What is Firebase App Check? Protecting against unauthorized clients

Google・クラウドカテゴリを表すパンダのイラスト Google Cloud
Google Cloudや関連サービスをやさしく学ぶためのカテゴリ画像です。

About this article

This article was generated using an automated workflow powered by generative AI.

Firebase App Check is a protection feature that verifies whether requests coming to backend services like Firebase originate from registered, legitimate applications using attestation (a mechanism to verify the validity of the app and execution environment), thereby reducing abuse from unauthorized clients.

Information verification date: 2026-09-19

Conclusion first

While Authentication verifies "who the user is," App Check operates on a different layer to verify "whether the app sending the request is legitimate." Combining both does not eliminate the need for Security Rules or IAM.

LayerWhat is verifiedRepresentative example
AuthenticationThe user themselvesFirebase Authentication
App attestationLegitimate app / execution environmentFirebase App Check
AuthorizationWhat can be read and writtenSecurity Rules / IAM
Backend validationRequest payloadApplication-specific validation
flowchart LR
 User[利用者] --> App[正規アプリ]
 App --> Provider[Attestation Provider]
 Provider --> Token[App Check token]
 Token --> Backend[Firebase / Backend]
 Auth[User Authentication] --> Backend
 Rules[Rules / IAM] --> Backend

Positioning within Google's ecosystem

This is the security layer for Firebase. It can protect requests to supported services such as Cloud Firestore, Realtime Database, Cloud Storage, Authentication, and Cloud Functions, and the supported scope, including the Maps JavaScript API and Places API (New), can be verified in the official documentation. You can also verify App Check tokens in a custom backend.

Who is affected?

  • General users and administrative staff: Typically not something you need to be aware of, but it is relevant as a mechanism to reduce service abuse by unauthorized clients.

  • IT administrators: Review enforcement targets, metrics, providers, IAM, and rollback procedures in the event of an outage.

  • Developers: Implement SDKs, attestation providers, tokens, debug providers, and custom backend validation.

Key points for implementation

Enabling enforcement immediately may block legitimate users. The official documentation also recommends first distributing the SDK, checking the impact using App Check metrics, and then enabling enforcement. For Apple App Attest, the token TTL can be set from 30 minutes to 7 days; while a shorter TTL increases security, it involves trade-offs with attestation frequency, latency, and quotas or costs.

How does it compare to Microsoft / Azure?

It is not identical to user authentication in Microsoft Entra ID. App Check functions closer to an app attestation layer, determining whether a request comes from a legitimate application rather than identifying the user ID. When comparing features like Microsoft app attestation capabilities, it is best to treat user authentication and app attestation as distinct concepts.

Testing safely

Register the target app with App Check in a test project, use the debug/development provider according to the official instructions, and check the metrics. The success criterion is that requests from legitimate test apps can be observed as valid. Do not enable production enforcement from the beginning.

Do not store App Check debug tokens or credentials in public GitHub repositories. When verifying tokens in a custom backend, also check the signature, issuer, expiration, audience, and other parameters according to official guidelines.

Official Google documentation

What should you do next?

Determine the protected services and platforms, and register App Check in the staging environment. Verify through metrics that legitimate requests are passing through, understand the impact on users, and then consider enforcement in stages.

Deep dive into individual primary sources

Firebase App Check is an additional defense mechanism that verifies whether requests coming to Firebase or a custom backend originate from legitimate applications and devices. While authentication verifies the user, App Check confirms the legitimacy of the application; they are not mutually exclusive alternatives.

Official Google primary sources

Papanda TRY: Visualizing App Check as distinct from authentication

Create HTML learning material that separates user authentication and App Check into different lanes, displaying "who is using it" and "whether it came from a legitimate app" side by side. Do not use actual attestation tokens, and set the success condition as not confusing the two concepts.

What kind of service is this overall?

Firebase App Check is a security layer that confirms whether a request is likely to have originated from a registered, legitimate app, thereby reducing backend abuse. It is important to understand it not as a replacement for Authentication or Security Rules, but as an additional defense layer alongside them.

Document information

Article title
What is Firebase App Check? Protecting against unauthorized clients
Published
Updated
Source
https://papanda925.com/?p=17737&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL