Firebase identity and profile

Use these operations with an already-configured Firebase integration. Read the account settings, sign in to obtain an ID token, then exchange it for Wallkit member context. Verification inspects an ID token. Registration creates or links Wallkit records. Password-reset and email-link requests start separate provider flows. Follow the Firebase identity.

Firebase context

Use this resource’s existing Firebase configuration and public resource key. These actions permit guest ACL access, but each operation’s explicit member and context requirements still apply. Shared credential checks can reject a supplied stale session before the action. Configured provider services must be available; client configuration alone does not prove that.

Keep Firebase custom tokens, Firebase ID tokens and Wallkit session tokens separate. The credential definitions explain their uses. Each request table specifies headers or body transport. Examples are synthetic; see sample runtimes.

Operations

TaskMethod / path
Connect a Firebase identity to WallkitPOST /api/v1/firebase/oauth/token
Sign in to Firebase with a passwordPOST /api/v1/firebase/sign-in
Verify a Firebase ID tokenPOST /api/v1/firebase/verify-token
Register a Wallkit member from FirebasePOST /api/v1/firebase/registration
Revoke the Firebase identity’s sessionsPOST /api/v1/firebase/revoke-token
Create a custom token for a Wallkit sessionGET /api/v1/firebase/custom-token
Read the resource’s Firebase client configurationGET /api/v1/firebase/account
Find Wallkit/Firebase relationships by emailGET /api/v1/firebase/check/email
Request a Firebase password-reset linkPOST /api/v1/firebase/password-reset
Request a Firebase email sign-in linkPOST /api/v1/firebase/email-auth-link
Update the member’s Firestore fieldsPUT /api/v1/firebase/firestore/user

Connect a Firebase identity to Wallkit

POST /api/v1/firebase/oauth/token

Exchange a Firebase ID token for a Wallkit session token. This can create/link a user/resource relationship, default membership, session and Firestore record; it can accept an invitation and record login/signup events. Existing linked identities return 200; the registration path returns 201. A protective spam branch also returns 201 with a placeholder token: HTTP 201 and existed:false alone do not prove usable authentication.

Before you call

Existing Firebase ID token from the resource’s configured project. Supply resource and firebase-token headers; no Wallkit token is needed for the normal exchange. See Firebase context for shared checks and credential distinctions.

Request

JSON body. This action also accepts form fields, which take precedence; use JSON for a typed boolean flag. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
firebase-tokenheaderstringrequired in this exampleMatching Firebase ID token, not custom or refresh token.
invitebodystringoptionalTrimmed invitation code; acceptance changes membership/team state.
сreate_wk_user_if_not_existbodyJSON booleanoptional; true defaultExact initial character is Cyrillic с (U+0441). Only a boolean is honored. false blocks a new resource relationship without an invitation; it does not prohibit every user creation branch. ASCII create_wk_user_if_not_exist is not an alias.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
tokenstringWallkit session token; use custom token header with the same resource and Firebase ID token. The protective 201 branch can supply an unusable placeholder.
existedbooleantrue for existing linked path; registration path reports whether the email/resource relationship already existed. false is not proof of a new usable account.

Example

The linked member branch returns 200; the flag prevents an uninvited new resource relationship. See sample runtimes.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/oauth/token" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "firebase-token: ${FIREBASE_ID_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{"сreate_wk_user_if_not_exist":false}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/oauth/token", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "firebase-token": process.env.FIREBASE_ID_TOKEN,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({"сreate_wk_user_if_not_exist":false})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/oauth/token')
body = {'сreate_wk_user_if_not_exist': False}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN'], "Content-Type": "application/json"}, method='POST')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
  "existed": true
}

Alternate result

With the exact flag false and no invite, a missing resource relationship is rejected. HTTP 403 response excerpt:

{
  "error": "user_resource_not_exist",
  "error_description": "Create user resource relationship forbidden"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
403user_resource_not_existCreating the required relationship is forbidden.Choose an authorized registration/invitation flow; do not silently change the flag.
401authorization_failLinked account locked/suspended or global user inactive.Resolve account state with administrator.
409service_not_active / empty_user_id / verify_failedInactive service, missing token claim or verification/invitation failure.Correct the token/project or existing configuration; obtain a valid invite if needed.
400oauth_failedExisting-user session issuance failed.Contact support; inspect existing identity state before repeating.

Shared errors cover initialization, resource and session checks.

