---
description: Unofficial Capacitor plugin for Firebase App Check SDK to protect your app's resources from abuse with support for Android, iOS, and Web.
title: Capacitor Firebase App Check Plugin - Capawesome
image: https://capawesome.io/docs/assets/images/social/sdks/capacitor/firebase/app-check.png
---

<!doctype html> 

[Skip to content ](#capacitor-firebaseapp-check) 

[🖥️ Introducing the **Capacitor Electron Platform** — build desktop apps for macOS, Windows, and Linux. Free & open source. ](/blog/announcing-the-capacitor-electron-platform/) 

* [ SDKs ](/docs/sdks/)
* [ iOS ](#ios)
* [ Web ](#web)
* [ Configuration ](#configuration)
* [ Firebase JavaScript SDK ](#firebase-javascript-sdk)
* [ Demo ](#demo)
* [ Usage ](#usage)
* [ API ](#api)
* [ Type Aliases ](#type-aliases)
* [ Testing ](#testing)
* [ FAQ ](#faq)
* [ Related Plugins ](#related-plugins)
* [ Newsletter ](#newsletter)
* [ Changelog ](#changelog)
* [ License ](#license)
* [ Authentication ](/docs/sdks/capacitor/firebase/authentication/)
* [ Crashlytics ](/docs/sdks/capacitor/firebase/crashlytics/)
* [ Cloud Firestore ](/docs/sdks/capacitor/firebase/cloud-firestore/)
* [ Cloud Functions ](/docs/sdks/capacitor/firebase/cloud-functions/)
* [ Cloud Messaging ](/docs/sdks/capacitor/firebase/cloud-messaging/)
* [ Cloud Storage ](/docs/sdks/capacitor/firebase/cloud-storage/)
* [ Performance Monitoring ](/docs/sdks/capacitor/firebase/performance-monitoring/)
* [ Remote Config ](/docs/sdks/capacitor/firebase/remote-config/)
* [ Formbricks ](/docs/sdks/capacitor/formbricks/)
* [ Geocoder ](/docs/sdks/capacitor/geocoder/)
* [ Google Sign-In ](/docs/sdks/capacitor/google-sign-in/)
* [ Grafana Faro ](/docs/sdks/capacitor/grafana-faro/)
* [ Gyroscope ](/docs/sdks/capacitor/gyroscope/)
* [ Haptics ](/docs/sdks/capacitor/haptics/)
* [ Home Indicator ](/docs/sdks/capacitor/home-indicator/)
* [ In-App Browser ](/docs/sdks/capacitor/in-app-browser/)
* [ Install Referrer ](/docs/sdks/capacitor/install-referrer/)
* [ Intercom ](/docs/sdks/capacitor/intercom/)
* [ Intune ](/docs/sdks/capacitor/intune/)
* [ Keep Awake ](/docs/sdks/capacitor/keep-awake/)
* [ libSQL ](/docs/sdks/capacitor/libsql/)
* [ Light Sensor ](/docs/sdks/capacitor/light-sensor/)
* [ Live Update ](/docs/sdks/capacitor/live-update/)
* [ Localization ](/docs/sdks/capacitor/localization/)
* [ Mail Composer ](/docs/sdks/capacitor/mail-composer/)
* [ Managed Configurations ](/docs/sdks/capacitor/managed-configurations/)
* [ Maps Launcher ](/docs/sdks/capacitor/maps-launcher/)
* [ Media Session ](/docs/sdks/capacitor/media-session/)
* [ ML Kit ](/docs/sdks/capacitor/mlkit/)
* [ Navigation Bar ](/docs/sdks/capacitor/navigation-bar/)
* [ Network ](/docs/sdks/capacitor/network/)
* [ NFC ](/docs/sdks/capacitor/nfc/)
* [ Node.js ](/docs/sdks/capacitor/nodejs/)
* [ OAuth ](/docs/sdks/capacitor/oauth/)
* [ Passkeys ](/docs/sdks/capacitor/passkeys/)
* [ Password Autofill ](/docs/sdks/capacitor/password-autofill/)
* [ PDF Generator ](/docs/sdks/capacitor/pdf-generator/)
* [ PDF Viewer ](/docs/sdks/capacitor/pdf-viewer/)
* [ Pedometer ](/docs/sdks/capacitor/pedometer/)
* [ Permissions ](/docs/sdks/capacitor/permissions/)
* [ Phone Dialer ](/docs/sdks/capacitor/phone-dialer/)
* [ Photo Editor ](/docs/sdks/capacitor/photo-editor/)
* [ Photo Manipulator ](/docs/sdks/capacitor/photo-manipulator/)
* [ PixLive ](/docs/sdks/capacitor/pixlive/)
* [ PostHog ](/docs/sdks/capacitor/posthog/)
* [ Printer ](/docs/sdks/capacitor/printer/)
* [ Privacy Screen ](/docs/sdks/capacitor/privacy-screen/)
* [ Proximity Sensor ](/docs/sdks/capacitor/proximity-sensor/)
* [ Purchases ](/docs/sdks/capacitor/purchases/)
* [ RealtimeKit ](/docs/sdks/capacitor/realtimekit/)
* [ Root Detection ](/docs/sdks/capacitor/root-detection/)
* [ Screen Brightness ](/docs/sdks/capacitor/screen-brightness/)
* [ Screen Orientation ](/docs/sdks/capacitor/screen-orientation/)
* [ Screen Reader ](/docs/sdks/capacitor/screen-reader/)
* [ Screenshot ](/docs/sdks/capacitor/screenshot/)
* [ Secure Preferences ](/docs/sdks/capacitor/secure-preferences/)
