Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Configure Clerk webhooks and handle authentication events. Use when setting up user sync, handling auth events, or integrating Clerk with external systems via Svix webhooks. Trigger with phrases like "clerk webhooks", "clerk events", "clerk user sync", "clerk svix", "clerk event handling".
.claude/skills/jeremylongshore-clerk-webhooks-events/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-08 | ✗→✓ | ▲ Improved | 113% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 23% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 119% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 80% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 437% | 0% |
Configure and handle Clerk webhooks for user lifecycle events and data synchronization. Clerk uses Svix for webhook delivery with HMAC-SHA256 signature verification. As of 2025, Clerk provides a built-in verifyWebhook() helper in @clerk/backend alongside the manual Svix approach.
ngrok for local dev)CLERK_WEBHOOK_SECRET environment variable (starts with whsec_)bash# Option A: Use @clerk/backend's built-in verifyWebhook() (recommended) # Already included with @clerk/nextjs — no extra install needed # Option B: Manual Svix verification npm install svix
typescript// app/api/webhooks/clerk/route.ts import { verifyWebhook } from '@clerk/backend/webhooks' import type { WebhookEvent } from '@clerk/nextjs/server' export async function POST(req: Request) { let evt: WebhookEvent try { evt = await verifyWebhook(req) } catch (err) { console.error('Webhook verification failed:', err) return new Response('Invalid signature', { status: 400 }) } return handleWebhookEvent(evt) }
typescript// app/api/webhooks/clerk/route.ts import { Webhook } from 'svix' import { headers } from 'next/headers' import type { WebhookEvent } from '@clerk/nextjs/server' export async function POST(req: Request) { const WEBHOOK_SECRET = process.env.CLERK_WEBHOOK_SECRET if (!WEBHOOK_SECRET) { throw new Error('Missing CLERK_WEBHOOK_SECRET env variable') } const headerPayload = await headers() const svixHeaders = { 'svix-id': headerPayload.get('svix-id') || '', 'svix-timestamp': headerPayload.get('svix-timestamp') || '', 'svix-signature': headerPayload.get('svix-signature') || '', } if (!svixHeaders['svix-id'] || !svixHeaders['svix-signature']) { return new Response('Missing svix headers', { status: 400 }) } // CRITICAL: Use req.text(), NOT req.json() — JSON parsing alters the payload // and breaks signature verification const body = await req.text() const wh = new Webhook(WEBHOOK_SECRET) let evt: WebhookEvent try { evt = wh.verify(body, svixHeaders) as WebhookEvent } catch (err) { console.error('Webhook verification failed:', err) return new Response('Invalid signature', { status: 400 }) } return handleWebhookEvent(evt) }
typescriptasync function handleWebhookEvent(evt: WebhookEvent) { const eventType = evt.type switch (eventType) { case 'user.created': { const { id, email_addresses, first_name, last_name, image_url } = evt.data const primaryEmail = email_addresses.find(e => e.id === evt.data.primary_email_address_id) await db.user.create({ data: { clerkId: id, email: primaryEmail?.email_address || email_addresses[0]?.email_address, firstName: first_name, lastName: last_name, avatarUrl: image_url, }, }) console.log(`[Webhook] User created: ${id}`) break } case 'user.updated': { const { id, email_addresses, first_name, last_name, image_url } = evt.data const primaryEmail = email_addresses.find(e => e.id === evt.data.primary_email_address_id) await db.user.upsert({ where: { clerkId: id }, update: { email: primaryEmail?.email_address, firstName: first_name, lastName: last_name, avatarUrl: image_url, }, create: { clerkId: id, email: primaryEmail?.email_address || '', firstName: first_name, lastName: last_name, avatarUrl: image_url, }, }) break } case 'user.deleted': { if (evt.data.id) { // Soft-delete or hard-delete based on your data retention policy await db.user.update({ where: { clerkId: evt.data.id }, data: { deletedAt: new Date() }, }) } break } case 'organization.created': { const { id, name, slug, created_by } = evt.data await db.organization.create({ data: { clerkOrgId: id, name, slug: slug || '', createdBy: created_by }, }) break } case 'organizationMembership.created': { const { organization, public_user_data, role } = evt.data await db.orgMembership.create({ data: { orgId: organization.id, userId: public_user_data.user_id, role, }, }) break } case 'session.created': console.log(`[Webhook] Session created for user: ${evt.data.user_id}`) break default: console.log(`[Webhook] Unhandled event: ${eventType}`) } return new Response('OK', { status: 200 }) }
