Goal
Create focused Cloud Functions for trusted backend work in Firebase systems.
When to Use
- The logic must run server-side in a Firebase stack.
- Auth-triggered, scheduled, webhook, or admin tasks are required.
- The client should not perform the privileged operation directly.
Instructions
- Define the trigger type and caller.
- Separate validation, auth checks, business logic, and persistence.
- Plan retries, idempotency, and logging.
- Protect secrets and admin SDK usage carefully.
- Align the function with Firestore rules and auth claims.
Constraints
- Do not put long-running or unrelated workflows into one function.
- Never expose admin credentials or privileged endpoints publicly without verification.
- Keep function contracts explicit.
Output Format
- Function summary
- Trigger/input/output
- Security notes
- Failure handling
- Scaffold direction
Examples
- "Build a Firebase Function for Stripe webhooks."
- "Plan a scheduled cleanup function."