Next task

Firebase identity

Sign in to Firebase with a password

POST /api/v1/firebase/sign-in

Verify the configured provider email/password and return its ID token. This does not issue a Wallkit session token. Provider authentication is a separate step from the Wallkit exchange.

Before you call

Existing provider account and resource with configured Firebase authentication. See Firebase context for shared checks and credential distinctions.

Request

JSON body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
emailbodystringrequiredValid email; sanitized/trimmed/lowercased.
passwordbodystringrequiredNonempty provider password; trimmed. No local password-length rule here.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
firebase_user_idstringAuthenticated provider UID, not a Wallkit user ID.
statusbooleantrue when this provider sign-in path completes.
firebase_token_idstringFirebase ID token; send as firebase-token to the Wallkit exchange, not as token.

Example

Verify the configured provider password and obtain an ID token. See Firebase context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/sign-in" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"email":"reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/sign-in", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({"email":"reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE"})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/sign-in')
body = {'email': 'reader@example.com', 'password': 'EXAMPLE_PASSWORD_DO_NOT_USE'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "firebase_user_id": "EXAMPLE_FIREBASE_UID",
  "status": true,
  "firebase_token_id": "EXAMPLE_FIREBASE_ID_TOKEN"
}

Alternate result

A missing JSON body cannot start provider sign-in. HTTP 400 response excerpt:

{
  "error": "incorrect_data",
  "error_description": "Body must be json format"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
400incorrect_dataMissing/non-JSON body.Send the documented JSON object.
409invalid_email / invalid_passwordMissing field or invalid email.Correct input.
400dynamic exception text in errorProvider/service/input orchestration exception.Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code.

Shared errors cover initialization, resource and session checks.

Next task

Exchange this ID token for a Wallkit session token.

Verify a Firebase ID token

POST /api/v1/firebase/verify-token

Verify the supplied Firebase ID token and inspect its user/expiration claims. This does not issue a Wallkit session token or establish content permission.

Before you call

Resource’s configured Firebase authentication and an ID token from its project. See Firebase context for shared checks and credential distinctions.

Request

No request body is required. The action reads headers and resolved context; the response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
firebase-tokenheaderstringrequired in this exampleMatching Firebase ID token, not custom or refresh token.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
statusbooleantrue after successful verification and the explicit expiry check.
expired_atformatted date string / raw claim / nullDateTimeImmutable expiration becomes Y-m-d H:i:s, without timezone in this string; another claim type is returned unchanged, missing claim is null. Do not assume one universal type/timezone.
firebase_user_idclaim value / nulluser_id claim when present; not a Wallkit user ID.

Example

Inspect the matching Firebase ID token. See Firebase context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/verify-token" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "firebase-token: ${FIREBASE_ID_TOKEN}"

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/verify-token", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "firebase-token": process.env.FIREBASE_ID_TOKEN
    }
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/verify-token')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN']}, method='POST')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "status": true,
  "expired_at": "2030-01-01 00:00:00",
  "firebase_user_id": "EXAMPLE_FIREBASE_UID"
}

Alternate result

Without firebase-token, the action reports its exact empty-token exception. HTTP 400 response excerpt:

{
  "error": "Empty Firebase Token"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
400Empty Firebase TokenMissing ID-token header.Supply firebase-token, not the Wallkit token.
400dynamic exception text in errorProvider/service/input orchestration exception.Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code.

Shared errors cover initialization, resource and session checks.

Next task

Connect a verified identity to Wallkit when you need member context.

Register a Wallkit member from Firebase

POST /api/v1/firebase/registration

Register/link a Wallkit resource member using a Firebase ID token in the JSON body. It can create/link users, default/invited membership, sessions, Firestore records and signup/login events. The body token is distinct from the header used by the OAuth exchange.

Before you call

Existing resource with Firebase enabled, valid token with email, user_id and email_verified claims. An existing email/resource relationship already carrying a Firebase UID is rejected rather than replaced. See Firebase context for shared checks and credential distinctions.

Request

JSON body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
firebase_id_tokenbodystringrequiredFirebase ID token; trimmed. This operation first requires JSON even though the shared extractor supports form fields.
invitebodystringoptionalTrimmed invitation code; otherwise resource email policy applies.

Result

HTTP 201 on this primary branch.

