App Check
Firebase App Check helps protect your backend resources, such as Firestore, Storage, and Cloud Functions, from abuse by verifying that requests originate from your genuine, unmodified application.
Why App Check Matters
Without App Check, malicious actors could potentially access your Firebase resources directly using your project’s public configuration, bypassing your actual application entirely.
Installing App Check
Configuring App Check Providers
Android uses Play Integrity API as its App Check provider, while iOS uses either DeviceCheck or the App Attest API, both verifying that requests come from an authentic app installation.
Using Debug Providers During Development
Enforcing App Check on Backend Resources
Once configured, App Check enforcement can be enabled per-service in the Firebase Console, rejecting requests that do not include a valid App Check token.
Monitoring App Check Metrics
The Firebase Console provides metrics showing the percentage of verified versus unverified requests, helping you monitor adoption before fully enforcing App Check in production.
Conclusion
Firebase App Check adds an essential layer of security, protecting your backend Firebase resources from abuse by verifying that requests genuinely originate from your React Native application.

