Clerk Core Workflow B: Session & Middleware
SkillDev tools'Implement session management and middleware with Clerk.
Use Clerk Core Workflow B: Session & Middleware in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Clerk Core Workflow B: Session & Middleware and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Clerk Core Workflow B: Session & Middleware skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by jeremylongshore/tons-of-skills-marketplace in skills/.curated/clerk-core-workflow-b/SKILL.md and read by Ahel’s review.
Overview
Implement session management and route protection with Clerk middleware. Covers
clerkMiddleware() configuration, auth() patterns, custom session claims, JWT
templates for external services, organization-scoped sessions, and session token v2.
Use when managing user sessions, configuring route protection, or implementing token refresh and custom JWT templates.
Prerequisites
@clerk/nextjsinstalled with ClerkProvider wrapping the app- Next.js 14+ with App Router (or adapt patterns for your stack)
- Working publishable + secret Clerk keys in env
Instructions
- Confirm ClerkProvider and env keys are live (see
clerk-install-auth/clerk-hello-world). - Configure
clerkMiddleware()matcher / public routes for the routes you want open. - Use
auth()/currentUser()on protected pages and API routes; fail closed when unauthenticated. - For custom claims or external JWT consumers, configure session token templates carefully (size limits).
- For org-scoped apps, bind authorization to org id + role claims, not only user id.
- Verify: signed-out user cannot hit protected routes; signed-in user can; org role gates hold.
Deep patterns, JWT templates, and edge cases: session-middleware-deep-dive.md.
Output
- Session/middleware configuration enforcing the requested protection rules
- Documented JWT/session claim changes when customized
- Verification steps for protected vs public routes
Examples
Protect all routes except marketing
User: Protect everything except /, /pricing, and Clerk sign-in routes.
Skill: configures clerkMiddleware publicRoutes / matcher and verifies unauth redirect.
Custom session claim for plan tier
User: Put plan_tier on the session JWT for feature flags.
Skill: configures session token template and validates claim size + read path.
Error Handling
| Condition | Response |
|---|---|
| Route is accidentally public | Fail the verification gate and narrow the matcher before release. |
| Session claim is absent or stale | Treat the request as unauthorized for the dependent feature and refresh through the supported path. |
| JWT exceeds consumer limits | Remove nonessential claims; retrieve server-side attributes through an authorized backend. |
| Organization context is missing | Deny the org-scoped operation and require explicit selection/role validation. |
Resources
Signals
- GitHub stars
- 3k
- Forks
- 415
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
clerk-core-workflow-b- Source
- github.com/jeremylongshore/tons-of-skills-marketplace
github.com/jeremylongshore/tons-of-skills-marketplace
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptclerk-nextjs-patterns
Skill · clerk
The pick for Next.jslogs-nextjs
Skill · posthog
The pick for Next.jsteach
Skill · mattpocock
More in Dev toolsimplement
Skill · mattpocock
More in Dev tools