Skip to content

Spring Boot + Firebase Auth

TL;DR / when to use this: Firebase as the auth provider for an Angular + Spring Boot stack: the frontend signs in with Firebase (popup/Google), and the backend verifies Firebase ID tokens with the Firebase Admin SDK. (The original post was written pre-verification — treat the Angular half as proven, the Spring half as the pattern to confirm against current Admin SDK docs.)

Angular side

npm install firebase @angular/fire

Initialize:

import { initializeApp } from "firebase/app";

const firebaseConfig = {
  apiKey: "YOUR_API_KEY",
  authDomain: "YOUR_AUTH_DOMAIN",
  projectId: "YOUR_PROJECT_ID",
  storageBucket: "YOUR_STORAGE_BUCKET",
  messagingSenderId: "YOUR_MESSAGING_SENDER_ID",
  appId: "YOUR_APP_ID",
};

const app = initializeApp(firebaseConfig);

Sign in with a popup:

import { getAuth, signInWithPopup, GoogleAuthProvider } from "firebase/auth";

const auth = getAuth();
const provider = new GoogleAuthProvider();

signInWithPopup(auth, provider)
  .then((result) => {
    const user = result.user;   // carries the ID token for the backend
  })
  .catch((error) => { /* ... */ });

Spring Boot side

Verify the ID token server-side with the Firebase Admin SDK (FirebaseApp.initializeApp with service-account credentials, then FirebaseAuth.getInstance().verifyToken(idToken)), and put the verified UID on the request context for your security layer. Full walkthrough in the original post.

See also