Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

UID -> Custom Token

Signs a Firebase custom token for the selected user with your service-account key. Signing happens on your machine; nothing is sent over the network.

Needs: a service account and a selected user.

Generating a token

  1. Pick a user in the Users panel.
  2. Optionally, enter claims in Custom claims (optional JSON).
  3. Click Generate.

The token appears under Custom Token with a Copy button. Open Decoded JWT claims to see what was signed.

A custom token is valid for one hour. It is not an ID token: a client signs in with it, using signInWithCustomToken in a Firebase SDK, and receives an ID token back. To skip that step, use UID -> ID Token.

Adding claims to one token

Claims typed here go into the token’s claims field and are carried into the ID token that the custom token is exchanged for. They are not stored on the user, so the next token you generate starts without them.

The box must hold a JSON object, such as:

{"tier": "beta", "beta_features": ["new-checkout"]}

To give a user claims that appear in every token they receive, use User Custom Claims instead.

What the token contains

ClaimValue
iss, subThe service account’s email address
audhttps://identitytoolkit.googleapis.com/google.identity.identitytoolkit.v1.IdentityToolkit
uidThe selected user’s UID
iat, expIssue time, and expiry one hour later
claimsYour optional claims, if any