NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3531 most downloaded on npm
Firebase admin SDK for Node.js
Last release 11 days ago
23 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
158 releases · first in 2014
fix: adds missing EMAIL_NOT_FOUND error code
One column per quarter.
fix(rtdb): Fixing a token refresh livelock in Cloud Functions
feat(rtdb): Support emulator mode for rules management operations
Improved OAuth 2.0 token caching and management. The SDK now treats any OAuth 2.0 token 5 minutes away from expiration as already expired, and proactively refreshes it. This helps avoid certain types of authorization-related race conditions.
The periodic token refresher background task has been decoupled from the SDK core and moved into the RTDB module. This task no longer starts automatically unless the admin.database() API is explicitly invoked.
feat(auth): Add ability to link a federated ID with the updateUser() method.
updateUser() method. (#770)Added a new getUserByProviderUid() method to look up user accounts by their providers.
The updateUser() method now supports linking a federated ID with a user account.
Allowed enabling of anonymous provider via tenant configuration.
The verifyIdToken() method now fully supports the Authentication emulator.
fix(fcm): Support arbitrary custom values in the ApnsPayload
fix(rc): Fix Version update time parsing failure
feat(firestore): Exposed more types from the admin.firestore namespace
Exposed several new types from the admin.firestore namespace. Newly exposed types include GrpcStatus , FirestoreDataConverter , UpdateData , and more.
Upgraded the @google-cloud/firestore dependency to v4.5.0.
build(deps): bump @actions/core in /.github/actions/send-tweet
Added support for generating unsigned custom tokens for testing.
Added support for verifying test ID tokens.
feat(ml): Adding Firebase ML support for AutoML models
fix(auth): Address several auth typing inconsistencies
feat(auth): Adds ability to enable MFA on a Google Cloud Identity Platform tenant
Added the ability to enable/disable multi-factor authentication with SMS on a Google Cloud Identity Platform tenant. Existing APIs like createTenant() and updateTenant() now support configuring multi-factor authentication and testing phone number/code pairs on a specified tenant.
Made displayName optional in AuthProviderConfig typings.
change: Dropped Node 8 support and upgraded Firestore/Storage dependencies
The Admin SDK now requires Node.js 10 or higher. Node.js 8 support has been discontinued.
Upgraded dependency on the @google-cloud/firestore package to v4.
Upgraded dependency on the @google-cloud/storage package to v5.
feat(rc): Add Remote Config Version Management API
Fixed a timestamp parsing issue in the UserMetadata.lastRefreshTime field.
The lastRefreshTime field has been removed from the UserMetadataRequest type used in the importUsers() API. Setting this field is currently not supported in the Firebase Authentication backend.
Added GetUsersResult and DeleteUsersResults interfaces to the exposed typings.
Mark UserMetadata::lastRefreshTime as optional.
feat(auth): Add bulk get/delete methods
UserRecord.customClaims type. (#866)Added getUsers() and deleteUsers() APIs for retrieving and deleting user accounts in bulk.
Updated the typings of the customClaims attribute on UserRecord and UserImportRecord interfaces.
feat: Remote Config Management API
DecodedIdToken types. (#852)feat(auth): Multi-factor Auth support with SMS for Google Cloud Identity Platform
Added multi-factor authentication support with SMS for Google Cloud Identity Platform . Existing APIs like createUser() and updateUser() now support configuring multi-factor authentication settings on user accounts. See documentation for more details and code samples.
Updated typings of the UserRecord.customClaims attribute to allow indexing by string keys. Thanks wSedlacek for the contribution .
Fixed a timestamp rounding error in the revokeRefreshTokens() API that caused some race conditions.
Fixed a credential loading issue that prevented some functions from being deployed via the Firebase CLI.
[Fixed] Fixed the inability to discover the project ID when running on GCP managed environments.
Fixed a bug in the admin.instanceId().deleteInstanceId() API that caused errors even when the operation completed successfully in the backend.
admin.instanceId().deleteInstanceId() API that caused errors even when the operation completed successfully in the backend.@google-cloud/firestore dependency to v3.0.0. See Firestore release notes for more details.sendMulticast() API now correctly copies the fcmOptions when sending a message to multiple recipients.@firebase/database dependency to v0.5.17.[Changed] Upgraded @google-cloud/storage dependency version to 4.1.2. This version contains some minor breaking changes. Check the release notes of th…
@google-cloud/firestore dependency version to 2.6.0.