Field / projectionType / presenceMeaning
top-level user + sessionmerged objectsResource-aware user with subscriptions and teams, without last_action; session projection is merged later. id therefore identifies the session.
subscription_idstored Pricing ID; conditionalAccepted invitation subscription ID, when present; not proof of a purchase.
refresh_tokenabsent on current helper pathThe helper returns null; this action does not issue a refresh token.

Example

Register or link Wallkit records using the body ID token. See Firebase context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/registration" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"firebase_id_token":"EXAMPLE_FIREBASE_ID_TOKEN"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/registration", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({"firebase_id_token":"EXAMPLE_FIREBASE_ID_TOKEN"})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/registration')
body = {'firebase_id_token': 'EXAMPLE_FIREBASE_ID_TOKEN'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 201 response excerpt:

{
  "id": 7001,
  "email": "reader@example.com",
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
  "expires": 1893456000
}

Alternate result

The registration action requires a JSON body before extracting the token. HTTP 400 response excerpt:

{
  "error": "incorrect_data",
  "error_description": "Body must be json format"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
400incorrect_dataMissing/non-JSON body.Send the documented JSON object.
400dynamic exception text in errorProvider/service/input orchestration exception.Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code.

Shared errors cover initialization, resource and session checks.

Next task

Firebase identity

Revoke the Firebase identity’s sessions

POST /api/v1/firebase/revoke-token

Request provider refresh-token revocation for the verified Firebase UID and delete Wallkit sessions for the mapped user in this resource. This changes provider and Wallkit session state. It does not delete every Wallkit session across resources or promise instantaneous invalidation of every already-issued provider token.

Before you call

Resolved Wallkit member, resource and matching Firebase ID token. Use both token headers to establish the member context. See Firebase context for shared checks and credential distinctions.

Request

No request body is required. The action reads headers and resolved context; the response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
tokenheaderstringrequired in this exampleExisting Wallkit session token.
firebase-tokenheaderstringrequired in this exampleMatching Firebase ID token, not custom or refresh token.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
statusbooleanProvider revocation helper result; true after the helper call and resource session-deletion loop. No separate count of deleted sessions.

Example

Revoke the matching provider identity and this resource’s mapped Wallkit sessions. See Firebase context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/revoke-token" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "token: ${USER_TOKEN}" \
  -H "firebase-token: ${FIREBASE_ID_TOKEN}"

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/revoke-token", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "token": process.env.USER_TOKEN,
      "firebase-token": process.env.FIREBASE_ID_TOKEN
    }
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/revoke-token')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY'], 'token': os.environ['USER_TOKEN'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN']}, method='POST')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "status": true
}

Alternate result

A missing Firebase ID-token header cannot be revoked. HTTP 400 response excerpt:

{
  "error": "Empty Firebase Token"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
400Empty Firebase TokenNo provider token supplied.Supply matching firebase-token.
400dynamic exception text in errorProvider/service/input orchestration exception.Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code.
404user_not_existNo resolved user; the request stops.Restore valid Wallkit member context with the matching resource and Firebase identity.

Shared errors cover initialization, resource and session checks.

Next task

Obtain fresh credentials through the configured sign-in flow when the user returns.

Create a custom token for a Wallkit session

GET /api/v1/firebase/custom-token

Obtain a Firebase custom token for the user associated with an existing Wallkit session. This GET can create a provider account, save a resource Firebase UID and create/update Firestore before returning the token. Avoid background polling or blind retries.

Before you call

Existing Wallkit session, resource relationship and configured Firebase authentication. When this is a Firebase-enabled member context, supply the matching Firebase ID token as well. See Firebase context for shared checks and credential distinctions.

Request

No request body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
tokenheaderstringrequired in this exampleExisting Wallkit session token.
firebase-tokenheaderstringrequired in this exampleMatching Firebase ID token, not custom or refresh token.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
firebase_custom_tokenstringFirebase custom token for the resource relationship’s UID; not an ID token or Wallkit session token.

