Ruby on Rails
Rails 8 Authentication Generator vs Devise: Which One Should You Use?
Rails 8 added a built-in authentication generator, and new projects now face a choice that used to be automatic: generate the code or install Devise. Both are valid. The difference is how much you want to own and how many features you need on day one.
What the Rails 8 generator creates
Running bin/rails generate authentication adds a User model with has_secure_password, a Session model and a Current model, a SessionsController and a PasswordsController, a PasswordsMailer for password resets, an Authentication concern included in ApplicationController, the login and reset views, migrations for users and sessions, and the bcrypt gem.
It does not include sign-up. The official guide is explicit that you implement your own registration flow, views and routes.
What Devise adds
Devise is a mature engine with modules you enable as needed: registrations, email confirmation, account locking after failed attempts, session timeouts, remember-me, sign-in tracking and integration with OmniAuth for social and SSO logins. It also has a large ecosystem of extensions, for example for two-factor authentication.
How to choose
Consider who maintains the code and which requirements are already on the table.
- Choose the generator for internal tools and small products where login and password reset are enough, and where you prefer readable code in your own repository over a dependency.
- Choose Devise when you need confirmation emails, account locking, OmniAuth or SSO from the start, or when the team already knows it well.
- For existing apps on Devise, there is rarely a business reason to migrate; the risk of breaking login usually outweighs the benefit.
Security either way
Neither option is secure by default without review. Rate-limit login and password reset endpoints, make reset tokens expire, avoid revealing whether an email exists, log authentication events and add two-factor authentication for administrative accounts. A focused security review of the login flow is one of the cheapest ways to reduce risk in a Rails application.
Key takeaways
- The Rails 8 generator gives you login, sessions and password reset, but not sign-up.
- Devise brings registrations, confirmation, locking and OmniAuth out of the box.
- Generator for small apps you want to own; Devise for richer requirements.
- Review rate limits, token expiry and 2FA whichever you choose.
Related
Want to review your case with context?
Share the codebase, workflow, or systems involved and the result you need. We will use the call to decide a practical next step.