Thanks arjunyel for the contribution.@google-cloud/storage dependency version to 4.1.2. This version contains some minor breaking changes. Check the release notes of the dependency for more information. Thanks arjunyel for the contribution.verifyIdToken() method now correctly uses the http.Agent configured during SDK initialization.sendAll() and sendMulticast() now support sending up to 500 messages in a single call.Added a series of new parameters to the AndroidNotification class that allow further customization of notifications that target Android devices.
AndroidNotification class
that allow further customization of notifications that target Android devices.[Fixed] `UserRecord` no longer exposes password hashes that are redacted due to lack of permissions in the service account credentials.
UserRecord no longer exposes password hashes that are redacted due to lack of permissions in the service account credentials.setCustomUserClaims() API to accept null.UserRecord no longer exposes password hashes that are redacted due to lack of permissions in the service account credentials.
Updated the typings of the setCustomUserClaims() API to accept null .
[Feature] Added a new admin.securityRules() API for managing Firebase security rules applied on services like Cloud Firestore and Cloud Storage.
admin.securityRules() API for managing Firebase security rules applied on services like Cloud Firestore and Cloud Storage.getFirestoreRuleset() and getStorageRuleset() methods for retrieving rulesets that are currently in effect.releaseFirestoreRuleset() and releaseStorageRuleset() methods for creating new rulesets and applying them to Firestore and Storage.getRuleset(), createRuleset() and deleteRuleset() methods for managing the lifecycle of a ruleset.Added a new admin.securityRules() API for managing Firebase security rules applied on services like Cloud Firestore and Cloud Storage . See the Firebase documentation to learn more about how to use the Admin SDK to manage and deploy security rules.
Added getFirestoreRuleset() and getStorageRuleset() methods for retrieving rulesets that are currently in effect.
Added releaseFirestoreRuleset() and releaseStorageRuleset() methods for creating new rulesets and applying them to Cloud Firestore and Cloud Storage .
Added getRuleset() , createRuleset() and deleteRuleset() methods for managing the lifecycle of a ruleset.
[Feature] Added multi-tenancy support to the authentication service (Google Cloud Identity Platform project required). Tenant related APIs are exposed
tenantManager() on the admin.auth interface.authForTenant(), getTenant(), listTenants(), deleteTenant(), createTenant() and updateTenant() to the newly defined TenantManager.TenantAwareAuth interface retrieved via TenantManager#authForTenant() for managing users, configuring SAML/OIDC providers, generating email links for password reset, email verification, etc for specific tenants.@firebase/database dependency version to 0.5.1. This helps avoid some peer dependency warnings that were observed during package installation.[Feature] Added support for specifying the analytics label for notifications. Thanks chemidy for the contribution.
Added an `admin.database().getRules()` method to retrieve the currently applied Realtime Database rules text.
admin.database().getRules() method to retrieve the currently applied Realtime Database rules text.admin.database().getRulesJSON() method to retrieve the currently applied Realtime Database rules as a
parsed JSON object.admin.database().setRules() method to update Realtime Database rules.@firebase/app package to a dev dependency.admin.auth().importUsers() API.@google-cloud/storage dependency to v3.0.0. This new major version drops support for Node.js versions older than v8. Since firebase-admin already supports only Node.js v8 and above, this does not have a noticeable impact on users of the Admin SDK.Updated the metadata server URL (used by the application default credentials) to the v1 endpoint. This makes it possible to use the SDK in Google Kube
v1 endpoint. This makes it possible to use the SDK in Google Kubernetes Engine again.@firebase/database dependency to v0.4.4.messaging.sendAll() and messaging.sendMulticast() APIs.The SDK now automatically retries HTTP calls failing due to 503 errors.
projectManagement.listAppMetadata() API to list the summarized details of up to 100 apps in a Firebase project.projectManagement.setDisplayName() API to update the display name of a Firebase project.The Admin SDK no longer supports Node 6. Developers must use Node 8.13.0 or higher when deploying the Admin SDK.
Support for Node 6 is now deprecated. Developers are recommended to use Node 8 or higher when deploying the Admin SDK. An upcoming release will comple…
admin.database.ThenableReference type to extend from the built-in Promise type.[feature] Added the provider config management APIs for managing OIDC and SAML provider configurations (CRUD) via auth.listProviderConfigs(), auth.get
auth.listProviderConfigs(), auth.getProviderConfig(), auth.deleteProviderConfig(), auth.updateProviderConfig() and auth.createProviderConfig().Added new APIs for managing SAML and OIDC provider configurations. These APIs support CRUD operations on auth provider configurations:
auth.listProviderConfigs()
auth.getProviderConfig()
auth.deleteProviderConfig()
auth.updateProviderConfig()
auth.createProviderConfig()
Upgraded the Cloud Firestore client dependency to v1.2.0. This upgrade exposes the v1beta and v1 clients, which provide direct access to the underlyin
v1beta and v1 clients, which provide direct access to the underlying Firestore and Firestore Admin RPCs. Please note that you must provide your Firebase credentials directly to these clients.Fixed a bug in the FCM batch APIs that prevented them from correctly handling some message parameters like AndroidConfig.ttl.
