Agent skill

Firebase Auth

by evanca in evanca/flutter-ai-rules

A skill your agent uses when setting up auth, managing auth state, implementing email/password or social sign-in, handling auth errors, or managing users.

MITAuto-check passedBackend & APIs

Install Firebase Auth

skills CLI
$ npx skills add evanca/flutter-ai-rules --skill firebase-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install evanca/flutter-ai-rules firebase-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/evanca/flutter-ai-rules.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/firebase-auth .claude/skills/firebase-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
firebase-auth
GitHub stars
647
Token cost
~3.1k tokens
SKILL.md length
1,074 words
Files
1
Skills in repo
37
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when setting up auth, managing auth state, implementing email/password or social sign-in, handling auth errors, or managing users.

  • Works in 10 steps: Setup and Configuration → Authentication State Management → Email and Password Authentication → …
  • Setting up auth
  • SKILL.md covers When to Use, 1. Setup and Configuration, 2. Authentication State… and 3. Email and Password…, plus 8 more sections
  • Calls flutter; reaches googleapis.com

What it does

Firebase Auth is an agent skill from evanca/flutter-ai-rules. Use when setting up auth, managing auth state, implementing email/password or social sign-in, handling auth errors, or managing users.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Firebase. The repository describes itself as: Flutter AI Skills and Rules for Claude, Codex, Cursor, and Other AI-Powered IDEs. The licence is MIT.

When your agent uses it

  • Setting up auth
  • Managing auth state
  • Implementing email/password
  • Handling auth errors

Example prompts

  • “/firebase-auth”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Setup and Configuration
  2. Authentication State Management
  3. Email and Password Authentication
  4. Social Authentication
  5. Phone Number Authentication
  6. Error Handling
  7. User Management
  8. Security Best Practices
  9. Multi-Factor Authentication
  10. Email Link Authentication

What it can do on your machine

Read from SKILL.md and the folder at commit 7b9cce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • flutter

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com

    Also links to:

    • firebase.google.com
    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Firebase Auth loads about 3.1k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 1,074 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from evanca/flutter-ai-rules at commit 7b9cce2, republished under its MIT licence (© evanca). 1,074 words, ~3,084 tokens.

Download SKILL.mdSave it as .claude/skills/firebase-auth/SKILL.md (or your agent's skills folder).
name
firebase-auth
description
Use when setting up auth, managing auth state, implementing email/password or social sign-in, handling auth errors, or managing users.
license
MIT

Firebase Authentication Skill

This skill defines how to correctly use Firebase Authentication in Flutter applications.

When to Use

Use this skill when:

  • Setting up Firebase Authentication in a Flutter project.
  • Listening to authentication state changes.
  • Implementing email/password, phone number, or social sign-in.
  • Managing user profiles, account linking, or MFA.
  • Handling authentication errors (including iOS recaptcha-sdk-not-linked for phone auth).
  • Applying security best practices for auth flows.

1. Setup and Configuration

flutter pub add firebase_auth
dart
import 'package:firebase_auth/firebase_auth.dart';
  • Enable desired authentication providers in the Firebase console before using them.
  • Initialize Firebase before using any Firebase Authentication features.

Local emulator for testing:

dart
Future<void> main() async {
  WidgetsFlutterBinding.ensureInitialized();
  await Firebase.initializeApp();
  await FirebaseAuth.instance.useAuthEmulator('localhost', 9099);
  // ...
}

2. Authentication State Management

Use the appropriate stream based on what you need to observe:

StreamFires when
authStateChanges()User signs in or out
idTokenChanges()ID token changes (including custom claims)
userChanges()User data changes (e.g., profile updates)
dart
FirebaseAuth.instance
  .authStateChanges()
  .listen((User? user) {
    if (user == null) {
      print('User is currently signed out!');
    } else {
      print('User is signed in!');
    }
  });
  • Listen to these streams immediately when the app starts to handle the initial auth state.
  • Custom claims are only available after sign-in, re-authentication, token expiration, or manual token refresh.

