Skip to content
CAI
Software that uses CAICheck a score

waiting-for-dev/devise-jwt

57.2

Weak · 20 September 2026

466

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Devise extension that provides JWT-based authentication for Ruby on Rails applications. It centralizes JWT configuration within Devise and offers multiple strategies for token revocation, including allowlist, denylist, and JTI matcher approaches. The library automates the setup of authentication mappings and dispatches tokens for sign-in and registration flows.

How it got here

2016 — JWT configuration centralization

6 changes.

The Devise JWT extension was refactored to centralize configuration within a unified Devise::JWT module, automating setup via Railties and introducing new revocation strategies. This period also involved modernizing code style, updating test infrastructure for coverage, and ensuring compatibility with Rails 8 and Devise 5.

2017 — JWT revocation strategies and test coverage

10 changes.

This period focused on implementing and testing new JWT revocation strategies, including Allowlist, Denylist, JTIMatcher, and Null, while updating terminology from whitelist/blacklist. It also introduced the JwtAuthenticatable module for user lookup and established comprehensive test coverage using a Rails 8 fixture application to validate these authentication flows.

Features

Add JWTAuthenticatable module for JWT-based user lookup

Introduces the JwtAuthenticatable module, which enables models to authenticate via JWT by providing a find\_for\_jwt\_authentication method that locates users using the primary key and a jwt\_subject method that returns the user's ID.

lib/devise/jwt/models · high confidence

Behavioural changes

Automated JWT configuration and new revocation strategies

The library now automatically configures JWT mappings, dispatch requests (sign-in, registration), and revocation requests (sign-out) by inspecting Devise mappings via a new Railtie and DefaultsGenerator, removing the need for manual setup. It introduces new revocation strategies (Null, Allowlist, Denylist) and a test helper for generating authentication headers. The module namespace is also updated from \Devise::Jwt\ to \Devise::JWT\ and the version is bumped to 0.13.0.

lib/devise/jwt · high confidence

JWT configuration is now centralized in Devise with Warden delegation

The JWT extension for Devise has been refactored to encapsulate its API within a single \Devise::JWT\ module, replacing the previous placeholder implementation. Users can now configure JWT settings (such as secret, algorithm, expiration, and issuer) directly through the \Devise.jwt\ block, which automatically forwards these values to the underlying \Warden::JWTAuth\ configuration. This change introduces support for rotation secrets, asymmetric algorithms, and configurable request formats, providing a unified interface for JWT authentication within Devise.

lib/devise · high confidence

New JWT revocation strategies and terminology update

This change introduces three new JWT revocation strategies for users to choose from: Allowlist (tracks issued tokens in a dedicated table and revokes by deletion), Denylist (tracks revoked tokens by adding their JTI to a table), and JTIMatcher (binds a unique JTI to the user record, revoking by updating that column). It also adds a Null strategy that performs no revocation checks. Additionally, the previous whitelist and blacklist strategies have been renamed to allowlist and denylist respectively to use inclusive terminology.

_lib/devise/jwt/revocation\strategies · high confidence

Syntax modernization in bin/console

The bin/console script has been updated to use single quotes for string literals and includes a frozen\_string\_literal pragma, aligning the code style with RuboCop standards.

bin · high confidence

Test coverage

Added Rails 8 fixture application for testing; Added integration tests for JWT authorization, token dispatch, and revocation; Added test coverage for JWT defaults, mapping inspection, railtie configuration, and test helpers; Added test coverage for new JWT revocation strategies; Added test fixture controllers for JWT authentication scenarios; Added test support helpers and fixtures for authentication scenarios; Added tests for Devise JWT configuration and module registration; Added tests for JwtAuthenticatable model behavior; Updated test environment configuration and added fixture application job; Updated test fixtures for JWT revocation strategies.

Dependencies

Updated gemspec dependencies and fixture app for Rails 8 compatibility

The gemspec now requires warden-jwt\_auth \~\> 0.10 and allows bundler \> 1, while the fixture application has been updated to use Rails 8.0.2 and Devise 5.0.0.rc to ensure the gem works with the latest versions of these frameworks.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 57.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 47
  • Readiness 50
  • Security 96

Changes since last survey

  • 245 commits — 203 feature/other, 42 fixes

By area

  • (root) — 137 commits
  • lib/devise — 46 commits
  • spec/fixtures — 28 commits
  • spec/devise — 14 commits
  • .github/workflows — 7 commits
  • spec/features — 5 commits
  • (repo) — 3 commits
  • spec/spec_helper.rb — 3 commits
  • .github/FUNDING.yml — 1 commit
  • .github/dependabot.yml — 1 commit

Notable commits

  • fix: Disable reek and fix rest of cops
  • fix: FIX: "No verification key available" on token decode
  • fix: Fix CC reporting config
  • fix: Fix Changelog format
  • fix: Fix README title
  • fix: Fix URL to revocation strategy article (#223)
  • fix: Fix URLs to articles
  • fix: Fix behavior when reloading code
  • fix: Fix blank path segments generating double slash paths
  • fix: Fix cops
  • fix: Fix cops
  • fix: Fix cops
  • fix: Fix cops
  • fix: Fix cops
  • fix: Fix date in the Changelog
  • fix: Fix date of most recent change
  • fix: Fix deprecation warning in fixture app
  • fix: Fix dry-configuration compatibility
  • fix: Fix error when revoking an expired token
  • fix: Fix exchanging methods
  • …and 225 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

waiting-for-dev/devise-jwt was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 22c9ec2ec52a4edfd6d51ad185a02d68d146039a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.