Firebase Authentication alternatives
In short
- The stack is moving off Google Cloud and identity is the piece that will not come.
- A second client — a native app, a partner integration — needs standard OIDC rather than a Firebase SDK.
- Auth state is entangled with Firestore rules and Cloud Functions in ways that now constrain the product.
| SingleSign | Firebase Authentication | |
|---|---|---|
| Standalone of any cloud project | Yes | No |
| Any standard OIDC client library | Yes | No |
| Firestore rules read auth state directly | No | Yes |
| Anonymous accounts that upgrade later | No | Yes |
| SMS / phone sign-in handled for you | No | Yes |
| You hold user records | No | Yes |
| Per-app consent the user can see | Yes | No |
What moving off Firebase Authentication actually involves
- 1
Find everything reading the Firebase token
Firestore security rules, Cloud Functions triggers and Analytics user properties all read Firebase auth state. Each one is a place the migration has to touch, and this list is usually longer than expected.
- 2
Swap the client SDK for an OIDC library
Firebase auth calls are replaced with a standard Authorization Code with PKCE flow. Any conformant OIDC library works, on any platform.
- 3
Decide what happens to the exported users
Firebase exports users with their password hashes, so the records are portable in principle. They are not portable to SingleSign, where accounts belong to the people who hold them — so the export is a reconciliation aid, not an import.
- 4
Rewrite the security rules against your own backend
This is the largest piece of work. Rules that trusted Firebase auth state now need your backend to verify a SingleSign token and enforce access itself.
When to stay on Firebase Authentication
- Firestore security rules are doing real authorisation work for you.
- You depend on anonymous-to-permanent account upgrades.
- Phone-number sign-in with managed SMS is a core part of onboarding.
Still deciding rather than migrating? The head-to-head comparison covers the same ground for someone who has not committed yet.
Try the integration before you plan the migration.
Read the quickstartAlso worth reading
- identity provider alternativesIdentity provider alternatives, by the provider you are leaving: what actually has to change in your code, and what does not.
- Firebase Auth comparisonSingleSign vs Firebase Authentication on lock-in, portability and consent, plus the cases where staying on Firebase is right.
- alternative to Auth0Auth0 alternatives compared, plus the part most listicles skip: what migrating off Auth0 actually involves, which code changes, and which does not.