diff --git a/.changeset/thirty-chefs-unite.md b/.changeset/thirty-chefs-unite.md new file mode 100644 index 00000000000..7b16e9dc54f --- /dev/null +++ b/.changeset/thirty-chefs-unite.md @@ -0,0 +1,5 @@ +--- +'@clerk/backend': patch +--- + +Increase the default value for clock skew in `verifyJwt` from 2 to 5 seconds diff --git a/packages/backend/src/tokens/jwt/verifyJwt.ts b/packages/backend/src/tokens/jwt/verifyJwt.ts index 2e75dde17ea..e5a8b6feba1 100644 --- a/packages/backend/src/tokens/jwt/verifyJwt.ts +++ b/packages/backend/src/tokens/jwt/verifyJwt.ts @@ -9,7 +9,7 @@ import { assertAudienceClaim } from './assertions'; type IssuerResolver = string | ((iss: string) => boolean); -const DEFAULT_CLOCK_SKEW_IN_SECONDS = 2 * 1000; +const DEFAULT_CLOCK_SKEW_IN_SECONDS = 5 * 1000; const algToHash: Record = { RS256: 'SHA-256',