Choose the tool that fits the login system you want to own. AddAuth extends Rails’ generated authentication; Devise, Rodauth, and Sorcery offer different starting points.
Its column describes 0.2.0.dev development features, not a published gem. The other projects have published packages. Compare the fit, then check the release and upgrade requirements of the version you would install.
Where each approach fits
- AddAuth: you want to keep Rails’ generated account and session models while adding email links, passkeys, and checks before sensitive changes. You can wait for the first RubyGems release and own signup and deployment operations.
- Devise: you want an authentication framework with account signup, password reset, confirmation, and configurable modules. It supplies controllers and views; additional gems extend the feature set. Devise overview.
- Rodauth with rodauth-rails: you want a broad feature set, including passkeys and multiple second-factor options. It brings its own authentication configuration and feature tables; its Rails integration connects views, mail, and models. Rails integration.
- Sorcery: you want login helpers and optional modules while writing your app’s controllers and pages yourself. That gives you more presentation work to own. Sorcery overview.
These fit suggestions are our interpretation of the projects’ documented designs. They are not a security ranking or a reason to migrate a working app on their own.
Compare the features
Checked on against official documentation. Included means the project provides the feature, often as an option you must enable. Extra gem means a separate integration. App-owned means your application supplies the flow. Not in core means it is not provided by the built-in modules reviewed here; extensions or custom code may add it.
On a narrow screen, scroll the table sideways. With a keyboard, focus the table area and use the arrow keys.
| Feature | AddAuth Unreleased development | Devise | Rodauth with rodauth-rails | Sorcery |
|---|---|---|---|---|
| Password sign-in | Included; uses the Rails account | Included | Included | Included |
| Email-link sign-in | Included | Extra gem | Included | Not in core |
| Passkeys | Included | Extra gem | Included; login and autofill | Not in core |
| Expire an idle session | Included; also a total time limit | Included; Timeoutable | Included; also a total time limit | Included |
| Sign out all browsers | Included; confirm identity again | Not in core | Included; Active Sessions | Included; optional invalidation |
| Account signup | App-owned | Included; Registerable | Included | App-owned; model helpers |
| Forgotten-password reset | App-owned; keeps Rails’ flow | Included; Recoverable | Included | Reset module; app-owned pages |
| Codes from an authenticator app A second-factor option, often called TOTP | Not included | Extra gem | Included | Not in core |
| Backup recovery codes | Future consideration | Extra gem | Included | Not in core |
| Google or GitHub sign-in | Not included | OmniAuth integration + provider strategy | Extra gem | Included; External module |
| Turnstile / reCAPTCHA bot checks | Included adapters; provider setup required | Not in core | Not in core | Not in core |
| Customize authentication pages | Included pages; copy and edit | Included views; copy and edit | View generator in rodauth-rails | Write your own pages |
Feature names do not imply identical behavior. For example, password reset, email-link sign-in, and passkey recovery are different flows. Review expiry, fallback rules, session invalidation, and failure handling for your app. Listed extensions are examples, not a compatibility test or endorsement of every combination.
All four approaches run in your application. You still operate delivery and storage, protect secrets, apply updates, and decide what signed-in users may do.
Sources and review scope
The table uses the projects’ documented core features and the named extensions, not an exhaustive survey of their ecosystems. Package versions observed on the review date: Devise 5.0.4, Rodauth 2.47.0, rodauth-rails 2.2.2, and Sorcery 0.18.0. Official documentation and extension compatibility can move independently of a release; check the version you choose.
- AddAuth features and roadmap, for the planned prerelease.
- Devise core modules and customization; community extensions. Email-link, passkey, and two-factor cells link to their respective extension authors.
- Rodauth feature reference and Rails integration, including generated views and database setup.
- Sorcery module list and controller and view setup.
- Published packages: Devise, Rodauth, rodauth-rails, and Sorcery.
Already using one of these gems? Check its extensions and upgrade path before replacing it. Starting with Rails’ authentication generator? Read what AddAuth adds, then follow the development quickstart.