Firebase identity and profile
Use these operations with an already-configured Firebase integration. Read the account settings, sign in to obtain an ID token, then exchange it for Wallkit member context. Verification inspects an ID token. Registration creates or links Wallkit records. Password-reset and email-link requests start separate provider flows. Follow the Firebase identity.
Firebase context
Use this resource’s existing Firebase configuration and public resource key. These actions permit guest ACL access, but each operation’s explicit member and context requirements still apply. Shared credential checks can reject a supplied stale session before the action. Configured provider services must be available; client configuration alone does not prove that.
Keep Firebase custom tokens, Firebase ID tokens and Wallkit session tokens separate. The credential definitions explain their uses. Each request table specifies headers or body transport. Examples are synthetic; see sample runtimes.
Operations
| Task | Method / path |
|---|---|
| Connect a Firebase identity to Wallkit | POST /api/v1/firebase/oauth/token |
| Sign in to Firebase with a password | POST /api/v1/firebase/sign-in |
| Verify a Firebase ID token | POST /api/v1/firebase/verify-token |
| Register a Wallkit member from Firebase | POST /api/v1/firebase/registration |
| Revoke the Firebase identity’s sessions | POST /api/v1/firebase/revoke-token |
| Create a custom token for a Wallkit session | GET /api/v1/firebase/custom-token |
| Read the resource’s Firebase client configuration | GET /api/v1/firebase/account |
| Find Wallkit/Firebase relationships by email | GET /api/v1/firebase/check/email |
| Request a Firebase password-reset link | POST /api/v1/firebase/password-reset |
| Request a Firebase email sign-in link | POST /api/v1/firebase/email-auth-link |
| Update the member’s Firestore fields | PUT /api/v1/firebase/firestore/user |
Connect a Firebase identity to Wallkit
POST /api/v1/firebase/oauth/token
Exchange a Firebase ID token for a Wallkit session token. This can create/link a user/resource relationship, default membership, session and Firestore record; it can accept an invitation and record login/signup events. Existing linked identities return 200; the registration path returns 201. A protective spam branch also returns 201 with a placeholder token: HTTP 201 and existed:false alone do not prove usable authentication.
Before you call
Existing Firebase ID token from the resource’s configured project. Supply resource and firebase-token headers; no Wallkit token is needed for the normal exchange. See Firebase context for shared checks and credential distinctions.
Request
JSON body. This action also accepts form fields, which take precedence; use JSON for a typed boolean flag. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| firebase-token | header | string | required in this example | Matching Firebase ID token, not custom or refresh token. |
| invite | body | string | optional | Trimmed invitation code; acceptance changes membership/team state. |
| сreate_wk_user_if_not_exist | body | JSON boolean | optional; true default | Exact initial character is Cyrillic с (U+0441). Only a boolean is honored. false blocks a new resource relationship without an invitation; it does not prohibit every user creation branch. ASCII create_wk_user_if_not_exist is not an alias. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| token | string | Wallkit session token; use custom token header with the same resource and Firebase ID token. The protective 201 branch can supply an unusable placeholder. |
| existed | boolean | true for existing linked path; registration path reports whether the email/resource relationship already existed. false is not proof of a new usable account. |
Example
The linked member branch returns 200; the flag prevents an uninvited new resource relationship. See sample runtimes.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/oauth/token" \
-H "resource: ${RESOURCE_KEY}" \
-H "firebase-token: ${FIREBASE_ID_TOKEN}" \
-H "Content-Type: application/json" \
--data '{"сreate_wk_user_if_not_exist":false}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/oauth/token", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
"resource": process.env.RESOURCE_KEY,
"firebase-token": process.env.FIREBASE_ID_TOKEN,
"Content-Type": "application/json"
},
body: JSON.stringify({"сreate_wk_user_if_not_exist":false})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/oauth/token')
body = {'сreate_wk_user_if_not_exist': False}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN'], "Content-Type": "application/json"}, method='POST')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
"existed": true
}
Alternate result
With the exact flag false and no invite, a missing resource relationship is rejected. HTTP 403 response excerpt:
{
"error": "user_resource_not_exist",
"error_description": "Create user resource relationship forbidden"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 403 | user_resource_not_exist | Creating the required relationship is forbidden. | Choose an authorized registration/invitation flow; do not silently change the flag. |
| 401 | authorization_fail | Linked account locked/suspended or global user inactive. | Resolve account state with administrator. |
| 409 | service_not_active / empty_user_id / verify_failed | Inactive service, missing token claim or verification/invitation failure. | Correct the token/project or existing configuration; obtain a valid invite if needed. |
| 400 | oauth_failed | Existing-user session issuance failed. | Contact support; inspect existing identity state before repeating. |
Shared errors cover initialization, resource and session checks.
