Firebase跨Web应用共享认证用户实现单点登录(SSO)技术问询
Great question! The error you’re seeing makes total sense—signInWithCustomToken() is specifically designed to work with custom tokens generated by the Firebase Admin SDK, not the ID tokens you get from a regular Firebase Auth sign-in. Those ID tokens have a different format and purpose, so they can’t be passed directly to that method.
Let’s break down the solutions based on whether your two apps are part of the same Firebase project or separate ones:
Solution 1: Same Firebase Project (Simplest Case)
If both App A and App B belong to the same Firebase project, you don’t need to manually pass tokens at all. Firebase Auth automatically handles cross-domain session sharing as long as you:
- Add both app domains to the Authorized Domains list in your Firebase Console (under Authentication > Sign-in method > Authorized domains).
- Use the exact same Firebase configuration (API key, project ID, etc.) in both apps.
When a user signs into App A, App B will detect the existing session automatically when you initialize Firebase Auth and listen to the auth state change:
firebase.auth().onAuthStateChanged((user) => { if (user) { // User is already signed in to App B automatically! console.log("Auto-signed in:", user); } });
Solution 2: Different Firebase Projects
If your apps are in separate Firebase projects, you have two secure options to implement SSO without using the Admin SDK:
Option A: Reuse Third-Party Provider Sessions
If you’re using a third-party identity provider (like Google, Facebook, or Apple) with FirebaseUI, you can leverage the provider’s own cross-app session:
- When the user signs into App A via the provider, their browser will have an active session with that provider.
- In App B, trigger the same provider sign-in flow (e.g.,
signInWithPopuporsignInWithRedirect). - The provider will recognize the existing browser session and auto-authenticate the user without requiring them to re-enter credentials.
This is the most secure approach because you don’t have to handle passing tokens between apps. Example code for App B:
const googleProvider = new firebase.auth.GoogleAuthProvider(); firebase.auth().signInWithPopup(googleProvider) .then((result) => { // User is signed in to App B automatically console.log("Auto-signed in via Google:", result.user); }) .catch((error) => { // Handle errors like user cancellation });
Option B: Pass ID Tokens Securely (For Email/Password or Custom Providers)
If you’re using email/password auth or a custom provider, you can pass the ID token from App A to App B, then use it to create a credential for sign-in:
- In App A, get the user’s ID token after sign-in:
firebase.auth().currentUser.getIdToken() .then((idToken) => { // Securely send this ID token to App B (see notes below) }); - Securely transmit the ID token to App B. Never pass it via URL parameters (risk of exposure in logs). Instead:
- If apps are on subdomains, use
postMessageto send the token directly. - If apps are on separate domains, use a backend API to relay the token (ensure the API uses HTTPS and validates the token’s integrity).
- If apps are on subdomains, use
- In App B, convert the ID token to a credential and sign in. For email/password users, use the email auth provider:
Note: For cross-project use, ensure the ID token is valid for the target project. If this causes issues, using the Admin SDK to generate a custom token for the target project is more reliable, but since you can’t use the Admin SDK, this is the best alternative.// First, extract the user's email from the ID token (you can decode it client-side or via a backend) const decodedToken = firebase.auth().currentUser?.getIdTokenResult(); const userEmail = decodedToken?.claims.email; const credential = firebase.auth.EmailAuthProvider.credential(userEmail, null); credential.idToken = receivedIdToken; firebase.auth().signInWithCredential(credential) .then((user) => { // User is signed in to App B }) .catch((error) => { // Handle invalid token or authentication errors });
Key Safety Notes
- ID tokens expire after 1 hour, but Firebase Auth automatically refreshes them for active sessions.
- Always use HTTPS to prevent token interception.
- Avoid storing tokens in local storage if possible—rely on Firebase Auth’s built-in session management instead.
内容的提问来源于stack exchange,提问作者Nik

