← FirebaseCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Firebase
Snapshot Sep 30, 2026 · 23:02 UTC · version 1.0.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "firebase-auth-basics",
"description": "Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.",
"included_files": [
{
"relative_path": "references/client_sdk_android.md",
"size_in_bytes": 4717
},
{
"relative_path": "references/client_sdk_web.md",
"size_in_bytes": 7670
},
{
"relative_path": "references/flutter_setup.md",
"size_in_bytes": 5596
},
{
"relative_path": "references/ios_setup.md",
"size_in_bytes": 2487
},
{
"relative_path": "references/security_rules.md",
"size_in_bytes": 1309
}
],
"skill_md_contents": "---\nname: firebase-auth-basics\ndescription: Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.\ncompatibility: This skill is best used with the Firebase CLI, but does not require it. Firebase CLI can be accessed through `npx -y firebase-tools@latest`.\nmetadata:\n category: Identity\n---\n\n## Prerequisites\n\n- **Firebase Project**: Created via\n `npx -y firebase-tools@latest projects:create` (see `firebase-basics`).\n- **Firebase CLI**: Installed and logged in (see `firebase-basics`).\n\n## Core Concepts\n\nFirebase Authentication provides backend services, easy-to-use SDKs, and\nready-made UI libraries to authenticate users to your app.\n\n### Users\n\nA user is an entity that can sign in to your app. Each user is identified by a\nunique ID (`uid`) which is guaranteed to be unique across all providers. User\nproperties include:\n\n- `uid`: Unique identifier.\n- `email`: User's email address (if available).\n- `displayName`: User's display name (if available).\n- `photoURL`: URL to user's photo (if available).\n- `emailVerified`: Boolean indicating if the email is verified.\n\n### Identity Providers\n\nFirebase Auth supports multiple ways to sign in:\n\n- **Email/Password**: Basic email and password authentication.\n- **Federated Identity Providers**: Google, Facebook, Twitter, GitHub,\n Microsoft, Apple, etc.\n- **Phone Number**: SMS-based authentication.\n- **Anonymous**: Temporary guest accounts that can be linked to permanent\n accounts later.\n- **Custom Auth**: Integrate with your existing auth system.\n\nGoogle Sign In is recommended as a good and secure default provider.\n\n### Tokens\n\nWhen a user signs in, they receive an ID Token (JWT). This token is used to\nidentify the user when making requests to Firebase services (Realtime Database,\nCloud Storage, Firestore) or your own backend.\n\n- **ID Token**: Short-lived (1 hour), verifies identity.\n- **Refresh Token**: Long-lived, used to get new ID tokens.\n\n## Workflow\n\n### 1. Provisioning\n\n#### Option 1. Enabling Authentication via CLI\n\nOnly Google Sign In, anonymous auth, and email/password auth can be enabled via\nCLI. For other providers, use the Firebase Console.\n\nConfigure Firebase Authentication in `firebase.json` by adding an 'auth' block:\n\n```\n{\n \"auth\": {\n \"authorizedDomains\": [\"localhost\"],\n \"providers\": {\n \"anonymous\": true,\n \"emailPassword\": true,\n \"googleSignIn\": {\n \"oAuthBrandDisplayName\": \"Your Brand Name\",\n \"supportEmail\": \"support@example.com\"\n }\n }\n }\n}\n```\n\n> [!NOTE] If the Google Sign-In popup opens and immediately closes with the\n> error `[firebase_auth/unauthorized-domain]`, it means the domain is not\n> authorized. For local development, ensure `localhost` is included in the\n> **Authorized Domains** list in the Firebase Console or via the\n> `authorizedDomains` field in `firebase.json`. **CRITICAL**: Do NOT include the\n> protocol or port number in the Authorized Domains list (e.g., use `localhost`,\n> NOT `http://localhost:9090`).\n\n**CRITICAL**: After configuring `firebase.json`, you MUST deploy the auth\nconfiguration to the Firebase backend for the changes to take effect. This is\nessential for auth providers like Google Sign-In, email/password, etc. to\nauto-generate the necessary OAuth clients for your app platforms. Run:\n\n```bash\nnpx -y firebase-tools@latest deploy --only auth\n```\n\n#### Option 2. Enabling Authentication in Console\n\nEnable other providers in the Firebase Console.\n\n1. Go to the\n https://console.firebase.google.com/project/_/authentication/providers\n1. Select your project.\n1. Enable the desired Sign-in providers (e.g., Email/Password, Google).\n\n### 2. Client Setup & Usage\n\n**Web** See [references/client_sdk_web.md](references/client_sdk_web.md).\n\n**Flutter** See [references/flutter_setup.md](references/flutter_setup.md).\n**Android (Kotlin)** See\n[references/client_sdk_android.md](references/client_sdk_android.md).\n\n### 3. Security Rules\n\nSecure your data using `request.auth` in Firestore/Storage rules.\n\nSee [references/security_rules.md](references/security_rules.md).\n"
}SHA-256: 8ae13b0234c19a44c5cad9264896acf005e96b38679e47ec8c2cc4a401115dd1