Source profileQuality 95/100

evanca/flutter-ai-rules/skills/firebase-messaging/SKILL.md

firebase-messaging

Use when setting up Firebase Cloud Messaging, managing permissions and tokens, handling background/foreground notification taps, or dispatching messages server-side (HTTP v1).

Source repository stars
620
Declared platforms
0
Static risk flags
2
Last source update
2026-08-27
Source checked
2026-08-28

Decision brief

What it does: where it fits

This skill defines how to correctly use Firebase Cloud Messaging (FCM) in Flutter applications.

Best for

  • Setting up push notifications with FCM in a Flutter project.
  • Handling messages in foreground, background, and terminated states.
  • Managing notification permissions and FCM tokens.

Not for

  • Tasks that require unconfirmed production actions or broad system permissions.
  • Environments where the pinned source and install steps cannot be inspected.

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeNot declaredNo explicit evidencePortability before use
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/evanca/flutter-ai-rules --skill "skills/firebase-messaging"
Safe inspection promptEditorial

Inspect the Agent Skill "firebase-messaging" from https://github.com/evanca/flutter-ai-rules/blob/713576e02b6a17de4cc5a95ad55bdcca3a0827a6/skills/firebase-messaging/SKILL.md at commit 713576e02b6a17de4cc5a95ad55bdcca3a0827a6. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    1. Setup and Configuration

    iOS: - Enable Push Notifications and Background Modes in Xcode. - Upload your APNs authentication key to Firebase before using FCM. - Do not disable method swizzling — it is required for FCM token handling. - Ensure the bundle ID for your APNs authentication key matches your app…

    Enable Push Notifications and Background Modes in Xcode.Upload your APNs authentication key to Firebase before using FCM.Do not disable method swizzling — it is required for FCM token handling.
  2. 02

    When to Use

    Setting up push notifications with FCM in a Flutter project. Handling messages in foreground, background, and terminated states. Managing notification permissions and FCM tokens. Configuring platform-specific notification display behavior.

    Setting up push notifications with FCM in a Flutter project.Handling messages in foreground, background, and terminated states.Managing notification permissions and FCM tokens.
  3. 03

    2. Message Handling

    Background handler rules: - Must be a top-level function (not anonymous, not a class method). - Annotate with @pragma('vm:entry-point') (Flutter 3.3.0+) to prevent removal during tree shaking in release mode. - Cannot update app state or execute UI-impacting logic — runs in a se…

    Must be a top-level function (not anonymous, not a class method).Annotate with @pragma('vm:entry-point') (Flutter 3.3.0+) to prevent removal during tree shaking in release mode.Cannot update app state or execute UI-impacting logic — runs in a separate isolate.
  4. 04

    3. Permissions

    iOS / macOS / Web / Android 13+: Must request permission before receiving FCM payloads.

    iOS / macOS / Web / Android 13+: Must request permission before receiving FCM payloads.Android < 13: authorizationStatus returns authorized if the user has not disabled notifications in OS settings.Android 13+: Track permission requests in your app — there's no way to determine if the user chose to grant/deny.
  5. 05

    4. Token Management

    Get FCM registration token (use to send messages to a specific device):

    Get FCM registration token (use to send messages to a specific device):Web — provide VAPID key:Listen for token refresh:

Permission review

Static risk signals and limitations

Writes files

medium · line 34

The documentation asks the agent to create, modify, or delete local files.

Create and register a service worker file named `firebase-messaging-sw.js` in your `web/` directory:

Network access

medium · line 37

The documentation includes network, browsing, or remote request actions.

importScripts("https://www.gstatic.com/firebasejs/10.7.0/firebase-app-compat.js");

Network access

medium · line 38

The documentation includes network, browsing, or remote request actions.

importScripts("https://www.gstatic.com/firebasejs/10.7.0/firebase-messaging-compat.js");

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score95/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars620SourceRepository attention, not individual Skill quality
Compatibility0 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
evanca/flutter-ai-rules
Skill path
skills/firebase-messaging/SKILL.md
Commit
713576e02b6a17de4cc5a95ad55bdcca3a0827a6
License
MIT
Collected
2026-08-28
Default branch
main
View the original SKILL.md

Firebase Cloud Messaging Skill

This skill defines how to correctly use Firebase Cloud Messaging (FCM) in Flutter applications.

When to Use

Use this skill when:

  • Setting up push notifications with FCM in a Flutter project.
  • Handling messages in foreground, background, and terminated states.
  • Managing notification permissions and FCM tokens.
  • Configuring platform-specific notification display behavior.

1. Setup and Configuration

flutter pub add firebase_messaging

iOS:

  • Enable Push Notifications and Background Modes in Xcode.
  • Upload your APNs authentication key to Firebase before using FCM.
  • Do not disable method swizzling — it is required for FCM token handling.
  • Ensure the bundle ID for your APNs authentication key matches your app's bundle ID.

Android:

  • Devices must run Android 4.4+ with Google Play services installed.
  • Check for Google Play services compatibility in both onCreate() and onResume().

