What Firebase is
Firebase is Google's platform for building mobile and web apps, part of Google since 2014. Two of its products matter here. Firebase Authentication signs users in with email and password, phone numbers or accounts such as Google, Apple and Microsoft. Firebase Cloud Messaging delivers notifications and data messages to Android, Apple devices and the web.
Both come with official SDKs for Flutter, the toolkit our mobile apps are built with. That is why Firebase is one of the identity providers of our authentication module and one of the push providers of our notifications module.
What it does in your platform
Authentication
Signs customers in with Firebase Authentication: email and password, phone numbers, or Google, Apple and Microsoft accounts. The module verifies Firebase's ID tokens on the server and adds its own trusted devices, sessions and the second factor on payments.
Notifications
Delivers push notifications to your customers' phones through Firebase Cloud Messaging: payment receipts, security alerts and declined cards, from templates your team edits in the backoffice. On iPhones, Firebase hands each message to Apple's push service.
How the connection works
The apps use Firebase's official Flutter plugins. On the server, the platform verifies sign-in tokens with Firebase's Admin SDK and sends messages through the FCM HTTP v1 API, authorised with short-lived OAuth 2.0 access tokens.
A customer signs in
Firebase Authentication signs them in inside the app, with the methods you enabled, and gives the app an ID token.
The platform checks it
The module verifies the token's signature, audience and expiry against Google's public keys, then opens its own session on that device.
The phone registers
The app's Firebase Cloud Messaging plugin gets a registration token for the device, and the platform stores it against the customer.
A payment goes through
The notifications module picks the template in the customer's language and sends the message through the FCM HTTP v1 API.
The phone lights up
FCM delivers it to Android phones, and to iPhones through Apple's push service. Delivery is tracked, and critical alerts fall back to a second channel.
Next to other providers
In the notifications module, Firebase Cloud Messaging sits next to Apple Push Notification service and OneSignal, with a second provider or channel standing by for critical messages such as one-time codes.
In the authentication module, Firebase Authentication can sign in your customers while staff use your company directory. Because the platform verifies tokens and keeps sessions itself, moving sign-in or push to another provider later does not change your apps.
When Firebase fits best
A strong fit when
- Your apps already use Firebase, or you want sign-in and push from one Google project.
- You want official Flutter SDKs for both.
- You want phone-number and social sign-in without running an identity server.
Also worth a look
- AWS Cognito or Auth0 for sign-in, when your stack runs on AWS or you want a dedicated customer identity platform.
- OneSignal, or Apple's push service directly, next to Firebase Cloud Messaging for push.
How we get you live
The Firebase project
We set up the Firebase project your apps will use in your Google account, or connect the one you already have.
Sign-in and push
We enable the sign-in methods you want, upload your Apple push key so Firebase can reach iPhones, and set up the message templates with your team.
The keys
The service account credentials go into your platform's secrets and nowhere else. The apps only carry Firebase's public configuration.
A full test run
We test sign-in and a push for every kind of message in a separate test project before your first real customer.
