Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
For a conventional API, put an HTTPS Cloud Function in front of Firestore: validate the request in server-side code, use the Firebase Admin SDK for the database operation, and return a deliberate HTTP status and JSON response. Choose a callable function instead when a Firebase app is the caller and you want Firebase’s client protocol to carry available authentication and App Check tokens. Use Firestore’s REST API when you specifically need direct access to Firestore rather than your own application endpoint.
The right choice depends on who calls the API and which authorization boundary you need. The examples below use JavaScript for a small HTTPS endpoint, then explain how to test it locally, authenticate it, deploy it, and decide whether direct REST or a callable function fits better.
Choose the Firebase API shape that fits the caller
Firebase is not one API-building mechanism. You can expose your own HTTP contract with Cloud Functions, use Firebase’s callable-function protocol, or call a Firebase service’s REST endpoints directly. Those options differ in who owns request parsing, how authentication is conveyed, and whether your code controls the business logic.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors| Approach | Caller and protocol | Authentication and authorization | Best fit |
|---|---|---|---|
| HTTPS Cloud Function | Any HTTP client; you define routes, inputs, and responses. | Your handler decides how to authenticate and authorize. Server-side Admin SDK operations are privileged and must be protected by your code. | A REST-style API for web, mobile, server, or third-party clients. |
| Callable Cloud Function | Firebase-aware app using the Firebase client SDK and callable protocol. | Available Firebase Authentication, FCM, and App Check tokens are included automatically; the callable trigger validates tokens and deserializes the request. | A Firebase client that benefits from Firebase-managed request handling. |
| Firestore REST API | HTTP requests directly to Firestore REST endpoints under https://firestore.googleapis.com/v1/. |
Firebase ID-token requests are governed by Firestore Security Rules; service-account OAuth requests are governed by IAM. | Direct Firestore access where a separate custom API layer is unnecessary. |
| Firebase Authentication REST API | HTTPS requests to Firebase Authentication operations. | Authentication operations have their own request and credential requirements. | Tasks such as creating users, signing in, or editing or deleting users without a client SDK. |
For a normal application backend, begin with an HTTPS Cloud Function if you need to validate input, enforce application-specific rules, combine operations, or hide privileged logic. A callable function is usually the simpler fit when all callers are Firebase apps. Direct REST is not equivalent to a custom API: it exposes Firestore operations under Firestore’s own rules or IAM permissions rather than your application’s chosen contract.
#1 Best Overall
Build a small HTTPS API with Cloud Functions
Cloud Functions for Firebase runs backend code in response to HTTPS requests as well as Firebase events and schedules. An HTTPS handler can validate a request, use the Admin SDK to read or write Firestore, and return JSON. Keep Admin SDK code and other privileged operations on the server; do not put service-account credentials or server secrets in a browser or mobile app.
1. Create the Firebase project and initialize the services
Select or create a Firebase project, then install and authenticate the Firebase CLI. The Firebase tutorial’s initialization sequence is:
firebase login
firebase init firestore
firebase init functions
Choose JavaScript, TypeScript, or Python when prompted for the Functions language. The example below is JavaScript. During setup, use the selected project consistently for local emulation and deployment so you do not accidentally test against or deploy to the wrong environment.
Free tools Windows power users keep installed
One-click scans. No signup required.
2. Implement an HTTP handler
This example accepts a JSON object with a non-empty text string, writes it to a Firestore collection named messages, and returns the new document ID. It deliberately does not implement user authentication, rate limiting, or application-specific authorization; add those before exposing a privileged write endpoint publicly.
Rank #2
- HTML CSS Design and Build Web Sites
- Comes with secure packaging
- It can be a gift option
const { onRequest } = require("firebase-functions/v2/https");
const { initializeApp } = require("firebase-admin/app");
const { getFirestore } = require("firebase-admin/firestore");
initializeApp();
const db = getFirestore();
exports.addMessage = onRequest(async (req, res) => {
if (req.method !== "POST") {
res.set("Allow", "POST").status(405).json({ error: "Method not allowed" });
return;
}
const text = req.body && req.body.text;
if (typeof text !== "string" || text.trim().length === 0) {
res.status(400).json({ error: "A non-empty text string is required" });
return;
}
try {
const doc = await db.collection("messages").add({
text: text.trim(),
createdAt: new Date().toISOString()
});
res.status(201).json({ id: doc.id, ok: true });
} catch (error) {
console.error("Could not save message", error);
res.status(500).json({ error: "Could not save message" });
}
});
The function uses the Admin SDK, which is appropriate for server-side Firestore operations. Because Admin SDK access is privileged, Firestore Security Rules should not be treated as the authorization check for this handler. Authenticate the caller and verify that caller’s permission in the function before performing a privileged write. Also set sensible request-size and field constraints for your own application rather than accepting arbitrary client data.
3. Call the endpoint
After deployment, use the HTTPS URL shown for the function and send JSON. Replace FUNCTION_URL with that actual URL:
curl -X POST "FUNCTION_URL"
-H "Content-Type: application/json"
-d '{"text":"A message from my API client"}'
A successful request returns HTTP 201 with a JSON body containing ok and the new Firestore document ID. A request using a method other than POST receives HTTP 405; an empty or incorrectly typed text receives HTTP 400. The example does not provide a universal API URL because Firebase assigns the deployed function endpoint for the project and deployment.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Authenticate callers and protect database access
Authentication answers who is making the request; authorization decides what that identity may do. Keep the distinction clear when choosing between a callable function, a custom HTTPS handler, and direct REST.
