Skip to content

Commit 6b7403b

Browse files
chore(update-plugins): Tue Sep 15 13:07:21 UTC 2026
1 parent cf9b79f commit 6b7403b

1 file changed

Lines changed: 17 additions & 0 deletions

File tree

‎content/plugins/firebase-app-check.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,23 @@ If unset, the "tokenAutoRefreshEnabled" setting will defer to the app's "automat
104104

105105
The [official documentation](https://firebase.google.com/docs/app-check/web/custom-resource) shows how to use getToken to access the current App Check token and then verify it in external services.
106106

107+
```ts
108+
const { token } = await firebase().appCheck().getToken(false)
109+
// send `token` to your backend, e.g. as the X-Firebase-AppCheck header
110+
```
111+
112+
`getToken` returns a cached token that App Check refreshes in the background, so the same token is reused until it nears expiry. That is what you want for most requests.
113+
114+
### Replay protection (limited-use tokens)
115+
116+
If your backend enables [replay protection](https://firebase.google.com/docs/app-check/custom-resource-backend#replay-protection), it consumes each token once and rejects any token it has already seen. A cached token from `getToken` would fail on its second use, so those endpoints need a fresh, single-use token instead:
117+
118+
```ts
119+
const { token } = await firebase().appCheck().getLimitedUseToken()
120+
```
121+
122+
Call it per request — the token is deliberately not cached — and verify it on your backend with `verifyToken(token, { consume: true })`.
123+
107124
## License
108125

109126
Apache License Version 2.0

0 commit comments

Comments
 (0)