Goal
Plan Firebase Auth so identity, claims, and app access rules stay coherent.
When to Use
- The stack uses Firebase Auth.
- Claims, roles, or sign-in methods must be chosen.
- Firestore or Functions permissions depend on identity design.
Instructions
- Define user types, sign-in providers, and session expectations.
- Decide when custom claims are needed and how they are assigned.
- Map auth flows to Firestore access and Cloud Functions behavior.
- Plan invite, onboarding, and account recovery paths.
- Note admin-only operations and how they are protected.
Constraints
- Keep privileged claim assignment server-side.
- Do not overload claims with high-cardinality or fast-changing data.
- Distinguish auth provider identity from app-level membership.
Output Format
- Identity model
- Provider/session plan
- Claims strategy
- Access control notes
Examples
- "Design Firebase Auth for a consumer app with Google sign-in."
- "Should we use custom claims for admin access?"