Rank #3
- Brand: Wiley
- Set of 2 Volumes
- A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers
Firebase app calling a callable function
Callable functions are invoked using Firebase client SDKs. When available, Firebase Authentication, FCM, and App Check tokens are automatically included, and the callable trigger validates tokens and deserializes the request body. This removes some protocol plumbing, but it does not eliminate the need to decide what an authenticated user may do in your function.
Custom HTTPS function
An ordinary HTTPS endpoint has a conventional HTTP request and response contract, which suits clients that are not Firebase apps. You must define how the client proves its identity, verify credentials on the server, and reject requests the identity is not allowed to perform. Never trust a user ID or role merely because the client included it in JSON. Validate types, required fields, ownership, and permitted operations before calling the Admin SDK.
Direct Firestore REST access
Firestore REST requests can use a Firebase ID token for user-context access, in which case Firestore Security Rules apply. Server-to-server access using a service-account OAuth 2.0 token is governed by IAM instead. These credentials represent different security models; a service-account token is not a substitute for a user’s Firebase ID token. Keep service-account credentials off client devices.
Firebase Authentication also offers REST operations for tasks such as creating users, signing in, and editing or deleting users. Those requests must use HTTPS. Use the Authentication API for identity operations, not as a replacement for a custom business API that needs to coordinate authorization and data changes.
Rank #4
Test locally before deployment
Use the Firebase Local Emulator Suite as an offline sandbox before touching production services. The Functions tutorial uses the emulators to test HTTP and Firestore-triggered functions. Exercise both the successful path and rejected requests, then verify that the expected document is written in the emulator rather than production.
- Initialize Firestore and Functions for the project with the Firebase CLI.
- Start the Local Emulator Suite for the services your function depends on, including Functions and Firestore for this example.
- Send a valid POST request to the emulator’s local function endpoint, using the URL printed by the emulator.
- Check the response status and JSON, then inspect the emulator’s Firestore data for the written message.
- Repeat with a missing
textfield, a non-string value, an empty string, and a non-POST method. Confirm each request is rejected without creating a document. - Test authorization cases as well as input validation once authentication is added: unauthenticated, authenticated but unauthorized, and authorized.
Using the emulator makes the test boundary explicit: test data and operations stay in the local sandbox rather than relying on production services. The particular endpoint and emulator settings depend on the CLI project configuration, so use the values reported by your local setup rather than copying a production URL.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Deploy and operate the API
Deploy Cloud Functions with the Firebase CLI after local tests pass. The Firebase Functions tutorial states that deployment requires the Blaze pricing plan. Cloud Functions manages instances and scales them with load; monitor logs and operational behavior in the Google Cloud console after deployment.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Production readiness is more than a successful deploy. Decide which failures should be client errors, which indicate server faults, and what response details can safely be returned. Log server-side diagnostic context without returning stack traces, tokens, or sensitive data to clients. Review authorization and database access when adding a new endpoint, because a handler that uses the Admin SDK can perform operations beyond what a client governed by Firestore Security Rules could do.
Best Value
Common errors and practical fixes
UNAUTHENTICATED: The request lacks valid credentials or its token cannot be authenticated. Send the correct identity token for the chosen access path, and verify it on the server when using a custom HTTPS function.PERMISSION_DENIED: A Firestore request was rejected by Security Rules or IAM. Check whether the request uses a Firebase ID token or service-account OAuth credentials, then inspect the corresponding rules or IAM permissions. Do not solve a user-access problem by placing an administrative credential in the client.INVALID_ARGUMENT: A request field, type, or format is not accepted. Validate inputs at the API boundary and make the client send the expected JSON shape.RESOURCE_EXHAUSTED: A service or request limit has been reached. Check the failed operation and its usage before retrying; avoid immediate, unbounded retry loops.- HTTP handler returns 400: In the example,
textis missing, blank, or not a string. Send a non-empty string in a JSON request body. - HTTP handler returns 405: The example accepts POST only. Use POST or deliberately add other methods and their input handling.
- Unexpected production data changes during testing: The client is likely pointed at a deployed endpoint or production project rather than the local emulator. Check the target project and the endpoint printed by the emulator before sending test requests.
Firestore REST documents error classes including PERMISSION_DENIED, UNAUTHENTICATED, INVALID_ARGUMENT, and RESOURCE_EXHAUSTED. Handle errors according to their cause; do not return a success response for a failed database operation.
Or skip the browser setup
ScreenshotNeo is a separate website screenshot API and MCP server, not a Firebase API builder or a replacement for Cloud Functions. It can be useful if your development workflow also needs page captures for documentation or QA. One GET request returns a screenshot or PDF; see the ScreenshotNeo API documentation for parameters and response details.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before the capture; bot checks, blank pages, failed loads, and cache hits are not billed. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up for 1,000 free screenshots a month, with no card required.
Choose the implementation you can secure and operate
Use HTTPS Cloud Functions for a conventional API contract, callable functions for Firebase-client callers, and direct REST when direct service-level access is actually what the client needs. Whichever path you choose, make the authorization model explicit, validate inputs at the boundary, and test both data writes and denial cases in the Local Emulator Suite before deploying.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