Next task
Sign in to Firebase with a password
POST /api/v1/firebase/sign-in
Verify the configured provider email/password and return its ID token. This does not issue a Wallkit session token. Provider authentication is a separate step from the Wallkit exchange.
Before you call
Existing provider account and resource with configured Firebase authentication. See Firebase context for shared checks and credential distinctions.
Request
JSON body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| body | string | required | Valid email; sanitized/trimmed/lowercased. | |
| password | body | string | required | Nonempty provider password; trimmed. No local password-length rule here. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| firebase_user_id | string | Authenticated provider UID, not a Wallkit user ID. |
| status | boolean | true when this provider sign-in path completes. |
| firebase_token_id | string | Firebase ID token; send as firebase-token to the Wallkit exchange, not as token. |
Example
Verify the configured provider password and obtain an ID token. See Firebase context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/sign-in" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"email":"reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/sign-in", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
"resource": process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({"email":"reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE"})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/sign-in')
body = {'email': 'reader@example.com', 'password': 'EXAMPLE_PASSWORD_DO_NOT_USE'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"firebase_user_id": "EXAMPLE_FIREBASE_UID",
"status": true,
"firebase_token_id": "EXAMPLE_FIREBASE_ID_TOKEN"
}
Alternate result
A missing JSON body cannot start provider sign-in. HTTP 400 response excerpt:
{
"error": "incorrect_data",
"error_description": "Body must be json format"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 400 | incorrect_data | Missing/non-JSON body. | Send the documented JSON object. |
| 409 | invalid_email / invalid_password | Missing field or invalid email. | Correct input. |
| 400 | dynamic exception text in error | Provider/service/input orchestration exception. | Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code. |
Shared errors cover initialization, resource and session checks.
Next task
Verify a Firebase ID token
POST /api/v1/firebase/verify-token
Verify the supplied Firebase ID token and inspect its user/expiration claims. This does not issue a Wallkit session token or establish content permission.
Before you call
Resource’s configured Firebase authentication and an ID token from its project. See Firebase context for shared checks and credential distinctions.
Request
No request body is required. The action reads headers and resolved context; the response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| firebase-token | header | string | required in this example | Matching Firebase ID token, not custom or refresh token. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| status | boolean | true after successful verification and the explicit expiry check. |
| expired_at | formatted date string / raw claim / null | DateTimeImmutable expiration becomes Y-m-d H:i:s, without timezone in this string; another claim type is returned unchanged, missing claim is null. Do not assume one universal type/timezone. |
| firebase_user_id | claim value / null | user_id claim when present; not a Wallkit user ID. |
Example
Inspect the matching Firebase ID token. See Firebase context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/verify-token" \
-H "resource: ${RESOURCE_KEY}" \
-H "firebase-token: ${FIREBASE_ID_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/verify-token", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
"resource": process.env.RESOURCE_KEY,
"firebase-token": process.env.FIREBASE_ID_TOKEN
}
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/verify-token')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN']}, method='POST')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"status": true,
"expired_at": "2030-01-01 00:00:00",
"firebase_user_id": "EXAMPLE_FIREBASE_UID"
}
Alternate result
Without firebase-token, the action reports its exact empty-token exception. HTTP 400 response excerpt:
{
"error": "Empty Firebase Token"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 400 | Empty Firebase Token | Missing ID-token header. | Supply firebase-token, not the Wallkit token. |
| 400 | dynamic exception text in error | Provider/service/input orchestration exception. | Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code. |
Shared errors cover initialization, resource and session checks.
