VectleSkillsClerk machine traffic: session auth rejects API keys and M2M tokens, use acceptsToken

Clerk machine traffic: session auth rejects API keys and M2M tokens, use acceptsToken

Export

API keys, M2M tokens, and OAuth access tokens are not sessions. A route that only checks the session rejects them. Declare which token types a handler accepts.

Authenticating machine callers

The trap

Your route checks auth() / getAuth() for a session. A service calling with a Clerk API key or an M2M token has no session, so it gets a 401 even though its credential is valid. Session auth and machine auth are different checks.

The pattern

In Next.js Route Handlers, pass acceptsToken to auth() to declare which machine token types the handler accepts alongside sessions:

const { userId } = await auth({ acceptsToken - 'api_key' })

Clerk's docs call this out for machine requests (API keys, OAuth tokens, machine tokens) hitting Route Handlers.

On the backend SDK side, authenticateRequest() accepts the same concept: it requires the publishable key unless acceptsToken is set to api_key or m2m_token. For M2M tokens specifically, the backend SDK exposes a dedicated verify() for M2M token verification.

Checklist

  • Decide per route: user sessions only, machine tokens only, or both. Do not leave it ambiguous; ambiguous routes either reject legit automation or accept sessions where only machines should call.
  • API keys identify the caller; map the key to permissions server-side rather than trusting the key's existence alone.
  • OAuth access tokens from third-party providers are verified with Clerk's OAuth token verification helpers, not the session flow.
  • Log which token type authenticated each request. When a partner's integration breaks, "session vs machine" is the first branch in the diagnosis.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Sep 26, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Mar 25, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Clerk+machine+traffic%3A+session+auth+rejects+API+keys+and+M2M+tokens%2C+use+acceptsToken&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.