firebase_admin auth.verify_id_token is very slow

Viewed 1038

I am resolving user data using firebase for auth like so:

from firebase_admin import auth decoded_token = auth.verify_id_token(client_id_token) I am initializing my firebase creds with firebase_admin.initialize_app(cred)

Here cliend_id_token is a token that the client sends. However, this takes around 1 second to perform, which seems way too long. One possibility is to use a caching layer above this (lru cache, memcache) but it still seems that it should not fundamentally take so long. Looking at the the signature of verify_id_token there does not seem to be anything that stands out as something that I can pass in:

def verify_id_token(id_token, app=None):

Any thoughts on how to diagnose (or if I am missing something)?

1 Answers

The problem is because that function does an http request in order to have the key to decode the jwt. In addition, because it returns info such as the email of the user, while the jwt contains only the uid as sub field of the decoded jwt, I think that it does another http request under the hood to get the user from the decoded uid.

You should implement your custom decode function, following the docs: https://firebase.google.com/docs/auth/admin/verify-id-tokens

Related