All skills
firebase avatar

/firebase-auth-basics

@4e28cb3
by firebasefirebase/skills461 stars
102

Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.

Use this Skill: https://skilld.dev/gh/firebase/skills/firebase-auth-basics

This session only. Nothing lands on disk.

referencessecurity_rules.md

≈361 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Authentication in Security Rules

Firebase Security Rules work with Firebase Authentication to provide rule-based access control. For Firestore Security Rules (firestore.rules), delegate to the firestore-rules-author subagent if subagent delegation is available, or see the firestore-rules-creation skill otherwise. For Cloud Storage rules, enable the firebase-storage-basics skill.

The request.auth variable contains authentication information for the user requesting data.

Basic Checks

Check if user is signed in

allow read, write: if request.auth != null;

Check if user owns the data

Access data only if the document ID matches the user's UID.

allow read, write: if request.auth != null && request.auth.uid == userId;

(Where userId is a path variable, e.g., match /users/{userId})

Check if user owns the document (field-based)

Access data only if the document has a owner_uid field matching the user's UID.

allow read, write: if request.auth != null && request.auth.uid == resource.data.owner_uid;

Token Properties

request.auth.token contains standard JWT claims and custom claims.

  • request.auth.token.email: The user's email address.
  • request.auth.token.email_verified: If the email is verified.
  • request.auth.token.name: The user's display name.

Example: Email Verification Check

allow create: if request.auth.token.email_verified == true;

Source: SKILL.md on GitHub

No alerts2d5 checks · Risk SAFE
  • Gen Agent Trust Hub2d

    This skill provides a comprehensive and secure guide for integrating Firebase Authentication into Web, Android, iOS, and Flutter applications. It correctly guides users through using official Firebase CLI tools and SDKs, provides essential troubleshooting for common OAuth issues, and emphasizes the importance of using Firebase Security Rules to protect data. No malicious patterns or security risks were detected.

  • Socket2d

    No alerts

  • Snyk2d

    Risk: LOW · No issues

  • Runlayer6mo

    3 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 4e28cb3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
metadata
{
  "category": "Identity"
}
Other metadata
compatibility
This skill is best used with the Firebase CLI, but does not require it. Firebase CLI can be accessed through `npx -y firebase-tools@latest`.
  • Auth
  • firebase
  • authentication
  • web
  • flutter
  • android
  • oauth
  • jwt
  • firestore
  • security-rules

README badge

README badge for firebase/skills/firebase-auth-basics

Provides guidance for setting up Firebase Authentication, including user management, identity providers (email/password, Google Sign-In, phone, anonymous, custom), token handling, and security rules. Use this when building sign-in flows or securing data access with auth rules in Firebase projects.

Generated from the current SKILL.md.

Does this skill require the Firebase CLI?
No, but it is recommended. The Firebase CLI can be accessed via `npx -y firebase-tools@latest` and is needed to deploy auth configuration changes.
Which identity providers can be enabled via CLI?
Only Google Sign In, anonymous auth, and email/password auth can be configured through the CLI. Other providers (Facebook, Twitter, GitHub, etc.) must be enabled in the Firebase Console.
What do I do if Google Sign-In returns an 'unauthorized-domain' error?
The domain must be added to the Authorized Domains list. For local development, add `localhost` (without protocol or port) to the list in the Firebase Console or via the `authorizedDomains` field in `firebase.json`.
Does this skill cover all platforms?
The skill includes references for Web, Flutter, and Android (Kotlin) client setup, but the core guide focuses on configuration and concepts. Platform-specific implementation details are in separate reference files.
What happens after I configure firebase.json with auth settings?
You must run `npx -y firebase-tools@latest deploy --only auth` to deploy the configuration to Firebase and auto-generate the necessary OAuth clients for your app.

Generated from the current SKILL.md. These answers refresh after source changes.