# Unless using Public rules in Firebase, the API key can’t access data

**URL:** <https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375>\
**Category:** Questions about Thunkable X\
**Tags:** firebase\
**Created:** [November 16, 2020, 9:00pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375 "2020-11-16T21:00:17Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![appspark.uk](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/appspark.uk/32/84980_2.png) [@appspark.uk](https://community.thunkable.com/u/appspark.uk)\
**Post date:** [November 16, 2020, 9:00pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/1 "2020-11-16T21:00:17Z")

</div>

_Update: Please watch the video before you reply, it explains things in more detail. I have no problems setting rules, and no problems accessing data when rules are set to “true”. I am not using Firebase Authentication, just the Web API key._

One of the issues with using these Firebase Rules:

> ```
> {
> "rules": {
> ".read": true,
> ".write": true
> }
> }
> 
> ```

…is that anyone can access your Firebase DB via API (e.g. via cURL), **without the API key** , because those rules above mean that the Firebase DB is _open to the public_, as shown in this warning:

 ![firebase-rules-warning](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/1/1/1154a4bb0d730fd02d000cd6c3194545ccf0f453.png)

Essentially this means that you don’t need to use the API key, if your rules are set to the same as those above. I’ve done a video here (please do not share this video elsewhere), to demonstrate the data issues.

[![](https://img.youtube.com/vi/-XRDzPwahA8/maxresdefault.jpg "thunkable firebase rules demo") ](https://www.youtube.com/watch?v=-XRDzPwahA8)

Common database rules for Firebase: [Common Database Rules for Firebase · GitHub](https://gist.github.com/easaw/0e0ef0720a1726ac54cb4f9b3a1e1b14)

I’d also like to point out that for the time being I am using a REST API build on MySQL, instead of Firebase to ensure my data is secure. It’s not ideal, but secure is far more important than Realtime data.

_For those interested in the Dark Theme, there is a new post about it,_ [_more info here_](http://community.thunkable.com/t/unofficial-dark-theme-for-thunkable-x-with-video/978367)

---

<div class="post-metadata">

**Author:** ![eddie.rebehy](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/eddie.rebehy/32/67993_2.png) [@eddie.rebehy](https://community.thunkable.com/u/eddie.rebehy)\
**Post date:** [November 16, 2020, 9:45pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/2 "2020-11-16T21:45:42Z")

</div>

I have had no trouble setting rules. I will take a closer look at your post when in front of my screen.

I assume you have put in your own firebase credentials into Thunkable and you are not trying to sey rules using Thunkables default account.

---

<div class="post-metadata">

**Author:** ![drted](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/drted/32/92694_2.png) [@drted](https://community.thunkable.com/u/drted)\
**Post date:** [November 16, 2020, 9:49pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/3 "2020-11-16T21:49:16Z")

</div>

You are right, the rules need to be changed as soon as you figure out firebase. At a minimum, I use these

{  
“rules”: {  
“.read”: “auth.uid != null”,  
“.write”: “auth.uid != null”  
}  
}

---

<div class="post-metadata">

**Author:** ![appspark.uk](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/appspark.uk/32/84980_2.png) [@appspark.uk](https://community.thunkable.com/u/appspark.uk)\
**Post date:** [November 16, 2020, 9:55pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/5 "2020-11-16T21:55:34Z")

</div>

Please watch the video if you have time, it explains in more detail. Thank you.

---

<div class="post-metadata">

**Author:** ![eddie.rebehy](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/eddie.rebehy/32/67993_2.png) [@eddie.rebehy](https://community.thunkable.com/u/eddie.rebehy)\
**Post date:** [November 16, 2020, 9:58pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/6 "2020-11-16T21:58:25Z")

</div>

I’ve settled on this:

{  
“rules”: {  
“users”: {  
“$user\_id”: {  
“.write”: “$user\_id === auth.uid”,  
“.read”: “$user\_id === auth.uid”  
}  
}  
}  
}

excerpt of larger set. the parenthesis may not be paired. havn’t got my glasses with me. 🤣

---

<div class="post-metadata">

**Author:** ![appspark.uk](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/appspark.uk/32/84980_2.png) [@appspark.uk](https://community.thunkable.com/u/appspark.uk)\
**Post date:** [November 16, 2020, 10:00pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/7 "2020-11-16T22:00:52Z")

</div>

> [@drted](#):
>
> {  
> “rules”: {  
> “.read”: “auth.uid != null”,  
> “.write”: “auth.uid != null”  
> }  
> }

I can confirm that this does not allow API access to Firebase (unless using Firebase Auth as well).

---

<div class="post-metadata">

**Author:** ![appspark.uk](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/appspark.uk/32/84980_2.png) [@appspark.uk](https://community.thunkable.com/u/appspark.uk)\
**Post date:** [November 16, 2020, 10:03pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/8 "2020-11-16T22:03:42Z")

</div>

> [@eddie.rebehy](#):
>
> {  
> “rules”: {  
> “users”: {  
> “$user\_id”: {  
> “.write”: “$user\_id === auth.uid”,  
> “.read”: “$user\_id === auth.uid”  
> }  
> }  
> }  
> }
> 
> excerpt of la

I will try it, but I think you’ve use the wrong kind of inverted commas, it should be straight ones like this:

# "

Not 66/99 like this

# ”

Update: These kind of Rules will only work when using Firebase Authentication. **I am not using Firebase authentication.** As it states in the video.

---

<div class="post-metadata">

**Author:** ![eddie.rebehy](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/eddie.rebehy/32/67993_2.png) [@eddie.rebehy](https://community.thunkable.com/u/eddie.rebehy)\
**Post date:** [November 16, 2020, 10:11pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/9 "2020-11-16T22:11:52Z")

</div>

It may my phones keyboard doing that but…

i didn’t know it made a difference. lll have to research that.👍

---

<div class="post-metadata">

**Author:** ![appspark.uk](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/appspark.uk/32/84980_2.png) [@appspark.uk](https://community.thunkable.com/u/appspark.uk)\
**Post date:** [November 16, 2020, 10:13pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/10 "2020-11-16T22:13:21Z")

</div>

Please can anyone on this thread not shoot out a quick reply with what you assume is the answer, unless you actually watch the video, because at the moment everyone is giving wrong solutions.

If you have a solution, great, please post it! But I’m not here to ask for people to guess and post their suggestions…

---

<div class="post-metadata">

**Author:** ![eddie.rebehy](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/eddie.rebehy/32/67993_2.png) [@eddie.rebehy](https://community.thunkable.com/u/eddie.rebehy)\
**Post date:** [November 16, 2020, 10:16pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/11 "2020-11-16T22:16:48Z")

</div>

> [@appspark.uk](#):
>
> Please can anyone on this thread not shoot out a quick reply with what you assume is the answer, unless you actually watch the video, because at the moment everyone is giving wrong solutions.

interesting response. I answer threads for the benefit of the community in addition to the person posting. Apologies for my trigger happy reaponse. I will now leave this thread to someone that has access to the video with their glasses on. 😆

---

<div class="post-metadata">

**Author:** ![Dean\_Artis](https://avatars.discourse-cdn.com/v4/letter/d/a8b319/32.png) [@Dean\_Artis](https://community.thunkable.com/u/Dean_Artis)\
**Post date:** [November 17, 2020, 12:05am UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/12 "2020-11-17T00:05:57Z")

</div>

Interestingly I asked something not too dissimilar on the AI2 Forum. You can check out the topic [here](https://community.appinventor.mit.edu/t/questions-about-firebase-rules/20419/3).

---

<div class="post-metadata">

**Author:** ![eddie.rebehy](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/eddie.rebehy/32/67993_2.png) [@eddie.rebehy](https://community.thunkable.com/u/eddie.rebehy)\
**Post date:** [November 19, 2020, 5:41am UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/13 "2020-11-19T05:41:55Z")

</div>

What you are effectively seeking is the Firebase Admin SDK as opposed to the JS Client SDK. I have managed to implement this on my server and using it with Node JS and am looking into it for my PHP development. After communication with ‘Firebase support’ and a thread in the github community, I found out that unlike the Client SDK the admin sdk is not available on the web client side. As you say, this is not a Thunkable issue but a Google design parameter.

If you do find a workable solution, please update this thread and of course I will do the same.

---

<div class="post-metadata">

**Author:** ![appspark.uk](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/appspark.uk/32/84980_2.png) [@appspark.uk](https://community.thunkable.com/u/appspark.uk)\
**Post date:** [November 27, 2020, 5:20pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/14 "2020-11-27T17:20:18Z")

</div>

I think you may be right, and I might just have to use the web API to interface rather than using Thunkable’s solution, or role my own damn server with something like Mongo…

It sounds like you are using Thunkable to extend your existing web development skills, which is brilliant! It is exactly what I see this kind of environment as being the best use case for, rather than (just) those with zero coding skills, because it enables quick app development with existing data, which for me at least is exactly what I need!

For now I’m using SQL on cloud and JWT Auth to manage data. SQL on cloud has taken standard hosting MySQL response time from 9s, down to 0.5s!  
…EXCELLENT (Mr Burns)

---

<div class="post-metadata">

**Author:** ![shaabazk](https://avatars.discourse-cdn.com/v4/letter/s/ecd19e/32.png) [@shaabazk](https://community.thunkable.com/u/shaabazk)\
**Post date:** [November 17, 2021, 5:42am UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/15 "2021-11-17T05:42:11Z")

</div>

If you are ONLY using the Realtime DB and NOT Firebase Authentication, I would set read to true but write to false, this allows you to read the data but not edit it. Hope this helps!

---

<div class="post-metadata">

**Author:** ![muneer](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/muneer/32/75210_2.png) [@muneer](https://community.thunkable.com/u/muneer)\
**Post date:** [November 17, 2021, 7:48am UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/16 "2021-11-17T07:48:25Z")

</div>

@shaabazk  
You are replying on a post where the last response was **a year ago**.

---

<div class="post-metadata">

**Author:** ![ioannis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ioannis/32/146956_2.png) [@ioannis](https://community.thunkable.com/u/ioannis)\
**Post date:** [November 8, 2024, 12:21pm UTC](https://community.thunkable.com/t/unless-using-public-rules-in-firebase-the-api-key-can-t-access-data/978375/17 "2024-11-08T12:21:24Z")

</div>