AndroidConfig.ttl.A new `messaging.sendMulticast()` API for sending a message to a list of device registration tokens.
messaging.sendMulticast() API for sending a message to a list of device registration tokens.messaging.sendAll() API for sending a list of messages as a single batch.auth.UpdateRequest interface to clearly specify the nullable fields.Updated the Google Cloud Firestore client to v1.0.1. This contains breaking changes. Refer to the Cloud Firestore release notes for more details and m…
verifyIdToken() and verifySessionCookie() methods now return auth/id-token-expired and auth/session-cookie-expired error codes for expired JWTs.Implemented a Node.js environment check that is executed at package import time.
GOOGLE_APPLICATION_CREDENTIALS environment variable to a refresh token file instead of a service account is now supported.Setting the GOOGLE_APPLICATION_CREDENTIALS environment variable to a refresh token file instead of a service account file is now supported. Thanks yinzara for the contribution .
Implemented an environment check that is executed at package import time. The Admin SDK logs a warning if imported into a client environment such as a web browser.
A new shaCertificate() method for creating instances of `admin.projectManagement.ShaCertificate`.
shaCertificate() method for creating instances of admin.projectManagement.ShaCertificate.UserRecord type.[added] messaging.Aps type now supports configuring a critical sound. A new messaging.CriticalSound type has been introduced for this purpose.
messaging.Aps type now supports configuring a critical sound. A new messaging.CriticalSound type has been introduced for this purpose.messaging.AndroidNotification type now supports channel_id.AppOptions now accepts an optional http.Agent object. The http.Agent specified via this API is used when the SDK makes backend HTTP calls. This can be used when it is required to deploy the Admin SDK behind a proxy.admin.credential.cert(), admin.credential.applicationDefault(), and admin.credential.refreshToken() methods now accept an http.Agent as an optional argument. If specified, the http.Agent will be used when calling Google backend servers to fetch OAuth2 access tokens.AppOptions now accepts an optional http.Agent object. The http.Agent specified via this API is used when the SDK makes backend HTTP calls. This can be used when it is required to deploy the Admin SDK behind a proxy.
admin.credential.cert() , admin.credential.applicationDefault() , and admin.credential.refreshToken() methods now accept an http.Agent as an optional argument. If specified, the http.Agent is used when calling Google backend servers to fetch OAuth2 access tokens.
The messaging.Aps type now supports configuring a critical alert sound. A new messaging.CriticalSound type has been introduced for this purpose.
The messaging.AndroidNotification type now supports specifying a channelId field when sending messages to Android O clients.
A new `admin.projectManagement()` API for managing apps in a Firebase project.
admin.projectManagement() API for managing apps in a Firebase project.listAndroidApps() and listIosApps() methods for listing the existing apps in a project.createAndroidApp() and createIosApp() methods for creating new apps in a project.AndroidApp and IosApp APIs for updating individual apps.ApsAlert type now supports specifying a subtitle. Thanks chemidy for the
contribution.Added the email action link generation APIs for creating links for password reset, email verification and email link sign-in via auth.generatePassword
auth.generatePasswordResetLink(), auth.generateEmailVerificationLink() and auth.generateSignInWithEmailLink().Transaction type from the admin.firestore namespace.type.googleapis.com/google.firebase.fcm.v1.FcmError to set error code. Thanks chemidy for the contribution.Upgraded Cloud Firestore client to v0.19.0.
Exposed the Transaction type from the admin.firestore namespace.
Upgraded Cloud Firestore client to v0.18.0.
CollectionReference, WriteBatch, WriteResult and
QueryDocumentSnapshot types from the admin.firestore namespace.The Admin SDK no longer supports Node.js 4. Developers must use Node.js 6 or higher to deploy the Admin SDK.
array-contains query operator and FieldValue.arrayUnion() and FieldValue.arrayRemove() APIs.Upgraded Cloud Firestore client to v0.15.4.
