Messages appear in one of three places: the status bar under the tabs, the
Users panel, or in red as Error: … under a tab’s button. Error text from
Google is passed through unchanged, so search the message itself if it is not
listed here.
If no graphics backend works, the app shows a dialog that begins
“Firebase Token Toolkit could not start.” The app tries OpenGL first and then
wgpu, which can fall back to a software renderer, so this almost always means a
virtual machine or remote desktop session with no usable graphics at all.
Enabling 3D acceleration for the VM usually fixes it.
On Linux, launching from a terminal shows the detail. A line like
OpenGL backend unavailable (…); retrying with wgpu is informational; the app
carries on with wgpu.
Load a service account and set Project ID to browse users.
Load a key and make sure Project ID is filled in.
No user found for that query
Lookup needs the whole value: a complete email (case does not matter), a phone number in full + country-code form, or an exact UID. To match part of a value, type into the search box without pressing Enter; that filters the users already loaded.
API error (403): …
The service account lacks permission to read users, or the Identity Toolkit API is disabled for the project.
GET accounts:batchGet
The request never reached Google. Check your connection.
The pasted text is not a whole token. It usually lost characters while being copied.
API error (400): INVALID_CUSTOM_TOKEN … with other text
The token has expired (custom tokens last one hour) or is malformed. Generate a new one.
API error (400): CREDENTIAL_MISMATCH
The custom token was signed with a key from a different project than the API key belongs to. Check that the profile’s key and API key are from the same project.
API error (400): API key not valid. Please pass a valid API key.
The API key is wrong or deleted. Copy it again from Project settings → General.
API error (403): Requests from this Android client application <empty> are blocked. (or the iOS equivalent)
The key is restricted to an Android or iOS app, but the selected app is a different type, or its Package or Bundle ID is empty. Select the matching app, or fill in its identifiers.
API error (403): Requests from this Android client application dev.example.app are blocked.
The package or SHA-1 does not match the key’s restriction. Check both against the key in Google Cloud Console → Credentials. A SHA-1 marked invalid in the top bar is not sent.
API error (403): Requests from this iOS client application <bundle> are blocked.
The bundle ID does not match the key’s restriction.
API error (403): … are blocked. (other)
The API key has restrictions that exclude the Identity Toolkit API or the App Check API. Loosen them in Google Cloud Console.
Invalid claims JSON: … / custom claims must be a JSON object
The optional claims box must hold a JSON object, such as {"role":"admin"}, or be empty.
The debug token is not registered for this App ID. Check it under App Check → Manage debug tokens, and that it was registered for the same app as the App ID in the top bar.
API error (403): … with other text
The App Check API is not enabled for the project, or the API key’s restrictions exclude it.
API error (404): …
The App ID does not exist in the project named in Project ID.
The service account may not read Firebase apps, or the Firebase Management API is disabled. Grant Firebase Viewer (roles/firebase.viewer), or add the app by hand with + Add app.
No apps found in this Firebase project.
The project has no registered apps. Add one under Project settings → General → Your apps.
Loaded apps: … Some details are missing — …
The list loaded, but one app’s config or certificates could not be read. That app is listed without its key; fill it in by hand.
Browse… does nothing. The file chooser goes through an XDG desktop
portal. Install xdg-desktop-portal-gtk (or your desktop’s portal) and log in
again.
Copy shows copy failed: …. The clipboard needs X11 or XWayland. Under a
pure Wayland session without XWayland, select the token text and copy it with
Ctrl+C instead.
The Changelog and Security notes links in the About dialog point at
the git tag matching the app’s version. A build from an untagged commit has no
such tag, so the links 404. Release builds are not affected.