Preliminary Checks
Reproduction
The bug is visible in the source, no project needed: https://github.com/clerk/javascript/blob/main/packages/shared/src/errors/clerkApiError.ts#L21-L38
Publishable key
Not needed: the behavior does not depend on an instance, it is in the error parser.
Description
When an account reaches the user lockout threshold, the Frontend API answers the failed attempt with 403 user_locked and includes how long the lockout lasts in meta.lockout_expires_in_seconds. ClerkAPIError builds its meta from a fixed list of known keys (param_name, session_id, identifiers, zxcvbn, plan, …), so lockout_expires_in_seconds is dropped and the app cannot tell the user when they can try again.
Steps to reproduce:
- Enable user lockout on an instance (e.g. 10 attempts, 60 minutes).
- Sign in with a phone code and submit wrong codes until the attempt returns
user_locked.
- Inspect the network response:
errors[0].meta.lockout_expires_in_seconds is present (e.g. 3599).
- Inspect the thrown
ClerkAPIResponseError: errors[0].meta has no lockout field.
Expected behavior:
ClerkAPIError.meta exposes the lockout duration (e.g. lockoutExpiresInSeconds), the same way ClerkAPIResponseError.retryAfter already exposes Retry-After for too_many_requests, so apps can show a countdown or hide "resend code" until the lockout ends.
Actual behavior:
The value is discarded during parsing. The only way to read it is to bypass the SDK and parse the raw response.
Environment
@clerk/shared 4.31.0 (also on main as of 2026-10-01)
@clerk/clerk-expo, React Native (Expo SDK), iOS and Android
Preliminary Checks
Reproduction
The bug is visible in the source, no project needed: https://github.com/clerk/javascript/blob/main/packages/shared/src/errors/clerkApiError.ts#L21-L38
Publishable key
Not needed: the behavior does not depend on an instance, it is in the error parser.
Description
When an account reaches the user lockout threshold, the Frontend API answers the failed attempt with
403 user_lockedand includes how long the lockout lasts inmeta.lockout_expires_in_seconds.ClerkAPIErrorbuilds itsmetafrom a fixed list of known keys (param_name,session_id,identifiers,zxcvbn,plan, …), solockout_expires_in_secondsis dropped and the app cannot tell the user when they can try again.Steps to reproduce:
user_locked.errors[0].meta.lockout_expires_in_secondsis present (e.g.3599).ClerkAPIResponseError:errors[0].metahas no lockout field.Expected behavior:
ClerkAPIError.metaexposes the lockout duration (e.g.lockoutExpiresInSeconds), the same wayClerkAPIResponseError.retryAfteralready exposesRetry-Afterfortoo_many_requests, so apps can show a countdown or hide "resend code" until the lockout ends.Actual behavior:
The value is discarded during parsing. The only way to read it is to bypass the SDK and parse the raw response.
Environment