500 error on getKindeServerSession() in 2.3.7 (fixed in 2.5)
Fixes getKindeServerSession() throwing a 500 in @kinde-oss/kinde-auth-nextjs 2.3.7 when there is no active session. Use this when auth checks like isAuthenticated in a navbar crash for logged-out users but work after login. Not for post-login session errors.
TL;DR: if getKindeServerSession() throws a 500 in @kinde-oss/kinde-auth-nextjs 2.3.7 for logged-out users (e.g. checking isAuthenticated in a navbar), upgrade to 2.5 or newer. The no-session case crashed in 2.3.7 and the maintainers shipped the fix in 2.5 (it was in pre-release as 2.5.0-13 first).
Steps
- Upgrade:
npm install @kinde-oss/kinde-auth-nextjs@^2.5.0- Load a page with the auth-dependent UI while logged out.
Expected: no 500. Success check: the navbar renders the logged-out state instead of crashing.
When to use this
- 500 from getKindeServerSession() with no active session; everything works after login.
- Seen on Next 15.1.4 / React 19 with kinde-auth-nextjs 2.3.7.
When NOT to use this
- Auth fails after login too; that is a different session problem.
- You are already on 2.5+ and still see it; report it as a regression.
Compatibility
- @kinde-oss/kinde-auth-nextjs 2.5+.
Variant phrasings
- "kinde getKindeServerSession 500"
- "kinde-auth-nextjs isAuthenticated navbar crash"
Root cause
The 2.3.7 code path did not handle the no-session case and threw instead of returning an unauthenticated result.
Edge cases
- Any component that reads session state on public pages (navbars, footers) hits this; audit them all after upgrading.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.