* [ Settings Launcher ](/docs/sdks/capacitor/settings-launcher/)
* [ Shake ](/docs/sdks/capacitor/shake/)
* [ Silent Mode ](/docs/sdks/capacitor/silent-mode/)
* [ SIM ](/docs/sdks/capacitor/sim/)
* [ SMS Composer ](/docs/sdks/capacitor/sms-composer/)
* [ Speech Recognition ](/docs/sdks/capacitor/speech-recognition/)
* [ Speech Synthesis ](/docs/sdks/capacitor/speech-synthesis/)
* [ Share Target ](/docs/sdks/capacitor/share-target/)
* [ Square Mobile Payments ](/docs/sdks/capacitor/square-mobile-payments/)
* [ SQLite ](/docs/sdks/capacitor/sqlite/)
* [ Superwall ](/docs/sdks/capacitor/superwall/)
* [ System WebView ](/docs/sdks/capacitor/system-webview/)
* [ Tauri ](/docs/sdks/capacitor/tauri/)
* [ Text Interaction ](/docs/sdks/capacitor/text-interaction/)
* [ Text Zoom ](/docs/sdks/capacitor/text-zoom/)
* [ Thermal State ](/docs/sdks/capacitor/thermal-state/)
* [ Toast ](/docs/sdks/capacitor/toast/)
* [ Torch ](/docs/sdks/capacitor/torch/)
* [ Vault ](/docs/sdks/capacitor/vault/)
* [ Volume ](/docs/sdks/capacitor/volume/)
* [ Wallet ](/docs/sdks/capacitor/wallet/)
* [ Wifi ](/docs/sdks/capacitor/wifi/)
* [ YouTube Player ](/docs/sdks/capacitor/youtube-player/)
* [ Zip ](/docs/sdks/capacitor/zip/)
* [ Cordova ](/docs/sdks/cordova/)
* [ Cloud ](/docs/cloud/)
* [ Integrations ](/docs/cloud/live-updates/integrations/)
* Concepts
* Reference
* [ Troubleshooting ](/docs/cloud/live-updates/troubleshooting/)
* [ FAQ ](/docs/cloud/live-updates/faq/)
* [ Native Builds ](/docs/cloud/native-builds/)
* [ Set Up Environments ](/docs/cloud/native-builds/environments/)
* [ Overwrite Native Configurations ](/docs/cloud/native-builds/native-configurations/)
* [ Auto-Increment Build Numbers ](/docs/cloud/native-builds/auto-incrementing-build-numbers/)
* [ Configure the Web Build Script ](/docs/cloud/native-builds/web-build-script/)
* [ Build from a Monorepo ](/docs/cloud/native-builds/monorepo/)
* [ Use pnpm, Yarn, or bun ](/docs/cloud/native-builds/package-managers/)
* [ Install Private npm Packages ](/docs/cloud/native-builds/npm-private-registry/)
* [ Override the Java Version ](/docs/cloud/native-builds/override-java-version/)
* [ Custom iOS Provisioning Profiles ](/docs/cloud/native-builds/custom-ios-provisioning-profiles/)
* [ Build without Git ](/docs/cloud/native-builds/build-without-git/)
* [ Access Git Behind a Firewall ](/docs/cloud/native-builds/firewall-access/)
* [ Integrations ](/docs/cloud/native-builds/integrations/)
* Reference
* [ Troubleshooting ](/docs/cloud/native-builds/troubleshooting/)
* [ FAQ ](/docs/cloud/native-builds/faq/)
* [ App Store Publishing ](/docs/cloud/app-store-publishing/)
* [ Submit a Build ](/docs/cloud/app-store-publishing/submit-a-build/)
* [ Submit Automatically After a Build ](/docs/cloud/app-store-publishing/submit-automatically/)
* [ Troubleshooting ](/docs/cloud/app-store-publishing/troubleshooting/)
* [ FAQ ](/docs/cloud/app-store-publishing/faq/)
* [ Automations ](/docs/cloud/automations/)
* [ Reference ](/docs/cloud/automations/reference/)
* [ Troubleshooting ](/docs/cloud/automations/troubleshooting/)
* [ FAQ ](/docs/cloud/automations/faq/)
* [ Assist ](/docs/cloud/assist/)
* [ CLI ](/docs/cloud/cli/)
* APIs and SDKs
* [ Webhooks ](/docs/cloud/webhooks/)
* [ Integrations ](/docs/cloud/integrations/)
* Account
* [ Organization ](/docs/cloud/organizations/)
* [ Two-Factor Enforcement ](/docs/cloud/organizations/two-factor-authentication/)
* [ Audit Logs ](/docs/cloud/organizations/audit-logs/)
* [ Billing ](/docs/cloud/organizations/billing/)
* [ License Keys ](/docs/cloud/license-keys/)
* [ AI ](/docs/ai/)
* [ Insiders ](/docs/insiders/)
* [ Billing & Plans ](/docs/insiders/billing-and-plans/)
* [ FAQ ](/docs/insiders/faq/)
* [ License ](https://capawesome.io/legal/eula/)
* [ Support ](/docs/support/)
* [ Contributing ](/docs/contributing/)
* Contributing code
* [ Code of Conduct ](/docs/contributing/code-of-conduct/)
* [ Questions ](https://docs.github.com/en/discussions/collaborating-with-your-community-using-discussions/participating-in-a-discussion#creating-a-discussion)
* [ Blog ](/blog/)
* Categories