Timestamp type from the admin.firestore namespace.The Admin SDK can now read the Firebase/Google Cloud Platform project ID from both GCLOUD_PROJECT and GOOGLE_CLOUD_PROJECT environment variables.
GCLOUD_PROJECT and GOOGLE_CLOUD_PROJECT environment variables.serviceAccountId app option, which can be used to specify just the client email of a service account.admin.database.Query.once() method to return a more specific type.admin.messaging.WebpushNotification type to include all supported notification fields.Admin SDK now lazy loads all child namespaces and certain heavy dependencies for faster load times. This change also ensures that only the sources for
Admin SDK now lazy loads all child namespaces and certain heavy dependencies for faster load times. This change also ensures that only the sources for namespaces that are actually used get loaded into the Node.js process.
Upgraded the Cloud Firestore client from 0.13.0 to 0.14.0.
A new `auth.createSessionCookie()` method for creating a session cookie from a Firebase ID token.
auth.createSessionCookie() method for creating a session cookie from a Firebase ID token.auth.verifySessionCookie() method for validating a given session cookie string.mutableContent optional field to the messaging.Aps type. This can be used to set the mutable-content property when sending FCM messages to APNS targets.messaging.Aps type.A new `auth.importUsers()` method for importing users to Firebase Auth in bulk.
auth.importUsers() method for importing users to Firebase Auth in bulk.Upgraded Realtime Database client to v0.2.0. With this upgrade developers can call the admin.database().ref() method with another Reference instance a
admin.database().ref() method with another Reference instance as the argument.Upgraded the Realtime Database client from 0.1.11 to 0.2.0. This provides the ability to call admin.database().ref() with an existing reference as the argument.
Upgraded the Cloud Firestore client from 0.12.0 to 0.13.0 .
The admin.initializeApp() method can now be invoked without a credential option. This prompts the SDK to use Google Application Default Credentials.
admin.initializeApp() method can now be invoked without a credential option. This prompts the SDK to use Google Application Default Credentials.The admin.initializeApp() method can now be invoked without a credential option. The SDK uses Google Application Default Credentials when initialized this way.
Upgraded the Cloud Firestore client from 0.11.1 to 0.12.0 .
Upgraded the Cloud Storage client from 1.2.1 to 1.6.0.
Upgraded the Realtime Database client from 0.1.3 to 0.1.11.
A new `messaging.send()` method for sending messaging messages.
messaging.send() method for sending messaging messages.[changed] Exposed admin.firestore.DocumentReference and admin.firestore.DocumentSnapshot types from the Admin SDK typings.
admin.firestore.DocumentReference and admin.firestore.DocumentSnapshot types from the Admin SDK typings.Exposed admin.firestore.DocumentReference and admin.firestore.DocumentSnapshot types from the Admin SDK typings.
Upgraded Firestore dependency version to 0.11.2. This includes several bug fixes including a fix in the DocumentReference.update() operation.
This release upgrades the Cloud Firestore dependency version from 0.10.0 to 0.11.1, which includes several bug fixes in Cloud Firestore.
The `admin.initializeApp()` method can now be invoked without any arguments. This will initialize an app using Google Application Default Credentials,
admin.initializeApp() method can now be invoked without any arguments. This will initialize an app using Google Application Default Credentials, and other AppOptions loaded from the FIREBASE_CONFIG environment variable.jsonwebtoken library to 8.1.0.A new `revokeRefreshTokens()` method for revoking refresh tokens issued to a user.
revokeRefreshTokens() method for revoking refresh tokens issued to a user.verifyIdToken() method now accepts an optional checkRevoked argument, which can be used to check if a given ID token has been revoked.A new `admin.instanceId()` API that facilitates deleting instance IDs and associated user data from Firebase projects.
admin.instanceId() API that facilitates deleting instance IDs and associated user data from Firebase projects.admin.AppOptions to reflect the introduction of the projectId option.@google-cloud/firestore dependency to latest.Upgraded the Cloud Firestore client to the latest available version, which adds input validation to several operations, and retry logic to handle netw
`app.database()` method now optionally accepts a database URL. This feature can be used to access multiple Realtime Database instances from the same a
app.database() method now optionally accepts a database URL. This feature can be used to access multiple Realtime Database instances from the same app.Fixed a regression in module loading that prevented using the Admin SDK in environments like AWS Lambda. This regression was introduced in the 5.4.0 r
Upgraded the Cloud Firestore client dependency to 0.8.2, which resolves an issue with saving objects with nested document references.
Your coding agent can read these notes before it upgrades. Set up the MCP server →