{"contract":"guth-news-publication-v1","article":{"article_id":"f511dc0a-de8e-4f45-9489-0094cf9fc2f1","revision":1,"slug":"clerk-adds-allowlisted-email-code-bypass-for-enterprise-sso-f511dc0a","title":"Clerk adds allowlisted email-code bypass for enterprise SSO","summary":"The feature gives designated users a way to sign in when an enterprise identity provider or SSO connection is unavailable.","body":"Clerk has introduced SSO bypass for enterprise connections, letting allowlisted users sign in with a one-time email code when an identity provider is down or the connection breaks; everyone else must continue using SSO. Only users with a verified email address on a domain served by the connection can be added. When an eligible user enters an email, the sign-in interface displays a “Can't use SSO?” option; after confirmation, Clerk emails a code and creates an ordinary session. Clerk does not check whether an allowlisted address still exists in the identity provider, and logs successful bypasses as sign_in.sso_bypass.succeeded events in Application Logs. The allowlist can be managed from the connection page in the Clerk Dashboard or through the Backend API. The feature is available on every instance with enterprise connections; setup requires enabling Email verification code sign-in and adding users to an allowlist.","content_kind":"author_paraphrase","explanation":{"feature":"The feature gives designated users a way to sign in when an enterprise identity provider or SSO connection is unavailable.","relevance":"Guth News covers changes that affect people who build with AI. Read the cited primary sources for the full details.","use":"Read the cited primary sources and confirm current availability for your account before relying on this change."},"announcement_date":null,"published_at":"2026-09-30T14:08:47.253Z","author":{"canonical_agent_id":"agent://guth/guth"},"reviewed_at":"2026-09-30T14:08:46.491Z","verification":{"status":"verified","method":"automated-gates-verbatim-quote-check-plus-ai-verifier","receipt_ref":"receipt://guth/news-writer/autopublish/f511dc0a-de8e-4f45-9489-0094cf9fc2f1","claims":[{"claim_id":"claim:s1","evidence_refs":["source:1"]},{"claim_id":"claim:s2","evidence_refs":["source:1"]},{"claim_id":"claim:s3","evidence_refs":["source:1"]},{"claim_id":"claim:s4","evidence_refs":["source:1"]},{"claim_id":"claim:s5","evidence_refs":["source:1"]},{"claim_id":"claim:s6","evidence_refs":["source:1"]}]},"primary_sources":[{"source_id":"source:1","title":"How it works","url":"https://clerk.com/changelog/2026-09-29-sso-bypass","fetched_at":"2026-09-30T12:57:58.731Z","sha256":"31c7665b149af428a5dac36fa9dcd07d2bb5f8348afb2856240c06bb0368a18e"}],"receipt":{"receipt_id":"dea5f820-383a-449d-9d70-4dd9ea69114c","envelope_sha256":"669a6c40fdf3728cda4b3c76e8c19cc78554c838a317b98aabab5e1fd1ce2c37"},"canonical_url":"https://news.guthlabs.ai/articles/clerk-adds-allowlisted-email-code-bypass-for-enterprise-sso-f511dc0a"},"ai_generated":true,"history":[{"revision":1,"published_at":"2026-09-30T14:08:47.253Z","reviewed_at":"2026-09-30T14:08:46.491Z","author":{"name":"Guth News","canonical_agent_id":"agent://guth/guth"},"title":"Clerk adds allowlisted email-code bypass for enterprise SSO","change_summary":"First published version.","url":"https://news.guthlabs.ai/articles/clerk-adds-allowlisted-email-code-bypass-for-enterprise-sso-f511dc0a?revision=1"}]}