Preliminary Checks
Reproduction
https://github.com/clerk/javascript/blob/main/packages/ui/src/components/OAuthConsent/OAuthConsent.tsx (any OAuth application; authorize with scope=offline_access only)
Publishable key
n/a — reproduces on any instance with a Clerk OAuth application
Description
<OAuthConsent /> renders the "This will allow {application} access to:" list group header even when the list is empty.
displayedScopes filters offline_access out (line ~152) and the scope is instead surfaced as the oauthConsent.offlineAccessNotice footer line. When an OAuth client requests only offline_access (Smithery's MCP connector does this against our server), the user sees the header over a blank box and nothing else in the permissions section. The only hint that anything was granted is the small footer sentence.
Steps:
- Register a Clerk OAuth application (we use it as the authorization server for a remote MCP server;
scopes_supported advertises profile email offline_access).
- Start an authorization request with
scope=offline_access and open the consent page.
- Observe: "This will allow X access to:" header, empty list, then Deny/Allow.
Expected: either hide the list group when displayedScopes is empty, or render a row for offline_access (e.g. the text now in offlineAccessNotice), so the permissions box is never blank.
Screenshot from our consent page (Clerk-hosted component, custom appearance only): header present, list empty, footer notice present.
Environment
@clerk/nextjs 7.9.x (packages/ui OAuthConsent), Next.js App Router, custom consent path configured under Configure → Paths; observed 2026-09-22 with Smithery's OAuth client (client_id https://connect.smithery.ai/.well-known/oauth-client, DCR).
Preliminary Checks
Reproduction
https://github.com/clerk/javascript/blob/main/packages/ui/src/components/OAuthConsent/OAuthConsent.tsx (any OAuth application; authorize with
scope=offline_accessonly)Publishable key
n/a — reproduces on any instance with a Clerk OAuth application
Description
<OAuthConsent />renders the "This will allow {application} access to:" list group header even when the list is empty.displayedScopesfiltersoffline_accessout (line ~152) and the scope is instead surfaced as theoauthConsent.offlineAccessNoticefooter line. When an OAuth client requests onlyoffline_access(Smithery's MCP connector does this against our server), the user sees the header over a blank box and nothing else in the permissions section. The only hint that anything was granted is the small footer sentence.Steps:
scopes_supportedadvertisesprofile email offline_access).scope=offline_accessand open the consent page.Expected: either hide the list group when
displayedScopesis empty, or render a row foroffline_access(e.g. the text now inofflineAccessNotice), so the permissions box is never blank.Screenshot from our consent page (Clerk-hosted component, custom
appearanceonly): header present, list empty, footer notice present.Environment