Next task
Connect a verified identity to Wallkit when you need member context.
Register a Wallkit member from Firebase
POST /api/v1/firebase/registration
Register/link a Wallkit resource member using a Firebase ID token in the JSON body. It can create/link users, default/invited membership, sessions, Firestore records and signup/login events. The body token is distinct from the header used by the OAuth exchange.
Before you call
Existing resource with Firebase enabled, valid token with email, user_id and email_verified claims. An existing email/resource relationship already carrying a Firebase UID is rejected rather than replaced. See Firebase context for shared checks and credential distinctions.
Request
JSON body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| firebase_id_token | body | string | required | Firebase ID token; trimmed. This operation first requires JSON even though the shared extractor supports form fields. |
| invite | body | string | optional | Trimmed invitation code; otherwise resource email policy applies. |
Result
HTTP 201 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| top-level user + session | merged objects | Resource-aware user with subscriptions and teams, without last_action; session projection is merged later. id therefore identifies the session. |
| subscription_id | stored Pricing ID; conditional | Accepted invitation subscription ID, when present; not proof of a purchase. |
| refresh_token | absent on current helper path | The helper returns null; this action does not issue a refresh token. |
Example
Register or link Wallkit records using the body ID token. See Firebase context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/registration" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"firebase_id_token":"EXAMPLE_FIREBASE_ID_TOKEN"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/registration", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
"resource": process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({"firebase_id_token":"EXAMPLE_FIREBASE_ID_TOKEN"})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/registration')
body = {'firebase_id_token': 'EXAMPLE_FIREBASE_ID_TOKEN'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 201 response excerpt:
{
"id": 7001,
"email": "reader@example.com",
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
"expires": 1893456000
}
Alternate result
The registration action requires a JSON body before extracting the token. HTTP 400 response excerpt:
{
"error": "incorrect_data",
"error_description": "Body must be json format"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 400 | incorrect_data | Missing/non-JSON body. | Send the documented JSON object. |
| 400 | dynamic exception text in error | Provider/service/input orchestration exception. | Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code. |
Shared errors cover initialization, resource and session checks.
Next task
Revoke the Firebase identity’s sessions
POST /api/v1/firebase/revoke-token
Request provider refresh-token revocation for the verified Firebase UID and delete Wallkit sessions for the mapped user in this resource. This changes provider and Wallkit session state. It does not delete every Wallkit session across resources or promise instantaneous invalidation of every already-issued provider token.
Before you call
Resolved Wallkit member, resource and matching Firebase ID token. Use both token headers to establish the member context. See Firebase context for shared checks and credential distinctions.
Request
No request body is required. The action reads headers and resolved context; the response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| token | header | string | required in this example | Existing Wallkit session token. |
| firebase-token | header | string | required in this example | Matching Firebase ID token, not custom or refresh token. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| status | boolean | Provider revocation helper result; true after the helper call and resource session-deletion loop. No separate count of deleted sessions. |
Example
Revoke the matching provider identity and this resource’s mapped Wallkit sessions. See Firebase context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/revoke-token" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}" \
-H "firebase-token: ${FIREBASE_ID_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/revoke-token", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
"resource": process.env.RESOURCE_KEY,
"token": process.env.USER_TOKEN,
"firebase-token": process.env.FIREBASE_ID_TOKEN
}
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/revoke-token')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY'], 'token': os.environ['USER_TOKEN'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN']}, method='POST')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"status": true
}
Alternate result
A missing Firebase ID-token header cannot be revoked. HTTP 400 response excerpt:
{
"error": "Empty Firebase Token"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 400 | Empty Firebase Token | No provider token supplied. | Supply matching firebase-token. |
| 400 | dynamic exception text in error | Provider/service/input orchestration exception. | Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code. |
| 404 | user_not_exist | No resolved user; the request stops. | Restore valid Wallkit member context with the matching resource and Firebase identity. |
Shared errors cover initialization, resource and session checks.
