Firebase connector

Moderation for Firebase apps

Limenia enforces bans directly in Firebase Authentication as soon as your team has decided. Even while your webhook receiver is down.

What the connector does

Bans that take effect at once

The connector complements the webhook. When your team decides on a suspension or ban, Limenia disables the account in Firebase Authentication and revokes its refresh tokens.

DecisionIn Firebase Authentication
Temporary suspension, permanent banDisable account, revoke refresh tokens
Restore account, end of a suspensionEnable account
Remove content, warnNothing, this goes through the webhook
Setup

Connected in four steps

Everything happens in the dashboard under the app, Connectors tab. The dashboard shows the commands ready-made with your project ID.

  1. Enter the Firebase project ID.
  2. Create a custom role with three permissions and grant it to Limenia’s service account.
  3. Prove ownership: set a label with your tenant ID on the project.
  4. Enable the connector and click “Check access”. Limenia looks up a user that does not exist and changes nothing.
Create the custom role
gcloud iam roles create limeniaConnector --project=PROJECT_ID \
  --title="Limenia Connector" \
  --permissions=firebaseauth.users.get,firebaseauth.users.update,resourcemanager.projects.get
Security

No keys, narrow permissions

Limenia stores no keys to your project. Access runs through a role you can revoke at any time.

  • Only three permissions: read users, update users, read the project.
  • Every action checks the label on the project again.
  • A Firebase project can be connected to one app only.
  • All actions are in the delivery log and retried up to 12 times.
Good to know

What Firebase decides itself

ID tokens that Firebase has already issued stay valid until they expire, at most one hour.

  • Verify tokens in your backend with verifyIdToken(token, true) if bans should take effect immediately.
  • The connector does not touch content, Firestore, Storage or custom claims. That goes through the webhook.
  • An example with Firebase Cloud Functions is in the examples repository on GitHub.

Frequently asked questions

Your question is not here? Write to us, a person will answer.

[email protected]

Does Limenia need a service account key for my project?

No. You grant Limenia’s service account a custom role with three permissions. Limenia stores no keys to your project, and you can revoke the role at any time.

Which user ID does my backend have to send?

The Firebase UID. If the external user ID is something else, Limenia cannot find the account, and the delivery log shows user_not_found.

What happens when an appeal lifts a ban?

The new decision works like any other: Limenia enables the account in Firebase Authentication again and sends the decision via webhook.

Do I still need a webhook?

Yes. The connector only handles the account. Removing content, warnings and showing the statement of reasons happen in your app through the webhook.

Ready for your notice and action process?

We show you Limenia with an example and work out what your app needs for the DSA and the app stores.

Or email us directly: [email protected]