{
  "id": 12899371,
  "title": "How to get a Firebase ID token for testing your API (without writing a script)",
  "url": "https://urgent.news/2026/10/08/how-to-get-a-firebase-id-token-for-testing-your-api-without-writing-a",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T15:59:28.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/smaranjit_maiti/how-to-get-a-firebase-id-token-for-testing-your-api-without-writing-a-script-1f8o"
  },
  "original_language": "en",
  "account": "To obtain a Firebase ID token for testing your API without writing a script, follow these steps:\n\n1. Download the Firebase Token Toolkit, a desktop app that simplifies the process.\n2. Launch the app and browse for your service-account JSON file.\n3. Click \"Load apps\" to import your project's web, Android, and iOS apps, along with their API keys.\n4. Select a user from the list and click \"Generate\" to create a custom token for that user using the service-account key.\n5. The toolkit will return a real ID token, refresh token, and expiry information. This token is identical to one a client would receive after signing in, so it will pass verification on your server.\n6. Use the ID token in your API calls by adding it to the Authorization header, like so: `curl -H \"Authorization: Bearer ID token\" https://localhost:8080/api/me`.\n7. The toolkit also handles custom claims and App Check tokens, making it a comprehensive solution for your testing needs.\n\nKeep in mind that this method requires a development project, as the service-account key can sign in as any user and communicate with real Firebase. The ID token obtained will be valid for approximately an hour. The Firebase Token Toolkit is a native Rust app available for Linux, Windows, and macOS, and is MIT licensed with no telemetry.",
  "summary": "Your backend verifies Firebase ID tokens. You want to call it from curl or Postman as a specific user. Firebase gives you no button for that. The usual answers are a sign-in REST call with an email and password (only works for password users), the Auth emulator (not your real project), or a small Admin SDK script that creates a custom token and exchanges it. I wrote that script one too many…",
  "key_points": [
    "Download Firebase Token Toolkit desktop app to simplify process",
    "Load service-account JSON file and API keys in app",
    "Generate custom ID token for selected user with expiration"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}