VibeCoded

Firebase security rules checklist

Firebase lets the browser read and write your database directly. Security rules are the only thing standing between a user and every other user's data, so they have to be written for your app, not left at a default.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

A Firebase app is protected by its Firestore, Realtime Database and Storage security rules and by nothing else, because the client talks to them directly. Before launch, replace any test-mode rules, tie every read and write to request.auth.uid, validate the shape of writes, apply the same thinking to Storage, and test the rules in the emulator with more than one user.

Rules

0 of 0 done ·

Keys and project settings

0 of 0 done ·

Cloud Functions

0 of 0 done ·

Testing rules

Write rules tests with the Firebase emulator suite: one authenticated user, a second user and an unauthenticated request against each collection. A rule that lets the second user read the first user's document is the finding. For anything holding personal information or payments, have the app security tested as well. The same logic applies to Supabase; see the Supabase checklist.

Have your rules checked

Share the app and the collections it uses.

Get matched

Common questions

Is the Firebase web API key a secret?

No. It identifies the project. Restrict it to your domains, and rely on rules for data protection.

Do Cloud Functions ignore security rules?

Functions using the Admin SDK bypass rules entirely, so they must check permissions in their own code.