On this page
Overview
OmniAuth is a Ruby Rack middleware for external authentication initiation and callbacks. Provider strategies share a flow and return an Auth Hash for application-owned user and session handling.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Unify strategies behind common endpoints
A POST to /auth/:provider starts a strategy, and the callback places omniauth.auth in the Rack environment. The application remains responsible for linking users and creating sessions.
Sources: [1]
Best fit
Fit Rack applications with multiple external providers
It fits Rails and Sinatra applications that want a common flow across providers. The developer strategy can exercise request, callback, and Auth Hash handling without provider secrets.
Sources: [1]
Before adoption
Official sources
- [1]OmniAuth README at v2.1.4(2026-10-05)
- [2]OmniAuth gemspec at v2.1.4(2026-10-05)
- [3]OmniAuth LICENSE at v2.1.4(2026-10-05)
- [4]OmniAuth v2.1.4 release(2026-10-05)
Supplemental curator note
Before adoption, run the smallest official example on the target environment and verify application responsibilities and dependencies.
Try it in 3 steps
- 1
Create a pinned trial environment
With Ruby and Bundler installed, create omniauth-demo with OmniAuth 2.1.4 and Rack::Test pinned in its Gemfile.
mkdir omniauth-demo && cd omniauth-demo && printf '%s\n' "source 'https://rubygems.org'" "gem 'omniauth', '2.1.4'" "gem 'rack-test'" > Gemfile - 2
Write a developer-strategy test
Use test_mode and a mock AuthHash to POST /auth/developer, follow its callback, and assert the uid in omniauth.auth without provider secrets.
bundle install && printf '%s\n' "require 'omniauth'" "require 'rack/test'" "OmniAuth.config.test_mode = true" "OmniAuth.config.mock_auth[:developer] = OmniAuth::AuthHash.new(provider: 'developer', uid: 'example-user', info: {name: 'Example User'})" "app = OmniAuth::Builder.new(->(env) { [200, {'content-type'=>'text/plain'}, [(env['omniauth.auth'] || {}).to_h.inspect]] }) { provider :developer }" "session = Rack::Test::Session.new(Rack::MockSession.new(app))" "session.post('/auth/developer')" "session.follow_redirect!" "abort 'missing AuthHash' unless session.last_response.body.include?('example-user')" > demo.rb - 3
Exercise POST through Auth Hash
Run the test through Bundler and verify that the authentication flow passes an AuthHash to the application; this does not validate production OAuth.
bundle exec ruby demo.rb
Growth
Growth trends · Last 30 days
8,102 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 0
- Open PRs
- 20
- Issues opened
- 1
- Issues closed
- 1
- PRs opened
- 1
- PRs merged
- 0
Issues
1 / 1
Pull requests
1 / 0
Maintenance
- Median first response
- Not specified
- Issue response rate
- 0% (0/1)
Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- omniauth
- authentication
- hacktoberfest
- ruby
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- ActiveAdmin9,713 Stars
2 shared tag(s) · 1 shared category(s) · Same language
embed an administration engine in Rails and define resources and actions through a DSL
Ruby - Auth.js28,369 Stars
2 shared tag(s) · 1 shared category(s)
Compose OAuth/OIDC, passwordless, WebAuthn, and stateless or database-backed sessions from packages built around standard Web APIs
TypeScript - ZITADEL15,199 Stars
2 shared tag(s) · 1 shared category(s)
manage SSO, MFA, passkeys, and B2B multi-tenancy through an API-first IAM
Go - OAuth2 Proxy15,046 Stars
2 shared tag(s) · 1 shared category(s)
Put authentication in front of web applications and pass through authorized users
Go - Logto14,652 Stars
2 shared tag(s) · 1 shared category(s)
centralize authentication, authorization, and organizations for SaaS and AI apps on OIDC and OAuth 2.1
TypeScript - Mastodon50,351 Stars
2 shared tag(s) · Same language
run a community-governed server that federates across the Fediverse with ActivityPub
Ruby
Report incorrect information
Tell us if any listing information is incorrect or outdated.