* [ iOS ](#ios)
* [ Web ](#web)
* [ Configuration ](#configuration)
* [ Firebase JavaScript SDK ](#firebase-javascript-sdk)
* [ Demo ](#demo)
* [ Usage ](#usage)
* [ API ](#api)
* [ Type Aliases ](#type-aliases)
* [ Testing ](#testing)
* [ FAQ ](#faq)
* [ Related Plugins ](#related-plugins)
* [ Newsletter ](#newsletter)
* [ Changelog ](#changelog)
* [ License ](#license)

# @capacitor-firebase/app-check[¶](#capacitor-firebaseapp-check "Permanent link")

Unofficial Capacitor plugin for [Firebase App Check](https://firebase.google.com/docs/app-check).[1](#fn:1)

[ ![Deliver Live Updates to your Capacitor app with Capawesome Cloud](../../../../assets/external/cloud.capawesome.io/assets/banners/cloud-build-and-deploy-capacitor-apps.69628c3f.png) ](https://cloud.capawesome.io/) 

## Use Cases[¶](#use-cases "Permanent link")

The Firebase App Check plugin is typically used to verify that requests to your backend originate from your authentic app, for example:

* **Protecting Firebase resources**: Ensure that only your genuine app can access services like Cloud Firestore or Cloud Functions by attesting requests with Play Integrity, App Attest, or reCAPTCHA v3.
* **Securing custom backends**: Retrieve an App Check token with `getToken(...)` and send it along with requests to your own backend for server-side verification.
* **Automatic token refresh**: Keep App Check tokens up to date with `setTokenAutoRefreshEnabled(...)` and react to changes via the `tokenChanged` listener.
* **Local development**: Use the debug provider to test your app on unverified devices such as emulators.

## Compatibility[¶](#compatibility "Permanent link")

| Plugin Version | Capacitor Version | Status         |
| -------------- | ----------------- | -------------- |
| 8.x.x          | \>=8.x.x          | Active support |
| 7.x.x          | 7.x.x             | Deprecated     |
| 6.x.x          | 6.x.x             | Deprecated     |
| 5.x.x          | 5.x.x             | Deprecated     |

## Installation[¶](#installation "Permanent link")

You can use our **AI-Assisted Setup** to install the plugin. Add the [Capawesome Skills](https://github.com/capawesome-team/skills) to your AI tool using the following command:

`[](#%5F%5Fcodelineno-0-1)npx skills add capawesome-team/skills --skill capacitor-plugins
`

Then use the following prompt:

`` [](#%5F%5Fcodelineno-1-1)Use the `capacitor-plugins` skill from `capawesome-team/skills` to install the `@capacitor-firebase/app-check` plugin in my project.
 ``

If you prefer **Manual Setup**, install the plugin by running the following commands and follow the platform-specific instructions below:

`[](#%5F%5Fcodelineno-2-1)npm install @capacitor-firebase/app-check firebase
[](#%5F%5Fcodelineno-2-2)npx cap sync
`

Add Firebase to your project if you haven't already ([Android](https://github.com/capawesome-team/capacitor-firebase/blob/main/docs/firebase-setup.md#android) / [iOS](https://github.com/capawesome-team/capacitor-firebase/blob/main/docs/firebase-setup.md#ios) / [Web](https://github.com/capawesome-team/capacitor-firebase/blob/main/docs/firebase-setup.md#web)).

### Android[¶](#android "Permanent link")

See [Set up your Firebase project](https://firebase.google.com/docs/app-check/android/play-integrity-provider#project-setup) and follow the instructions to set up your app correctly.

#### Variables[¶](#variables "Permanent link")

If needed, you can define the following project variable in your app’s `variables.gradle` file to change the default version of the dependency:

* `$firebaseAppCheckPlayIntegrityVersion` version of `com.google.firebase:firebase-appcheck-playintegrity` (default: `19.0.1`)
* `$firebaseAppCheckDebugVersion` version of `com.google.firebase:firebase-appcheck-debug` (default: `19.0.1`)

This can be useful if you encounter dependency conflicts with other plugins in your project.

### iOS[¶](#ios "Permanent link")

On **iOS 14 and later**, see [Set up your Firebase project](https://firebase.google.com/docs/app-check/ios/app-attest-provider#project-setup) and follow the instructions to set up your app correctly.

On **iOS 13**, see [Set up your Firebase project](https://firebase.google.com/docs/app-check/ios/devicecheck-provider#project-setup) and follow the instructions to set up your app correctly.

Make sure that the private key (\*.p8) you upload to Firebase has `DeviceCheck` selected as a service.

#### Swift Package Manager[¶](#swift-package-manager "Permanent link")

Add the following to your `capacitor.config.json` (or `capacitor.config.ts`) to avoid a [SwiftPM package identity collision](https://github.com/capawesome-team/capacitor-firebase/issues/959):

`[](#%5F%5Fcodelineno-3-1){
[](#%5F%5Fcodelineno-3-2)  "experimental": {
[](#%5F%5Fcodelineno-3-3)    "ios": {
[](#%5F%5Fcodelineno-3-4)      "spm": {
[](#%5F%5Fcodelineno-3-5)        "packageOptions": {
[](#%5F%5Fcodelineno-3-6)          "@capacitor-firebase/app-check": {
[](#%5F%5Fcodelineno-3-7)            "symlink": true
[](#%5F%5Fcodelineno-3-8)          }
[](#%5F%5Fcodelineno-3-9)        }
[](#%5F%5Fcodelineno-3-10)      }
[](#%5F%5Fcodelineno-3-11)    }
[](#%5F%5Fcodelineno-3-12)  }
[](#%5F%5Fcodelineno-3-13)}
`

**Attention**: SPM `packageOptions` support requires Capacitor CLI **8.4.0+**.

### Web[¶](#web "Permanent link")

See [Set up your Firebase project](https://firebase.google.com/docs/app-check/web/recaptcha-provider#project-setup) and follow the instructions to set up your app correctly.

## Configuration[¶](#configuration "Permanent link")

No configuration required for this plugin.

## Firebase JavaScript SDK[¶](#firebase-javascript-sdk "Permanent link")

[Here](https://github.com/capawesome-team/capacitor-firebase/blob/main/packages/app-check/docs/firebase-js-sdk.md) you can find information on how to use the plugin with the Firebase JS SDK.

## Demo[¶](#demo "Permanent link")

A working example can be found here: [robingenz/capacitor-firebase-plugin-demo](https://github.com/robingenz/capacitor-firebase-plugin-demo)

## Usage[¶](#usage "Permanent link")

The following examples show how to initialize App Check, get the current token, enable automatic token refresh, and listen for token changes.

