Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Implement session management and middleware with Clerk. Use when managing user sessions, configuring route protection, or implementing token refresh and custom JWT templates. Trigger with phrases like "clerk session", "clerk middleware", "clerk route protection", "clerk token", "clerk JWT".
.claude/skills/jeremylongshore-clerk-core-workflow-b/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 22% | 0% |
| case-21 | ✓→✗ | ▼ Worse | -10% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 4% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 25% | 0% |
Implement session management and route protection with Clerk middleware. Covers clerkMiddleware() configuration, auth() patterns, custom session claims, JWT templates for external services, organization-scoped sessions, and session token v2.
Use when managing user sessions, configuring route protection, or implementing token refresh and custom JWT templates.
@clerk/nextjs installed with ClerkProvider wrapping the appclerk-install-auth / clerk-hello-world).clerkMiddleware() matcher / public routes for the routes you want open.auth() / currentUser() on protected pages and API routes; fail closed when unauthenticated.Deep patterns, JWT templates, and edge cases: session-middleware-deep-dive.md.
User: Protect everything except /, /pricing, and Clerk sign-in routes.
Skill: configures clerkMiddleware publicRoutes / matcher and verifies unauth redirect.User: Put plan_tier on the session JWT for feature flags.
Skill: configures session token template and validates claim size + read path.| Condition | Response | |---|---| | Route is accidentally public | Fail the verification gate and narrow the matcher before release. | | Session claim is absent or stale | Treat the request as unauthorized for the dependent feature and refresh through the supported path. | | JWT exceeds consumer limits | Remove nonessential claims; retrieve server-side attributes through an authorized backend. | | Organization context is missing | Deny the org-scoped operation and require explicit selection/role validation. |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 9,224 | 7,432 | -19% | 1 | 1 | 0% | 1,842 | 1,913 | +4% | 0 | 0 | — |
case-02 | pass→pass | 7,995 | 10,269 | +28% | 1 | 1 | 0% | 1,475 | 1,851 | +25% | 0 | 0 | — |
case-03 | pass→pass | 8,299 | 4,560 | -45% | 1 | 1 | 0% | 1,343 | 1,326 | -1% | 0 | 0 | — |
case-04 | pass→pass | 5,121 | 3,985 | -22% | 1 | 1 | 0% | 995 | 1,205 | +21% | 0 | 0 | — |
case-05 | pass→pass | 12,727 | 13,833 | +9% | 1 | 1 | 0% | 2,406 | 2,924 | +22% | 0 | 0 | — |
case-06 | fail→pass | 12,624 | 9,112 | -28% | 1 | 1 | 0% | 2,216 | 2,257 | +2% | 0 | 0 | — |
case-07 | pass→pass | 10,589 | 8,993 | -15% | 1 | 1 | 0% | 1,909 | 2,021 | +6% | 0 | 0 | — |
case-08 | pass→pass | 12,343 | 9,525 | -23% | 1 | 1 | 0% | 2,066 | 2,184 | +6% | 0 | 0 | — |
case-09 | pass→pass | 13,929 | 19,134 | +37% | 1 | 1 | 0% | 2,737 | 2,366 | -14% | 0 | 0 | — |
case-10 | pass→pass | 7,070 | 6,916 | -2% | 1 | 1 | 0% | 1,264 | 1,814 | +44% | 0 | 0 | — |
case-11 | pass→pass | 9,704 | 6,851 | -29% | 1 | 1 | 0% | 1,742 | 1,702 | -2% | 0 | 0 | — |
case-12 | pass→pass | 9,351 | 8,115 | -13% | 1 | 1 | 0% | 1,791 | 2,042 | +14% | 0 | 0 | — |
case-13 | fail→pass | 11,508 | 12,399 | +8% | 1 | 1 | 0% | 2,195 | 2,684 | +22% | 0 | 0 | — |
case-14 | pass→pass | 9,353 | 7,498 | -20% | 1 | 1 | 0% | 1,605 | 1,814 | +13% | 0 | 0 | — |
case-15 | pass→pass | 7,058 | 12,492 | +77% | 1 | 1 | 0% | 1,167 | 2,571 | +120% | 0 | 0 | — |
case-16 | pass→pass | 14,332 | 9,179 | -36% | 1 | 1 | 0% | 2,449 | 2,156 | -12% | 0 | 0 | — |
case-17 | pass→pass | 4,865 | 4,922 | +1% | 1 | 1 | 0% | 977 | 1,359 | +39% | 0 | 0 | — |
case-18 | pass→pass | 8,584 | 7,184 | -16% | 1 | 1 | 0% | 1,433 | 1,834 | +28% | 0 | 0 | — |
case-19 | pass→pass | 6,526 | 4,771 | -27% | 1 | 1 | 0% | 1,333 | 1,280 | -4% | 0 | 0 | — |
case-20 | pass→pass | 11,570 | 11,610 | +0% | 1 | 1 | 0% | 2,499 | 2,811 | +12% | 0 | 0 | — |
case-21 | pass→fail | 14,089 | 10,713 | -24% | 1 | 1 | 0% | 3,065 | 2,750 | -10% | 0 | 0 | — |
case-22 | pass→pass | 12,309 | 8,193 | -33% | 1 | 1 | 0% | 2,190 | 1,856 | -15% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +5 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.