同一Firebase项目下两款Android应用实现独立身份验证的技术问询
Hey there! Great question—this is a super common scenario when managing multiple apps under a single Firebase project, and it’s totally achievable without major roadblocks. Let’s break down the best ways to set up separate authentication flows for your two Android apps:
First, let’s clarify: Firebase doesn’t restrict you from having separate auth mechanisms for multiple apps in the same project. The core idea is to use app identifiers and custom logic/rules to segregate user pools between your two apps.
Option 1: Distinguish Users by App ID (Most Common Approach)
Every Android app linked to your Firebase project has a unique applicationId (found in your google-services.json as mobilesdk_app_id). You can tag users with this ID when they sign up, then use it to enforce app-specific auth rules and access controls.
Step-by-Step Implementation:
Capture the App ID in Each App
On Android, you can get the current app’s ID viaBuildConfig.APPLICATION_ID(make sure you’ve enabled build config in your Gradle setup).Store App ID as a User Attribute
When a user signs up, attach the app ID to their Firebase Auth user record. For security, it’s better to do this via the Firebase Admin SDK (backend) instead of the client, since client-side changes can be tampered with.Example using Node.js Admin SDK:
const admin = require('firebase-admin'); // After a user signs up, call this to set their app ID claim function setAppIdClaim(uid, appId) { return admin.auth().setCustomUserClaims(uid, { app_id: appId }); }If you need to do it client-side (not recommended for sensitive data), you can update the user’s profile:
val currentUser = FirebaseAuth.getInstance().currentUser val profileUpdates = UserProfileChangeRequest.Builder() .setDisplayName(currentUser?.displayName) // Add app ID as part of the user's profile (or use a custom claim) .build() currentUser?.updateProfile(profileUpdates) ?.addOnCompleteListener { task -> if (task.isSuccessful) { // App ID added successfully } }Enforce App-Specific Rules
Use theapp_idcustom claim in your Firebase Security Rules (for Firestore, Realtime Database, etc.) to restrict access to only users from the correct app. For example, in Realtime Database:{ "app1_data": { ".read": "auth.token.app_id === 'com.your.first.app'", ".write": "auth.token.app_id === 'com.your.first.app' && auth.uid === $uid" }, "app2_data": { ".read": "auth.token.app_id === 'com.your.second.app'", ".write": "auth.token.app_id === 'com.your.second.app' && auth.uid === $uid" } }
Option 2: Restrict Sign-In Providers Per App
If your two apps need entirely different sign-in methods (e.g., one uses email/password, the other uses Google Sign-In), you can configure Firebase Auth to enable providers only for specific apps:
- Go to your Firebase Console > Authentication > Sign-in method.
- For each provider (like Email/Password), click "Edit".
- Under "Authorized apps" section, select which apps are allowed to use that provider. The other app won’t have access to it, creating a natural separation of user pools.
Option 3: Use a Second Firebase Instance (Full Isolation)
If you need completely separate auth user pools (no overlap at all), you can create a second Firebase project instance for one of your apps. This way, each app uses its own Auth service, but you can still share database resources via Firebase Admin SDK or cross-project cloud functions.
To set this up:
- Create a new Firebase project for one app.
- Initialize the second Firebase instance in your Android app using a separate
google-services.jsonfile, or manually configure Firebase options in code.
Key Security Notes:
- Always prefer using custom claims (set via Admin SDK) over client-side profile updates, since claims can’t be modified by users.
- Make sure your security rules strictly validate the
app_idclaim to prevent cross-app access.
内容的提问来源于stack exchange,提问作者Tarek Alabd