Next task
Obtain fresh credentials through the configured sign-in flow when the user returns.
Create a custom token for a Wallkit session
GET /api/v1/firebase/custom-token
Obtain a Firebase custom token for the user associated with an existing Wallkit session. This GET can create a provider account, save a resource Firebase UID and create/update Firestore before returning the token. Avoid background polling or blind retries.
Before you call
Existing Wallkit session, resource relationship and configured Firebase authentication. When this is a Firebase-enabled member context, supply the matching Firebase ID token as well. See Firebase context for shared checks and credential distinctions.
Request
No request body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| token | header | string | required in this example | Existing Wallkit session token. |
| firebase-token | header | string | required in this example | Matching Firebase ID token, not custom or refresh token. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| firebase_custom_token | string | Firebase custom token for the resource relationship’s UID; not an ID token or Wallkit session token. |
Example
Create a provider custom token from the existing Wallkit session. See Firebase context for configuration and sample conventions.
cURL
curl -X GET "${WALLKIT_API_BASE}/api/v1/firebase/custom-token" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}" \
-H "firebase-token: ${FIREBASE_ID_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/custom-token", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "GET",
headers: {
"resource": process.env.RESOURCE_KEY,
"token": process.env.USER_TOKEN,
"firebase-token": process.env.FIREBASE_ID_TOKEN
}
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/custom-token')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY'], 'token': os.environ['USER_TOKEN'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN']}, method='GET')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"firebase_custom_token": "EXAMPLE_FIREBASE_CUSTOM_TOKEN"
}
Alternate result
An inactive Firebase authentication service prevents creating the custom token. HTTP 400 response excerpt:
{
"error": "Firebase Service Not Enabled"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 400 | dynamic service/provider exception text | Inactive/misconfigured provider or creation failure. | Ask integration owner to resolve configuration; inspect account state before repeating this GET. |
| 404 | user_session_not_found / user_not_exist / resource_not_exist | Missing session, user or resource; the request stops. | Supply the established Wallkit session and its resource; include the matching Firebase ID token when required. |
Shared errors cover initialization, resource and session checks.
Next task
Read the resource’s Firebase client configuration
GET /api/v1/firebase/account
Read authentication enablement and the resource’s configured web client settings. This is configuration discovery, not proof that provider requests will succeed.
Before you call
Existing resource public key; no member identity is required by the action. See Firebase context for shared checks and credential distinctions.
Request
No request body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| is_enabled_firebase_auth | configured flag value | Resource firebase_auth setting; default false, returned without a local boolean cast. |
| active | boolean | true when resource firebase_account exists and is active. Distinct from authentication enablement. |
| web_app_config | dynamic configured value / null | Configured web_app_config only for an active account; null otherwise. Its keys/types are configuration-defined; no service-account secret is returned by this action. |
Example
Read this resource’s Firebase client settings. See Firebase context for configuration and sample conventions.
cURL
curl -X GET "${WALLKIT_API_BASE}/api/v1/firebase/account" \
-H "resource: ${RESOURCE_KEY}"
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/account", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "GET",
headers: {
"resource": process.env.RESOURCE_KEY
}
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/account')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY']}, method='GET')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"is_enabled_firebase_auth": false,
"active": false,
"web_app_config": null
}
Alternate result
An active configured account can expose client settings; this excerpt does not define a closed web configuration schema. HTTP 200 response excerpt:
{
"is_enabled_firebase_auth": true,
"active": true,
"web_app_config": {
"projectId": "example-project"
}
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| context-dependent | Shared context errors | Missing/invalid resource. | Check the supplied public resource key with the integration owner. |
Shared errors cover initialization, resource and session checks.
