Do not pass a Firebase user’s password to Puppeteer. Sign the user in with Firebase Auth on the client, call the HTTPS callable with the Firebase Functions SDK, and authorize the operation from request.auth. Firebase automatically includes the user’s ID token in a callable request when one is available. Pass credentials to Puppeteer only when it must authenticate to a separate website, and then use that site’s authorized login or session mechanism rather than treating a Firebase token as a universal browser password.
First identify which account Puppeteer must access
The correct implementation depends on the identity boundary. A Firebase account, a third-party website account, and a browser session are different things.
The user’s Firebase account
For Firebase email/password authentication, the password belongs in the client-side Firebase Auth sign-in call. After successful sign-in, Firebase maintains an ID token for the user. When the client invokes an HTTPS callable through the Firebase Functions SDK, the SDK automatically sends available Firebase Authentication tokens. The callable receives the resulting identity in request.auth; it does not need the password to identify the caller.
A separate website account
Firebase authentication does not log Puppeteer into another service. A Firebase ID token is not the password, cookie, or session token for an unrelated website. If automation must access that site, use its official API, OAuth or delegated authorization, service account, or documented session method. Only submit a password to the site’s own login endpoint when that is explicitly authorized and unavoidable.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
A Firebase-protected resource
If the target data is in Firebase, prefer Firebase APIs and the caller’s Firebase identity instead of opening a browser and logging into a web page. Browser automation adds secret exposure, timing failures, and maintenance cost.
Recommended Firebase flow
- Sign in on the client with
signInWithEmailAndPassword(auth, email, password). - Call the callable with the Firebase Functions client SDK. The SDK attaches the ID token when the user is signed in.
- In the function, reject unauthenticated requests and authorize the requested operation for
request.auth.uid. - Start Puppeteer only after authorization succeeds.
- If a separate site is required, obtain that site’s approved session or delegated credential and limit its lifetime and scope.
Client: sign in, then call the function
This browser example sends the Firebase password only to Firebase Auth. It does not put the password in callable data.
import { initializeApp } from "firebase/app";
import { getAuth, signInWithEmailAndPassword } from "firebase/auth";
import { getFunctions, httpsCallable } from "firebase/functions";
const app = initializeApp(firebaseConfig);
const auth = getAuth(app);
const functions = getFunctions(app);
const credential = await signInWithEmailAndPassword(
auth,
emailInput.value,
passwordInput.value
);
const runAutomation = httpsCallable(functions, "runAutomation");
const result = await runAutomation({
job: "authorized-task",
targetId: "record-123"
});
console.log(result.data);
Do not add password to that data object merely so the function can discover the Firebase user. A callable’s request.data is application input; request.auth is Firebase-provided caller context.
Callable function: verify and authorize before Puppeteer
A callable handler should check authentication and application authorization before launching a browser. The following Node.js example uses Firebase Functions’ callable API and keeps the Puppeteer portion deliberately site-neutral.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteconst { onCall, HttpsError } = require("firebase-functions/https");
const puppeteer = require("puppeteer");
exports.runAutomation = onCall(async (request) => {
if (!request.auth) {
throw new HttpsError(
"unauthenticated",
"Sign in before running this action."
);
}
const uid = request.auth.uid;
const { job, targetId } = request.data || {};
// Replace this with your database-backed authorization check.
const allowed = await userMayRunJob(uid, job, targetId);
if (!allowed) {
throw new HttpsError("permission-denied", "This action is not allowed.");
}
const browser = await puppeteer.launch({ headless: true });
try {
const page = await browser.newPage();
// Perform only the authorized, user-scoped operation here.
// Do not assume request.data.password exists or is needed.
await page.goto("https://your-authorized-app.example", {
waitUntil: "networkidle2",
timeout: 30000
});
return { ok: true, uid };
} finally {
await browser.close();
}
});
Authentication answers who called the function. Authorization still determines whether that caller may run the requested job. Consider enabling App Check enforcement for callable endpoints exposed to untrusted clients; it helps reduce abuse but does not replace authorization.
If another website really requires a password
First look for an official API or delegated sign-in. If password submission is an explicitly authorized requirement, treat the credential as a high-value secret:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Require
request.authand authorize the Firebase UID before accepting any credential. - Validate the target and operation server-side; never let the client choose an arbitrary login URL.
- Use HTTPS and keep the password in memory only for the shortest practical time.
- Never log, persist, echo, return, screenshot, or include the password in error messages.
- Do not place it in URLs, query strings, analytics events, or durable job records.
- Prefer a short-lived, narrowly scoped delegated credential supplied by the target service.
Passing a field such as { password } in callable data is technically possible because callable data is JSON, but that transport capability does not make the design safe or appropriate. It also does not turn a Firebase password into a login for a third-party site.