### Initialize App Check[¶](#initialize-app-check "Permanent link")

Activate App Check for your app. This can be called only once per app. On the Web, pass a provider such as `ReCaptchaV3Provider`; on Android and iOS, the native attestation providers are used:

`[](#%5F%5Fcodelineno-4-1)import { FirebaseAppCheck } from '@capacitor-firebase/app-check';
[](#%5F%5Fcodelineno-4-2)import { ReCaptchaV3Provider } from '@capacitor-firebase/app-check';
[](#%5F%5Fcodelineno-4-3)import { Capacitor } from '@capacitor/core';
[](#%5F%5Fcodelineno-4-4)
[](#%5F%5Fcodelineno-4-5)const initialize = async () => {
[](#%5F%5Fcodelineno-4-6)  await FirebaseAppCheck.initialize({
[](#%5F%5Fcodelineno-4-7)    provider: Capacitor.getPlatform() === 'web' ? new ReCaptchaV3Provider('myKey') : undefined,
[](#%5F%5Fcodelineno-4-8)  });
[](#%5F%5Fcodelineno-4-9)};
`

### Get the current App Check token[¶](#get-the-current-app-check-token "Permanent link")

Retrieve the current App Check token, for example to send it to your own backend. Set `forceRefresh` to `true` if you always want to fetch a fresh token instead of a cached one:

`[](#%5F%5Fcodelineno-5-1)import { FirebaseAppCheck } from '@capacitor-firebase/app-check';
[](#%5F%5Fcodelineno-5-2)
[](#%5F%5Fcodelineno-5-3)const getToken = async () => {
[](#%5F%5Fcodelineno-5-4)  const { token } = await FirebaseAppCheck.getToken({
[](#%5F%5Fcodelineno-5-5)    forceRefresh: false,
[](#%5F%5Fcodelineno-5-6)  });
[](#%5F%5Fcodelineno-5-7)  return token;
[](#%5F%5Fcodelineno-5-8)};
`

### Enable automatic token refresh[¶](#enable-automatic-token-refresh "Permanent link")

Set whether the App Check token should be refreshed automatically as needed:

`[](#%5F%5Fcodelineno-6-1)import { FirebaseAppCheck } from '@capacitor-firebase/app-check';
[](#%5F%5Fcodelineno-6-2)
[](#%5F%5Fcodelineno-6-3)const setTokenAutoRefreshEnabled = async () => {
[](#%5F%5Fcodelineno-6-4)  await FirebaseAppCheck.setTokenAutoRefreshEnabled({ enabled: true });
[](#%5F%5Fcodelineno-6-5)};
`

### Listen for token changes[¶](#listen-for-token-changes "Permanent link")

Get notified whenever the App Check token changes:

`[](#%5F%5Fcodelineno-7-1)import { FirebaseAppCheck } from '@capacitor-firebase/app-check';
[](#%5F%5Fcodelineno-7-2)
[](#%5F%5Fcodelineno-7-3)const addTokenChangedListener = async () => {
[](#%5F%5Fcodelineno-7-4)  await FirebaseAppCheck.addListener('tokenChanged', event => {
[](#%5F%5Fcodelineno-7-5)    console.log('tokenChanged', { event });
[](#%5F%5Fcodelineno-7-6)  });
[](#%5F%5Fcodelineno-7-7)};
`

### Remove all listeners[¶](#remove-all-listeners "Permanent link")

Remove all listeners for this plugin. Only available on Web:

`[](#%5F%5Fcodelineno-8-1)import { FirebaseAppCheck } from '@capacitor-firebase/app-check';
[](#%5F%5Fcodelineno-8-2)
[](#%5F%5Fcodelineno-8-3)const removeAllListeners = async () => {
[](#%5F%5Fcodelineno-8-4)  await FirebaseAppCheck.removeAllListeners();
[](#%5F%5Fcodelineno-8-5)};
`

## API[¶](#api "Permanent link")

* [getToken(...)](#gettoken)
* [initialize(...)](#initialize)
* [setTokenAutoRefreshEnabled(...)](#settokenautorefreshenabled)
* [addListener('tokenChanged', ...)](#addlistenertokenchanged-)
* [removeAllListeners()](#removealllisteners)
* [Interfaces](#interfaces)
* [Type Aliases](#type-aliases)

### getToken(...)[¶](#gettoken "Permanent link")

`[](#%5F%5Fcodelineno-9-1)getToken(options?: GetTokenOptions | undefined) => Promise<GetTokenResult>
`

Get the current App Check token.

| Param       | Type                                |
| ----------- | ----------------------------------- |
| **options** | [GetTokenOptions](#gettokenoptions) |

**Returns:** `Promise<[GetTokenResult](#gettokenresult)>`

**Since:** 1.3.0

---

### initialize(...)[¶](#initialize "Permanent link")

`[](#%5F%5Fcodelineno-10-1)initialize(options?: InitializeOptions | undefined) => Promise<void>
`