Next task
Choose the configured sign-in flow after confirming the resource’s settings.
Find Wallkit/Firebase relationships by email
GET /api/v1/firebase/check/email
Inspect an existing Wallkit user’s relationships across resources belonging to this resource’s partner. Despite the path name, this is not a direct provider email-existence query.
Before you call
Resource public key and an existing Wallkit email. The returned resources are partner-scoped; no active-only filter or ordering/pagination guarantee. See Firebase context for shared checks and credential distinctions.
Request
No request body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| query | string | required | Email-filtered query value; not lowercased or trimmed explicitly here. URL-encode it. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| resources | array | Partner resources; empty when no rows are selected. No paginator. |
| resources[].resource_id | stored integer ID | Resource record ID. |
| resources[].resource_key | string | Public integration resource key. |
| resources[].has_user_resource_relationship | boolean | Whether this user has a relationship to the resource. |
| resources[].has_firebase_relationship | boolean | Relationship exists and has a nonempty Firebase UID; not proof the provider account currently exists. |
Example
Inspect partner-resource relationships for reader@example.com. See Firebase context for configuration and sample conventions.
cURL
curl -X GET "${WALLKIT_API_BASE}/api/v1/firebase/check/email?email=reader%40example.com" \
-H "resource: ${RESOURCE_KEY}"
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/check/email?email=reader%40example.com", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "GET",
headers: {
"resource": process.env.RESOURCE_KEY
}
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/check/email?email=reader%40example.com')
request = Request(url, headers={'resource': os.environ['RESOURCE_KEY']}, method='GET')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"resources": [
{
"resource_id": 1001,
"resource_key": "EXAMPLE_RESOURCE_PUBLIC_KEY",
"has_user_resource_relationship": true,
"has_firebase_relationship": true
}
]
}
Alternate result
No global Wallkit user matches the supplied email. HTTP 404 response excerpt:
{
"error": "user_not_found",
"error_description": "User not found"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 409 | invalid_email | Empty email after filtering. | Send a valid encoded email query. |
| 404 | invalid_resource / user_not_found | Missing resource or Wallkit user. | Check context and email; choose an authorized registration flow for a new user. |
| 400 | dynamic exception text in error | Provider/service/input orchestration exception. | Check this resource’s existing Firebase configuration and credential; show a useful error without assuming a fixed provider code. |
Shared errors cover initialization, resource and session checks.
Next task
Request a Firebase password-reset link
POST /api/v1/firebase/password-reset
Generate a provider password-reset link and dispatch the configured mail/event path. This can contact Firebase and enqueue events. A response does not prove delivery or completion of the password change. A configured no-session branch returns an out-of-band code without requesting mail.
Before you call
Resource, configured Firebase authentication and an existing provider email. The skip-mail decision checks current and archived Wallkit sessions for this email/resource; a lookup exception is treated as no matching user/session. See Firebase context for shared checks and credential distinctions.