Web:

  • Create and register a service worker file named firebase-messaging-sw.js in your web/ directory:
importScripts("https://www.gstatic.com/firebasejs/10.7.0/firebase-app-compat.js");
importScripts("https://www.gstatic.com/firebasejs/10.7.0/firebase-messaging-compat.js");

firebase.initializeApp({ /* your config */ });

const messaging = firebase.messaging();

messaging.onBackgroundMessage((message) => {
  console.log("onBackgroundMessage", message);
});

2. Message Handling

Foreground messages:

FirebaseMessaging.onMessage.listen((RemoteMessage message) {
  print('Foreground message data: ${message.data}');
  if (message.notification != null) {
    print('Notification: ${message.notification}');
  }
});

Background messages:

@pragma('vm:entry-point')
Future<void> _firebaseMessagingBackgroundHandler(RemoteMessage message) async {
  // Initialize Firebase before using other Firebase services in background
  await Firebase.initializeApp();
  print("Background message: ${message.messageId}");
}

void main() {
  FirebaseMessaging.onBackgroundMessage(_firebaseMessagingBackgroundHandler);
  runApp(MyApp());
}

Background handler rules:

  • Must be a top-level function (not anonymous, not a class method).
  • Annotate with @pragma('vm:entry-point') (Flutter 3.3.0+) to prevent removal during tree shaking in release mode.
  • Cannot update app state or execute UI-impacting logic — runs in a separate isolate.
  • Call Firebase.initializeApp() before using any other Firebase services.

3. Permissions

NotificationSettings settings = await FirebaseMessaging.instance.requestPermission(
  alert: true,
  badge: true,
  sound: true,
  announcement: false,
  carPlay: false,
  criticalAlert: false,
  provisional: false,
);

print('Authorization status: ${settings.authorizationStatus}');
  • iOS / macOS / Web / Android 13+: Must request permission before receiving FCM payloads.
  • Android < 13: authorizationStatus returns authorized if the user has not disabled notifications in OS settings.
  • Android 13+: Track permission requests in your app — there's no way to determine if the user chose to grant/deny.
  • Use provisional permissions on iOS (provisional: true) to let users choose notification types after receiving their first notification.

4. Token Management

Get FCM registration token (use to send messages to a specific device):

final fcmToken = await FirebaseMessaging.instance.getToken();

Web — provide VAPID key:

final fcmToken = await FirebaseMessaging.instance.getToken(
  vapidKey: "BKagOny0KF_2pCJQ3m....moL0ewzQ8rZu"
);

Listen for token refresh:

FirebaseMessaging.instance.onTokenRefresh.listen((fcmToken) {
  // Send updated token to your application server
}).onError((err) {
  // Handle error
});

Apple platforms — ensure APNS token is available before FCM calls:

final apnsToken = await FirebaseMessaging.instance.getAPNSToken();
if (apnsToken != null) {
  // Safe to make FCM plugin API requests
}

Token Lifecycle (Auth State): Tokens should be tied to user sessions. Save the token to your database when a user signs in, and delete the token (or remove it from the user's document) when they sign out. An FCM token is device-specific, not inherently tied to user auth data — failing to clear it on sign-out means the next user on that device might receive the previous user's notifications.


5. Platform-Specific Behavior

  • iOS: If the user swipes away the app from the app switcher, it must be manually reopened for background messages to work again.
  • Android: If the user force-quits from device settings, the app must be manually reopened.
  • iOS foreground notifications: Update presentation options to display notifications while the app is in the foreground:
    await FirebaseMessaging.instance.setForegroundNotificationPresentationOptions(
      alert: true,
      badge: true,
      sound: true,
    );
    
  • Android foreground notifications: Notification messages arriving while the app is in the foreground won't display a visible notification by default. You must consume the payload via the onMessage stream and manually display a visual cue (using your own UI logic or a local notifications plugin).
  • Android default channel: To set a default channel for background notifications, add this meta-data to your <application> block in AndroidManifest.xml:
    <meta-data
        android:name="com.google.firebase.messaging.default_notification_channel_id"
        android:value="high_importance_channel" />
    

6. Auto-Initialization Control

Disable auto-init — iOS (Info.plist):

FirebaseMessagingAutoInitEnabled = NO

Disable auto-init — Android (AndroidManifest.xml):

<meta-data android:name="firebase_messaging_auto_init_enabled" android:value="false" />
<meta-data android:name="firebase_analytics_collection_enabled" android:value="false" />

Re-enable at runtime:

await FirebaseMessaging.instance.setAutoInitEnabled(true);
  • The auto-init setting persists across app restarts once set.

7. iOS Image Notifications

Important: The iOS simulator does not display images in push notifications. Test on a physical device.

  • Add a Notification Service Extension in Xcode.
  • Use Messaging.serviceExtension().populateNotificationContent() in the extension for image handling.
  • Swift: add the FirebaseMessaging Swift package to your extension target.
  • Objective-C: add the Firebase/Messaging pod to your Podfile.