Using cookies or an existing browser session
When the target service supports an authorized session-cookie workflow, create the session through its documented mechanism and give Puppeteer only the resulting session data. Puppeteer’s current API reference marks the page-level cookie method obsolete and recommends browser- or browser-context-level methods.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11const browser = await puppeteer.launch({ headless: true });
const context = await browser.createBrowserContext();
await context.setCookie({
name: "session",
value: shortLivedSessionValue,
domain: "authorized-app.example",
path: "/",
secure: true,
httpOnly: true
});
const page = await context.newPage();
await page.goto("https://authorized-app.example/account", {
waitUntil: "networkidle2"
});
Use the exact cookie attributes and domain required by the target service. Do not copy a user’s browser profile or reuse long-lived cookies without permission. A cookie authenticates to the service that issued it; it does not establish Firebase identity.
Verifying an ID token outside a callable
For a non-callable endpoint or another backend boundary, Firebase Admin SDK can verify the ID token and return decoded claims such as the UID.
const { getAuth } = require("firebase-admin/auth");
const decoded = await getAuth().verifyIdToken(idToken);
const uid = decoded.uid;
Firebase documents that verifyIdToken() does not check revocation by default. If revocation status matters to your threat model, use the documented revocation-checking option and account for its additional lookup cost. This verification step is still unrelated to supplying a password to Puppeteer.
Custom tokens are not website passwords
Firebase custom tokens are minted server-side and exchanged by the client with signInWithCustomToken(). They are an alternative Firebase sign-in mechanism, not a general browser credential for arbitrary websites. Firebase documents a one-hour expiration for custom tokens and requires service-account private keys to remain confidential.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Common failures and fixes
request.auth is null
Usually the client is not signed in, the call is being made without the Firebase Functions SDK, or the request is reaching a different project or region than the client configuration. Confirm that signInWithEmailAndPassword() resolved, that the callable name and region match, and that the user’s current Auth state is available before invoking the function.
The function says the user is authenticated but access is denied
Authentication does not grant every permission. Check the UID-to-resource authorization rule, roles, tenant boundaries, and ownership record used by userMayRunJob(). Never authorize from a client-supplied UID.
Puppeteer reaches a login page
That is expected when the target site has no session. A Firebase ID token will not create the site’s session. Use the site’s official API or its supported OAuth, cookie, or login flow.
Cookies do not work
Check domain, path, Secure and HttpOnly attributes, expiration, consent requirements, and whether the cookie is scoped to a different host. Set cookies on the browser context before navigation, using the current Puppeteer API rather than the obsolete page-level method.
Recommended Free Tools
Callable requests time out
Browser launches and third-party pages can exceed function limits. Set explicit navigation and action timeouts, close the browser in a finally block, avoid unbounded waits, and consider an asynchronous job queue for long work. Return a job identifier rather than holding a callable open when the operation cannot reliably finish within the function’s execution window.
A password appears in logs
Search application logs, request tracing, exception serialization, and browser console forwarding. Remove password fields from structured logging, redact caught errors, rotate the exposed credential, and review retention policies. Do not capture screenshots while a password is visible.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Security and lifecycle checklist
- Firebase password is used only by the Firebase Auth sign-in flow.
- Callable checks
request.authand authorizes the UID. - Target-site credentials are distinct from Firebase credentials.
- Secrets are not logged, stored, returned, or placed in URLs.
- Browser context and cookies are short-lived and closed after the job.
- Target URLs and actions are allowlisted server-side.
- App Check and rate limits are considered for public callable endpoints.
- Long-running browser work is moved to an asynchronous, monitored job when necessary.
Or skip the browser setup
If your actual goal is to capture a page rather than automate a logged-in workflow, ScreenshotNeo provides a website screenshot API and MCP server. One request can return PNG, JPEG, WebP, or PDF without launching Puppeteer in your callable.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for options and authentication. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf for AI clients. The free plan includes 1,000 screenshots per month with no card, and paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Bottom line
Pass a Firebase password to Firebase Auth, not to Puppeteer or callable data. Let the callable identify the signed-in user through request.auth, authorize that UID, and use a separate, explicitly supported session mechanism only when Puppeteer must access another website.
Frequently Asked Questions
Can I read the Firebase password inside a Cloud Function?
No. The normal email/password flow sends it to Firebase Auth from the client; the callable receives authenticated identity through the ID token and request.auth.
Will a Firebase ID token log Puppeteer into my website?
Not automatically. It authenticates the Firebase project, not an unrelated website. That site must support its own API, delegated authorization, or browser session.
Is sending a password in request.data ever valid?
Callable data can contain JSON fields, but include a password only for an explicitly authorized target-site flow, with strict validation, short retention, and no logging or persistence.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

