waiting-for-dev/devise-jwt
57.2
Weak · 20 September 2026
466
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is a Devise extension that provides JWT-based authentication for Ruby on Rails applications. It centralizes JWT configuration within Devise and offers multiple strategies for token revocation, including allowlist, denylist, and JTI matcher approaches. The library automates the setup of authentication mappings and dispatches tokens for sign-in and registration flows.
How it got here
2016 — JWT configuration centralization
6 changes.
The Devise JWT extension was refactored to centralize configuration within a unified Devise::JWT module, automating setup via Railties and introducing new revocation strategies. This period also involved modernizing code style, updating test infrastructure for coverage, and ensuring compatibility with Rails 8 and Devise 5.
2017 — JWT revocation strategies and test coverage
10 changes.
This period focused on implementing and testing new JWT revocation strategies, including Allowlist, Denylist, JTIMatcher, and Null, while updating terminology from whitelist/blacklist. It also introduced the JwtAuthenticatable module for user lookup and established comprehensive test coverage using a Rails 8 fixture application to validate these authentication flows.
Features
Add JWTAuthenticatable module for JWT-based user lookup
Introduces the JwtAuthenticatable module, which enables models to authenticate via JWT by providing a find\_for\_jwt\_authentication method that locates users using the primary key and a jwt\_subject method that returns the user's ID.
lib/devise/jwt/models · high confidence
Behavioural changes
Automated JWT configuration and new revocation strategies
The library now automatically configures JWT mappings, dispatch requests (sign-in, registration), and revocation requests (sign-out) by inspecting Devise mappings via a new Railtie and DefaultsGenerator, removing the need for manual setup. It introduces new revocation strategies (Null, Allowlist, Denylist) and a test helper for generating authentication headers. The module namespace is also updated from \Devise::Jwt\ to \Devise::JWT\ and the version is bumped to 0.13.0.
lib/devise/jwt · high confidence
JWT configuration is now centralized in Devise with Warden delegation
The JWT extension for Devise has been refactored to encapsulate its API within a single \Devise::JWT\ module, replacing the previous placeholder implementation. Users can now configure JWT settings (such as secret, algorithm, expiration, and issuer) directly through the \Devise.jwt\ block, which automatically forwards these values to the underlying \Warden::JWTAuth\ configuration. This change introduces support for rotation secrets, asymmetric algorithms, and configurable request formats, providing a unified interface for JWT authentication within Devise.
lib/devise · high confidence
New JWT revocation strategies and terminology update
This change introduces three new JWT revocation strategies for users to choose from: Allowlist (tracks issued tokens in a dedicated table and revokes by deletion), Denylist (tracks revoked tokens by adding their JTI to a table), and JTIMatcher (binds a unique JTI to the user record, revoking by updating that column). It also adds a Null strategy that performs no revocation checks. Additionally, the previous whitelist and blacklist strategies have been renamed to allowlist and denylist respectively to use inclusive terminology.
_lib/devise/jwt/revocation\strategies · high confidence
Syntax modernization in bin/console
The bin/console script has been updated to use single quotes for string literals and includes a frozen\_string\_literal pragma, aligning the code style with RuboCop standards.
bin · high confidence
Test coverage
Added Rails 8 fixture application for testing; Added integration tests for JWT authorization, token dispatch, and revocation; Added test coverage for JWT defaults, mapping inspection, railtie configuration, and test helpers; Added test coverage for new JWT revocation strategies; Added test fixture controllers for JWT authentication scenarios; Added test support helpers and fixtures for authentication scenarios; Added tests for Devise JWT configuration and module registration; Added tests for JwtAuthenticatable model behavior; Updated test environment configuration and added fixture application job; Updated test fixtures for JWT revocation strategies.
Dependencies
Updated gemspec dependencies and fixture app for Rails 8 compatibility
The gemspec now requires warden-jwt\_auth \~\> 0.10 and allows bundler \> 1, while the fixture application has been updated to use Rails 8.0.2 and Devise 5.0.0.rc to ensure the gem works with the latest versions of these frameworks.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 57.
Lenses
- Code Health 100
- Architecture 69
- Maturity 47
- Readiness 50
- Security 96
Changes since last survey
- 245 commits — 203 feature/other, 42 fixes
By area
- (root) — 137 commits
- lib/devise — 46 commits
- spec/fixtures — 28 commits
- spec/devise — 14 commits
- .github/workflows — 7 commits
- spec/features — 5 commits
- (repo) — 3 commits
- spec/spec_helper.rb — 3 commits
- .github/FUNDING.yml — 1 commit
- .github/dependabot.yml — 1 commit
Notable commits
- fix: Disable reek and fix rest of cops
- fix: FIX: "No verification key available" on token decode
- fix: Fix CC reporting config
- fix: Fix Changelog format
- fix: Fix README title
- fix: Fix URL to revocation strategy article (#223)
- fix: Fix URLs to articles
- fix: Fix behavior when reloading code
- fix: Fix blank path segments generating double slash paths
- fix: Fix cops
- fix: Fix cops
- fix: Fix cops
- fix: Fix cops
- fix: Fix cops
- fix: Fix date in the Changelog
- fix: Fix date of most recent change
- fix: Fix deprecation warning in fixture app
- fix: Fix dry-configuration compatibility
- fix: Fix error when revoking an expired token
- fix: Fix exchanging methods
- …and 225 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
waiting-for-dev/devise-jwt was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 22c9ec2ec52a4edfd6d51ad185a02d68d146039a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.