript: ^7.0.2 => 7.0.2

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

needs-triageA ticket that needs to be triaged by a team member

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions