NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3531 most downloaded on npm
Firebase admin SDK for Node.js
Last release 11 days ago
23 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
158 releases · first in 2014
feat(fcm): migrate topic subscriptions to FCM v1 API
feat(ml): deprecate Machine Learning APIs
@excludeFromDocs tag to filter generated docs (#3206)One column per quarter.
feat(dataconnect): update "X-Client-Version" header value to match the Node/Admin/{version} convention
Node/Admin/{version} convention (#3230)@google-cloud and typescript-eslint dependencies (#3236)Added X-Firebase-Sqlconnect-Affinity header to outgoing requests to enable backend affinity routing to improve server resource usage efficiency and performance.
Added X-Client-Version header to outgoing requests to enable usage tracking.
Security audit: remove unused dependencies and remediate dev vulnerabilities
@allow directive (#3182)Deprecated the extensionId parameter in taskQueue() .
Added FunctionScope type and updated taskQueue() to support explicit scoping ( current , global , or extension ). This optimizes scope resolution, improves task isolation for Firebase Extensions and simplifies code to be the same whether deployed in extensions or functions. Adopting this pattern is recommended to ensure compatibility with future updates.
feat(fcm): Enable fid and deprecate token for Send API
fid and deprecate token for Send API (#3145)Deprecated the token property along with the TokenMessage and legacy MulticastMessage types.
Added FidMessage and FidMulticastMessage types as replacements, allowing you to target Firebase Installation IDs (FIDs) in Firebase Messaging.
Updated the sendEachForMulticast() function to support both tokens and FIDs .
change(instance-id): Remove deprecated Instance ID service
CLOUD_TASKS_EMULATOR_HOST at construction time (#3167)CreateRequest interface from UpdateRequest (#3165)RESOURCE_EXHAUSTED server code to new TOPICS_SUBSCRIPTION_RATE_EXCEEDED SDK error code (#3148)send-tweet and upgrade GitHub Actions (#3158)Dropped support for Node.js 18 and 20. You should use Node.js 22 or higher when deploying the Admin SDK.
Removed legacy namespace support. To import Admin SDK APIs you should use the ES module entry points.
Removed the deprecated Instance ID API. This completes the migration to the replacement Firebase installations API, which you can use for deleting Firebase instance IDs and installation IDs.
Revamped SDK-wide error handling by providing more options for detailed error information. This includes new error types and codes to allow for more advanced error handling logic. See the error handling guide for more details.
Replaced usage of deprecated url.parse() with built-in Node.js URL module. Thanks kyungseopk1m for the contribution .
Removed the deprecated legacy message types DataMessagePayload , MessagingOptions , MessagingPayload , and NotificationMessagePayload .
Mapped the topic subscription RESOURCE_EXHAUSTED server code to a more accurate TOPICS_SUBSCRIPTION_RATE_EXCEEDED SDK error code.
Decoupled CreateRequest and UpdateRequest interfaces to correct misleading valid parameter types for each request type.
Skipped project config resource name check when running in emulator. Thanks kyungseopk1m for the contribution .
Cached the emulator host at instance construction time instead of at request time. Thanks daytonmux for the contribution .
feat(appcheck): Add support for minting limited-use tokens and custom JTI
Replaced node-forge dependency with the built-in Node.js crypto module for private key validation. Thanks ido-seraphic for the contribution .
Removed uuid dependency and replaced its usage with the built-in Node.js crypto module. Thanks gameroman for the contribution .
chore: Deprecate support for Node.js 20
feat(pnv): Add support for Phone Number Verification
chore: Deprecate Node.js 18 support
Upgraded @google-cloud/storage dependency to v7.19.0 . This addresses vulnerability CVE-2026-25128 in fast-xml-parser , a dependency of @google-cloud/storage . This fix also includes an update to TypeScript.
Deprecated support for Node.js 18. Instead use Node.js 20 or higher when deploying the Admin SDK. Node.js 18 support will be dropped in the next major version.
fix: Refactor isURL() to use Built-in URL Constructor
isURL() to use Built-in URL Constructor (#3061)feat(dc): Add executeQuery and executeMutation APIs to Data Connect
Updated Firebase SQL Connect APIs to use the v1 service endpoint instead of the v1alpha endpoint.
Added the new executeQuery() and executeMutation() APIs allowing for the execution of Firebase SQL Connect operations defined in GraphQL files. Additionally, you can generate a type-safe generated SDK for these GraphQL operations.
feat: initializeApp idempotency
apns.live_activity_token field in FCM ApnsConfig (#2891)feat(fdc): Data Connect Bulk Import
feat(fcm): Support proxy field in FCM AndroidNotification
proxy field in FCM AndroidNotification (#2874)AggregateError to remove ambiguity (#2879)Added support for proxy field in FCM AndroidNotification .
Fixed an issue which caused session errors to not be thrown when sending messages using HTTP/2.
Unwrapped aggregated HTTP/2 session errors to surface the sub errors which caused them.
feat(fdc): Add support for Data Connect Impersonation
Fixed equality comparison for semantic version when the number of segments is equal to the max allowed segments.
Added support for exporting a serialized config response from the Remote Config server side SDK.
Fixed a bug that was causing credential lookup errors when connecting to the Firebase SQL Connect emulator.
Added support for Firebase SQL Connect impersonation which allows for the execution of admin operations based on limited credentials on behalf of a specific user.
Fixed a bug that was causing credential lookup errors when enqueueing tasks in emulator.
feat(auth): Added FDL deprecation support for Firebase Auth
fix(auth): Fix credentials issue in createToken() when using ADC
fix: Fix the property names when initializing the SDK with ServiceAccount type
change(fcm): Remove deprecated FCM APIs
X-Goog-Api-Client metric header to outgoing authorized http requests (#2763)Migrated credentials handling to use google-auth-library . The SDK now supports new authentication methods including Workload Identity Federation and service account impersonation.
Dropped support for Node.js 14 and 16. You should use Node.js 18 or higher when deploying the Admin SDK.
Upgraded TypeScript to v5.5.4.
Upgraded the @firebase/database-compat package to v2.
Added the directBootOk field to the AndroidConfig type.
Removed deprecated sendAll() , sendMulticast() , sendToDevice() , sendToDeviceGroup() , sendToTopic() , and sendToCondition() APIs.
feat(auth): Add recaptcha and sms toll fraud support for phone auth
@firebase/database-compat to v1.0.8 (#2739)X-Goog-Api-Client metric header to Auth and FCM requests (#2738)fix(auth): Add missing Math.floor() when setting validDuration in createSessionCookie()
Math.floor() when setting validDuration in createSessionCookie() (#2712)Added the new executeGraphql() and executeGraphqlRead() APIs to perform administrative queries and mutations on a Firebase SQL Connect service.
Added support for the DATA_CONNECT_EMULATOR_HOST environment variable.
fix: updating comments with VibrateTimingsMillis and defaultVibrateTimings instead of vibrate_timings and default_vibrate_timings
chore: Deprecate sendToTopic and Condition
fix: getToken() returns existing promise to a token if one exists instead of a new token.
getToken() returns existing promise to a token if one exists instead of a new token. (#2648)feat(fcm): Add HTTP2 support for sendEach() and sendEachForMulticast()
sendEach() and sendEachForMulticast() (#2550)change: Deprecate Node.js 16 support
farmhash with farmhash-modern (#2603)Deprecated support for Node.js 16. Instead use Node.js 18 or higher when deploying the Admin SDK. Node.js 16 support will be dropped in the next major version.
Fixed optional chaining in FirebaseError type that caused issues when using vitest .
Added x-goog-user-project header to outgoing requests. Thanks foxrafa for the contribution .
build(deps-dev): bump @firebase/auth-types from 0.12.1 to 0.12.2
[chore] Update Github action workflows to fix node version and set-output deprecation warnings
set-output deprecation warnings (#2431)mailgun.js to v10.1.0 (#2451)@actions/core to ^1.10.1 to remove set-output warning and set action to use Node 20 (#2432)Breaking change: Upgraded the @google-cloud/firestore package to v7. This is a breaking change. Refer to the Cloud Firestore release notes for more de…
Breaking change: Upgraded the @google-cloud/firestore package to v7. This is a breaking change. Refer to the Cloud Firestore release notes for more details.
Breaking change: Upgraded the @google-cloud/storage package to v7. This is a breaking change. Refer to the Cloud Storage release notes for more details.
Breaking change: Upgraded TypeScript to v5.1.6.
Deprecated support for Node.js 14. Instead use Node.js 16 or higher when deploying the Admin SDK. Node.js 14 support will be dropped in the next major version.
Upgraded the google-cloud/firestore dependency to v7.1.0 to support sum() and `average() aggregation functions.
Upgraded the @firebase/database-compat package to v1.
Dropped AutoML model support (#1974)
Breaking change: Upgraded the @google-cloud/firestore package to v7. This is a breaking change. Refer to the Cloud Firestore release notes for more details.
Breaking change: Upgraded the @google-cloud/storage package to v7. This is a breaking change. Refer to the Cloud Storage release notes for more details.
Breaking change: Upgraded TypeScript to v5.1.6 .
Deprecated support for Node.js 14. Instead use Node.js 16 or higher when deploying the Admin SDK. Node.js 14 support will be dropped in the next major version.
build(deps): bump jwks-rsa from 3.0.1 to 3.1.0
feat(auth): Add Email Privacy support in Project and Tenant config
github.ref value in release.yml (#2313)Revert "chore: upgrade databse-compat (#2244)"
feat(functions): Add features to task queue functions
TotpInfo field to UserRecord (#2197)getDownloadUrl method to the Storage API (#2036)getDownloadURL (#2241)Caution: This version introduced a regression in Realtime Database that caused the incompatibility in Realtime Database types. Upgrade to 11.10.1 or later.
Added the ability to name tasks by including an id when enqueueing tasks.
Added the ability to delete an enqueued task if it has not yet completed.
Headers passed to TaskQueue HTTPS handlers are now available in the context/event object.
Added TotpInfo field to the UserRecord type.
Fixed a memory leak in the internal http timeout handling code that affected the listUsers() API. Thanks adrianjost for the contribution .
feat(auth): Add Password Policies support in Project and Tenant config
Filter type from Firestore (#2192)feat(appcheck): Added replay protection feature to App Check verifyToken() API
verifyToken() API (#2148)feat(auth): reCAPTCHA Public preview
sendEach and sendEachForMulticast for FCM batch send (#2138)Added sendEach() and sendEachForMulticast() APIs.
sendAll() and sendMulticast() APIs are now deprecated. Use sendEach() and sendEachForMulticast() APIs instead.
Deprecate sendToDevice and sendToDeviceGroup and their response classes
feat: Fix impersonated service account parsing exception
fix: Update jsonwebtoken to v9.0.0
change: Deprecate AutoML model support
feat(extensions): Add extensions namespace
fix(firestore): added missing 'ReadWriteTransactionOptions' export
feat(auth): Support sms region config change on Tenant and Project level
build(deps-dev): bump eslint from 8.23.0 to 8.24.0
fix: Add update or create release
change: Upgrade Firestore and Storage Dependencies
Breaking change: Dropped support for Node.js 12. Developers should use Node.js 14 or higher when deploying the Admin SDK.
Breaking change: Upgraded TypeScript to v4.6.4 .
Breaking change: Upgraded the @google-cloud/firestore package to v5. This contains breaking changes. Refer to the Cloud Firestore release notes for more details.
Breaking change: Upgraded the @google-cloud/storage package to v6. This contains breaking changes. Refer to the Cloud Storage release notes for more details.
fix: Add type declarations to exports fields
Deprecated support for Node.js 12. Instead use Node.js 14 or higher when deploying the Admin SDK. Node.js 12 support will be dropped in the next major version.
Replaced the dicer package with @fastify/busboy to address security issues in dicer .
feat(auth): Support generate oob code request type VERIFY_AND_CHANGE_EMAIL
Adding in alpha interface for blocking token verification
Revert TS4 and Firestore 5.x updates
fix(firestore): Expose more types from gcp firestore
The createSessionCookie() API now correctly parses and maps USER_DISABLED server errors.
Removed request body from the deleteTenant() API.
change: Dropped support for Node.js 10. Developers should use Node.js 12 or up when deploying the Admin SDK (#1445).
firebase-admin/app, firebase-admin/auth etc)The Admin SDK now requires Node.js 12 or higher. Node.js 10 support has been discontinued.
The Admin SDK now exposes a series of ES module entry points. Developers are recommended to import Admin SDK APIs from these entry points. The namespaced version of the API will be removed in a future major release. Refer to the migration guide for details on how to update your existing code to use the new ES module entry points.
The new module entry points can be used in native ESM runtimes. You can enable the native ESM support on a server running Node.js 12+ by setting the type: "module" parameter in your project's package.json file. See Node.js documentation for more details.
Nothing published for this version
Nothing published for this version
feat(rc): Add Remote Config Parameter Value Type Support
fix: Update comments in index files
feat(fac): Add custom TTL options for App Check
feat(fis): Adding the admin.installations() API for deleting Firebase installation IDs
Added a new admin.installations() API to replace the existing admin.instanceId() API.
The admin.instanceId() API is now deprecated and the developers are advised to migrate to the admin.installations() API for deleting Firebase instance IDs and installation IDs.
change: The Admin SDK now requires Node.js 10.13.0 or higher.
Made multi-factor authentication uid optional for updateUser operations.
Added support for configuring the authorization code flow for OIDC providers (previously only supported the idToken flow).
Added OAuthResponseType for specifying the responseType in OIDC provider flow.
Added INVALID_OAUTH_RESPONSETYPE and MISSING_OAUTH_CLIENT_SECRET error codes.
Your coding agent can read these notes before it upgrades. Set up the MCP server →