Example

Create a provider custom token from the existing Wallkit session. See Firebase context for configuration and sample conventions.

cURL

curl -X GET "${WALLKIT_API_BASE}/api/v1/firebase/custom-token" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "token: ${USER_TOKEN}" \
  -H "firebase-token: ${FIREBASE_ID_TOKEN}"

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/custom-token", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "GET",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "token": process.env.USER_TOKEN,
      "firebase-token": process.env.FIREBASE_ID_TOKEN
    }
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/custom-token')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY'], 'token': os.environ['USER_TOKEN'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN']}, method='GET')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "firebase_custom_token": "EXAMPLE_FIREBASE_CUSTOM_TOKEN"
}

Alternate result

An inactive Firebase authentication service prevents creating the custom token. HTTP 400 response excerpt:

{
  "error": "Firebase Service Not Enabled"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
400dynamic service/provider exception textInactive/misconfigured provider or creation failure.Ask integration owner to resolve configuration; inspect account state before repeating this GET.
404user_session_not_found / user_not_exist / resource_not_existMissing session, user or resource; the request stops.Supply the established Wallkit session and its resource; include the matching Firebase ID token when required.

Shared errors cover initialization, resource and session checks.

Next task

Firebase identity

Read the resource’s Firebase client configuration

GET /api/v1/firebase/account

Read authentication enablement and the resource’s configured web client settings. This is configuration discovery, not proof that provider requests will succeed.

Before you call

Existing resource public key; no member identity is required by the action. See Firebase context for shared checks and credential distinctions.

Request

No request body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
is_enabled_firebase_authconfigured flag valueResource firebase_auth setting; default false, returned without a local boolean cast.
activebooleantrue when resource firebase_account exists and is active. Distinct from authentication enablement.
web_app_configdynamic configured value / nullConfigured web_app_config only for an active account; null otherwise. Its keys/types are configuration-defined; no service-account secret is returned by this action.

Example

Read this resource’s Firebase client settings. See Firebase context for configuration and sample conventions.

cURL

curl -X GET "${WALLKIT_API_BASE}/api/v1/firebase/account" \
  -H "resource: ${RESOURCE_KEY}"

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/account", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "GET",
    headers: {
      "resource": process.env.RESOURCE_KEY
    }
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/account')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY']}, method='GET')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "is_enabled_firebase_auth": false,
  "active": false,
  "web_app_config": null
}

Alternate result

An active configured account can expose client settings; this excerpt does not define a closed web configuration schema. HTTP 200 response excerpt:

{
  "is_enabled_firebase_auth": true,
  "active": true,
  "web_app_config": {
    "projectId": "example-project"
  }
}

Recovery

HTTP statusAPI code / shapeCauseNext action
context-dependentShared context errorsMissing/invalid resource.Check the supplied public resource key with the integration owner.

Shared errors cover initialization, resource and session checks.

Next task

Choose the configured sign-in flow after confirming the resource’s settings.

Find Wallkit/Firebase relationships by email

GET /api/v1/firebase/check/email

Inspect an existing Wallkit user’s relationships across resources belonging to this resource’s partner. Despite the path name, this is not a direct provider email-existence query.

Before you call

Resource public key and an existing Wallkit email. The returned resources are partner-scoped; no active-only filter or ordering/pagination guarantee. See Firebase context for shared checks and credential distinctions.

Request

No request body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
emailquerystringrequiredEmail-filtered query value; not lowercased or trimmed explicitly here. URL-encode it.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
resourcesarrayPartner resources; empty when no rows are selected. No paginator.
resources[].resource_idstored integer IDResource record ID.
resources[].resource_keystringPublic integration resource key.
resources[].has_user_resource_relationshipbooleanWhether this user has a relationship to the resource.
resources[].has_firebase_relationshipbooleanRelationship exists and has a nonempty Firebase UID; not proof the provider account currently exists.

Example

Inspect partner-resource relationships for reader@example.com. See Firebase context for configuration and sample conventions.

cURL

curl -X GET "${WALLKIT_API_BASE}/api/v1/firebase/check/email?email=reader%40example.com" \
  -H "resource: ${RESOURCE_KEY}"

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/check/email?email=reader%40example.com", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "GET",
    headers: {
      "resource": process.env.RESOURCE_KEY
    }
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/check/email?email=reader%40example.com')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY']}, method='GET')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "resources": [
    {
      "resource_id": 1001,
      "resource_key": "EXAMPLE_RESOURCE_PUBLIC_KEY",
      "has_user_resource_relationship": true,
      "has_firebase_relationship": true
    }
  ]
}

Alternate result

No global Wallkit user matches the supplied email. HTTP 404 response excerpt:

{
  "error": "user_not_found",
  "error_description": "User not found"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
409invalid_emailEmpty email after filtering.Send a valid encoded email query.
404invalid_resource / user_not_foundMissing resource or Wallkit user.Check context and email; choose an authorized registration flow for a new user.
400dynamic exception text in errorProvider/service/input orchestration exception.Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code.

