> For the complete documentation index, see [llms.txt](https://estare.gitbook.io/firebase-auth-firestore-and-storage-plugin/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://estare.gitbook.io/firebase-auth-firestore-and-storage-plugin/setup/secure-your-credentials-and-data.md).

# Secure your credentials and data

To operate fast and on the front-end, the Firebase plugin must expose your Firebase App credentials. This poses a security risk for your business, if not dealt correctly.

Follow the instructions below on how to secure your app and keep using the power of Firebase without any concerns.

{% embed url="<https://youtu.be/SdVx17vCfNw?si=vNSZZSbj2p1uKxxl>" %}

{% content-ref url="/pages/4l8tZS12KeGK5uyTKCjp" %}
[Restrict your api-key to your domain](/firebase-auth-firestore-and-storage-plugin/setup/secure-your-credentials-and-data/restrict-your-api-key-to-your-domain.md)
{% endcontent-ref %}

{% content-ref url="/pages/A6iepnqaYJuSbRg4RIWq" %}
[Security Rules on Firebase](/firebase-auth-firestore-and-storage-plugin/setup/secure-your-credentials-and-data/security-rules-on-firebase.md)
{% endcontent-ref %}
