DEV Community

Smaranjit Maiti
Smaranjit Maiti

Posted on

How to get a Firebase ID token for testing your API (without writing a script)

Your backend verifies Firebase ID tokens. You want to call it from curl or
Postman as a specific user. Firebase gives you no button for that.

The usual answers each cover only some users: a sign-in REST call needs the
user's email and password, an OAuth user (Google, Apple, GitHub) can't sign in
from curl at all, and the Auth emulator isn't your real project. I wanted one
way that works for every user, however they sign in, so I built a desktop app
for it.

One flow for every user

Firebase lets a service account sign in as any user by UID, whatever provider
that user normally uses:

  1. Sign a custom token for the user's UID with a service-account key (createCustomToken in the Admin SDK).
  2. Exchange it at accounts:signInWithCustomToken with your project's API key. Google returns a real ID token, refresh token and expiry.

The token carries the user's real UID, email, display name and custom claims,
so it passes verifyIdToken on your server like a token from a normal sign-in.
It works for any user, whether they normally sign in with email/password,
Google, Apple, phone or anonymously. You never go through their sign-in: no
password, no provider login page, no SMS code.

Firebase Token Toolkit

Loading apps, picking a user and generating an ID token

Firebase Token Toolkit
does those steps in one click:

  1. Browse for your service-account JSON.
  2. Click Load apps to import your project's web, Android and iOS apps and their API keys.
  3. Pick any user from the list, whatever their sign-in method, and click Generate.

You get the ID token, a copy button, and the decoded claims underneath. Then:

curl -H "Authorization: Bearer <ID token>" https://localhost:8080/api/me
Enter fullscreen mode Exit fullscreen mode

It also covers the jobs next door:

  • Custom claims: load a user's claims as JSON, edit, save, with the 1,000-byte limit checked as you type.
  • App Check: exchange a registered debug token for an App Check token for the X-Firebase-AppCheck header.
  • Restricted keys: if your API key is restricted to an Android or iOS app, Google rejects requests that don't name the app. The toolkit sends X-Android-Package + X-Android-Cert, or X-Ios-Bundle-Identifier, like the mobile SDKs do.

Things to know

  • Use a development project: a service-account key can sign in as any user.
  • It talks to real Firebase projects, not the Auth emulator.
  • The token's firebase.sign_in_provider is custom, not the user's usual provider. If your backend checks the provider (say, requires google.com), that check will reject these tokens.
  • New custom claims show up in new tokens; existing ones keep the old claims until they refresh (about an hour).

It's a native Rust app for Linux, Windows and macOS, MIT licensed, with no
telemetry. The user guide
has screenshots of every tab and a
FAQ.

If it saves you a script, a ⭐ on
GitHub helps.

Top comments (0)