3. Email and Password Authentication

Create a new account:

dart
try {
  final credential = await FirebaseAuth.instance.createUserWithEmailAndPassword(
    email: emailAddress,
    password: password,
  );
} on FirebaseAuthException catch (e) {
  if (e.code == 'weak-password') {
    print('The password provided is too weak.');
  } else if (e.code == 'email-already-in-use') {
    print('The account already exists for that email.');
  }
} catch (e) {
  print(e);
}

Sign in:

dart
try {
  final credential = await FirebaseAuth.instance.signInWithEmailAndPassword(
    email: emailAddress,
    password: password,
  );
} on FirebaseAuthException catch (e) {
  if (e.code == 'invalid-credential') {
    // Email enumeration protection enabled (default since Sep 2023):
    // replaces 'user-not-found' and 'wrong-password'.
    print('Invalid email or password.');
  } else if (e.code == 'user-not-found') {
    print('No user found for that email.');
  } else if (e.code == 'wrong-password') {
    print('Wrong password provided for that user.');
  }
}
  • Verify the user's email address after account creation.
  • Firebase rate-limits new email/password sign-ups from the same IP to protect against abuse.
  • On iOS/macOS, authentication state persists between app re-installs via the system keychain.
  • Since September 2023, Firebase enables email enumeration protection by default on new projects, replacing user-not-found and wrong-password with invalid-credential. Manage this in the Firebase console under Authentication > Settings.
  • When email enumeration protection is enabled, sendPasswordResetEmail() may complete without an error even if the email is not registered. Treat this as expected behavior and do not use password-reset responses to infer whether an email exists.

Share authentication state between Apple apps:

On Apple platforms, share auth state between apps in the same developer account by storing it in a shared Keychain access group. Enable the Keychain Sharing capability for each app with the same access group, then configure Firebase Auth with the fully qualified access group:

dart
await FirebaseAuth.instance.setSettings(
  userAccessGroup: 'TEAMID.com.example.group1',
);

Switching from the default Keychain to a shared access group signs out the existing user unless migrated. Pass migrateCurrentUser: true (requires a non-null userAccessGroup) to preserve the current session, including an anonymous one — safe to call at app startup before any other Auth call, since it reads the existing session straight from the Keychain before Auth restores it. Migration can overwrite a user already stored in the destination access group.


4. Social Authentication

Google Sign-In (native platforms):

dart
Future<UserCredential> signInWithGoogle() async {
  final GoogleSignInAccount? googleUser = await GoogleSignIn.instance.authenticate();
  final GoogleSignInAuthentication googleAuth = googleUser.authentication;
  final credential = GoogleAuthProvider.credential(idToken: googleAuth.idToken);
  return await FirebaseAuth.instance.signInWithCredential(credential);
}

Google Sign-In (web):

dart
Future<UserCredential> signInWithGoogle() async {
  GoogleAuthProvider googleProvider = GoogleAuthProvider();
  googleProvider.addScope('https://www.googleapis.com/auth/contacts.readonly');
  googleProvider.setCustomParameters({'login_hint': 'user@example.com'});
  return await FirebaseAuth.instance.signInWithPopup(googleProvider);
}
  • Configure platform-specific settings for each provider (e.g., SHA1 key for Google Sign-In on Android).
  • If a user signs in with a social provider after registering with the same email manually, Firebase's trusted provider concept will automatically change their authentication provider.
  • On Android, signInWithProvider opens a Chrome Custom Tab. If AndroidManifest.xml contains android:taskAffinity="" (Flutter's default), the tab closes when the user switches apps (e.g., to use a password manager), causing a web-context-already-presented error. Remove android:taskAffinity="" to fix this.
  • When signing in with Apple, add the email and name scopes to present the full first-time sign-in UI (including "Share/Hide email"):
    dart
    final appleProvider = AppleAuthProvider();
    appleProvider.addScope('email');
    appleProvider.addScope('name');
  • To revoke Apple auth tokens after sign-in, use the appropriate API per platform:
    • Apple platforms (iOS/macOS/web): use revokeTokenWithAuthorizationCode() with the authorization code from userCredential.additionalUserInfo?.authorizationCode.
    • Android: use revokeAccessToken() with the access token from userCredential.credential?.accessToken.
    dart
    // Apple platforms (iOS/macOS/web)
    final authCode = userCredential.additionalUserInfo?.authorizationCode;
    if (authCode != null) {
      await FirebaseAuth.instance.revokeTokenWithAuthorizationCode(authCode);
    }
    
    // Android
    final accessToken = userCredential.credential?.accessToken;
    if (accessToken != null) {
      await FirebaseAuth.instance.revokeAccessToken(accessToken);
    }

5. Phone Number Authentication

Before using phone authentication, ensure platform-specific prerequisites are met:

  • Android: SHA-1 hashes must be configured in the Firebase console and Google Play Integrity API enabled.
  • iOS: APNs authentication key must be configured with FCM and background modes for remote notifications enabled.
  • Web: Add your application's domain to the Firebase console under OAuth redirect domains.

