I twice worked at companies that built authentication as part of their application (using open source libraries, not from scratch). It's a mistake, and a mistake that's very expensive to fix later. Even more expensive not to fix given the sensitivity of this area of software.