For a conventional API, create an HTTPS Cloud Function that validates each request, uses the Firebase Admin SDK to read or write Firestore, and returns a deliberate HTTP status and JSON response. Use a callable function instead when your caller is a Firebase app and you want Firebase’s client SDK to handle available authentication and App Check tokens. Use Firestore’s REST API when you need direct service-level access to Firestore rather than your own application endpoint.
The right choice depends on who calls the API and which authorization layer should govern access. The examples below show a protected HTTPS endpoint, explain the callable and direct-REST alternatives, and cover local testing and deployment.
Choose the Firebase API shape that fits the caller
Firebase offers several ways to expose or use an API; they are not interchangeable. Cloud Functions can respond to HTTPS requests as well as Firebase events. A function is a good fit when you need your own request and response contract, validation, business logic, or a server-side Firestore operation. Firebase’s official starter tutorial demonstrates the basic pattern with an addmessage endpoint that accepts text, writes a Firestore document, and responds to the caller.
| Approach | Caller and protocol | Authentication and authorization | Best fit |
|---|---|---|---|
| HTTPS Cloud Function | Ordinary HTTP clients, including non-Firebase clients | Your handler validates credentials and applies application authorization; server-side Admin SDK operations are privileged | A REST-style API with a contract you control |
| Callable Cloud Function | Firebase app using the Firebase client SDK’s callable protocol | When available, Firebase Authentication, FCM, and App Check tokens are included automatically; the callable trigger validates tokens and deserializes the request | A Firebase client that benefits from built-in token handling |
| Firestore REST API | HTTP requests to Firestore endpoints under https://firestore.googleapis.com/v1/ | Firebase ID-token requests are governed by Firestore Security Rules; service-account OAuth requests are governed by IAM | Direct Firestore access without a custom function endpoint |
For a user-facing client that should be constrained by database rules, use a Firebase ID token and Security Rules. For trusted server-to-server administration, use a service account and IAM, and keep its credentials on the server. A service-account identity is not the same as an authenticated end user.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Set up a project and Functions workspace
You need a Firebase project with Firestore and Cloud Functions initialized. The Firebase CLI tutorial starts with these commands:
firebase login
firebase init firestore
firebase init functions
Choose JavaScript, TypeScript, or Python for Cloud Functions; those are the languages listed in Firebase’s Functions documentation. The example below uses JavaScript and the Functions SDK layout generated by the CLI. Run commands from the project directory initialized for Functions.
Build a protected HTTPS endpoint
This example accepts a JSON body containing text, verifies a Firebase ID token supplied as a bearer token, writes a document through the Admin SDK, then returns JSON. It rejects other HTTP methods, missing credentials, invalid tokens, and malformed input. The Admin SDK runs on the server; do not put privileged server code or service-account credentials in a browser or mobile client.
const functions = require("firebase-functions");
const admin = require("firebase-admin");
admin.initializeApp();
exports.addMessage = functions.https.onRequest(async (req, res) => {
if (req.method !== "POST") {
return res.status(405).json({ error: "Method not allowed" });
}
const authorization = req.get("authorization") || "";
const match = authorization.match(/^Bearers+(.+)$/i);
if (!match) {
return res.status(401).json({ error: "Bearer token required" });
}
let user;
try {
user = await admin.auth().verifyIdToken(match[1]);
} catch (error) {
return res.status(401).json({ error: "Invalid or expired token" });
}
const text = req.body && req.body.text;
if (typeof text !== "string" || text.trim().length === 0) {
return res.status(400).json({ error: "text must be a non-empty string" });
}
try {
const doc = await admin.firestore().collection("messages").add({
text: text.trim(),
uid: user.uid,
createdAt: admin.firestore.FieldValue.serverTimestamp()
});
return res.status(201).json({ id: doc.id, ok: true });
} catch (error) {
console.error("Could not create message", error);
return res.status(500).json({ error: "Could not create message" });
}
});
The sample assumes the project’s Functions environment has the Firebase Functions and Admin SDK dependencies installed as part of CLI initialization. It accepts only a non-empty string, but production APIs should also impose an appropriate maximum length, validate every field and nested value, and authorize the requested operation for that specific user. Returning a generic server error avoids exposing internal exception details to callers; the server log retains diagnostic context.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Call the endpoint from an HTTP client
Obtain a Firebase ID token through the Firebase Authentication client flow, then send it as a bearer token. Replace the endpoint URL with the deployed function URL and the token placeholder with a real, short-lived ID token. Do not place a service-account credential in this request.
curl -X POST "YOUR_DEPLOYED_FUNCTION_URL"
-H "Authorization: Bearer YOUR_FIREBASE_ID_TOKEN"
-H "Content-Type: application/json"
-d '{"text":"Hello from my app"}'
A successful request returns HTTP 201 with a document ID and ok value. A missing or invalid token returns 401, a non-POST request returns 405, and invalid input returns 400. A Firestore failure returns 500; use the function logs to investigate rather than returning privileged details to the client.
When callable functions or direct REST are better
Callable functions for Firebase clients
Callables use the Firebase client SDK protocol, not an arbitrary REST endpoint contract. When available, Firebase Authentication, FCM, and App Check tokens are automatically included in callable requests. The callable trigger validates those tokens and deserializes the request body. This reduces protocol plumbing for a Firebase application, but a non-Firebase HTTP integration may be more naturally served by an HTTPS function.