Activate App Check for the given app. Can be called only once per app.

| Param       | Type                                    |
| ----------- | --------------------------------------- |
| **options** | [InitializeOptions](#initializeoptions) |

**Since:** 1.3.0

---

### setTokenAutoRefreshEnabled(...)[¶](#settokenautorefreshenabled "Permanent link")

`[](#%5F%5Fcodelineno-11-1)setTokenAutoRefreshEnabled(options: SetTokenAutoRefreshEnabledOptions) => Promise<void>
`

Set whether the App Check token should be refreshed automatically or not.

| Param       | Type                                                                    |
| ----------- | ----------------------------------------------------------------------- |
| **options** | [SetTokenAutoRefreshEnabledOptions](#settokenautorefreshenabledoptions) |

**Since:** 1.3.0

---

### addListener('tokenChanged', ...)[¶](#addlistenertokenchanged "Permanent link")

`[](#%5F%5Fcodelineno-12-1)addListener(eventName: 'tokenChanged', listenerFunc: TokenChangedListener) => Promise<PluginListenerHandle>
`

Called when the App Check token changed.

| Param            | Type                                          |
| ---------------- | --------------------------------------------- |
| **eventName**    | 'tokenChanged'                                |
| **listenerFunc** | [TokenChangedListener](#tokenchangedlistener) |

**Returns:** `Promise<[PluginListenerHandle](#pluginlistenerhandle)>`

**Since:** 1.3.0

---

### removeAllListeners()[¶](#removealllisteners "Permanent link")

`[](#%5F%5Fcodelineno-13-1)removeAllListeners() => Promise<void>
`

Remove all listeners for this plugin.

Only available for Web.

**Since:** 1.3.0

---

### Interfaces[¶](#interfaces "Permanent link")

#### GetTokenResult[¶](#gettokenresult "Permanent link")

| Prop                 | Type   | Description                                                                                                      | Since |
| -------------------- | ------ | ---------------------------------------------------------------------------------------------------------------- | ----- |
| **token**            | string | The App Check token in JWT format.                                                                               | 1.3.0 |
| **expireTimeMillis** | number | The timestamp after which the token will expire in milliseconds since epoch. Only available for Android and iOS. | 1.3.0 |

#### GetTokenOptions[¶](#gettokenoptions "Permanent link")

| Prop             | Type    | Description                                                                                             | Default | Since |
| ---------------- | ------- | ------------------------------------------------------------------------------------------------------- | ------- | ----- |
| **forceRefresh** | boolean | If true, will always try to fetch a fresh token. If false, will use a cached token if found in storage. | false   | 1.3.0 |

#### InitializeOptions[¶](#initializeoptions "Permanent link")

| Prop                          | Type              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                     | Default             | Since |
| ----------------------------- | ----------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------- | ----- |
| **debug**                     | boolean           | If true, the debug provider is used. ⚠️ **Attention**: The debug provider allows access to your Firebase resources from unverified devices. Don't use the debug provider in production builds of your app, and don't share your debug builds with untrusted parties. ⚠️ **Deprecated**: Use debugToken instead. This option will be removed in the next major version. Read more: https://firebase.google.com/docs/app-check/web/debug-provider | false               | 1.3.0 |
| **debugToken**                | string \| boolean | If true, the debug provider is used. On **Web**, you can also set a predefined debug token string instead of true. On Android and iOS, you have to use environment variables for this. ⚠️ **Attention**: The debug provider allows access to your Firebase resources from unverified devices. Don't use the debug provider in production builds of your app, and don't share your debug builds with untrusted parties.                          | false               | 7.1.0 |
| **isTokenAutoRefreshEnabled** | boolean           | If true, the SDK automatically refreshes App Check tokens as needed.                                                                                                                                                                                                                                                                                                                                                                            | false               | 1.3.0 |
| **provider**                  | any               | The provider to use for App Check. Must be an instance of ReCaptchaV3Provider, ReCaptchaEnterpriseProvider, or CustomProvider. Only available for Web.                                                                                                                                                                                                                                                                                          | ReCaptchaV3Provider | 7.1.0 |
| **siteKey**                   | string            | The reCAPTCHA v3 site key (public key). This option is ignored when provider is set. Only available for Web.                                                                                                                                                                                                                                                                                                                                    |                     | 1.3.0 |

#### SetTokenAutoRefreshEnabledOptions[¶](#settokenautorefreshenabledoptions "Permanent link")

| Prop        | Type    | Description                                                                                                                    | Since |
| ----------- | ------- | ------------------------------------------------------------------------------------------------------------------------------ | ----- |
| **enabled** | boolean | If true, the SDK automatically refreshes App Check tokens as needed. This overrides any value set during initializeAppCheck(). | 1.3.0 |

