Clerk Upgrade MigrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
npm install @clerk/nextjs@latest @clerk/themes@latest
npm install @clerk/[email protected] # Replace with your previous version
npm install
npm install @clerk/nextjs@latest
npm install
npm install @clerk/[email protected] # Previous version
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: clerk-upgrade-migration description: 'Manage Clerk SDK version upgrades and handle breaking changes. Use when upgrading Clerk packages, migrating to new SDK versions, or handling deprecation warnings. Trigger with phrases like "upgrade clerk", "clerk migration", "update clerk SDK", "clerk breaking changes". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Bash(pnpm:*), Grep version: 1.15.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - clerk - migration compatibility: Designed for Claude Code --- # Clerk Upgrade & Migration ## Current State !`npm list @clerk/nextjs @clerk/clerk-react @clerk/express 2>/dev/null | grep clerk || echo 'No Clerk packages found'` ## Overview Safely upgrade Clerk SDK versions and handle breaking changes. Covers version checking, upgrade procedures, common migration patterns, and rollback planning. ## Prerequisites - Current Clerk integration working - Git repository with clean working state - Test environment available for validation ## Instructions ### Step 1: Check Current Version and Available Updates ```bash # Check installed version npm list @clerk/nextjs # Check latest available npm view @clerk/nextjs version # Check all Clerk packages and their versions npm outdated | grep clerk ``` ### Step 2: Review Breaking Changes ```bash # View changelog for the target version npx open-cli https://clerk.com/changelog # Check GitHub releases for migration notes npx open-cli https://github.com/clerk/javascript/releases ``` Key version milestones to watch for: - **v5 to v6**: `auth()` became async (must `await auth()`) - **v5 to v6**: `authMiddleware` renamed to `clerkMiddleware` - **v5 to v6**: Import paths changed to `@clerk/nextjs/server` ### Step 3: Upgrade Process ```bash # Create upgrade branch git checkout -b chore/upgrade-clerk # Upgrade all Clerk packages together (they must version-match) npm install @clerk/nextjs@latest @clerk/themes@latest # If using other Clerk packages: # npm install @clerk/clerk-react@latest @clerk/express@latest @clerk/backend@latest # Verify no version mismatches npm list | grep clerk ``` ### Step 4: Handle Common Migration Patterns **v5 to v6: `auth()` is now async** ```typescript // BEFORE (v5): auth() was synchronous // const { userId } = auth() // AFTER (v6): auth() returns a Promise const { userId } = await auth() ``` Find all affected files: ```bash # Search for synchronous auth() calls that need await grep -rn "const.*= auth()" --include="*.ts" --include="*.tsx" | grep -v "await" ``` **v5 to v6: Middleware migration** ```typescript // BEFORE (v5): // import { authMiddleware } from '@clerk/nextjs' // export default authMiddleware({ publicRoutes: ['/'] }) // AFTER (v6): import { clerkMiddleware, createRouteMatcher } from '@clerk/nextjs/server' const isPublicRoute = createRouteMatcher(['/']) export default clerkMiddleware(async (auth, req) => { if (!isPublicRoute(req)) { await auth.protect() } }) ``` **v5 to v6: Import path changes** ```typescript // BEFORE: // import { auth, currentUser } from '@clerk/nextjs' // AFTER: import { auth, currentUser } from '@clerk/nextjs/server' ``` Fix import paths across codebase: ```bash # Find files using old import path grep -rn "from '@clerk/nextjs'" --include="*.ts" --include="*.tsx" | grep -v "node_modules" | grep -v "/server" ``` ### Step 5: Update Type Definitions ```typescript // If using custom type extensions, update them // BEFORE: // declare module '@clerk/nextjs' { ... } // AFTER: declare module '@clerk/nextjs/server' { interface AuthObject { // Custom session claims type sessionClaims?: { metadata?: { role?: string } } } } ``` ### Step 6: Test Upgrade ```bash # Build to catch type errors npm run build # Run tests npm test # Start dev server and test manually npm run dev # Test critical flows: # 1. Sign in with email/password # 2. Sign in with OAuth # 3. Protected route access # 4. API route authentication # 5. Webhook endpoint # 6. Sign out ``` ### Step 7: Rollback Plan ```bash # If upgrade fails, rollback to previous version git stash # Save any manual changes # Install previous version npm install @clerk/[email protected] # Replace with your previous version # Or restore from git git checkout main -- package.json package-lock.json npm install # Verify rollback works npm run build && npm test ``` ## Output - Clerk SDK upgraded to latest version - Breaking changes migrated (async auth, new middleware, import paths) - Type definitions updated - All tests passing - Rollback procedure documented ## Error Handling | Error | Cause | Solution | |-------|-------|----------| | Type errors after upgrade | API signature changes | Add `await` to `auth()`, update imports | | `authMiddleware is not exported` | Renamed in v6 | Use `clerkMiddleware` from `@clerk/nextjs/server` | | `auth() returns Promise` | Now async in v6 | Add `await` to all `auth()` calls | | Import not found | Path changed | Use `@clerk/nextjs/server` for server-side imports | | Version mismatch | Clerk packages on different versions | Update all `@clerk/*` packages together | ## Examples ### Automated Migration Script ```bash #!/bin/bash # scripts/migrate-clerk-v6.sh set -euo pipefail echo "=== Clerk v5 to v6 Migration ===" # 1. Fix auth() calls (add await) echo "Adding await to auth() calls..." find . -name "*.ts" -o -name "*.tsx" | xargs grep -l "const.*= auth()" 2>/dev/null | while read file; do sed -i 's/const \(.*\) = auth()/const \1 = await auth()/g' "$file" echo " Fixed: $file" done # 2. Fix import paths echo "Updating import paths..." find . -name "*.ts" -o -name "*.tsx" | xargs grep -l "from '@clerk/nextjs'" 2>/dev/null | while read file; do if grep -q "auth\|currentUser\|clerkClient" "$file"; then sed -i "s/from '@clerk\/nextjs'/from '@clerk\/nextjs\/server'/g" "$file" echo " Fixed: $file" fi done echo "Done. Run 'npm run build' to check for
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__clerk-upgrade-migration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Clerk Upgrade Migration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Clerk Upgrade Migration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Clerk Upgrade Migration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Clerk Upgrade Migration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.