GCP.FirebaseAppCheck reference
AppsDebugToken
Section titled “AppsDebugToken”Source:
src/GCP/FirebaseAppCheck/AppsDebugToken.ts
A Firebase App Check debug token. Debug tokens let development and integration testing bypass app attestation while App Check still protects production Firebase services.
Debug tokens have no labels field, so Alchemy stamps ownership into
displayName for list / nuke. app and token are identity —
changing either replaces the token. Display name updates in place.
GCP never returns token after create; Alchemy stores the secret in
state so ExchangeDebugToken can redeem it.
AppsDebugToken: Creating a Debug Token
Section titled “AppsDebugToken: Creating a Debug Token”Generated UUID
const debug = yield* GCP.FirebaseAppCheck.AppsDebugToken("Local", { app: "1:123:web:abc", displayName: "ios simulator",});Explicit UUID4
const debug = yield* GCP.FirebaseAppCheck.AppsDebugToken("Local", { app: "1:123:web:abc", displayName: "android emulator", token: "123e4567-e89b-12d3-a456-426614174000",});AppsDebugToken: Updating a Debug Token
Section titled “AppsDebugToken: Updating a Debug Token”const debug = yield* GCP.FirebaseAppCheck.AppsDebugToken("Local", { displayName: "ci runner",});AppsDebugToken: Exchanging a Debug Token
Section titled “AppsDebugToken: Exchanging a Debug Token”const exchange = yield* GCP.FirebaseAppCheck.ExchangeDebugToken(debug);const { token, ttl } = yield* exchange();ExchangeDebugToken
Section titled “ExchangeDebugToken”Source:
src/GCP/FirebaseAppCheck/ExchangeDebugToken.ts
Runtime binding for App Check apps.exchangeDebugToken.
Bind this operation to an AppsDebugToken in a Function/Action
init phase. Provide ExchangeDebugTokenHttp. The secret is read
from Alchemy state (token is never returned by get).
ExchangeDebugToken: Exchanging a Debug Token
Section titled “ExchangeDebugToken: Exchanging a Debug Token”Mint a session App Check token
const exchange = yield* GCP.FirebaseAppCheck.ExchangeDebugToken(debug);const { token, ttl } = yield* exchange();Limited-use token
const exchange = yield* GCP.FirebaseAppCheck.ExchangeDebugToken(debug);const { token } = yield* exchange({ limitedUse: true });ExchangeDebugTokenHttp
Section titled “ExchangeDebugTokenHttp”Source:
src/GCP/FirebaseAppCheck/ExchangeDebugTokenHttp.tsKind: Layer · Provides:GCP.FirebaseAppCheck.ExchangeDebugToken
HTTP implementation of ExchangeDebugToken.
ServicesResourcePolicy
Section titled “ServicesResourcePolicy”Source:
src/GCP/FirebaseAppCheck/ServicesResourcePolicy.ts
An App Check enforcement policy for a single resource of a Google
service that App Check supports. Currently only Google Identity for
iOS (oauth2.googleapis.com) accepts resource policies. The policy
overrides the service-level enforcement mode.
Resource policies have no labels field. When targetResource is
omitted, Alchemy points the policy at a dummy OAuth client whose id
starts with alc- so list / nuke can identify it. serviceId and
targetResource are identity — changing either replaces the policy.
Enforcement mode updates in place.
ServicesResourcePolicy: Creating a Resource Policy
Section titled “ServicesResourcePolicy: Creating a Resource Policy”Dummy target for tests
const policy = yield* GCP.FirebaseAppCheck.ServicesResourcePolicy( "IosOauth", { enforcementMode: "UNENFORCED" },);Real iOS OAuth client
const policy = yield* GCP.FirebaseAppCheck.ServicesResourcePolicy( "IosOauth", { targetResource: "//oauth2.googleapis.com/projects/123/oauthClients/abc.apps.googleusercontent.com", enforcementMode: "ENFORCED", },);ServicesResourcePolicy: Updating a Resource Policy
Section titled “ServicesResourcePolicy: Updating a Resource Policy”const policy = yield* GCP.FirebaseAppCheck.ServicesResourcePolicy( "IosOauth", { enforcementMode: "UNENFORCED", },);