CL

clerk-prod-checklist

Pre-deployment checklist for verifying Clerk security, environment keys, and production configuration.

Install

mkdir -p .claude/skills/clerk-prod-checklist && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7122" && unzip -o skill.zip -d .claude/skills/clerk-prod-checklist && rm skill.zip

Installs to .claude/skills/clerk-prod-checklist

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Production readiness checklist for Clerk deployment.
52 charsno explicit “when” trigger
Beginner

Key capabilities

  • Verify production environment variables
  • Validate Clerk API connectivity
  • Check middleware configuration
  • Audit security and monitoring settings
  • Automate readiness checks in CI

How it works

The skill executes a TypeScript validation script that checks for live API keys, webhook secrets, and middleware presence. It also provides a structured checklist for manual security, monitoring, and performance audits.

Inputs & outputs

You give it
Project environment variables and configuration files
You get back
Readiness status report and validation exit code

When to use clerk-prod-checklist

  • Verify production keys
  • Check security configuration
  • Validate environment variables
  • Review go-live checklist

About this skill

Clerk Production Checklist

Overview

Complete checklist to ensure your Clerk integration is production-ready. Covers environment config, security hardening, monitoring, error handling, and compliance.

Prerequisites

  • Clerk integration working in development
  • Production environment and domain configured
  • CI/CD pipeline ready

Instructions

Step 1: Environment Configuration Checklist

CheckStatusAction
Using pk_live_ keys[ ]Switch from test to live keys
CLERK_SECRET_KEY is sk_live_[ ]Never use test keys in production
.env.local in .gitignore[ ]Prevent accidental secret commits
CLERK_WEBHOOK_SECRET set[ ]Required for webhook verification
Production domain in Clerk Dashboard[ ]Dashboard > Domains
Sign-in/sign-up URLs configured[ ]Set NEXT_PUBLIC_CLERK_SIGN_IN_URL etc.

Step 2: Validation Script

// scripts/prod-readiness.ts
import { createClerkClient } from '@clerk/backend'

async function validateProduction() {
  const checks: { name: string; pass: boolean; detail: string }[] = []

  // 1. Live keys check
  const pk = process.env.NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY || ''
  const sk = process.env.CLERK_SECRET_KEY || ''
  checks.push({
    name: 'Live publishable key',
    pass: pk.startsWith('pk_live_'),
    detail: pk.startsWith('pk_live_') ? 'Using live key' : `Using ${pk.slice(0, 8)}... (should be pk_live_)`,
  })
  checks.push({
    name: 'Live secret key',
    pass: sk.startsWith('sk_live_'),
    detail: sk.startsWith('sk_live_') ? 'Using live key' : 'Should be sk_live_ for production',
  })

  // 2. API connectivity
  try {
    const clerk = createClerkClient({ secretKey: sk })
    await clerk.users.getUserList({ limit: 1 })
    checks.push({ name: 'API connectivity', pass: true, detail: 'Backend API reachable' })
  } catch (err: any) {
    checks.push({ name: 'API connectivity', pass: false, detail: err.message })
  }

  // 3. Webhook secret
  checks.push({
    name: 'Webhook secret configured',
    pass: !!process.env.CLERK_WEBHOOK_SECRET,
    detail: process.env.CLERK_WEBHOOK_SECRET ? 'Set' : 'CLERK_WEBHOOK_SECRET missing',
  })

  // 4. Middleware exists
  const fs = await import('fs')
  const hasMiddleware = fs.existsSync('middleware.ts') || fs.existsSync('src/middleware.ts')
  checks.push({
    name: 'Middleware present',
    pass: hasMiddleware,
    detail: hasMiddleware ? 'Found' : 'middleware.ts not found at project root',
  })

  // Print results
  console.log('\n=== Clerk Production Readiness ===\n')
  for (const check of checks) {
    const icon = check.pass ? 'PASS' : 'FAIL'
    console.log(`[${icon}] ${check.name}: ${check.detail}`)
  }

  const allPass = checks.every((c) => c.pass)
  console.log(`\nResult: ${allPass ? 'READY for production' : 'NOT READY — fix failing checks'}`)
  process.exit(allPass ? 0 : 1)
}

validateProduction()

Run with:

npx tsx scripts/prod-readiness.ts

Step 3: Security Checklist

CheckStatusAction
Middleware protects all routes[ ]Verify non-public routes require auth
API routes check userId[ ]Return 401 if userId is null
Webhook signatures verified[ ]Use svix library for verification
CORS configured correctly[ ]Only allow production domain
Rate limiting on sensitive endpoints[ ]Use @upstash/ratelimit or similar
CSP headers set[ ]Add Clerk domains to Content-Security-Policy
No secret keys in client code[ ]CLERK_SECRET_KEY never exposed

