← FirebaseCONTENT HISTORY

Update to Firebase

Snapshot Sep 30, 2026 · 23:02 UTC · version 1.0.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "firebase-auth-basics",
  "description": "Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.",
  "included_files": [
    {
      "relative_path": "references/client_sdk_android.md",
      "size_in_bytes": 4717
    },
    {
      "relative_path": "references/client_sdk_web.md",
      "size_in_bytes": 7670
    },
    {
      "relative_path": "references/flutter_setup.md",
      "size_in_bytes": 5596
    },
    {
      "relative_path": "references/ios_setup.md",
      "size_in_bytes": 2487
    },
    {
      "relative_path": "references/security_rules.md",
      "size_in_bytes": 1309
    }
  ],
  "skill_md_contents": "---\nname: firebase-auth-basics\ndescription: Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.\ncompatibility: This skill is best used with the Firebase CLI, but does not require it. Firebase CLI can be accessed through `npx -y firebase-tools@latest`.\nmetadata:\n  category: Identity\n---\n\n## Prerequisites\n\n- **Firebase Project**: Created via\n  `npx -y firebase-tools@latest projects:create` (see `firebase-basics`).\n- **Firebase CLI**: Installed and logged in (see `firebase-basics`).\n\n## Core Concepts\n\nFirebase Authentication provides backend services, easy-to-use SDKs, and\nready-made UI libraries to authenticate users to your app.\n\n### Users\n\nA user is an entity that can sign in to your app. Each user is identified by a\nunique ID (`uid`) which is guaranteed to be unique across all providers. User\nproperties include:\n\n- `uid`: Unique identifier.\n- `email`: User's email address (if available).\n- `displayName`: User's display name (if available).\n- `photoURL`: URL to user's photo (if available).\n- `emailVerified`: Boolean indicating if the email is verified.\n\n### Identity Providers\n\nFirebase Auth supports multiple ways to sign in:\n\n- **Email/Password**: Basic email and password authentication.\n- **Federated Identity Providers**: Google, Facebook, Twitter, GitHub,\n  Microsoft, Apple, etc.\n- **Phone Number**: SMS-based authentication.\n- **Anonymous**: Temporary guest accounts that can be linked to permanent\n  accounts later.\n- **Custom Auth**: Integrate with your existing auth system.\n\nGoogle Sign In is recommended as a good and secure default provider.\n\n### Tokens\n\nWhen a user signs in, they receive an ID Token (JWT). This token is used to\nidentify the user when making requests to Firebase services (Realtime Database,\nCloud Storage, Firestore) or your own backend.\n\n- **ID Token**: Short-lived (1 hour), verifies identity.\n- **Refresh Token**: Long-lived, used to get new ID tokens.\n\n## Workflow\n\n### 1. Provisioning\n\n#### Option 1. Enabling Authentication via CLI\n\nOnly Google Sign In, anonymous auth, and email/password auth can be enabled via\nCLI. For other providers, use the Firebase Console.\n\nConfigure Firebase Authentication in `firebase.json` by adding an 'auth' block:\n\n```\n{\n  \"auth\": {\n  \"authorizedDomains\": [\"localhost\"],\n    \"providers\": {\n      \"anonymous\": true,\n      \"emailPassword\": true,\n      \"googleSignIn\": {\n        \"oAuthBrandDisplayName\": \"Your Brand Name\",\n        \"supportEmail\": \"support@example.com\"\n      }\n    }\n  }\n}\n```\n\n> [!NOTE] If the Google Sign-In popup opens and immediately closes with the\n> error `[firebase_auth/unauthorized-domain]`, it means the domain is not\n> authorized. For local development, ensure `localhost` is included in the\n> **Authorized Domains** list in the Firebase Console or via the\n> `authorizedDomains` field in `firebase.json`. **CRITICAL**: Do NOT include the\n> protocol or port number in the Authorized Domains list (e.g., use `localhost`,\n> NOT `http://localhost:9090`).\n\n**CRITICAL**: After configuring `firebase.json`, you MUST deploy the auth\nconfiguration to the Firebase backend for the changes to take effect. This is\nessential for auth providers like Google Sign-In, email/password, etc. to\nauto-generate the necessary OAuth clients for your app platforms. Run:\n\n```bash\nnpx -y firebase-tools@latest deploy --only auth\n```\n\n#### Option 2. Enabling Authentication in Console\n\nEnable other providers in the Firebase Console.\n\n1. Go to the\n   https://console.firebase.google.com/project/_/authentication/providers\n1. Select your project.\n1. Enable the desired Sign-in providers (e.g., Email/Password, Google).\n\n### 2. Client Setup & Usage\n\n**Web** See [references/client_sdk_web.md](references/client_sdk_web.md).\n\n**Flutter** See [references/flutter_setup.md](references/flutter_setup.md).\n**Android (Kotlin)** See\n[references/client_sdk_android.md](references/client_sdk_android.md).\n\n### 3. Security Rules\n\nSecure your data using `request.auth` in Firestore/Storage rules.\n\nSee [references/security_rules.md](references/security_rules.md).\n"
}

SHA-256: 8ae13b0234c19a44c5cad9264896acf005e96b38679e47ec8c2cc4a401115dd1