Your backend verifies Firebase ID tokens. You want to call it from curl or
Postman as a specific user. Firebase gives you no button for that.
The usual answers each cover only some users: a sign-in REST call needs the
user's email and password, an OAuth user (Google, Apple, GitHub) can't sign in
from curl at all, and the Auth emulator isn't your real project. I wanted one
way that works for every user, however they sign in, so I built a desktop app
for it.
One flow for every user
Firebase lets a service account sign in as any user by UID, whatever provider
that user normally uses:
- Sign a custom token for the user's UID with a service-account key
(
createCustomTokenin the Admin SDK). - Exchange it at
accounts:signInWithCustomTokenwith your project's API key. Google returns a real ID token, refresh token and expiry.
The token carries the user's real UID, email, display name and custom claims,
so it passes verifyIdToken on your server like a token from a normal sign-in.
It works for any user, whether they normally sign in with email/password,
Google, Apple, phone or anonymously. You never go through their sign-in: no
password, no provider login page, no SMS code.
Firebase Token Toolkit
Firebase Token Toolkit
does those steps in one click:
- Browse for your service-account JSON.
- Click Load apps to import your project's web, Android and iOS apps and their API keys.
- Pick any user from the list, whatever their sign-in method, and click Generate.
You get the ID token, a copy button, and the decoded claims underneath. Then:
curl -H "Authorization: Bearer <ID token>" https://localhost:8080/api/me
It also covers the jobs next door:
- Custom claims: load a user's claims as JSON, edit, save, with the 1,000-byte limit checked as you type.
-
App Check: exchange a registered debug token for an App Check token for
the
X-Firebase-AppCheckheader. -
Restricted keys: if your API key is restricted to an Android or iOS app,
Google rejects requests that don't name the app. The toolkit sends
X-Android-Package+X-Android-Cert, orX-Ios-Bundle-Identifier, like the mobile SDKs do.
Things to know
- Use a development project: a service-account key can sign in as any user.
- It talks to real Firebase projects, not the Auth emulator.
- The token's
firebase.sign_in_provideriscustom, not the user's usual provider. If your backend checks the provider (say, requiresgoogle.com), that check will reject these tokens. - New custom claims show up in new tokens; existing ones keep the old claims until they refresh (about an hour).
It's a native Rust app for Linux, Windows and macOS, MIT licensed, with no
telemetry. The user guide
has screenshots of every tab and a
FAQ.
If it saves you a script, a β on
GitHub helps.


Top comments (0)