Shared errors cover initialization, resource and session checks.

Next task

Connect the member in the selected resource rather than treating another resource’s relationship as access.

POST /api/v1/firebase/password-reset

Generate a provider password-reset link and dispatch the configured mail/event path. This can contact Firebase and enqueue events. A response does not prove delivery or completion of the password change. A configured no-session branch returns an out-of-band code without requesting mail.

Before you call

Resource, configured Firebase authentication and an existing provider email. The skip-mail decision checks current and archived Wallkit sessions for this email/resource; a lookup exception is treated as no matching user/session. See Firebase context for shared checks and credential distinctions.

Request

JSON body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
emailbodystringrequiredValid email; sanitized/trimmed/lowercased.
use_oob_codebodyboolean-filtered inputoptional; false defaultRequests code-only branch only when skip-mail setting is enabled and no current/archived Wallkit sessions are found for this email/resource.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
resultbooleantrue when link/event preparation completes; not password-changed state.
is_sent_mailbooleantrue for mail/event branch; false for configured code-only branch. This records the chosen branch, not delivery confirmation.
messagestring; mail branchFixed acknowledgement text; interpret as request acknowledgement.
oob_codestring / null; code-only branchParsed provider oobCode value, absent/null if unavailable. Use only in the configured provider completion flow; not a Wallkit session token.

Example

Request the configured reset-link mail branch for reader@example.com. See Firebase context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/password-reset" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"email":"reader@example.com"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/password-reset", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({"email":"reader@example.com"})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/password-reset')
body = {'email': 'reader@example.com'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "result": true,
  "is_sent_mail": true,
  "message": "Mail with instructions has been sent to your email address"
}

Alternate result

With use_oob_code:true, allow_email_auth_skip_mail_without_sessions enabled and no matching current/archived sessions found, the code-only branch returns this excerpt. HTTP 200 response excerpt:

{
  "result": true,
  "is_sent_mail": false,
  "oob_code": "EXAMPLE_FIREBASE_OOB_CODE"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
409invalid_data / invalid_emailNon-JSON body, missing email or invalid format.Correct JSON/email.
404invalid_emailProvider email absent.Check the email and configured project; do not assume a Wallkit user means a provider account exists.
409invalid_linkGenerated link has no usable query parameters.Contact integration owner; avoid assuming a completion code was issued.
409fixed operation failure text in errorOther provider/orchestration failure.Show failure and contact support; no delivery/completion state is established.

Shared errors cover initialization, resource and session checks.

Next task

Complete the configured provider password reset, then sign in with the new password.

POST /api/v1/firebase/email-auth-link

Generate a provider email sign-in link and dispatch the configured mail/event path. This can contact Firebase and enqueue events. A response does not prove delivery or completion of sign-in. A configured no-session branch returns an out-of-band code without requesting mail.

Before you call

Resource, configured Firebase authentication and an existing provider email. The skip-mail decision checks current and archived Wallkit sessions for this email/resource; a lookup exception is treated as no matching user/session. See Firebase context for shared checks and credential distinctions.

Request

JSON body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
emailbodystringrequiredValid email; sanitized/trimmed/lowercased.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
resultbooleantrue when link/event preparation completes; not signed-in state.
is_sent_mailbooleantrue for mail/event branch; false for configured code-only branch. This records the chosen branch, not delivery confirmation.
messagestring; mail branchFixed acknowledgement text; interpret as request acknowledgement.
oob_codestring / null; code-only branchParsed provider oobCode value, absent/null if unavailable. Use only in the configured provider completion flow; not a Wallkit session token.

Example

Request the configured sign-in-link mail branch for reader@example.com. See Firebase context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/email-auth-link" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"email":"reader@example.com"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/email-auth-link", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({"email":"reader@example.com"})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/email-auth-link')
body = {'email': 'reader@example.com'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "result": true,
  "is_sent_mail": true,
  "message": "Mail with instructions has been sent to your email address"
}

Alternate result

With allow_email_auth_skip_mail_without_sessions enabled and no matching current/archived sessions found, the code-only branch returns this excerpt. HTTP 200 response excerpt:

{
  "result": true,
  "is_sent_mail": false,
  "oob_code": "EXAMPLE_FIREBASE_OOB_CODE"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
409invalid_data / invalid_emailNon-JSON body, missing email or invalid format.Correct JSON/email.
404invalid_emailProvider email absent.Check the email and configured project; do not assume a Wallkit user means a provider account exists.
409invalid_auth_linkGenerated link has no usable query parameters.Contact integration owner; avoid assuming a completion code was issued.
409fixed operation failure text in errorOther provider/orchestration failure.Show failure and contact support; no delivery/completion state is established.

