All skills
firebase avatar

/firebase-auth-basics

@4e28cb3
by firebasefirebase/skills461 stars
102

Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.

Use this Skill: https://skilld.dev/gh/firebase/skills/firebase-auth-basics

This session only. Nothing lands on disk.

referencesios_setup.md

≈622 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Firebase Auth iOS Setup Guide

⛔️ CRITICAL RULE: NO INLINE INITIALIZATION ⛔️

NEVER write let auth = Auth.auth() as an inline class or struct property if there is ANY chance the object is instantiated before FirebaseApp.configure() executes in the app root.

  • FATAL CRASH: @Observable class AuthManager { let auth = Auth.auth() } initialized as a @State in the App root.
  • SAFE PATTERN: Initialize Auth.auth() lazily (lazy var auth = Auth.auth()) OR explicitly initialize the manager after FirebaseApp.configure() finishes.

1. Import and Initialize

Ensure you have installed the FirebaseAuth SDK. Use the xcode-project-setup skill to automate adding the SPM dependency to the Xcode project.

Note: Ensure FirebaseApp.configure() has been executed in your app's entry point before calling any Auth.auth() methods, otherwise your app will crash. Do not initialize Auth objects in SwiftUI @State properties at the App root level.

import FirebaseAuth

2. Authentication State

To listen for authentication state changes (recommended way to check if a user is signed in):

var handle: AuthStateDidChangeListenerHandle?

handle = Auth.auth().addStateDidChangeListener { auth, user in
  if let user = user {
    print("User is signed in with uid: \(user.uid)")
  } else {
    print("User is signed out")
  }
}

// To remove the listener when no longer needed:
if let handle = handle {
  Auth.auth().removeStateDidChangeListener(handle)
}

3. Email and Password Authentication (Modern Concurrency)

Modern Swift projects should prioritize async/await for authentication calls to avoid nested completion handlers and improve readability.

Sign Up

do {
    let authResult = try await Auth.auth().createUser(withEmail: "user@example.com", password: "password")
    print("User created successfully with uid: \(authResult.user.uid)")
} catch {
    print("Error creating user: \(error.localizedDescription)")
}

Sign In

do {
    let authResult = try await Auth.auth().signIn(withEmail: "user@example.com", password: "password")
    print("User signed in successfully with uid: \(authResult.user.uid)")
} catch {
    print("Error signing in: \(error.localizedDescription)")
}

4. Sign Out

do {
  try Auth.auth().signOut()
  print("Successfully signed out")
} catch let signOutError as NSError {
  print("Error signing out: \(signOutError)")
}

Source: SKILL.md on GitHub

No alerts5d5 checks · Risk SAFE
  • Gen Agent Trust Hub5d

    The skill provides standard guidelines and code snippets for implementing Firebase Authentication across various platforms (Web, Android, iOS, and Flutter). It uses official Firebase CLI tools and follows best practices for security rules and SDK initialization. No malicious patterns or security vulnerabilities were detected.

  • Socket5d

    No alerts

  • Snyk5d

    Risk: LOW · No issues

  • Runlayer6mo

    3 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 4e28cb3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
metadata
{
  "category": "Identity"
}
Other metadata
compatibility
This skill is best used with the Firebase CLI, but does not require it. Firebase CLI can be accessed through `npx -y firebase-tools@latest`.
  • Auth
  • firebase
  • authentication
  • web
  • flutter
  • android
  • oauth
  • jwt
  • firestore
  • security-rules

README badge

README badge for firebase/skills/firebase-auth-basics

Provides guidance for setting up Firebase Authentication, including user management, identity providers (email/password, Google Sign-In, phone, anonymous, custom), token handling, and security rules. Use this when building sign-in flows or securing data access with auth rules in Firebase projects.

Generated from the current SKILL.md.

Does this skill require the Firebase CLI?
No, but it is recommended. The Firebase CLI can be accessed via `npx -y firebase-tools@latest` and is needed to deploy auth configuration changes.
Which identity providers can be enabled via CLI?
Only Google Sign In, anonymous auth, and email/password auth can be configured through the CLI. Other providers (Facebook, Twitter, GitHub, etc.) must be enabled in the Firebase Console.
What do I do if Google Sign-In returns an 'unauthorized-domain' error?
The domain must be added to the Authorized Domains list. For local development, add `localhost` (without protocol or port) to the list in the Firebase Console or via the `authorizedDomains` field in `firebase.json`.
Does this skill cover all platforms?
The skill includes references for Web, Flutter, and Android (Kotlin) client setup, but the core guide focuses on configuration and concepts. Platform-specific implementation details are in separate reference files.
What happens after I configure firebase.json with auth settings?
You must run `npx -y firebase-tools@latest deploy --only auth` to deploy the configuration to Firebase and auto-generate the necessary OAuth clients for your app.

Generated from the current SKILL.md. These answers refresh after source changes.