> For the complete documentation index, see [llms.txt](https://estare.gitbook.io/firebase-auth-firestore-and-storage-plugin/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://estare.gitbook.io/firebase-auth-firestore-and-storage-plugin/setup/secure-your-credentials-and-data/restrict-your-api-key-to-your-domain.md).

# Restrict your api-key to your domain

A good way to secure your app is to restrict any front-end api-key to be accessible only on the domains you choose.

Firebase automatically configures the api-key for us, but this key is currently unrestricted. To restrict the domains that can use it, we must go to Google Cloud API console. The URL to do so will be something like:

{% embed url="<https://console.cloud.google.com/apis/credentials?project=YOUR_APP_ID_HERE>" %}
Change the YOUR\_APP\_ID\_HERE text to your Firebase APP ID.
{% endembed %}

Remember, you can see your app ID on the Firebase Console, settings (see image below).

<div align="left"><figure><img src="https://284736847-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiWu3FezEjWxrPbkf8zIP%2Fuploads%2FTD4eKtwVThfEFTta14uc%2Fimage.png?alt=media&amp;token=f073c3bc-26fa-4238-b5b0-c03fc4e94536" alt=""><figcaption></figcaption></figure></div>

## Restricting your api-key

1\) The Firebase generated API-KEY will be identified as being "auto created by Firebase". Click on the key, to open it's settings.

<div align="left"><figure><img src="https://284736847-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiWu3FezEjWxrPbkf8zIP%2Fuploads%2F8hdfYXWvuibuZmEJJFBM%2Fimage.png?alt=media&amp;token=fe7c0fc7-ceac-434f-86fc-621b8a098eed" alt=""><figcaption></figcaption></figure></div>

2\) On the "Key restrictions" settings, choose the "Websites" option.

<div align="left"><figure><img src="https://284736847-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiWu3FezEjWxrPbkf8zIP%2Fuploads%2F84sxGEjrHu9GBpqkzl4v%2Fimage.png?alt=media&amp;token=c1c85e14-bd76-4942-97bd-43f32a45347f" alt=""><figcaption></figcaption></figure></div>

3\) Finally, enter the URLs or domains you'd like to allow your credentials to be used and hit "Save".

You can leave "API restrictions" as it is, with "Don't restrict key" checked.

{% hint style="warning" %}
Important! You must also allow the domains on your Firebase Authentication Settings for features like Google/Facebook/Github login to work properly.

For instance, "yourfirebaseappid.firebaseapp.com".
{% endhint %}

<div align="left"><figure><img src="https://284736847-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiWu3FezEjWxrPbkf8zIP%2Fuploads%2FdGbLT5YfISVUkOfnkCAC%2Fimage.png?alt=media&amp;token=3aea09de-99ec-4445-8523-fb2636590d2b" alt=""><figcaption></figcaption></figure></div>

Done! Your api-key is now secure.