Firestore REST for direct database operations
Use the Firestore REST API if a caller needs to access Firestore itself rather than invoke your own application logic. The REST guide places endpoints under https://firestore.googleapis.com/v1/. Authenticate a user-context request with a Firebase ID token so Firestore Security Rules apply. Authenticate server-level access with Google OAuth 2.0 using a service-account token, subject to IAM. Decide deliberately which identity and authorization model is appropriate; do not make privileged service access available to an untrusted client.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Firebase Authentication also provides REST operations for creating users, signing in, and editing or deleting users. HTTPS is required for those operations. Authentication REST endpoints are distinct from a custom Cloud Function API and from Firestore’s data API.
Test locally before deploying
Use the Firebase Local Emulator Suite as an offline sandbox before touching production services. Firebase’s Functions tutorial uses it to test HTTP functions and Firestore-triggered functions. Exercise both normal requests and failure cases while connected to emulated services, and verify the authorization and data paths that matter to your application.
- Initialize Firestore and Functions with
firebase init firestoreandfirebase init functionsif you have not already done so. - Start the Emulator Suite with
firebase emulators:startfrom the initialized project directory. - Send the same HTTP request shape you plan to use in production to the local function endpoint shown by the emulator.
- Check success, malformed input, missing or invalid authentication, and Firestore failure behavior. Confirm that test writes go to the emulator rather than production.
Local testing is especially useful for authorization: verify that user requests can perform only the intended actions, and that server-side Admin SDK code is not being confused with requests governed by Firestore Security Rules.
Deploy and operate the API
Deploy Cloud Functions with the Firebase CLI. The official Firebase Functions tutorial states that deployment requires the Blaze pricing plan. That requirement is separate from the cost of your particular usage; check the current Firebase and Google Cloud billing details for your project before deploying.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
firebase deploy --only functions
After deployment, use the Google Cloud console to monitor logs and operational behavior. Cloud Functions manages instances and scales them with load, but that does not remove the need to observe errors, request volume, latency, or downstream Firestore behavior. Keep validation and authorization in the function, avoid unnecessary database operations, and make failure responses consistent so clients can distinguish bad requests from authentication and server failures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot common API failures
| Symptom | Likely cause | What to check |
|---|---|---|
401 or UNAUTHENTICATED |
The request has no valid user token, or a token is expired or malformed | Send a Firebase ID token in the expected bearer format; do not substitute a service-account token for a user token |
PERMISSION_DENIED |
The identity lacks permission under Firestore Security Rules or IAM | Identify which authorization path the request uses. User-token requests use Security Rules; service-account OAuth requests use IAM |
400 or INVALID_ARGUMENT |
A required field is missing, malformed, or the wrong type | Check the JSON content type and body shape; validate input types and required fields before database work |
RESOURCE_EXHAUSTED |
A service limit or available resource has been exceeded | Inspect the error and project usage in the relevant Google Cloud or Firebase tooling; reduce request load or address the indicated quota/resource issue |
| Method not allowed | The caller used an unsupported HTTP method | Use POST for the sample and confirm the URL and client method |
| Function deploy fails | Functions deployment requirements are not met, including the project billing-plan requirement | Confirm the selected Firebase project and that it uses the Blaze plan required by the Firebase tutorial |
| Function returns 500 | The server-side operation failed | Inspect function logs for the logged error; check Firestore initialization and the operation’s data path |
Firestore REST documents the HTTP error classes PERMISSION_DENIED, UNAUTHENTICATED, INVALID_ARGUMENT, and RESOURCE_EXHAUSTED. A custom HTTPS function should return a similarly understandable, consistent error contract even though its own handler controls the response body.
Or skip the browser setup
ScreenshotNeo is a separate website screenshot API and MCP server; it does not build, host, or authenticate a Firebase API. If your adjacent task is capturing a website rather than implementing Firebase endpoints, one GET request returns a screenshot or PDF. See the ScreenshotNeo API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
It accepts cookie or consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers state the page verdict and billing result. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteSign up for ScreenshotNeo’s free plan to try website captures; it is not a substitute for the Firebase API implementation above.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Frequently asked questions
Can an HTTPS function return something other than JSON?
Yes. An HTTPS handler controls its HTTP response, so the sample’s JSON response is an API design choice, not a requirement to return that format for every endpoint.
Does the sample create a Firestore collection in advance?
No manual collection setup appears in the example. It writes a document to the messages collection through the Admin SDK when a valid request succeeds.
Can I use Python instead of JavaScript for Cloud Functions?
Yes. Firebase’s current Functions documentation lists Python alongside JavaScript and TypeScript. The implementation shown here is JavaScript, so its code and dependency setup should not be copied unchanged into a Python function.
Free tools Windows power users keep installed
One-click scans. No signup required.
Frequently Asked Questions
Can an HTTPS function return something other than JSON?
Yes. An HTTPS handler controls its HTTP response, so the sample’s JSON response is a design choice rather than a requirement.
Does the sample require creating the Firestore collection first?
No manual collection setup is shown; a successful write through the Admin SDK creates a document in the messages collection.
Can I use Python for Cloud Functions?
Yes. Firebase’s Functions documentation lists Python as supported, although the implementation here is JavaScript.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

