firebase-app-check
Installation
SKILL.md
Firebase App Check
App Check verifies that incoming traffic to your Firebase services comes from your authentic, unmodified app — not a script, scraper, or repackaged binary. Without it, anyone with your Firebase web config (which ships in your client bundle) can hit your APIs.
Minimum viable example
import appCheck from "@react-native-firebase/app-check";
const provider = appCheck().newReactNativeFirebaseAppCheckProvider();
provider.configure({
android: { provider: "playIntegrity" },
apple: { provider: "appAttestWithDeviceCheckFallback" },
});
await appCheck().initializeAppCheck({ provider, isTokenAutoRefreshEnabled: true });
Must run before any other Firebase call (auth, Firestore, etc). Then flip enforcement on per product in the Firebase Console — but monitor unverified traffic for a week first.