Auth Stack
Key Files
Panel Gating
Premium panels show a CTA overlay instead of content until the user meets the access requirements.Gate Reasons
How to Configure Which Panels Are Premium
Three files control gating. All three must stay in sync when adding or removing premium panels.1. Panel config — src/config/panels.ts
Add premium: 'locked' to the panel entry in the relevant variant:
2. Client-side gate set — src/app/panel-layout.ts
Add the panel key to WEB_PREMIUM_PANELS:
3. Server-side API enforcement (if the panel calls premium APIs)
Client token injection —src/services/runtime.ts (WEB_PREMIUM_API_PATHS):
Authorization: Bearer <token>.
Server gateway — server/gateway.ts (PREMIUM_RPC_PATHS):
session.role === 'pro'. Returns 403 if the user isn’t pro.
Currently Gated Panels
Desktop Behavior
Desktop users with a validWORLDMONITOR_API_KEY in the Tauri keychain bypass all panel gating. The existing API key flow is unaffected — bearer tokens are a second auth path, not a replacement.
Server-Side Session Enforcement
The Vercel API gateway accepts two forms of authentication for premium endpoints:- Static API key —
X-WorldMonitor-Keyheader (existing flow, unchanged) - Bearer token —
Authorization: Bearer <clerk_jwt>(for web users)
server/auth-session.ts. The JWT is verified against:
- Issuer:
CLERK_JWT_ISSUER_DOMAIN - Audience:
convex(matches the Clerk JWT template) - Signature: RSA256 via Clerk’s published JWKS
Environment Variables
User Roles
User roles (pro / free) are stored as a plan claim in the Clerk JWT. The server extracts this from the verified token payload. Unknown or missing plan values default to free (fail closed — never pro).
On the client side, getAuthState().user?.role exposes the role. Both isProUser() and hasPremiumAccess() check this alongside legacy API key gates.