Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Google endpoints

Every network request the app makes goes to a Google endpoint over TLS, and only when you click a button that needs it. There is no telemetry, analytics or update check. Opening a link from the About dialog hands that URL to your browser; nothing else leaves the app.

Action in the appRequestAuthenticated with
Generate on UID -> Custom TokenNone. The token is signed locally.—
Generate on UID -> ID Token, Exchange on Custom -> ID TokenPOST identitytoolkit.googleapis.com/v1/accounts:signInWithCustomTokenSelected app’s API key
Load users / RefreshGET identitytoolkit.googleapis.com/v1/projects/{project}/accounts:batchGet (1,000 per page, up to 5,000)OAuth access token
Lookup, Load currentPOST identitytoolkit.googleapis.com/v1/projects/{project}/accounts:lookupOAuth access token
Save, Clear all claimsPOST identitytoolkit.googleapis.com/v1/projects/{project}/accounts:update, then a lookup to read the result backOAuth access token
Exchange on App CheckPOST firebaseappcheck.googleapis.com/v1beta/projects/{project}/apps/{app}:exchangeDebugTokenSelected app’s API key
Load appsGET firebase.googleapis.com/v1beta1/projects/{project}:searchApps, then for each app GET …/webApps/{app}/config, …/androidApps/{app}/config and …/androidApps/{app}/sha, or …/iosApps/{app}/configOAuth access token

API keys and app identity

Requests authenticated with an API key send it as the key query parameter. For an Android or iOS app, the request also names the app, so that keys restricted to that app are accepted:

App typeHeaders
Webnone
AndroidX-Android-Package: <package>, X-Android-Cert: <SHA-1, 40 uppercase hex digits>
iOSX-Ios-Bundle-Identifier: <bundle ID>

A header is left out when its value is empty, and a SHA-1 that is not 40 hex digits is not sent.

OAuth access tokens

Calls marked OAuth access token first exchange a JWT, signed with the service-account key, at oauth2.googleapis.com/token. The token is requested with two scopes:

  • https://www.googleapis.com/auth/identitytoolkit
  • https://www.googleapis.com/auth/cloud-platform

It is cached in memory and refreshed when it is within about a minute of expiring. Switching profiles discards it.

cloud-platform is a broad scope. What the token can actually do is limited by the IAM roles granted to the service account, which is one more reason to use a development project’s key. See Security.