<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Smaranjit Maiti</title>
    <description>The latest articles on DEV Community by Smaranjit Maiti (@smaranjit_maiti).</description>
    <link>https://dev.to/smaranjit_maiti</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4171702%2Fe2fa28d9-b877-4637-966d-b00b9f9b3051.png</url>
      <title>DEV Community: Smaranjit Maiti</title>
      <link>https://dev.to/smaranjit_maiti</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/smaranjit_maiti"/>
    <language>en</language>
    <item>
      <title>How to get a Firebase ID token for testing your API (without writing a script)</title>
      <dc:creator>Smaranjit Maiti</dc:creator>
      <pubDate>Thu, 08 Oct 2026 15:59:28 +0000</pubDate>
      <link>https://dev.to/smaranjit_maiti/how-to-get-a-firebase-id-token-for-testing-your-api-without-writing-a-script-1f8o</link>
      <guid>https://dev.to/smaranjit_maiti/how-to-get-a-firebase-id-token-for-testing-your-api-without-writing-a-script-1f8o</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faqc2qzhrpohplbihs1fn.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faqc2qzhrpohplbihs1fn.png" alt=" " width="800" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Your backend verifies Firebase ID tokens. You want to call it from curl or&lt;br&gt;
Postman as a specific user. Firebase gives you no button for that.&lt;/p&gt;

&lt;p&gt;The usual answers each cover only some users: a sign-in REST call needs the&lt;br&gt;
user's email and password, an OAuth user (Google, Apple, GitHub) can't sign in&lt;br&gt;
from curl at all, and the Auth emulator isn't your real project. I wanted one&lt;br&gt;
way that works for every user, however they sign in, so I built a desktop app&lt;br&gt;
for it.&lt;/p&gt;
&lt;h2&gt;
  
  
  One flow for every user
&lt;/h2&gt;

&lt;p&gt;Firebase lets a service account sign in as any user by UID, whatever provider&lt;br&gt;
that user normally uses:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Sign a &lt;strong&gt;custom token&lt;/strong&gt; for the user's UID with a service-account key
(&lt;code&gt;createCustomToken&lt;/code&gt; in the Admin SDK).&lt;/li&gt;
&lt;li&gt;Exchange it at &lt;code&gt;accounts:signInWithCustomToken&lt;/code&gt; with your project's API key.
Google returns a real ID token, refresh token and expiry.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The token carries the user's real UID, email, display name and custom claims,&lt;br&gt;
so it passes &lt;code&gt;verifyIdToken&lt;/code&gt; on your server like a token from a normal sign-in.&lt;br&gt;
It works for any user, whether they normally sign in with email/password,&lt;br&gt;
Google, Apple, phone or anonymously. You never go through their sign-in: no&lt;br&gt;
password, no provider login page, no SMS code.&lt;/p&gt;
&lt;h2&gt;
  
  
  Firebase Token Toolkit
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fi3vs6jqerzzkzsm9jql2.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fi3vs6jqerzzkzsm9jql2.gif" alt="Loading apps, picking a user and generating an ID token" width="760" height="475"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/smaranjit/firebase-token-toolkit" rel="noopener noreferrer"&gt;Firebase Token Toolkit&lt;/a&gt;&lt;br&gt;
does those steps in one click:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Browse for your service-account JSON.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Load apps&lt;/strong&gt; to import your project's web, Android and iOS apps and
their API keys.&lt;/li&gt;
&lt;li&gt;Pick any user from the list, whatever their sign-in method, and click
&lt;strong&gt;Generate&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;You get the ID token, a copy button, and the decoded claims underneath. Then:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Authorization: Bearer &amp;lt;ID token&amp;gt;"&lt;/span&gt; https://localhost:8080/api/me
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It also covers the jobs next door:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Custom claims:&lt;/strong&gt; load a user's claims as JSON, edit, save, with the
1,000-byte limit checked as you type.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;App Check:&lt;/strong&gt; exchange a registered debug token for an App Check token for
the &lt;code&gt;X-Firebase-AppCheck&lt;/code&gt; header.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Restricted keys:&lt;/strong&gt; if your API key is restricted to an Android or iOS app,
Google rejects requests that don't name the app. The toolkit sends
&lt;code&gt;X-Android-Package&lt;/code&gt; + &lt;code&gt;X-Android-Cert&lt;/code&gt;, or &lt;code&gt;X-Ios-Bundle-Identifier&lt;/code&gt;, like
the mobile SDKs do.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Things to know
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Use a &lt;strong&gt;development project&lt;/strong&gt;: a service-account key can sign in as any user.&lt;/li&gt;
&lt;li&gt;It talks to real Firebase projects, not the Auth emulator.&lt;/li&gt;
&lt;li&gt;The token's &lt;code&gt;firebase.sign_in_provider&lt;/code&gt; is &lt;code&gt;custom&lt;/code&gt;, not the user's usual
provider. If your backend checks the provider (say, requires &lt;code&gt;google.com&lt;/code&gt;),
that check will reject these tokens.&lt;/li&gt;
&lt;li&gt;New custom claims show up in &lt;strong&gt;new&lt;/strong&gt; tokens; existing ones keep the old
claims until they refresh (about an hour).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It's a native Rust app for Linux, Windows and macOS, MIT licensed, with no&lt;br&gt;
telemetry. The &lt;a href="https://smaranjit.github.io/firebase-token-toolkit/" rel="noopener noreferrer"&gt;user guide&lt;/a&gt;&lt;br&gt;
has screenshots of every tab and a&lt;br&gt;
&lt;a href="https://smaranjit.github.io/firebase-token-toolkit/faq.html" rel="noopener noreferrer"&gt;FAQ&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;If it saves you a script, a ⭐ on&lt;br&gt;
&lt;a href="https://github.com/smaranjit/firebase-token-toolkit" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt; helps.&lt;/p&gt;

</description>
      <category>firebase</category>
      <category>testing</category>
      <category>rust</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
