All integrations
Catalogue metadata onlysecurity & identity toolsv20260826_00

FIREBASE

Firebase

Firebase Authentication client tools for project discovery, user sign-in and sign-up flows, out-of-band codes, and Secure Token refresh using a Firebase Web API Key.

Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.

Pakkawork boundary

Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.

No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Attributed source

8

Action summaries

Display-only definitions

0

Trigger types

Not installed instances

1

Auth modes

Field names, never values

No

Execution

No runtime adapter

Authentication map

What setup is declared?

Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
API_KEY

API_KEY

firebase_api_key

Provider setup

Developer setup

No fields declared in this snapshot.

User connection

  • Firebase Web API Keygeneric_api_key · stringRequired

Capability index

Actions and trigger definitions

Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.

Showing 1–8 of 8 actions

Discover Sign-In Methods

FIREBASE_DISCOVER_SIGN_IN_METHODS

Look up sign-in methods previously used by a Firebase account email. Firebase anti-enumeration settings can suppress results, so empty lists or an absent registered value do not prove that the account does not exist.

Untrusted display-only summary

Get Auth Project Config

FIREBASE_GET_AUTH_PROJECT_CONFIG

Get the public Firebase Authentication configuration associated with the connected Web API key, including the project ID and authorized domains. This does not authenticate a user or grant backend access.

Untrusted display-only summary

Refresh ID Token

FIREBASE_REFRESH_ID_TOKEN

Exchange a Firebase refresh token for a fresh Firebase ID token and rotated refresh token using Google's Secure Token service.

Untrusted display-only summary

Sign In With Custom Token

FIREBASE_SIGN_IN_WITH_CUSTOM_TOKEN

Exchange a trusted server-minted Firebase custom token for a Firebase ID token and refresh token. The exchange may create the Firebase user on their first sign-in.

Untrusted display-only summary

Sign In With Email Link

FIREBASE_SIGN_IN_WITH_EMAIL_LINK

Complete Firebase email-link sign-in using an email address and the one-time OOB code from a previously delivered sign-in link. This may create the Firebase user on first sign-in; it does not send email.

Untrusted display-only summary

Sign In With Identity Provider

FIREBASE_SIGN_IN_WITH_IDP

Sign in with one configured external identity provider using provider-specific OAuth or OIDC credential parameters. This sign-in-only tool may create the Firebase user on first sign-in and rejects Firebase idToken account-linking semantics.

Untrusted display-only summary

Sign In With Password

FIREBASE_SIGN_IN_WITH_PASSWORD

Sign in an existing Firebase Authentication user with email and password and return fresh ID and refresh tokens. Requires the Email/Password provider to be enabled.

Untrusted display-only summary

Verify Password Reset Code

FIREBASE_VERIFY_PASSWORD_RESET_CODE

Validate a Firebase password-reset OOB code and identify the associated email and request type without changing the password.

Untrusted display-only summary

Provenance

Versioned facts, explicit trust.

The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.

Repository
https://github.com/provider-directoryHQ/provider-directory
Commit
85e33f6a81dfe987f6fc3637d48d45052cea8ca5
Generated
2026-09-12
Trust policy
untrusted_display_only

Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.