A sweet spot only is as much as the code is already written, but there's a huge amount of ops and security work that goes into rolling your own auth.
For 99.9% of businesses, don't roll your own auth. Just don't do it. Use an auth service.
Is there a good one that integrates with Express?
Passport. It provides a lot of authentication schemes
Passport is an Express middleware for authentication. It supports pluggable "strategies" for supporting different types of authentication, from basic username/password to OAuth and many others.
Yes, this is an excellent choice as long as all of yours apps live in the Ruby world.
Actually I built a single sign on system for a Rails app and a WordPress site many years ago, based on Devise and probably (can't remember) some PHP code on WP. Probably also a Rails+phpBB SSO. They were meant to be short lived services and luckily they did. The reason is that in a mixed language / framework environment it's better to have some centralized authentication and authorization service and a standard API to access it. Having to write and maintain N adapters is going to take a toll on the development team. However I never self hosted a service like that so I don't want to give any suggestions about what to use.