#### PluginListenerHandle[¶](#pluginlistenerhandle "Permanent link")

| Prop       | Type                |
| ---------- | ------------------- |
| **remove** | () => Promise<void> |

#### TokenChangedEvent[¶](#tokenchangedevent "Permanent link")

| Prop      | Type   | Description                        | Since |
| --------- | ------ | ---------------------------------- | ----- |
| **token** | string | The App Check token in JWT format. | 1.3.0 |

### Type Aliases[¶](#type-aliases "Permanent link")

#### TokenChangedListener[¶](#tokenchangedlistener "Permanent link")

Callback to receive the token change event.

`(event: [TokenChangedEvent](#tokenchangedevent)): void`

## Testing[¶](#testing "Permanent link")

### Android[¶](#android%5F1 "Permanent link")

Follow these steps to test your implementation on a real device:

1. Start your app on the Android device.
2. Run the following command to grab your temporary secret from the android logs:

`[](#%5F%5Fcodelineno-14-1)adb logcat | grep DebugAppCheckProvider
`

The output should look like this:

`[](#%5F%5Fcodelineno-15-1)D DebugAppCheckProvider: Enter this debug secret into the allow list in
[](#%5F%5Fcodelineno-15-2)the Firebase Console for your project: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
`

1. Next, open the [App Check project](https://console.firebase.google.com/u/0/project/%5F/appcheck/apps) in the Firebase Console and select Manage debug tokens from the overflow menu of your app. Then, register the debug secret from the output.

## FAQ[¶](#faq "Permanent link")

### Which attestation providers does this plugin use?[¶](#which-attestation-providers-does-this-plugin-use "Permanent link")

On Android, the plugin uses the [Play Integrity](https://firebase.google.com/docs/app-check/android/play-integrity-provider#project-setup) provider. On iOS, it uses [App Attest](https://firebase.google.com/docs/app-check/ios/app-attest-provider#project-setup) on iOS 14 and later and [DeviceCheck](https://firebase.google.com/docs/app-check/ios/devicecheck-provider#project-setup) on iOS 13\. On the Web, it uses [reCAPTCHA v3](https://firebase.google.com/docs/app-check/web/recaptcha-provider#project-setup) by default, but you can also pass a `ReCaptchaEnterpriseProvider` or `CustomProvider` instance via the `provider` option.

### How can I test App Check on emulators and other unverified devices?[¶](#how-can-i-test-app-check-on-emulators-and-other-unverified-devices "Permanent link")

Use the debug provider by setting the `debugToken` option of the `initialize(...)` method. On Android, you can grab the temporary debug secret from the device logs and register it in the Firebase Console (see [Testing](#testing)). Never use the debug provider in production builds of your app and never share your debug builds with untrusted parties, as it allows access to your Firebase resources from unverified devices.

### How do I protect my own backend with App Check?[¶](#how-do-i-protect-my-own-backend-with-app-check "Permanent link")

Call the `getToken(...)` method to retrieve the current App Check token in JWT format and send it along with requests to your backend, where you can verify it server-side. Use the `tokenChanged` listener to get notified whenever the token changes.

### Why is my App Check token not refreshed automatically?[¶](#why-is-my-app-check-token-not-refreshed-automatically "Permanent link")

Automatic token refresh is disabled by default. You can enable it with the `isTokenAutoRefreshEnabled` option of the `initialize(...)` method or at any time with the `setTokenAutoRefreshEnabled(...)` method.

### Can I use this plugin with Ionic, React, Vue or Angular?[¶](#can-i-use-this-plugin-with-ionic-react-vue-or-angular "Permanent link")

Yes, the plugin is framework-agnostic. It works in any Capacitor app regardless of the web framework, including Ionic with Angular, React, or Vue, as well as plain JavaScript projects.

## Related Plugins[¶](#related-plugins "Permanent link")

* [Firebase Authentication](https://capawesome.io/docs/sdks/capacitor/firebase/authentication/): Unofficial Capacitor plugin for Firebase Authentication.
* [Firebase Cloud Firestore](https://capawesome.io/docs/sdks/capacitor/firebase/cloud-firestore/): Unofficial Capacitor plugin for Firebase Cloud Firestore.
* [Firebase Cloud Functions](https://capawesome.io/docs/sdks/capacitor/firebase/cloud-functions/): Unofficial Capacitor plugin for Firebase Cloud Functions.
* [Firebase Cloud Storage](https://capawesome.io/docs/sdks/capacitor/firebase/cloud-storage/): Unofficial Capacitor plugin for Firebase Cloud Storage.