typescript// lib/webhook-idempotency.ts // Clerk/Svix may retry failed deliveries — prevent duplicate processing export async function processIdempotently( svixId: string, eventType: string, handler: () => Promise<void> ): Promise<{ processed: boolean; duplicate: boolean }> { // Check if already processed (use your DB or Redis) const existing = await db.webhookEvent.findUnique({ where: { svixId }, }) if (existing) { console.log(`[Webhook] Duplicate event skipped: ${svixId} (${eventType})`) return { processed: false, duplicate: true } } // Mark as processing (before handler, to catch concurrent deliveries) await db.webhookEvent.create({ data: { svixId, eventType, status: 'processing', receivedAt: new Date() }, }) try { await handler() await db.webhookEvent.update({ where: { svixId }, data: { status: 'completed', processedAt: new Date() }, }) return { processed: true, duplicate: false } } catch (error) { await db.webhookEvent.update({ where: { svixId }, data: { status: 'failed', error: String(error) }, }) throw error } }
https://yourdomain.com/api/webhooks/clerkuser.created, user.updated, user.deletedorganization.created, organizationMembership.createdsession.created, session.ended (optional, high volume)whsec_...) to your .env.local:bashCLERK_WEBHOOK_SECRET=whsec_...
typescriptimport express from 'express' import { Webhook } from 'svix' const app = express() // CRITICAL: Use express.raw(), NOT express.json() for webhook routes app.post('/api/webhooks/clerk', express.raw({ type: 'application/json' }), (req, res) => { const wh = new Webhook(process.env.CLERK_WEBHOOK_SECRET!) try { const evt = wh.verify(req.body, { 'svix-id': req.headers['svix-id'] as string, 'svix-timestamp': req.headers['svix-timestamp'] as string, 'svix-signature': req.headers['svix-signature'] as string, }) // Handle event... res.status(200).json({ received: true }) } catch (err) { console.error('Webhook verification failed:', err) res.status(400).json({ error: 'Invalid signature' }) } } )
bash# Start ngrok tunnel for local webhook testing ngrok http 3000 # Copy the https://xxx.ngrok-free.app URL # Add it as webhook endpoint in Clerk Dashboard > Webhooks # URL: https://xxx.ngrok-free.app/api/webhooks/clerk
| Error | Cause | Solution | |-------|-------|----------| | Invalid signature | Wrong CLERK_WEBHOOK_SECRET | Re-copy signing secret from Dashboard > Webhooks | | Invalid signature | Body parsed with json() before verify | Use req.text() (Next.js) or express.raw() (Express) | | Missing svix headers | Request not from Clerk/Svix | Verify endpoint URL; check sender | | Duplicate processing | Clerk retried delivery | Implement idempotency with svix-id as unique key | | Handler timeout | Slow DB operations | Offload heavy work to a background job queue | | 404 on webhook URL | Route not matching | Ensure /api/webhooks is in middleware's isPublicRoute |
CLERK_WEBHOOK_SECRET like a password -- rotate it if compromised (Dashboard > Webhooks > Signing Secret > Rotate)svix-timestamp for replay attack protection (rejects events older than 5 minutes by default)verifyWebhook() from @clerk/backend/webhooks when possible -- it handles header extraction and secret key resolution automaticallyRecord the verified Svix event ID, event type, tenant/user scope when needed, timestamp/replay decision, idempotency result, queued work status, and redacted failure reason. A 2xx response is issued only after durable idempotency state is recorded; do not log signing secrets, raw event bodies, or unnecessary user attributes.
