Firebase config in an APK: what's public and what protects data

Updated

Decompile almost any Firebase app and you will find its API key, project ID and app ID in plain text, copied from google-services.json into the app's resources. People find this, panic, and ask whether they have leaked something.

Usually, no. Firebase's documentation says API keys for Firebase services "are not used to control access to backend resources", and that keys restricted to Firebase services "do not need to be treated as secrets". The real risk is somewhere else, and it is worth ten minutes to check.

Why is the key public in the first place?

Your app needs it to talk to Firebase, and anything your app has, anyone with the APK has. That is true of every client app. See how to check your APK for leaked keys for the keys where being public is a problem.

What actually protects your data?

In Firebase's words: "Security of your Realtime Database, Cloud Firestore, and Cloud Storage data is enforced using Firebase Security Rules, and protection of covered APIs is by Firebase App Check — not by keeping your Firebase API key secret."

  • Security Rules decide who may read or write each path or document. They are the lock.
  • App Check helps covered Firebase services accept requests only from your genuine app, which stops scripts that simply copied your config.

Are your Security Rules open?

The rules to look for are the ones that allow everything:

allow read, write: if true;

Firebase's warning next to that line is: "NEVER use this ruleset in production; it allows anyone to overwrite your entire database." Its explanation of why: without authentication and rules, "anyone who guesses your project ID can steal, modify, or delete the data." Your project ID is in your APK, so nobody has to guess.

Test-mode rules, which allow everything until a date, are the same thing with a timer. Replace them before launch.

What should the rules say instead?

Tie access to the signed-in user. Firebase's example of owner-only access for Firestore:

allow read, delete: if request.auth.uid == resource.data.author_uid;

And for data that everyone may read but only its author may write:

allow read: if true;
allow write: if request.auth.uid == request.resource.data.author_uid;

At minimum, nothing should be writable by a request with no request.auth. Check Cloud Storage rules as well as the database: uploads are where open rules cost money.

Is your key restricted to Firebase?

Firebase restricts the keys it creates for you to Firebase-related APIs. Two things undo that:

  • Adding other APIs to the same key. Firebase warns: "never include the Gemini Developer API in the allowlist for a publicly accessible API key or a key used for other services."
  • Reusing it for Google Cloud APIs. For any Google Cloud API that is not a Firebase service, Firebase "strongly recommends" separate, restricted keys.

If your app calls Gemini directly with a key, that key "should never be included in your code or configuration files." Put the call behind a server that holds the key.

A quick check before launch

  • Rules: no if true on writes, no test-mode expiry, auth checks on every path.
  • App Check: turned on for the Firebase services you use.
  • Keys: the key in the app is restricted to Firebase services and nothing else.

This is part of the Google Play pre-launch checklist. Google does not review your Firebase rules, so nobody else will check them for you.

Sources

Next steps

Still need testers? Get 12 testers for your closed test through a free test-for-test exchange - you test another developer's app, they test yours, and every opt-in is verified.

Applying for production soon? Check your APK against the Google Play launch checklist - target API, permissions that need a declaration, your Data Safety form and leaked keys. The first check is free.

Common questions

Is it safe that my Firebase API key is in my Android app?
Yes, if the key is restricted to Firebase services. Firebase says such keys are not used to control access to backend resources and do not need to be treated as secrets.
What actually protects my Firestore data?
Firebase Security Rules decide who can read and write each document, and App Check limits covered APIs to your genuine app. The API key protects nothing.
Can I use the same key for Gemini or other Google APIs?
No. Firebase says the Gemini Developer API key should never be in your code, and recommends separate, restricted keys for any Google Cloud API that is not a Firebase service.

Apps currently in closed testing

Real developers running the test described above. Test one, and get testers for your own app back.

Closed testing

FitLifeApp is a daily habit and goal-tracking app that helps users monitor water intake, step goals, and mood entries. Please test the following: - Set a daily water goal, add water intake, and check whether the totals and remaining amount update correctly. - Set a step goal and check the progress display. - Add mood entries and review previous records. - Close and reopen the app to check whether your saved data is still available. - Use the app on different days to check daily tracking and history. - Check for confusing navigation, overlapping text, or buttons that do not work correctly. Please join the Google Group and the Google Play closed test using the same Google account. Install the app through Google Play and stay enrolled for at least 14 consecutive days, using its features during the testing period. When reporting a problem, include what happened, the steps to reproduce it, your device model, and Android version. Screenshots are welcome. Thank you for helping improve FitLifeApp!

Health & FitnessProductivityLifestyle

Open to testers · 14-day test

Closed testing

Testers must join the Google Group using the same Google account they use on their Android device's Google Play Store. Testers must open the opt-in link, tap Become a tester, and then download the build via the Play Store link provided.

News & Books

Open to testers · 14-day test

Closed testing

Hi! I’m looking for testers for Crew Bites, a Flutter app that helps groups organize food orders, track who ordered what, and calculate the final bill fairly. Please test the main flow: add people, add food orders, select a restaurant/bundle, add tax/service/tip/delivery, review the total, and save or share the result. I’d especially appreciate feedback about usability, layout, performance, and any bugs on your Android device. Thank you!

Food & Drink

Open to testers · 14-day test

May we use analytics and ad measurement? Analytics (Vercel, and Ahrefs on our public pages) count page views without cookies. Ad measurement lets Google's tag on our public pages see which visits came from our Google ads, using a Google cookie. The site works the same either way. Cookie Policy · How Google uses data ·