You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase项目添加仅含Authentication权限及数据库只读权限的协作者

How to Restrict a Team Member to Firebase Authentication Admin + Database Read-Only Access

Got it, let's walk through exactly how to set up these permissions for your team member—this is a common scenario, so we can break it down step by step to make it clear.

Step 1: Access Firebase's IAM Permission Manager

First, log into your Firebase Console and navigate to your live project. Click the Project Settings (gear icon) in the left sidebar, then switch to the Permissions tab. This is where all project-level access controls live, powered by Google Cloud IAM.

Step 2: Add the Member & Assign Authentication Permissions

  • Click the Add button at the top of the Permissions page, then enter the team member's email address.
  • In the Role dropdown, search for and select the Firebase Authentication Admin role. This role specifically allows the user to:
    • Query all Authentication users (to check if a user exists)
    • Delete users as needed
    • It won't grant access to any other Firebase services, which aligns with your "only access Authentication" requirement.

Step 3: Configure Database Read-Only Access

Next, set up read-only access for the database—this depends on which Firebase database you're using:

For Firebase Realtime Database

  • Go back to your Firebase Console and open the Realtime Database module.
  • Navigate to the Rules tab, then update the rules to:
    {
      "rules": {
        ".read": "auth != null && request.auth.token.email == 'your-team-member@example.com'",
        ".write": false
      }
    }
    
    Replace your-team-member@example.com with the actual email of the person you're adding. This rule ensures only that specific user can read the database, and blocks all write operations entirely.

For Cloud Firestore

  • Open the Firestore Database module in the Firebase Console, then go to the Rules tab.
  • Update the rules to:
    rules_version = '2';
    service cloud.firestore {
      match /databases/{database}/documents {
        match /{document=**} {
          allow read: if request.auth.token.email == 'your-team-member@example.com';
          allow write: false;
        }
      }
    }
    
    Just like the Realtime Database rule, this restricts read access to your team member's email and disables all writes.

Step 4: Verify the Permissions

Once everything is set up, have the team member log into the Firebase Console and test:

  • Navigate to the Authentication module: confirm they can search for users and delete a test user (if you create one for testing).
  • Check the database module: make sure they can query user data, and that any attempt to edit/delete data gets blocked.

Pro tip: If you need to adjust permissions later, just head back to the IAM page to modify roles, or update the database rules. IAM handles console/API access at the project level, while database rules add granular document-level control—together, they give you exactly the access restrictions you need.

内容的提问来源于stack exchange,提问作者T Neate

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:50:10