## Newsletter[¶](#newsletter "Permanent link")

Stay up to date with the latest news and updates about the Capawesome, Capacitor, and Ionic ecosystem by subscribing to our [Capawesome Newsletter](https://cloud.capawesome.io/newsletter/).

## Changelog[¶](#changelog "Permanent link")

See [CHANGELOG.md](https://github.com/capawesome-team/capacitor-firebase/blob/main/packages/app-check/CHANGELOG.md).

## License[¶](#license "Permanent link")

See [LICENSE](https://github.com/capawesome-team/capacitor-firebase/blob/main/packages/app-check/LICENSE).

---

1. This project is not affiliated with, endorsed by, sponsored by, or approved by Google LLC or any of their affiliates or subsidiaries. [↩](#fnref:1 "Jump back to footnote 1 in the text")

July 8, 2026 

Back to top

```json
{"@context": "https://schema.org", "@graph": [{"@type": "TechArticle", "@id": "https://capawesome.io/docs/sdks/capacitor/firebase/app-check/#article", "headline": "Capacitor Firebase App Check Plugin", "name": "Capacitor Firebase App Check Plugin", "description": "Unofficial Capacitor plugin for Firebase App Check SDK to protect your app's resources from abuse with support for Android, iOS, and Web.", "inLanguage": "en", "url": "https://capawesome.io/docs/sdks/capacitor/firebase/app-check/", "mainEntityOfPage": "https://capawesome.io/docs/sdks/capacitor/firebase/app-check/", "author": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}, "publisher": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}, "about": {"@id": "https://capawesome.io/docs/sdks/capacitor/firebase/app-check/#software"}}, {"@type": "SoftwareSourceCode", "@id": "https://capawesome.io/docs/sdks/capacitor/firebase/app-check/#software", "name": "Capacitor Firebase App Check Plugin", "description": "Unofficial Capacitor plugin for Firebase App Check SDK to protect your app's resources from abuse with support for Android, iOS, and Web.", "url": "https://capawesome.io/docs/sdks/capacitor/firebase/app-check/", "programmingLanguage": "TypeScript", "runtimePlatform": "Capacitor", "codeRepository": "https://github.com/capawesome-team", "author": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}, "publisher": {"@type": "Organization", "name": "Capawesome", "url": "https://capawesome.io", "logo": {"@type": "ImageObject", "url": "https://capawesome.io/assets/images/logo.svg"}}}]}
{"@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "Which attestation providers does this plugin use?", "acceptedAnswer": {"@type": "Answer", "text": "On Android, the plugin uses the Play Integrity provider. On iOS, it uses App Attest on iOS 14 and later and DeviceCheck on iOS 13. On the Web, it uses reCAPTCHA v3 by default, but you can also pass a ReCaptchaEnterpriseProvider or CustomProvider instance via the provider option."}}, {"@type": "Question", "name": "How can I test App Check on emulators and other unverified devices?", "acceptedAnswer": {"@type": "Answer", "text": "Use the debug provider by setting the debugToken option of the initialize(...) method. On Android, you can grab the temporary debug secret from the device logs and register it in the Firebase Console (see Testing). Never use the debug provider in production builds of your app and never share your debug builds with untrusted parties, as it allows access to your Firebase resources from unverified devices."}}, {"@type": "Question", "name": "How do I protect my own backend with App Check?", "acceptedAnswer": {"@type": "Answer", "text": "Call the getToken(...) method to retrieve the current App Check token in JWT format and send it along with requests to your backend, where you can verify it server-side. Use the tokenChanged listener to get notified whenever the token changes."}}, {"@type": "Question", "name": "Why is my App Check token not refreshed automatically?", "acceptedAnswer": {"@type": "Answer", "text": "Automatic token refresh is disabled by default. You can enable it with the isTokenAutoRefreshEnabled option of the initialize(...) method or at any time with the setTokenAutoRefreshEnabled(...) method."}}, {"@type": "Question", "name": "Can I use this plugin with Ionic, React, Vue or Angular?", "acceptedAnswer": {"@type": "Answer", "text": "Yes, the plugin is framework-agnostic. It works in any Capacitor app regardless of the web framework, including Ionic with Angular, React, or Vue, as well as plain JavaScript projects."}}], "url": "https://capawesome.io/docs/sdks/capacitor/firebase/app-check/"}
```
