Skip to content

GCP.FirebaseAppCheck reference

Source: src/GCP/FirebaseAppCheck/AppsDebugToken.ts

A Firebase App Check debug token. Debug tokens let development and integration testing bypass app attestation while App Check still protects production Firebase services.

Debug tokens have no labels field, so Alchemy stamps ownership into displayName for list / nuke. app and token are identity — changing either replaces the token. Display name updates in place. GCP never returns token after create; Alchemy stores the secret in state so ExchangeDebugToken can redeem it.

Generated UUID

const debug = yield* GCP.FirebaseAppCheck.AppsDebugToken("Local", {
app: "1:123:web:abc",
displayName: "ios simulator",
});

Explicit UUID4

const debug = yield* GCP.FirebaseAppCheck.AppsDebugToken("Local", {
app: "1:123:web:abc",
displayName: "android emulator",
token: "123e4567-e89b-12d3-a456-426614174000",
});
const debug = yield* GCP.FirebaseAppCheck.AppsDebugToken("Local", {
displayName: "ci runner",
});
const exchange = yield* GCP.FirebaseAppCheck.ExchangeDebugToken(debug);
const { token, ttl } = yield* exchange();

Source: src/GCP/FirebaseAppCheck/ExchangeDebugToken.ts

Runtime binding for App Check apps.exchangeDebugToken.

Bind this operation to an AppsDebugToken in a Function/Action init phase. Provide ExchangeDebugTokenHttp. The secret is read from Alchemy state (token is never returned by get).

ExchangeDebugToken: Exchanging a Debug Token

Section titled “ExchangeDebugToken: Exchanging a Debug Token”

Mint a session App Check token

const exchange = yield* GCP.FirebaseAppCheck.ExchangeDebugToken(debug);
const { token, ttl } = yield* exchange();

Limited-use token

const exchange = yield* GCP.FirebaseAppCheck.ExchangeDebugToken(debug);
const { token } = yield* exchange({ limitedUse: true });

Source: src/GCP/FirebaseAppCheck/ExchangeDebugTokenHttp.ts Kind: Layer · Provides: GCP.FirebaseAppCheck.ExchangeDebugToken

HTTP implementation of ExchangeDebugToken.

Source: src/GCP/FirebaseAppCheck/ServicesResourcePolicy.ts

An App Check enforcement policy for a single resource of a Google service that App Check supports. Currently only Google Identity for iOS (oauth2.googleapis.com) accepts resource policies. The policy overrides the service-level enforcement mode.

Resource policies have no labels field. When targetResource is omitted, Alchemy points the policy at a dummy OAuth client whose id starts with alc- so list / nuke can identify it. serviceId and targetResource are identity — changing either replaces the policy. Enforcement mode updates in place.

ServicesResourcePolicy: Creating a Resource Policy

Section titled “ServicesResourcePolicy: Creating a Resource Policy”

Dummy target for tests

const policy = yield* GCP.FirebaseAppCheck.ServicesResourcePolicy(
"IosOauth",
{ enforcementMode: "UNENFORCED" },
);

Real iOS OAuth client

const policy = yield* GCP.FirebaseAppCheck.ServicesResourcePolicy(
"IosOauth",
{
targetResource:
"//oauth2.googleapis.com/projects/123/oauthClients/abc.apps.googleusercontent.com",
enforcementMode: "ENFORCED",
},
);

ServicesResourcePolicy: Updating a Resource Policy

Section titled “ServicesResourcePolicy: Updating a Resource Policy”
const policy = yield* GCP.FirebaseAppCheck.ServicesResourcePolicy(
"IosOauth",
{
enforcementMode: "UNENFORCED",
},
);