# Firebase app check

**URL:** <https://community.thunkable.com/t/firebase-app-check/1723136>\
**Category:** Questions about Thunkable X\
**Created:** [February 8, 2022, 7:50pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136 "2022-02-08T19:50:30Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [February 8, 2022, 7:50pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136/1 "2022-02-08T19:50:30Z")

</div>

hi

firebase has been offering for some time a new service app check it is the promise next to authentication to strengthen security my question can we implement this service with thunkable  
?

---

<div class="post-metadata">

**Author:** ![jared](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/jared/32/138473_2.png) [@jared](https://community.thunkable.com/u/jared)\
**Post date:** [February 8, 2022, 9:27pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136/2 "2022-02-08T21:27:43Z")

</div>

Not at the moment. Is this something you need? What kind of app are you building at the moment?

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [February 9, 2022, 5:14am UTC](https://community.thunkable.com/t/firebase-app-check/1723136/3 "2022-02-09T05:14:01Z")

</div>

hi

I gradually understand the importance of the data I would like to offer the maximum security that I can implement at my level of beginner ok I use the rules of firebase but by decompiling the application according to what I understood almost anyone can have access to the data even by game in my entourage certain will not miss it  
I intend to put this app on Playstore

I would like to know what the creator of this application thinks about it.

[https://apps.apple.com/us/app/behavior-report-card/id1493195492](https://apps.apple.com/us/app/behavior-report-card/id1493195492)

> We secure your data on our cloud server powered by Airtable with your login info managed by Google and the RealtimeDB, so you don’t ever need to worry about losing your data or your login information.

I would like to have at least this insurance

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [February 9, 2022, 10:29am UTC](https://community.thunkable.com/t/firebase-app-check/1723136/4 "2022-02-09T10:29:55Z")

</div>

> [@bibbi](#):
>
> I would like to have at least this insurance

Use `Sign in with Google` from the authentication of Firebase. This way, when your app is decompiled the information available is not useful to view database contents.

Of course, if you decide to do so then you need to create your own sign in procedure because Thunkable only provides `Username/Password Sign In` method.

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [February 9, 2022, 11:49am UTC](https://community.thunkable.com/t/firebase-app-check/1723136/5 "2022-02-09T11:49:08Z")

</div>

Hi

Thanks for your answer

it’s true that everyone does not use firebase or others in their applications but at the time of data sharing what type of application we are supposed to “write” while eminent developers who belong to the Thunkable staff do not mention not to my knowledge these subjects

---

<div class="post-metadata">

**Author:** ![jared](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/jared/32/138473_2.png) [@jared](https://community.thunkable.com/u/jared)\
**Post date:** [February 9, 2022, 11:52am UTC](https://community.thunkable.com/t/firebase-app-check/1723136/6 "2022-02-09T11:52:18Z")

</div>

> [@bibbi](#):
>
> application we are supposed to “write” while eminent developers who belong to the Thunkable staff do not mention not to my knowledge these subjects

I’m glad you are building cool apps. We are working on an academy of “best practices” but there’s no way we could possibly cover everything you need to know.

It seems you’re concerned that someone might decompile your app and then use that info to access your users private info. Is that accurate?

> [@bibbi](#):
>
> I would like to know what the creator of this application thinks about it.
> 
> [‎Behavior Report Card on the App&nbsp;Store](https://apps.apple.com/us/app/behavior-report-card/id1493195492)
> 
> > We secure your data on our cloud server powered by Airtable with your login info managed by Google and the RealtimeDB, so you don’t ever need to worry about losing your data or your login information.

This was my app. If it helps to know, I don’t even use airtable anymore. My app is 100% on Firebase for auth and DB work. And user data is still present and secure.

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [February 9, 2022, 4:22pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136/7 "2022-02-09T16:22:07Z")

</div>

Hi

Thanks for your answer

I really like the idea of ​​the best practices academy and I must say that there is always someone to guide us  
To put an end to my hesitation, so I can authenticate the user with the sign in block and use the other blocks without too much fear?

---

<div class="post-metadata">

**Author:** ![bibbi](https://avatars.discourse-cdn.com/v4/letter/b/db5fbb/32.png) [@bibbi](https://community.thunkable.com/u/bibbi)\
**Post date:** [February 9, 2022, 6:26pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136/8 "2022-02-09T18:26:43Z")

</div>

hi

I didn’t understand why using google for authentication was more secure than using email

I decompiled my app online to see I only browsed the android manifest file

---

<div class="post-metadata">

**Author:** ![jared](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/jared/32/138473_2.png) [@jared](https://community.thunkable.com/u/jared)\
**Post date:** [February 9, 2022, 6:36pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136/9 "2022-02-09T18:36:34Z")

</div>

> [@bibbi](#):
>
> To put an end to my hesitation, so I can authenticate the user with the sign in block and use the other blocks without too much fear?

absolutely. and if you started to use a backend sever, you could assign roles to your users and harness the power of IAM through firebase auth and really narrow down who has access to what docs.

Firebase can be used in HIPAA compliant systems when implemented the right way. It’s safe. What you need to worry about is your security rules. There [are](https://community.thunkable.com/t/firebase-rules-for-authenticated-users/1271480) [some good](https://community.thunkable.com/t/firebase-rules-for-secure-access-without-sign-in/1626508/6) threads about that in the community.

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [February 9, 2022, 6:48pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136/10 "2022-02-09T18:48:44Z")

</div>

> [@bibbi](#):
>
> I didn’t understand why using google for authentication was more secure than using email

If your worry is based on the fact that you actually supply the API key and Database URL in Thunkable project and this will be available in the Android APK when recompiled then using Google account authentication should clear the worry as you will not supply any API keys for Firebase and will use either an HTML file to authenticate or a server based approach such as GCP (Google Cloud Platform) and therefore your Firebase API keys will not be in the project anymore.

As I pointed out previously, the drawback of this approach is that you have to use APIs to read/write data to Firebase and not the normal Thunkable blocks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/0/f/0f59f292712368bce16ff80133ae10de8a6f27e8.png) [@system](https://community.thunkable.com/u/system)\
**Post date:** [May 10, 2022, 6:48pm UTC](https://community.thunkable.com/t/firebase-app-check/1723136/11 "2022-05-10T18:48:50Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
