Preliminary Checks
Reproduction
No public repo: the steps below reproduce it in any App Router app using @clerk/nextjs, and the faulty code path is two lines, quoted below.
Publishable key
pk_test_YnJpZWYtc2N1bHBpbi00NS5jbGVyay5hY2NvdW50cy5kZXYk (a development instance; the bug does not depend on the instance, and we hit it in production first)
Description
The App Router client ClerkProvider sets (@clerk/nextjs 7.4.1, dist/esm/app-router/client/ClerkProvider.js; the same code is in 7.9.7):
window.__internal_onBeforeSetActive = (intent) => {
return new Promise((resolve) => {
const nextVersion = window?.next?.version || "";
if ((nextVersion.startsWith("15") || nextVersion.startsWith("16")) && intent === "sign-out") {
resolve();
} else {
void invalidateCacheAction().then(() => resolve());
}
});
};
If invalidateCacheAction() rejects, resolve is never called and the promise never settles. clerk-js awaits this hook inside setActive and signOut, so they hang forever.
The rejection is routine on any self-hosted Next 15/16 app. Server action IDs are salted with a per-build encryption key, so after every redeploy a tab loaded from the previous build calls an action ID the new server does not know. The server answers 404 with x-nextjs-action-not-found: 1 and logs Failed to find Server Action "…". This request might be from an older or newer deployment., and Next rejects the call with UnrecognizedActionError. A network failure has the same effect.
What we measured, in tabs opened before a deploy:
- Sign-in and reverification (a password change in
<UserProfile />) spin forever.
signOut() calls the hook with no intent, so the Next 15/16 "sign-out" fast path does not apply, and it awaits the hook before removeSessions(). A stale-tab sign-out therefore leaves the user signed in.
Steps to reproduce:
- A fresh
create-next-app (App Router) with @clerk/nextjs and a <UserButton /> on a page.
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY=$(openssl rand -base64 32) next build && next start, open the page and sign in.
- Stop the server and rebuild with a different
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY (two plain local builds reuse the key cached in .next/cache/.rscinfo and keep the same IDs), then next start again. Do not reload the tab.
- In that tab, sign out from the
<UserButton />, or run await window.__internal_onBeforeSetActive() in the console.
Expected behavior:
The hook settles even when the cache-invalidation action fails (__internal_onAfterSetActive already calls router.refresh()), and sign-out, sign-in and reverification complete.
Actual behavior:
The promise never settles, the UI spins, and on sign-out the session is not removed. The console shows Uncaught (in promise) UnrecognizedActionError: Server Action "…" was not found on the server.
Suggested fix: invalidateCacheAction().then(() => resolve(), () => resolve()), or skip the action on Next ≥ 15 as #7873 proposed. Related prior art: #5084 and #7873 (closed unmerged), and #8122 (a never-settling variant with cacheComponents).
Our app-side workaround re-points window.__internal_onBeforeSetActive, from a descendant useEffect, to a wrapper that races Clerk's promise against an unhandledrejection listener for UnrecognizedActionError and a timeout.
Environment
next: 16.2.6 (webpack build, output: standalone, self-hosted)
@clerk/nextjs: 7.4.1 (the hook is identical in 7.9.7)
@clerk/clerk-js: 6.x (loaded from the CDN by major version)
react / react-dom: 19.2.4
node: 22 (production image)
browser: Chrome
Preliminary Checks
Reproduction
No public repo: the steps below reproduce it in any App Router app using
@clerk/nextjs, and the faulty code path is two lines, quoted below.Publishable key
pk_test_YnJpZWYtc2N1bHBpbi00NS5jbGVyay5hY2NvdW50cy5kZXYk(a development instance; the bug does not depend on the instance, and we hit it in production first)Description
The App Router client
ClerkProvidersets (@clerk/nextjs7.4.1,dist/esm/app-router/client/ClerkProvider.js; the same code is in 7.9.7):If
invalidateCacheAction()rejects,resolveis never called and the promise never settles. clerk-js awaits this hook insidesetActiveandsignOut, so they hang forever.The rejection is routine on any self-hosted Next 15/16 app. Server action IDs are salted with a per-build encryption key, so after every redeploy a tab loaded from the previous build calls an action ID the new server does not know. The server answers 404 with
x-nextjs-action-not-found: 1and logsFailed to find Server Action "…". This request might be from an older or newer deployment., and Next rejects the call withUnrecognizedActionError. A network failure has the same effect.What we measured, in tabs opened before a deploy:
<UserProfile />) spin forever.signOut()calls the hook with no intent, so the Next 15/16"sign-out"fast path does not apply, and it awaits the hook beforeremoveSessions(). A stale-tab sign-out therefore leaves the user signed in.Steps to reproduce:
create-next-app(App Router) with@clerk/nextjsand a<UserButton />on a page.NEXT_SERVER_ACTIONS_ENCRYPTION_KEY=$(openssl rand -base64 32) next build && next start, open the page and sign in.NEXT_SERVER_ACTIONS_ENCRYPTION_KEY(two plain local builds reuse the key cached in.next/cache/.rscinfoand keep the same IDs), thennext startagain. Do not reload the tab.<UserButton />, or runawait window.__internal_onBeforeSetActive()in the console.Expected behavior:
The hook settles even when the cache-invalidation action fails (
__internal_onAfterSetActivealready callsrouter.refresh()), and sign-out, sign-in and reverification complete.Actual behavior:
The promise never settles, the UI spins, and on sign-out the session is not removed. The console shows
Uncaught (in promise) UnrecognizedActionError: Server Action "…" was not found on the server.Suggested fix:
invalidateCacheAction().then(() => resolve(), () => resolve()), or skip the action on Next ≥ 15 as #7873 proposed. Related prior art: #5084 and #7873 (closed unmerged), and #8122 (a never-settling variant withcacheComponents).Our app-side workaround re-points
window.__internal_onBeforeSetActive, from a descendantuseEffect, to a wrapper that races Clerk's promise against anunhandledrejectionlistener forUnrecognizedActionErrorand a timeout.Environment
next: 16.2.6 (webpack build, output: standalone, self-hosted) @clerk/nextjs: 7.4.1 (the hook is identical in 7.9.7) @clerk/clerk-js: 6.x (loaded from the CDN by major version) react / react-dom: 19.2.4 node: 22 (production image) browser: Chrome