Request
JSON body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| body | string | required | Valid email; sanitized/trimmed/lowercased. | |
| use_oob_code | body | boolean-filtered input | optional; false default | Requests code-only branch only when skip-mail setting is enabled and no current/archived Wallkit sessions are found for this email/resource. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| result | boolean | true when link/event preparation completes; not password-changed state. |
| is_sent_mail | boolean | true for mail/event branch; false for configured code-only branch. This records the chosen branch, not delivery confirmation. |
| message | string; mail branch | Fixed acknowledgement text; interpret as request acknowledgement. |
| oob_code | string / null; code-only branch | Parsed provider oobCode value, absent/null if unavailable. Use only in the configured provider completion flow; not a Wallkit session token. |
Example
Request the configured reset-link mail branch for reader@example.com. See Firebase context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/password-reset" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"email":"reader@example.com"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/password-reset", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
"resource": process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({"email":"reader@example.com"})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/password-reset')
body = {'email': 'reader@example.com'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"result": true,
"is_sent_mail": true,
"message": "Mail with instructions has been sent to your email address"
}
Alternate result
With use_oob_code:true, allow_email_auth_skip_mail_without_sessions enabled and no matching current/archived sessions found, the code-only branch returns this excerpt. HTTP 200 response excerpt:
{
"result": true,
"is_sent_mail": false,
"oob_code": "EXAMPLE_FIREBASE_OOB_CODE"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 409 | invalid_data / invalid_email | Non-JSON body, missing email or invalid format. | Correct JSON/email. |
| 404 | invalid_email | Provider email absent. | Check the email and configured project; do not assume a Wallkit user means a provider account exists. |
| 409 | invalid_link | Generated link has no usable query parameters. | Contact integration owner; avoid assuming a completion code was issued. |
| 409 | fixed operation failure text in error | Other provider/orchestration failure. | Show failure and contact support; no delivery/completion state is established. |
Shared errors cover initialization, resource and session checks.
Next task
Complete the configured provider password reset, then sign in with the new password.
Request a Firebase email sign-in link
POST /api/v1/firebase/email-auth-link
Generate a provider email sign-in link and dispatch the configured mail/event path. This can contact Firebase and enqueue events. A response does not prove delivery or completion of sign-in. A configured no-session branch returns an out-of-band code without requesting mail.
Before you call
Resource, configured Firebase authentication and an existing provider email. The skip-mail decision checks current and archived Wallkit sessions for this email/resource; a lookup exception is treated as no matching user/session. See Firebase context for shared checks and credential distinctions.
Request
JSON body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| body | string | required | Valid email; sanitized/trimmed/lowercased. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| result | boolean | true when link/event preparation completes; not signed-in state. |
| is_sent_mail | boolean | true for mail/event branch; false for configured code-only branch. This records the chosen branch, not delivery confirmation. |
| message | string; mail branch | Fixed acknowledgement text; interpret as request acknowledgement. |
| oob_code | string / null; code-only branch | Parsed provider oobCode value, absent/null if unavailable. Use only in the configured provider completion flow; not a Wallkit session token. |
Example
Request the configured sign-in-link mail branch for reader@example.com. See Firebase context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/firebase/email-auth-link" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"email":"reader@example.com"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/email-auth-link", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
"resource": process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({"email":"reader@example.com"})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/email-auth-link')
body = {'email': 'reader@example.com'}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], "Content-Type": "application/json"}, method='POST')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"result": true,
"is_sent_mail": true,
"message": "Mail with instructions has been sent to your email address"
}
Alternate result
With allow_email_auth_skip_mail_without_sessions enabled and no matching current/archived sessions found, the code-only branch returns this excerpt. HTTP 200 response excerpt:
{
"result": true,
"is_sent_mail": false,
"oob_code": "EXAMPLE_FIREBASE_OOB_CODE"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 409 | invalid_data / invalid_email | Non-JSON body, missing email or invalid format. | Correct JSON/email. |
| 404 | invalid_email | Provider email absent. | Check the email and configured project; do not assume a Wallkit user means a provider account exists. |
| 409 | invalid_auth_link | Generated link has no usable query parameters. | Contact integration owner; avoid assuming a completion code was issued. |
| 409 | fixed operation failure text in error | Other provider/orchestration failure. | Show failure and contact support; no delivery/completion state is established. |
Shared errors cover initialization, resource and session checks.
Next task
Complete the configured provider email-link flow, then exchange its ID token for Wallkit context.
