Identity Toolkit API config returns "CONFIGURATION_NOT_FOUND"

Viewed 152

I am trying to enable Firebase Authentication in my project, and to add Phone Auth to it, via API (without using the GUI console).

I am using the Service Usage API in order to enable Identity Toolkit, and then trying to use Identity Toolkit API in order to add the Phone Auth.

I am enabling Identity Toolkit via the Service Usage API like this (POST request):

URL:

https://serviceusage.googleapis.com/v1/projects/MY_GCP_PROJ/services:batchEnable

Body:

{
  "serviceIds": ["identitytoolkit"]
}

And indeed, after running this request I see in GCP console that Identity Toolkit has been enabled.

After that, I try to update the config using Identity Toolkit API, like this (PATCH request):

URL:

https://identitytoolkit.googleapis.com/v2/projects/MY_GCP_PROJ/config?updateMask=signIn

Body:

{
    "signIn": {
        "phoneNumber": {
            "enabled": true,
            "testPhoneNumbers": {
                "+11111111111": "123456",
            }
        },
    }
}

But for some reason, I receive an error saying:

{
    "error": {
        "code": 404,
        "message": "CONFIGURATION_NOT_FOUND",
        "status": "NOT_FOUND"
    }
}

I can't understand why the Identity Toolkit API cannot find the configuration and update it as specified.

Does anyone know how it can be solved?

Thank you

2 Answers

Ok, the following works for me.

Per discussion, you must enable identitytoolkit in the Firebase project:

SERVICE="identitytoolkit"
gcloud services enable ${SERVICE}.googleapis.com \
--project=${PROJECT}

# verify:

gcloud services list \
--enabled \
--project=${PROJECT} \
--filter=config.name=${SERVICE}.googleapis.com \
--format="value(state)"
# Want: ENABLED

Then:

PROJECT="[YOUR-FIREBASE-AUTH-PROJECT]"
ACCOUNT="[YOUR-SERVICE-ACCOUNT]"
EMAIL="${ACCOUNT}@${PROJECT}.iam.gserviceaccount.com"

# Optional: Create Service Account in Firebase Auth project
gcloud iam service-accounts create ${ACCOUNT} \
--project=${PROJECT}

# Create a Key for it to use to authenticate gcloud
gcloud iam service-accounts keys create ${PWD}/${ACCOUNT}.json \
--iam-account=${EMAIL} \
--project=${PROJECT}

# Add Firebase Auth Admin role
gcloud projects add-iam-policy-binding ${PROJECT} \
--role="roles/firebaseauth.admin" \
--member=serviceAccount:${EMAIL}

# Authenticate `gcloud` with Service Account (key)
gcloud auth activate-service-account --key-file=${PWD}/${ACCOUNT}.json

# Obtain Access Token for Service Account
TOKEN=$(gcloud auth print-access-token ${EMAIL})

DATA='
{
  "signIn":{
    "phoneNumber":{
      "enabled":true,
      "testPhoneNumbers":{
        "+11111111111":"123456"
      }
    }
  }
}
'

curl \
--silent \
--request PATCH \
--header "Authorization: Bearer ${TOKEN}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "${DATA}" \
https://identitytoolkit.googleapis.com/v2/projects/${PROJECT}/config?updateMask=signIn

Then:

curl \
--silent \
--request GET \
--header "Authorization: Bearer ${TOKEN}" \
--header "Accept: application/json" \
https://identitytoolkit.googleapis.com/v2/projects/${PROJECT}/config \
| jq -r .signIn.phoneNumber
{
  "enabled": true,
  "testPhoneNumbers": {
    "+11111111111": "123456"
  }
}

The same issue happened to me when I was trying to use REST API but then I get to know that the URL I am using was wrong. Try Method: projects.updateConfig

Related