NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #512 most downloaded on Packagist
Firebase Admin SDK
Last release 25 days ago
12 Sep 2026
Release timing varies
gaps range from 2 weeks to 4 months
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
248 releases · first in 2015
Added support for providing a PSR-14 event dispatcher to the factory.
Added support for providing a PSR-14 event dispatcher to the factory.
Kreait\Firebase\Auth now dispatches events for user changes, refresh-token revocation, and sent email action links.Kreait\Firebase\Messaging now dispatches events for sent messages and validation errors.Kreait\Firebase\RemoteConfig now dispatches events for published and rolled-back templates.Re-release of 8.4.1 because its tag pointed to the wrong commit.
Re-release of 8.4.1 because its tag pointed to the wrong commit.
One column per quarter.
Fixed retrieving templates containing missing parameter groups ( #1133 ).
Full Changelog: 8.4.0...8.4.1
Added support for guzzlehttp/guzzle:^8.0 , guzzlehttp/psr7:^3.0 and guzzlehttp/promises:^3.0 .
guzzlehttp/guzzle:^8.0, guzzlehttp/psr7:^3.0 and guzzlehttp/promises:^3.0.firebase/php-jwt constraint to ^7.0.2.guzzlehttp/guzzle:^8.0, guzzlehttp/psr7:^3.0 and guzzlehttp/promises:^3.0.firebase/php-jwt constraint to ^7.0.2. Although
CVE-2025-45769 is rated as low severity, it has been
disputed on the basis that applications, rather than
the library, are responsible for choosing appropriate key lengths. Nevertheless, a review of the library's
most-downloaded dependents
showed that most already support version 7.x.Updated dependency mtdowling/jmespath.php to 2.9.2 to address CVE-2026-54133
mtdowling/jmespath.php to 2.9.2 to address CVE-2026-54133Added support for Unicode characters in email addresses.
verifyTokenWithReplayProtection(). The response now includes alreadyConsumed when replay protection is used.Kreait\Firebase\Contract\AppCheckWithReplayProtection. This was introduced to preserve backwards compatibility by avoiding a signature change to Kreait\Firebase\Contract\AppCheck::verifyToken() in the current major release.Kreait\Firebase\Exception\AppCheck\FailedToVerifyAppCheckReplayProtection for replay-protection verification failures. It extends Kreait\Firebase\Exception\AppCheck\FailedToVerifyAppCheckToken for backwards compatibility.Important
Support the project: This SDK is downloaded 1M+ times monthly and powers thousands of applications.
If it saves you or your team time, please consider sponsoring its development.
Added support for firebase/php-jwt:^7.0.2
Added support for firebase/php-jwt:^7.0.2
Important
Support the project: This SDK is downloaded 1M+ times monthly and powers thousands of applications.
If it saves you or your team time, please consider sponsoring its development.
Deprecated classes, methods and class constants have been removed.
#[SensitiveParameter] attributes to methods handling sensitive data (passwords, tokens, private keys)Stringable|string to string).Kreait\Firebase\Contract\Transitional\FederatedUserFetcher::getUserByProviderUid() methodKreait\Firebase\Contract\Auth interfacepsr/log has been moved from runtime dependencies to development dependenciesKreait\Firebase\Contract\Messaging::BATCH_MESSAGE_LIMIT constant has been removedKreait\Firebase\Messaging\CloudMessage builder methods have been renamed to follow the with* pattern:toToken() -> withToken(), toTopic() -> withTopic(), toCondition() -> withCondition().See UPGRADE-8.0 for more details on the changes between 7.x and 8.0.
https://github.com/kreait/firebase-php/blob/7.24.0/CHANGELOG.md
Important
Support the project: This SDK is downloaded 1M+ times monthly and powers thousands of applications.
If it saves you or your team time, please consider sponsoring its development.
Added support for firebase/php-jwt:^7.0.2 to remediate the vulnerabilities PKSA-y2cr-5h3j-g3ys and CVE-2025-4659 .
Added support for firebase/php-jwt:^7.0.2 to remediate the vulnerabilities PKSA-y2cr-5h3j-g3ys and CVE-2025-4659.
Important
Support the project: This SDK is downloaded 1M+ times monthly and powers thousands of applications.
If it saves you or your team time, please consider sponsoring its development.
Realtime Database references are now validated by the API instead of locally. Validation rules can change at any time, and the SDK can only adapt to c
#[SensitiveParameter] attribute again, because it's supported by PHP 8.1 itself, but not in combination with Valinor. (#1034)Important
Support the project: This SDK is downloaded 1M+ times monthly and powers thousands of applications.
If it saves you or your team time, please consider sponsoring its development.
Require cuyz/valinor:^2.2.1 for better mapping.
Require cuyz/valinor:^2.2.1 for better mapping.
The project now features a custom logo (I came up with it myself, and took the wise decision to not look up if there's something similar already)
Important
Support the project: This SDK is downloaded 1M+ times monthly and powers thousands of applications.
If it saves you or your team time, please consider sponsoring its development.
Re-added the #[SensitiveParameter] attribute because, while it's not supported in PHP 8.1, it can still be used if placed in a standalone line above t
#[SensitiveParameter] attribute because, while it's not supported in PHP 8.1, it can still be used if placed in a standalone line above the variable or property.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →