How can I rotate my API key for Firebase?












0














I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.



<script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
<script>
// Initialize Firebase
var config = {
apiKey: "my-key",
authDomain: "my_domain",
databaseURL: "my_db_url",
projectId: "my_project_id",
storageBucket: "my_storage_bucket",
messagingSenderId: "my_sender_id"
};
firebase.initializeApp(config);
</script>









share|improve this question



























    0














    I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.



    <script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
    <script>
    // Initialize Firebase
    var config = {
    apiKey: "my-key",
    authDomain: "my_domain",
    databaseURL: "my_db_url",
    projectId: "my_project_id",
    storageBucket: "my_storage_bucket",
    messagingSenderId: "my_sender_id"
    };
    firebase.initializeApp(config);
    </script>









    share|improve this question

























      0












      0








      0







      I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.



      <script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
      <script>
      // Initialize Firebase
      var config = {
      apiKey: "my-key",
      authDomain: "my_domain",
      databaseURL: "my_db_url",
      projectId: "my_project_id",
      storageBucket: "my_storage_bucket",
      messagingSenderId: "my_sender_id"
      };
      firebase.initializeApp(config);
      </script>









      share|improve this question













      I wasn't thinking and committed my project I'm starting to GitHub with my API key in one of my files. According to Google themselves, this isn't inherently dangerous itself but my concern is someone malicious could grab my key and use it in their project, potentially hitting limits on the free plan very quickly. I'm struggling to find out how I can grab a new key, any help? Below is a code snippet of what I exposed.



      <script src="https://www.gstatic.com/firebasejs/5.5.8/firebase.js"></script>
      <script>
      // Initialize Firebase
      var config = {
      apiKey: "my-key",
      authDomain: "my_domain",
      databaseURL: "my_db_url",
      projectId: "my_project_id",
      storageBucket: "my_storage_bucket",
      messagingSenderId: "my_sender_id"
      };
      firebase.initializeApp(config);
      </script>






      firebase google-cloud-platform






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 20 '18 at 14:35









      JoshJosh

      305518




      305518
























          1 Answer
          1






          active

          oldest

          votes


















          0














          While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL, projectId and storageBucket) can't be regenerated. You will have to create a new project to get all new keys.






          share|improve this answer

















          • 1




            Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
            – Josh
            Nov 20 '18 at 14:49






          • 1




            As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
            – Frank van Puffelen
            Nov 20 '18 at 14:57











          Your Answer






          StackExchange.ifUsing("editor", function () {
          StackExchange.using("externalEditor", function () {
          StackExchange.using("snippets", function () {
          StackExchange.snippets.init();
          });
          });
          }, "code-snippets");

          StackExchange.ready(function() {
          var channelOptions = {
          tags: "".split(" "),
          id: "1"
          };
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function() {
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled) {
          StackExchange.using("snippets", function() {
          createEditor();
          });
          }
          else {
          createEditor();
          }
          });

          function createEditor() {
          StackExchange.prepareEditor({
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader: {
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          },
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          });


          }
          });














          draft saved

          draft discarded


















          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53395331%2fhow-can-i-rotate-my-api-key-for-firebase%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          0














          While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL, projectId and storageBucket) can't be regenerated. You will have to create a new project to get all new keys.






          share|improve this answer

















          • 1




            Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
            – Josh
            Nov 20 '18 at 14:49






          • 1




            As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
            – Frank van Puffelen
            Nov 20 '18 at 14:57
















          0














          While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL, projectId and storageBucket) can't be regenerated. You will have to create a new project to get all new keys.






          share|improve this answer

















          • 1




            Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
            – Josh
            Nov 20 '18 at 14:49






          • 1




            As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
            – Frank van Puffelen
            Nov 20 '18 at 14:57














          0












          0








          0






          While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL, projectId and storageBucket) can't be regenerated. You will have to create a new project to get all new keys.






          share|improve this answer












          While some of these keys can be regenerated from the Firebase console, other keys (such as databaseURL, projectId and storageBucket) can't be regenerated. You will have to create a new project to get all new keys.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Nov 20 '18 at 14:45









          Frank van PuffelenFrank van Puffelen

          228k28373396




          228k28373396








          • 1




            Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
            – Josh
            Nov 20 '18 at 14:49






          • 1




            As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
            – Frank van Puffelen
            Nov 20 '18 at 14:57














          • 1




            Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
            – Josh
            Nov 20 '18 at 14:49






          • 1




            As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
            – Frank van Puffelen
            Nov 20 '18 at 14:57








          1




          1




          Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
          – Josh
          Nov 20 '18 at 14:49




          Got it. Luckily I'm only in the early stages so I can do this, but if someone made this mistake deep into their project they'd be hosed. Are there any plans to allow these to be rotated in the future?
          – Josh
          Nov 20 '18 at 14:49




          1




          1




          As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
          – Frank van Puffelen
          Nov 20 '18 at 14:57




          As you saw in other answers, there are not authentication credentials, but configuration data. Since the users of your app need this data for their app to be able to access the Firebase project, any malicious user can always get the exact same configuration data from the app.
          – Frank van Puffelen
          Nov 20 '18 at 14:57


















          draft saved

          draft discarded




















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.





          Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


          Please pay close attention to the following guidance:


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53395331%2fhow-can-i-rotate-my-api-key-for-firebase%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          "Incorrect syntax near the keyword 'ON'. (on update cascade, on delete cascade,)

          Alcedinidae

          Origin of the phrase “under your belt”?