App Check

React Native 6 min min read Updated: Aug 03, 2026 Advanced
App Check
Advanced Topic 13 of 18

App Check

Firebase App Check helps protect your backend resources, such as Firestore, Storage, and Cloud Functions, from abuse by verifying that requests originate from your genuine, unmodified application.

Why App Check Matters

Without App Check, malicious actors could potentially access your Firebase resources directly using your project’s public configuration, bypassing your actual application entirely.

Installing App Check

bash npm install @react-native-firebase/app-check

Configuring App Check Providers

Android uses Play Integrity API as its App Check provider, while iOS uses either DeviceCheck or the App Attest API, both verifying that requests come from an authentic app installation.

javascript import appCheck from '@react-native-firebase/app-check'; await appCheck().activate('your-recaptcha-or-provider-key', true);

Using Debug Providers During Development

javascript const rnfbProvider = appCheck().newReactNativeFirebaseAppCheckProvider(); rnfbProvider.configure({ android: { provider: __DEV__ ? 'debug' : 'playIntegrity' }, apple: { provider: __DEV__ ? 'debug' : 'appAttest' }, });

Enforcing App Check on Backend Resources

Once configured, App Check enforcement can be enabled per-service in the Firebase Console, rejecting requests that do not include a valid App Check token.

Monitoring App Check Metrics

The Firebase Console provides metrics showing the percentage of verified versus unverified requests, helping you monitor adoption before fully enforcing App Check in production.

Conclusion

Firebase App Check adds an essential layer of security, protecting your backend Firebase resources from abuse by verifying that requests genuinely originate from your React Native application.

Get Newsletter

Subscibe to our newsletter and we will notify you about the newest updates on Edugators