Identifying users.
WHAT IT PROVIDES
Sign-in with email and password, phone, and federated providers Anonymous sign-in Token issuance and refresh Integration with security rules
WHY IT IS WIDELY USED
It removes password handling, which is easy to implement subtly wrong.
WHAT TO ENABLE
Only the providers you actually offer.
WHAT TO CONFIGURE
Email enumeration protection Password policy Authorised domains
WHAT TO KNOW ABOUT PHONE AUTHENTICATION
It costs money per verification, and is a common target for abuse.
WHAT ABUSE LOOKS LIKE
Automated requests generating verification messages, at your expense.
WHAT TO DO ABOUT IT
Enable the platform's abuse protection, and monitor volume.
WHY THAT MATTERS LOCALLY
Message costs vary by country, and some are targeted deliberately.
WHAT CUSTOM CLAIMS PROVIDE
Additional information in the token, such as a role.
WHAT TO USE THEM FOR
Authorisation decisions in security rules.
WHAT TO NEVER DO
Let a client set its own claims.
WHAT TO SET THEM FROM
Server-side code only.
WHAT TO HANDLE
Token expiry and refresh Sign-out, revoking server-side