Step 4: Monitoring Checklist

CheckStatusAction
Health check endpoint[ ]/api/health monitoring Clerk API
Error tracking (Sentry)[ ]Clerk user context in error reports
Auth event logging[ ]Log sign-in, sign-out, permission denied
Webhook monitoring[ ]Alert on failed webhook deliveries
Uptime monitoring[ ]External monitor hitting health endpoint

Step 5: Error Handling Checklist

CheckStatusAction
Custom error pages[ ]/not-found, /error pages handle auth errors
Graceful auth failures[ ]Redirect to sign-in, don't show stack traces
Webhook retry handling[ ]Idempotency keys prevent duplicate processing
Session expiry UX[ ]Show "session expired" prompt, not blank page
// app/error.tsx — global error boundary with auth context
'use client'
import { useAuth } from '@clerk/nextjs'

export default function Error({ error, reset }: { error: Error; reset: () => void }) {
  const { isSignedIn } = useAuth()

  return (
    <div>
      <h2>Something went wrong</h2>
      <p>{error.message}</p>
      <button onClick={reset}>Try again</button>
      {!isSignedIn && <a href="/sign-in">Sign in</a>}
    </div>
  )
}

Step 6: Performance Checklist

CheckStatusAction
Middleware matcher excludes static files[ ]Don't auth-check images, fonts, CSS
User data cached (React.cache())[ ]Deduplicate within request
Auth components lazy loaded[ ]dynamic() for UserButton, SignInButton
Edge Runtime for middleware[ ]Faster cold starts on Vercel

Output

  • Environment configuration verified (live keys, webhook secret, domain)
  • Automated validation script (run in CI or before deploy)
  • Security, monitoring, error handling, and performance checklists
  • Global error boundary component with auth context

Error Handling

ErrorCauseSolution
Validation script failsTest keys in productionSwitch to pk_live_ / sk_live_ keys
API connectivity check failsWrong secret keyVerify key in Clerk Dashboard > API Keys
Middleware not foundFile in wrong locationPlace middleware.ts at project root (not inside app/)
Health check returns 503Clerk API unreachableCheck network, verify key, check status.clerk.com

Examples

CI Production Gate

# .github/workflows/deploy.yml — add as pre-deploy step
- name: Clerk production readiness
  run: npx tsx scripts/prod-readiness.ts
  env:
    NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY: ${{ secrets.CLERK_PK_PROD }}
    CLERK_SECRET_KEY: ${{ secrets.CLERK_SK_PROD }}
    CLERK_WEBHOOK_SECRET: ${{ secrets.CLERK_WEBHOOK_SECRET_PROD }}

Resources

Next Steps

Proceed to clerk-upgrade-migration for SDK version upgrades.

When not to use it

  • Development environment setup
  • SDK version migration tasks

Prerequisites

Clerk integration working in developmentProduction environment and domain configuredCI/CD pipeline ready

Limitations

  • Requires manual verification for non-automated checklist items
  • Depends on correct environment variable naming conventions

How it compares

Unlike manual documentation reviews, this skill provides an automated script to programmatically verify production readiness before deployment.

Compared to similar skills

clerk-prod-checklist side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
clerk-prod-checklist (this skill)127dReviewBeginner
auth-patterns77moReviewIntermediate
django-verification54moReviewIntermediate
clerk-incident-runbook127dCautionIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

auth-patterns

davepoon

This skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs guidance on implementing authentication and authorization in Next.js applications.

720

django-verification

affaan-m

Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

521

clerk-incident-runbook

jeremylongshore

Incident response procedures for Clerk authentication issues. Use when handling auth outages, security incidents, or production authentication problems. Trigger with phrases like "clerk incident", "clerk outage", "clerk down", "auth not working", "clerk emergency".

110

customerio-security-basics

jeremylongshore

Apply Customer.io security best practices. Use when implementing secure integrations, handling PII, or setting up proper access controls. Trigger with phrases like "customer.io security", "customer.io pii", "secure customer.io", "customer.io gdpr".

15

firebase-vertex-ai

jeremylongshore

Execute firebase platform expert with Vertex AI Gemini integration for Authentication, Firestore, Storage, Functions, Hosting, and AI-powered features. Use when asked to "setup firebase", "deploy to firebase", or "integrate vertex ai with firebase". Trigger with relevant phrases based on skill purpose.

14

deployment-validation-config-validate

sickn33

You are a configuration management expert specializing in validating, testing, and ensuring the correctness of application configurations. Create comprehensive validation schemas, implement configurat

13

Search skills

Search the agent skills registry