Shared errors cover initialization, resource and session checks.

Next task

Complete the configured provider email-link flow, then exchange its ID token for Wallkit context.

Update the member’s Firestore fields

PUT /api/v1/firebase/firestore/user

Write fields to the configured users/{Firebase UID} document and store the submitted field map plus id in the Wallkit resource relationship’s extra.firestore. Provider write happens before the local relationship save; do not assume an atomic cross-system update. Existing provider documents update supplied paths; missing documents are created.

Before you call

Resolved member/resource, existing resource relationship with Firebase UID, enabled Firestore and its existing service-account configuration. See Firebase context for shared checks and credential distinctions.

Request

JSON body. Response is JSON.

NameLocationTypeRequirement / defaultMeaning and constraints
resourceheaderstringrequired integration contextPublic key for the configured resource/project.
tokenheaderstringrequired in this exampleExisting Wallkit session token.
firebase-tokenheaderstringrequired in this exampleMatching Firebase ID token, not custom or refresh token.
firestorebodynonempty field maprequiredDynamic named fields/paths. Plain JSON values pass through. Structured {type,value} with both non-null members unwraps value; type=date converts value to a provider Timestamp. See field rules.

Result

HTTP 200 on this primary branch.

Field / projectionType / presenceMeaning
userobjectResource-aware user with subscriptions and teams, without last_action; additionally subscription history. Its id is the user ID.
user.extra.firestoredynamic mapSubmitted map plus id equal to Firebase UID; date/type wrappers remain in this local representation, rather than exposing the provider Timestamp. With existing extra data, submitted Firestore child keys are merged and untouched keys are retained; with empty extra, the submitted map initializes it. Other extra keys are preserved.
successbooleantrue after orchestration reaches the success response; no independent local-save verification is returned.

Example

Write newsletter_opt_in to the member’s Firestore document and local extra map. See Firebase context for configuration and sample conventions.

cURL

curl -X PUT "${WALLKIT_API_BASE}/api/v1/firebase/firestore/user" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "token: ${USER_TOKEN}" \
  -H "firebase-token: ${FIREBASE_ID_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{"firestore":{"newsletter_opt_in":true}}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/firebase/firestore/user", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "PUT",
    headers: {
      "resource": process.env.RESOURCE_KEY,
      "token": process.env.USER_TOKEN,
      "firebase-token": process.env.FIREBASE_ID_TOKEN,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({"firestore":{"newsletter_opt_in":true}})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/firestore/user')
body = {'firestore': {'newsletter_opt_in': True}}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], 'token': os.environ['USER_TOKEN'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN'], "Content-Type": "application/json"}, method='PUT')
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "user": {
    "id": 42,
    "email": "reader@example.com",
    "extra": {
      "firestore": {
        "newsletter_opt_in": true,
        "id": "EXAMPLE_FIREBASE_UID"
      }
    },
    "subscriptions": [],
    "teams": [],
    "subscriptions_history": []
  },
  "success": true
}

Alternate result

Disabled Firestore prevents the write. HTTP 404 response excerpt:

{
  "error": "firestore_not_active",
  "error_description": "Firestore service is not enabled"
}

Recovery

HTTP statusAPI code / shapeCauseNext action
400incorrect_dataNon-JSON body.Send JSON.
422invalid_firestoreMissing/empty firestore value.Supply the named nonempty field map.
404user_resource_not_exists / firebase_user_not_existsMissing membership or Firebase UID.Establish the intended resource identity first.
404firestore_not_activeDisabled Firestore.Ask integration owner to enable/configure the existing service.
404firestore_errorOther provider/local orchestration exception.Inspect both provider/local state with support before repeating; partial writes are possible.

Shared errors cover initialization, resource and session checks.

Next task

Use the member context for the content decision; stored profile fields do not grant access.

Full diagram

Use the arrow keys to scroll. Escape closes this view.

Search documentation

Enter at least 2 characters.

    ↑ ↓ move through results · Enter opens · Escape closes