OSS TanbouSign in with GitHub

Add multiple authentication strategies to Rack applications through one flow

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
8,102
Primary language
Ruby
License
MIT
Repository last updated
Feb 27, 2026
On this page

Overview

OmniAuth is a Ruby Rack middleware for external authentication initiation and callbacks. Provider strategies share a flow and return an Auth Hash for application-owned user and session handling.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Unify strategies behind common endpoints

A POST to /auth/:provider starts a strategy, and the callback places omniauth.auth in the Rack environment. The application remains responsible for linking users and creating sessions.

Sources: [1]

Best fit

Fit Rack applications with multiple external providers

It fits Rails and Sinatra applications that want a common flow across providers. The developer strategy can exercise request, callback, and Auth Hash handling without provider secrets.

Sources: [1]

Before adoption

Preserve POST and CSRF protections

Authentication initiation should use POST, with protection such as omniauth-rails_csrf_protection in Rails. The developer strategy must remain development-only and does not validate production OAuth.

Sources: [1][3]

Official sources

  1. [1]OmniAuth README at v2.1.4(2026-10-05)
  2. [2]OmniAuth gemspec at v2.1.4(2026-10-05)
  3. [3]OmniAuth LICENSE at v2.1.4(2026-10-05)
  4. [4]OmniAuth v2.1.4 release(2026-10-05)
Supplemental curator note

Before adoption, run the smallest official example on the target environment and verify application responsibilities and dependencies.

Try it in 3 steps

  1. 1

    Create a pinned trial environment

    With Ruby and Bundler installed, create omniauth-demo with OmniAuth 2.1.4 and Rack::Test pinned in its Gemfile.

    mkdir omniauth-demo && cd omniauth-demo && printf '%s\n' "source 'https://rubygems.org'" "gem 'omniauth', '2.1.4'" "gem 'rack-test'" > Gemfile
  2. 2

    Write a developer-strategy test

    Use test_mode and a mock AuthHash to POST /auth/developer, follow its callback, and assert the uid in omniauth.auth without provider secrets.

    bundle install && printf '%s\n' "require 'omniauth'" "require 'rack/test'" "OmniAuth.config.test_mode = true" "OmniAuth.config.mock_auth[:developer] = OmniAuth::AuthHash.new(provider: 'developer', uid: 'example-user', info: {name: 'Example User'})" "app = OmniAuth::Builder.new(->(env) { [200, {'content-type'=>'text/plain'}, [(env['omniauth.auth'] || {}).to_h.inspect]] }) { provider :developer }" "session = Rack::Test::Session.new(Rack::MockSession.new(app))" "session.post('/auth/developer')" "session.follow_redirect!" "abort 'missing AuthHash' unless session.last_response.body.include?('example-user')" > demo.rb
  3. 3

    Exercise POST through Auth Hash

    Run the test through Bundler and verify that the authentication flow passes an AuthHash to the application; this does not validate production OAuth.

    bundle exec ruby demo.rb
Check the official README

Growth

Growth trends · Last 30 days

8,102 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
0
Open PRs
20
Issues opened
1
Issues closed
1
PRs opened
1
PRs merged
0

Issues

1 / 1

Jul 8Oct 5
Issues openedIssues closed

Pull requests

1 / 0

Jul 8Oct 5
PRs openedPRs merged

Maintenance

Median first response
Not specified
Issue response rate
0% (0/1)

Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • omniauth
  • authentication
  • hacktoberfest
  • ruby
Stars
8,102
Forks
973
Watchers
119
Open issues
85
Contributors
168
Owner type
Organization
Primary language
Ruby
License
MIT
Repository last updated
Feb 27, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?