your door, your keys.

Right now your site signs people in with temporary keys. That is the "Configure your application" box you have been ignoring since you first ran it. Temporary keys are fine for a first look, but they are not yours: you cannot see who signed up, choose how people sign in, or take them to your live site. This step creates your own sign-in service with Clerk, connects it with two keys, and makes you the first person to sign up.

(Clerk handles passwords, email codes, and "Continue with Google" so your site never stores a password itself.)

BUILD.

✓ Success: your site knows you.

this is a work in progress

1️⃣ Create Your Clerk Application

Go to dashboard.clerk.com and sign up. Continuing with GitHub is quickest, since you already have that account. Then create an application:

  1. Application name — your site or business name. Visitors see it on your sign-in screen
  2. Sign-in options — turn on Email and, if you like, Google. You can change these any time
  3. Click Create application

Clerk's free plan is enough to get started. Check clerk.com/pricing as your membership grows.

2️⃣ Put Your Keys in .env

Clerk shows your keys right after you create the application, and you can find them again any time under API keys in the dashboard. You need two of them. Add both to the same .env file that already holds your database strings:

bash
# .env (below your database strings)
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY="pk_test_…"
CLERK_SECRET_KEY="sk_test_…"
  • The publishable key (pk_…) is meant to be public. Your site sends it to every visitor's browser, so it is safe to see
  • The secret key (sk_…) is not. Anyone who has it can act as your site. It never goes in a chat, an email, or any file except .env
  • test means development. Keys starting with pk_test and sk_test are for your computer. You get live keys (pk_live, sk_live) when you deploy and connect your domain

🔑 The One Setting Your Copy Needs

Your copy decides who gets into the members area (/party) and who is an admin by reading two labels on each account: role and waitlistStatus. Clerk keeps those labels on the account but does not send them to your site unless you ask. Ask once, now:

  1. In the Clerk dashboard, open Sessions
  2. Find Customize session token and open its claims editor
  3. Paste the text below, replacing anything already there, and click Save
json
{
  "metadata": "{{user.public_metadata}}"
}

Skip this and nothing breaks today. Then in the next step you make yourself an admin, and your site keeps treating you like a stranger.

3️⃣ Sign Up on Your Own Site

Restart your site so it picks up the new keys: click the terminal, press Ctrl + C, then run npm run dev again. The "Configure your application" box is gone, because your own keys are in charge now. Then:

  1. Open http://localhost:3000/sign-up and create your account, with the same email you have used for everything else
  2. Back in the Clerk dashboard, open Users. You are the first one
  3. Open http://localhost:3000/party. It sends you to a "pending" page. That is correct, and the next step fixes it

Your copy has a waitlist built in. Anyone can sign up, but only approved members and admins get into /party. Right now nobody is either, including you. Make yourself admin is next.

🧯 If Something Looks Wrong

  • The "Configure your application" box is still there — the site did not see your keys. Check that both names match exactly, the keys are inside quotes, and you restarted with Ctrl + C and npm run dev
  • An error mentions the publishable key — it was cut off when you copied it. Copy it again from API keys
  • You signed up, but Users in Clerk is empty — you are looking at a different application. Check the application name at the top of the dashboard

🤖 Ask Your LLM

prompt
I added Clerk keys to .env in a Next.js project and restarted it, but
[describe what you see]. Here is the terminal output: [paste it].
Do not ask me for my secret key. What should I check?

(In Claude Code, inside your copy)
Read src/middleware.ts and src/types/globals.d.ts. Explain in plain
words who can open /party and /admin, and why the session token
setting matters. Don't change anything.

✅ You Are Done When

  • .env has NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY and CLERK_SECRET_KEY, and the "Configure your application" box is gone
  • The session token has the metadata claim, saved
  • You signed up at /sign-up, and you appear under Users in Clerk
  • /party sends you to the pending page, for now

Next is Make yourself admin: one label on your account, and your site starts treating you as its owner. That is also when this setup checklist appears inside your site, with your progress saved in your database.

“The first account on your site should be yours.”

— unparty-app
#Clerk#Authentication#Sign In#Setup#Non-Technical Founders

🧗🏾‍♂️ in progress

THOUGHTS.

…