Phone number sign-in is only supported on real devices and the web. Testing on device emulators is not supported.

iOS: recaptcha-sdk-not-linked error

On iOS, verifyPhoneNumber can throw FirebaseAuthException with code recaptcha-sdk-not-linked when Identity Platform expects reCAPTCHA Enterprise but the native SDK is not linked. This cannot be resolved from Dart — fix it at the native iOS or GCP level:

  • Recommended: Link the reCAPTCHA Enterprise iOS SDK in Xcode following Google's guide.
  • Alternative: Disable reCAPTCHA SMS defense via the Identity Toolkit projects.updateConfig REST API (set recaptchaConfig.phoneEnforcementState to OFF and recaptchaConfig.useSmsTollFraudProtection to false). See the official steps. This reduces fraud protection — prefer linking the SDK.
  • If the SDK uses a Safari view controller-hosted challenge, handle the return URL using uni_links/app_links or application:openURL: in the iOS runner.

Show full SKILL.md (363 more words)Show less

6. Error Handling

  • Always use try-catch with FirebaseAuthException.
  • Check e.code to identify specific error types.
  • Handle account-exists-with-different-credential by fetching sign-in methods for the email and guiding users through the correct flow.
  • Handle too-many-requests with retry logic or user feedback.
  • Handle operation-not-allowed by ensuring the provider is enabled in the Firebase console.
  • On iOS, recaptcha-sdk-not-linked during verifyPhoneNumber is raised by the native Firebase iOS Auth SDK and requires native setup or GCP configuration changes — it cannot be fixed from Dart code alone.

7. User Management

dart
// Update profile
await FirebaseAuth.instance.currentUser?.updateProfile(
  displayName: "Jane Q. User",
  photoURL: "https://example.com/jane-q-user/profile.jpg",
);

// Update email (sends verification to new address first)
await user?.verifyBeforeUpdateEmail("newemail@example.com");
  • Use verifyBeforeUpdateEmail() — not updateEmail() — to change a user's email. The email only updates after the user verifies it.
  • Store only essential info in the auth profile; use a database for additional user data.
  • Use linkWithCredential() to connect multiple auth providers to a single account.
  • Verify the user's identity before linking new credentials.
  • Use fetchSignInMethodsForEmail() when handling account linking.

8. Security Best Practices

  • Never store sensitive authentication credentials in client-side code.
  • Monitor auth state changes for proper session management.
  • Validate user input before submitting authentication requests to prevent injection attacks.
  • Call FirebaseAuth.instance.signOut() when users exit the app.
  • For sensitive operations, re-authenticate users with reauthenticateWithCredential().
  • Enforce strong password policies for email/password auth.
  • In Realtime Database and Cloud Storage Security Rules, use the auth variable to get the signed-in user's UID for access control.
  • Use multi-factor authentication for sensitive applications.

9. Multi-Factor Authentication

Security warning: Avoid SMS-based MFA. SMS is insecure and easy to compromise or spoof.

Platform limitation: Windows does not support MFA. MFA with multiple tenants is not supported on Flutter.

  • Enable at least one MFA-compatible provider before implementing MFA.

Important: Firebase Dynamic Links is deprecated for email link authentication. Firebase Hosting is now used to send sign-in links.

  • Set handleCodeInApp: true in ActionCodeSettings — sign-in must always be completed in the app.
  • Store the user's email locally (e.g., SharedPreferences) when sending the sign-in link.
  • Never pass the user's email in redirect URL parameters — this enables session injection attacks.
  • Use HTTPS URLs in production to prevent link interception.
  • Configure the app to detect incoming links and parse the underlying deep link for sign-in completion.

References

© evanca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/firebase-auth of evanca/flutter-ai-rules.

Open the folder on GitHubat commit 7b9cce2

Compare with similar skills

Firebase Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Firebase Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Firebase Auth this skillevanca/flutter-ai-rules647—~3.1kAutomated safety check: PassMIT
Web3authWeb3Auth/web3auth-examples144—~1.4kAutomated safety check: PassMIT
Telnyx Webrtc Client Androidteam-telnyx/ai220—~6.7kAutomated safety check: PassMIT
Workosusenotra/notra255—~6.2kAutomated safety check: PassAGPL-3.0
JS Secrets Extractionuphiago/recon-skills1.3k—~2.6kAutomated safety check: PassMIT
Firebase Auth Basicsaiskillstore/marketplace430—~781Automated safety check: PassNone

Similar skills

  • Web3auth

    Web3Auth/web3auth-examples

    Integrates MetaMask Embedded Wallets (Web3Auth) for non-custodial wallets via social login or custom JWT (Firebase, Auth0, Cognito).

    144 GitHub stars~1.4k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Build VoIP calling apps on Android using Telnyx WebRTC SDK. An agent skill from team-telnyx/ai.