8. Notification Interaction Handling

When a user taps a notification, the app opens (or is brought to the foreground). Handle the interaction in both cases:

App was terminated:

RemoteMessage? initialMessage =
    await FirebaseMessaging.instance.getInitialMessage();
if (initialMessage != null) {
  // Navigate based on message content
}

App was in background:

FirebaseMessaging.onMessageOpenedApp.listen((RemoteMessage message) {
  // Navigate based on message content
});

Always handle both scenarios to ensure a smooth user experience regardless of app state when the notification was received.


9. Topic Messaging

  • Subscribing to a topic allows sending messages to multiple devices that have opted in.
  • Topic messages are best suited for publicly available information (e.g., weather updates), optimized for throughput rather than latency.
// Subscribe
await FirebaseMessaging.instance.subscribeToTopic("weather_alerts");

// Unsubscribe
await FirebaseMessaging.instance.unsubscribeFromTopic("weather_alerts");

Note: subscribeToTopic() and unsubscribeFromTopic() are not supported for web clients via the Flutter plugin.


10. Sending a Test Message

The official Firebase documentation often obscures the exact steps for sending a test push notification. To fire a push (test or real) using the Firebase Console:

  1. Obtain your device's FCM registration token (see Section 4).
  2. Go to the Firebase Console and select your project.
  3. In the left navigation panel, find the Engage (or Run) section and click Messaging (or Cloud Messaging).
  4. Click New campaign and select Notifications.
  5. Enter a Notification title and Notification text.
  6. Click Send test message (often a button on the right side of the screen).
  7. In the dialog, enter your FCM registration token and click the + icon to add it.
  8. Make sure the token is checked, then click Test.

To send real automated push notifications to production users, you must use a server implementation (via the FCM HTTP v1 API or the Firebase Admin SDK) rather than the console.


11. Server-Side Credentials & Security

The legacy FCM server key endpoint was deprecated in June 2024 — HTTP v1 is the only supported option for sending pushes.

To authenticate server-to-server calls for HTTP v1, you need a Service Account:

  1. Go to Firebase Console → Project settings → Service accounts.
  2. Click Generate new private key (downloads a .json file).
  3. CRITICAL: This file contains highly sensitive secrets and must never be committed to git.
  4. Store the file securely (e.g., in a Secret Manager) or pass its stringified contents as an environment variable (like FIREBASE_SERVICE_ACCOUNT) to your backend.

12. Sending Messages (HTTP v1)

To send an FCM HTTP v1 message, your backend must:

  1. Complete an OAuth2 JWT exchange (sign with RS256, scope https://www.googleapis.com/auth/firebase.messaging, endpoint https://oauth2.googleapis.com/token).
  2. Construct and POST a JSON payload to https://fcm.googleapis.com/v1/projects/{project_id}/messages:send.

Here is a minimal, complete working example using Node.js and the google-auth-library:

const { GoogleAuth } = require('google-auth-library');

// Read the securely-stored service account JSON from environment
const credentials = JSON.parse(process.env.FIREBASE_SERVICE_ACCOUNT);

async function getAccessToken() {
  const auth = new GoogleAuth({
    credentials,
    scopes: ['https://www.googleapis.com/auth/firebase.messaging']
  });
  const client = await auth.getClient();
  const token = await client.getAccessToken();
  return token.token;
}

async function sendPushNotification(fcmToken, title, body) {
  const accessToken = await getAccessToken();
  const projectId = credentials.project_id;
  const url = `https://fcm.googleapis.com/v1/projects/${projectId}/messages:send`;
  
  const payload = {
    message: {
      token: fcmToken,
      notification: {
        title: title,
        body: body,
      },
      // Target specific platform features (e.g., channel on Android, sound on iOS)
      android: {
        notification: {
          channel_id: 'high_importance_channel',
        }
      },
      apns: {
        payload: {
          aps: {
            sound: 'default',
          }
        }
      }
    }
  };

  const response = await fetch(url, {
    method: 'POST',
    headers: {
      'Authorization': `Bearer ${accessToken}`,
      'Content-Type': 'application/json'
    },
    body: JSON.stringify(payload)
  });

  return response.json();
}

References

Frequently asked questions

What to verify before installation and use

What does the firebase-messaging source document cover?

This skill defines how to correctly use Firebase Cloud Messaging (FCM) in Flutter applications.

How do I install firebase-messaging?

The source record exposes this install command: npx skills add https://github.com/evanca/flutter-ai-rules --skill "skills/firebase-messaging". Inspect the command and pinned source before running it.

Which permission-related actions were detected?

Static rules flagged write-files, network in the source; the page lists the matching lines and excerpts.

Alternatives

Compare before choosing

Computed 10045,960

coreyhaines31/marketingskills

ab-testing

When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program

Computed 10029,236

garrytan/gbrain

bulk-ingestion

End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.

Computed 10025,136

alirezarezvani/claude-skills

app-store-optimization

App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

Computed 1005,277

dotnet/skills

migrate-vstest-to-mtp

Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing