OSS TanbouSign in with GitHub

compose Rails authentication workflows from modular features on top of Warden

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
24,354
Primary language
Ruby
License
MIT
Repository last updated
Jun 22, 2026
On this page

Overview

Devise is an authentication solution for Rails built on Warden. Modules such as DatabaseAuthenticatable, Confirmable, Recoverable, Registerable, and Lockable can be combined on application models to provide sessions, password resets, registration, confirmation, and related account workflows.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Compose authentication behavior from model-level modules

Password authentication, registration, confirmation, password recovery, remember cookies, session timeout, and account locking are exposed as modules that applications can enable as needed.

Sources: [1]

Integrate authentication through Rails engines, routes, and controller helpers

Generators add initializer and model/route configuration, while helpers such as authenticate_user! and current_user expose authentication state to Rails controllers and views.

Sources: [1]

Support multiple models, OmniAuth, and different ORM configurations

Devise supports multiple authentication scopes, OmniAuth integration, and configurations for ActiveRecord and Mongoid so the authentication layer can follow the Rails application's architecture.

Sources: [1]

Best fit

Fits Rails applications that need standard account authentication workflows quickly

It is useful when teams want mature Rails integration for sign-in, registration, password reset, and confirmation without rebuilding those flows from scratch.

Sources: [1]

Before adoption

Devise 5 targets Rails 7+ and Ruby 2.7+

The README positions Devise 5 for Rails 7 and newer, while the v5.0.4 gemspec requires Ruby >= 2.7.0 and railties >= 7.0.

Sources: [1][3]

Version 5.0.4 contains an open-redirect security fix

Devise 5.0.4 fixes an open redirect in FailureApp caused by an unvalidated Referer header during non-GET session timeout handling (CVE-2026-40295 / GHSA-jp94-3292-c3xv). Users on the 5.0 line should be on at least 5.0.4.

Sources: [2][4]

Official sources

  1. [1]Devise v5.0.4 README(2026-10-04)
  2. [2]Devise v5.0.4 release(2026-10-04)
  3. [3]Devise v5.0.4 gemspec(2026-10-04)
  4. [4]Devise v5.0.4 changelog(2026-10-04)
  5. [5]Devise MIT license(2026-10-04)
Supplemental curator note

Devise provides authentication building blocks, but application-specific authorization, account lifecycle, and CSRF/session policies still require separate design.

Try it in 3 steps

  1. 1

    Add Devise 5.0.4 to an existing Rails application

    Pin the security-fixed 5.0.4 release in a Rails 7+ application.

    cd your-rails-app && bundle add devise --version 5.0.4
  2. 2

    Generate the Devise initializer

    Generate the authentication initializer and review environment requirements such as mailer URL settings.

    cd your-rails-app && bundle exec rails generate devise:install
  3. 3

    Generate Devise configuration for a User model

    Generate model, route, and migration changes. Review the migration and enabled modules before applying database changes.

    cd your-rails-app && bundle exec rails generate devise User
Check the official README

Growth

Growth trends · Last 30 days

24,354 Stars

Trend data is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • authentication
  • devise
  • rails
  • ruby
Stars
24,354
Forks
5,467
Watchers
24,354
Open issues
237
Owner type
Organization
Primary language
Ruby
License
MIT
Repository last updated
Jun 22, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?