    220 GitHub stars~6.7k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    255 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Firebase Auth Basics

    aiskillstore/marketplace

    Guide for setting up and using Firebase Authentication. An agent skill from aiskillstore/marketplace.

    430 GitHub stars~781 tokensUpdated today
    Backend & APIsAuto-check passed
  • Ktor server patterns including routing DSL, plugins, authentication, Koin DI, kotlinx.serialization, WebSockets, and testApplication testing.

    274k GitHub starsUsed in 4 repos~4.8k tokens
    Backend & APIsAuto-check passed

More from evanca/flutter-ai-rules

All 37 skills in this repo
  • Code Review

    evanca/flutter-ai-rules

    A skill your agent uses when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.

    647 GitHub stars~2.4k tokensUpdated 23 days ago
    Auto-check passed
  • Developing Genkit Dart

    evanca/flutter-ai-rules

    A skill your agent uses when building AI agents in Dart, implementing Genkit flows or tools, integrating LLMs into Dart or Flutter applications, or using Genkit Dart plugins.

    647 GitHub stars~961 tokensUpdated 23 days ago
    Auto-check passed
  • Generate Images With Firebase AI

    evanca/flutter-ai-rules

    A skill your agent uses when generating or editing images from Flutter/Dart with Firebase AI Logic and a Gemini image model (Nano Banana), making the first call work, choosing Gemini Developer API…

    647 GitHub stars~2.3k tokensUpdated 23 days ago
    Auto-check passed
  • Flutter Use Column Row First

    evanca/flutter-ai-rules

    A skill your agent uses when building any Flutter screen or component to choose responsive Row, Column, Expanded, Flexible, and Spacer layouts before fixed-size or coordinate-based alternatives.

    647 GitHub stars~1.3k tokensUpdated 23 days ago
    Auto-check passed
  • Architecture Feature First

    evanca/flutter-ai-rules

    A skill your agent uses when creating a feature, designing folder structure, adding repositories/services/view models, wiring dependency injection, or deciding which layer owns logic.

    647 GitHub stars~1.9k tokensUpdated 23 days ago
    Auto-check passed
  • Bloc

    evanca/flutter-ai-rules

    A skill your agent uses when creating a Cubit or Bloc, modeling state with sealed classes or status enums, wiring BlocBuilder/BlocListener/BlocProvider, writing bloc tests, or choosing between Cubit…

    647 GitHub stars~2.8k tokensUpdated 23 days ago
    Auto-check passed

Works with

Questions about Firebase Auth

What does Firebase Auth do?

A skill your agent uses when setting up auth, managing auth state, implementing email/password or social sign-in, handling auth errors, or managing users. Firebase Auth is an agent skill from evanca/flutter-ai-rules. Use when setting up auth, managing auth state, implementing email/password or social sign-in, handling auth errors, or managing users.

When should I use Firebase Auth?

Firebase Auth fits situations like: setting up auth; managing auth state; implementing email/password; handling auth errors.

How do I install Firebase Auth in Claude Code?

Run `npx skills add evanca/flutter-ai-rules --skill firebase-auth -a claude-code`. Or copy the skill folder (skills/firebase-auth in evanca/flutter-ai-rules) into .claude/skills/firebase-auth in your project. Claude Code loads it when a task matches its description.

How do I install Firebase Auth in Codex?

Run `npx skills add evanca/flutter-ai-rules --skill firebase-auth -a codex`. Or copy the skill folder (skills/firebase-auth in evanca/flutter-ai-rules) into .agents/skills/firebase-auth in your project. Codex loads it when a task matches its description.

Can I use Firebase Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add evanca/flutter-ai-rules --skill firebase-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/firebase-auth, .gemini/skills/firebase-auth, .github/skills/firebase-auth and .opencode/skills/firebase-auth in your project.

What does Firebase Auth need to run?

Going by SKILL.md and its folder, Firebase Auth needs the command-line tools its instructions call (flutter).

Does Firebase Auth access the network?

SKILL.md names 3 domains. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. As links in the text: firebase.google.com and cloud.google.com. This is read from the text; nothing was executed.

Is Firebase Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Firebase Auth use?

Firebase Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Firebase Auth use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Firebase Auth?

Skills that share tags, products or a category with Firebase Auth: Web3auth (Web3Auth/web3auth-examples, 144 stars), Telnyx Webrtc Client Android (team-telnyx/ai, 220 stars), Workos (usenotra/notra, 255 stars) and JS Secrets Extraction (uphiago/recon-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Firebase Auth?

evanca (a GitHub user) maintains it in evanca/flutter-ai-rules, which has 647 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on September 14, 2026.

Source: evanca/flutter-ai-rules on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.