Skip to main content

ClerkAuthLayer

Struct ClerkAuthLayer 

Source
pub struct ClerkAuthLayer { /* private fields */ }
Available on crate feature server only.
Expand description

Tower layer that verifies Clerk session JWTs and inserts a VerificationOutcome into request extensions. Valid bearer tokens (or __session cookies) produce VerificationOutcome::Valid(auth). The layer is non-rejecting for missing or invalid credentials: it records the outcome and lets the request continue so downstream code can decide how to handle anonymous requests.

§Restricting accepted tokens

With the default configuration, any JWT signed by your Clerk instance key verifies, including tokens minted from Clerk JWT templates for third-party integrations, which legitimately reach browsers. If your instance uses JWT templates, configure ClerkAuthLayerConfig::with_issuers and ClerkAuthLayerConfig::with_authorized_parties (and audiences where applicable) via ClerkAuthLayer::from_config so integration tokens cannot pass as session tokens.

§Verification model and limitations

Verification is stateless: each request is checked purely against the cached JWKS signing keys, with no call back to Clerk to consult live session state. Two consequences follow, both inherent to networkless JWT verification and matching Clerk’s own backend model:

  • No revocation window. A token whose session has since been signed out or revoked stays accepted until its exp. Clerk session tokens are short-lived (about a minute), so the exposure is bounded by that lifetime rather than by revocation. Gate anything that must react to revocation immediately on a fresh check rather than on a still-valid token.
  • Key-rotation lag. A token signed with a kid not in the cached JWKS triggers at most one refresh per unknown-kid refresh interval (5 minutes); within that window an unknown kid is rejected as invalid. Clerk pre-publishes new keys before signing with them, so this affects only rotations faster than the refresh floor, and the floor exists to keep an attacker from forcing unbounded JWKS refetches.

§worker feature

With the worker feature (server on wasm), the service future is wrapped in SendWrapper to satisfy Axum’s Send bound. This assumes a single-threaded runtime such as Cloudflare Workers: the future must be polled and dropped on the thread that created it, and doing otherwise panics deterministically.

Implementations§

Source§

impl ClerkAuthLayer

Source

pub fn new(secret_key: impl Into<String>) -> Result<Self, ClerkError>

Build a layer that verifies tokens against Clerk’s live JWKS using the given backend secret key. The JWKS is fetched lazily on the first valid-looking request and cached in memory.

Uses the default configuration; see the type-level docs on restricting accepted tokens when the Clerk instance mints JWT-template tokens.

Source

pub fn from_env() -> Result<Self, ClerkError>

Build a layer from the conventional CLERK_SECRET_KEY environment variable.

Uses the default configuration; see the type-level docs on restricting accepted tokens when the Clerk instance mints JWT-template tokens.

Source

pub fn from_config(config: ClerkAuthLayerConfig) -> Result<Self, ClerkError>

Build a layer from owned verifier configuration.

Use this when an application needs to override Clerk backend settings or enable optional claim validation.

Trait Implementations§

Source§

impl Clone for ClerkAuthLayer

Source§

fn clone(&self) -> ClerkAuthLayer

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ClerkAuthLayer

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<S> Layer<S> for ClerkAuthLayer

Source§

type Service = ClerkAuthService<S>

The wrapped service
Source§

fn layer(&self, inner: S) -> Self::Service

Wrap the given service with the middleware, returning a new service that has been decorated with the middleware.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> InitializeFromFunction<T> for T

Source§

fn initialize_from_function(f: fn() -> T) -> T

Create an instance of this type from an initialization function
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<Ret> SpawnIfAsync<(), Ret> for Ret

Source§

fn spawn(self) -> Ret

Spawn the value into the dioxus runtime if it is an async block
Source§

impl<T, O> SuperFrom<T> for O
where O: From<T>,

Source§

fn super_from(input: T) -> O

Convert from a type to another type.
Source§

impl<T, O, M> SuperInto<O, M> for T
where O: SuperFrom<T, M>,

Source§

fn super_into(self) -> O

Convert from a type to another type.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more