For a user.created event, verify the raw request, persist the svix-id with the allowed event metadata, enqueue one provisioning job, and return 200. If the same delivery retries, return a safe acknowledgement without provisioning again; reject invalid or expired signatures without echoing their contents.
Proceed to clerk-performance-tuning for optimization strategies.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 15,717 | 5,214 | -67% | 1 | 1 | 0% | 3,005 | 3,696 | +23% | 0 | 0 | — |
case-02 | pass→pass | 9,900 | 6,372 | -36% | 1 | 1 | 0% | 1,808 | 3,960 | +119% | 0 | 0 | — |
case-03 | pass→pass | 12,631 | 8,969 | -29% | 1 | 1 | 0% | 2,435 | 4,372 | +80% | 0 | 0 | — |
case-04 | pass→pass | 3,505 | 3,103 | -11% | 1 | 1 | 0% | 619 | 3,327 | +437% | 0 | 0 | — |
case-05 | fail→fail | 3,715 | 2,204 | -41% | 1 | 1 | 0% | 592 | 3,101 | +424% | 0 | 0 | — |
case-06 | pass→pass | 7,231 | 4,516 | -38% | 1 | 1 | 0% | 1,242 | 3,411 | +175% | 0 | 0 | — |
case-07 | fail→fail | 2,632 | 1,927 | -27% | 1 | 1 | 0% | 384 | 2,982 | +677% | 0 | 0 | — |
case-21 | pass→pass | 9,757 | 9,590 | -2% | 1 | 1 | 0% | 1,916 | 4,826 | +152% | 0 | 0 | — |
case-08 | fail→pass | 10,146 | 9,619 | -5% | 1 | 1 | 0% | 2,085 | 4,435 | +113% | 0 | 0 | — |
case-09 | pass→pass | 12,032 | 10,449 | -13% | 1 | 1 | 0% | 2,196 | 4,622 | +110% | 0 | 0 | — |
case-10 | pass→pass | 5,517 | 2,085 | -62% | 1 | 1 | 0% | 1,151 | 3,130 | +172% | 0 | 0 | — |
case-11 | pass→pass | 2,961 | 1,857 | -37% | 1 | 1 | 0% | 462 | 2,954 | +539% | 0 | 0 | — |
case-22 | pass→pass | 9,353 | 6,618 | -29% | 1 | 1 | 0% | 1,920 | 4,246 | +121% | 0 | 0 | — |
case-12 | pass→pass | 9,228 | 8,830 | -4% | 1 | 1 | 0% | 1,564 | 4,262 | +173% | 0 | 0 | — |
case-13 | pass→pass | 10,961 | 10,391 | -5% | 1 | 1 | 0% | 1,892 | 4,572 | +142% | 0 | 0 | — |
case-14 | pass→pass | 10,964 | 11,458 | +5% | 1 | 1 | 0% | 2,067 | 5,030 | +143% | 0 | 0 | — |
case-15 | pass→pass | 8,277 | 4,084 | -51% | 1 | 1 | 0% | 1,539 | 3,552 | +131% | 0 | 0 | — |
case-16 | pass→pass | 5,758 | 3,643 | -37% | 1 | 1 | 0% | 1,213 | 3,372 | +178% | 0 | 0 | — |
case-17 | pass→pass | 4,045 | 2,053 | -49% | 1 | 1 | 0% | 661 | 3,054 | +362% | 0 | 0 | — |
case-18 | pass→pass | 8,472 | 2,479 | -71% | 1 | 1 | 0% | 1,507 | 3,186 | +111% | 0 | 0 | — |
case-19 | pass→pass | 7,117 | 4,801 | -33% | 1 | 1 | 0% | 1,389 | 3,767 | +171% | 0 | 0 | — |
case-20 | pass→pass | 10,751 | 9,508 | -12% | 1 | 1 | 0% | 2,000 | 4,487 | +124% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +5 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.