Update the member’s Firestore fields
PUT /api/v1/firebase/firestore/user
Write fields to the configured users/{Firebase UID} document and store the submitted field map plus id in the Wallkit resource relationship’s extra.firestore. Provider write happens before the local relationship save; do not assume an atomic cross-system update. Existing provider documents update supplied paths; missing documents are created.
Before you call
Resolved member/resource, existing resource relationship with Firebase UID, enabled Firestore and its existing service-account configuration. See Firebase context for shared checks and credential distinctions.
Request
JSON body. Response is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraints |
|---|---|---|---|---|
| resource | header | string | required integration context | Public key for the configured resource/project. |
| token | header | string | required in this example | Existing Wallkit session token. |
| firebase-token | header | string | required in this example | Matching Firebase ID token, not custom or refresh token. |
| firestore | body | nonempty field map | required | Dynamic named fields/paths. Plain JSON values pass through. Structured {type,value} with both non-null members unwraps value; type=date converts value to a provider Timestamp. See field rules. |
Result
HTTP 200 on this primary branch.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| user | object | Resource-aware user with subscriptions and teams, without last_action; additionally subscription history. Its id is the user ID. |
| user.extra.firestore | dynamic map | Submitted map plus id equal to Firebase UID; date/type wrappers remain in this local representation, rather than exposing the provider Timestamp. With existing extra data, submitted Firestore child keys are merged and untouched keys are retained; with empty extra, the submitted map initializes it. Other extra keys are preserved. |
| success | boolean | true after orchestration reaches the success response; no independent local-save verification is returned. |
Example
Write newsletter_opt_in to the member’s Firestore document and local extra map. See Firebase context for configuration and sample conventions.
cURL
curl -X PUT "${WALLKIT_API_BASE}/api/v1/firebase/firestore/user" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}" \
-H "firebase-token: ${FIREBASE_ID_TOKEN}" \
-H "Content-Type: application/json" \
--data '{"firestore":{"newsletter_opt_in":true}}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/firebase/firestore/user", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "PUT",
headers: {
"resource": process.env.RESOURCE_KEY,
"token": process.env.USER_TOKEN,
"firebase-token": process.env.FIREBASE_ID_TOKEN,
"Content-Type": "application/json"
},
body: JSON.stringify({"firestore":{"newsletter_opt_in":true}})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], '/api/v1/firebase/firestore/user')
body = {'firestore': {'newsletter_opt_in': True}}
request = Request(url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers={'resource': os.environ['RESOURCE_KEY'], 'token': os.environ['USER_TOKEN'], 'firebase-token': os.environ['FIREBASE_ID_TOKEN'], "Content-Type": "application/json"}, method='PUT')
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"user": {
"id": 42,
"email": "reader@example.com",
"extra": {
"firestore": {
"newsletter_opt_in": true,
"id": "EXAMPLE_FIREBASE_UID"
}
},
"subscriptions": [],
"teams": [],
"subscriptions_history": []
},
"success": true
}
Alternate result
Disabled Firestore prevents the write. HTTP 404 response excerpt:
{
"error": "firestore_not_active",
"error_description": "Firestore service is not enabled"
}
Recovery
| HTTP status | API code / shape | Cause | Next action |
|---|---|---|---|
| 400 | incorrect_data | Non-JSON body. | Send JSON. |
| 422 | invalid_firestore | Missing/empty firestore value. | Supply the named nonempty field map. |
| 404 | user_resource_not_exists / firebase_user_not_exists | Missing membership or Firebase UID. | Establish the intended resource identity first. |
| 404 | firestore_not_active | Disabled Firestore. | Ask integration owner to enable/configure the existing service. |
| 404 | firestore_error | Other provider/local orchestration exception. | Inspect both provider/local state with support before repeating; partial writes are possible. |
Shared errors cover initialization, resource and session checks.
Next task
Use the member context for the content decision; stored profile fields do not grant access.