Conversation
🦋 Changeset detectedLatest commit: f9b9404 The changes in this PR will be included in the next version bump. This PR includes changesets to release 24 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueComment |
…kages/expo-native Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…elegate its config plugin Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… add changesets Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@clerk/expo-native now takes useAuth from @clerk/react, so the two workspace packages no longer form a cycle. The config plugin records the installed @clerk/expo version for the native host SDK header on both platforms via Info.plist and gradle.properties, and fails early if the installed @clerk/expo still bundles the native module. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
4 of 9 tasks
mikepitre
force-pushed
the
mike/clerk-js-trusted-device-resources
branch
from
September 27, 2026 15:17
2f8cdd1 to
03f95ab
Compare
mikepitre
changed the base branch from
main
to
mike/expo-native-remove-legacy-sync
September 27, 2026 15:17
4 of 9 tasks
…geset Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
mikepitre
force-pushed
the
mike/expo-native-remove-legacy-sync
branch
from
September 28, 2026 19:35
441f8a7 to
871298f
Compare
mikepitre
force-pushed
the
mike/clerk-js-trusted-device-resources
branch
from
September 28, 2026 19:35
03f95ab to
aa7405a
Compare
…/expo-native-components Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Adds an engine-agnostic behavior suite for JS <-> native client sync, backed by a fake Frontend API, a fake native SDK, and a clerk-js stand-in, with a thin adapter that drives today's ClerkProvider engine. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replace the JS <-> native client sync engine with one where native storage owns the single shared device token and each side refetches its own client on a payload-free "client changed" signal. Codes against the new ClerkExpo module contract (configureNative, getDeviceToken, setDeviceToken CAS, refreshClient, clerkNativeClientInvalidated). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Session updatedAt can move on session activity and token refresh, which would refresh the native client on every token refresh. Profile edits still reach native through the active user's updatedAt. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Remove configure, getClientToken, syncClientStateFromJs and the clerkNativeClientChanged event from the iOS and Android ClerkExpo module, along with the client observation loop and JS-sync suppression state that only served them. The JS engine now uses configureNative, getDeviceToken, setDeviceToken, refreshClient and clerkNativeClientInvalidated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
mikepitre
force-pushed
the
mike/expo-native-remove-legacy-sync
branch
from
September 28, 2026 20:23
871298f to
5a9f6ab
Compare
mikepitre
force-pushed
the
mike/clerk-js-trusted-device-resources
branch
from
September 28, 2026 20:23
aa7405a to
f9b9404
Compare
4 of 9 tasks
mikepitre
force-pushed
the
mike/expo-native-remove-legacy-sync
branch
from
September 29, 2026 22:11
5a9f6ab to
3b195e5
Compare
Contributor
Author
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Foundational, additive resource support for trusted devices (called biometric credentials in native SDKs), so
clerk-jscan talk to FAPI directly for Expo biometric sign-in. Device key creation, signing, and sign-in/enrollment orchestration will come in follow-up PRs.@clerk/sharedtypes:trusted_devicestrategy (TrustedDeviceStrategy) added toSignInStrategy, toSignInCreateParams(withtrustedDeviceId), and toAttemptFirstFactorParams(TrustedDeviceAttempt:trustedDeviceId,clientData,signature,algorithm: 'ES256').SignInFirstFactor/SignInSecondFactorare unchanged, since FAPI does not listtrusted_devicein sign-in supported factors and sign-inattempt_second_factordoes not accept it.TrustedDeviceChallengeJSON/TrustedDeviceChallengeResource, exposed as an optionaltrustedDeviceChallengeonVerificationResource.NativeSettingsJSON/NativeSettingsResource, exposed asnativeSettingsonAuthConfigResource.BiometricCredentialJSON/BiometricCredentialResource, plusPrepareBiometricCredentialParams/AttemptBiometricCredentialParams.@clerk/clerk-js:Verificationparsestrusted_device_challenge(FAPI'sexpires_atthere is in seconds) and includes it in the snapshot when present.AuthConfigparsesnative_settingsand includes it in its snapshot.BiometricCredentialresource, plusUser.__experimental_getBiometricCredentials(),__experimental_prepareBiometricCredential(),__experimental_attemptBiometricCredential()and__experimental_revokeBiometricCredential(id)for/v1/me/biometric_credentials.publicKeyJwkaccepts a JWK object or its JSON string.signIn.create/signIn.attemptFirstFactoralready forward params as-is, sotrusted_devicerequests serialize totrusted_device_id,client_data,signature,algorithmwith no runtime changes.All new surface is additive and marked
@experimental. Nothing on theClerkclass changes.Bundlewatch:
clerk.native.jsgoes from 79.94KB to 80.63KB gzip, so itsmaxSizegoes from 80KB to 82KB. Other entries grew by about 0.7KB and remain under their limits.Checklist
pnpm testruns as expected.pnpm buildruns as expected.Type of change
🤖 Generated with Claude Code