Firebase Reset Password Link is failing because it's using rotated/old API Key

Viewed 43

I rotated the API Key that is used for setting up the firebase/auth app. Upon calling sendPasswordResetEmail successfully, I receive a link that is using the previous API Key.

Here's the API Key:

old and new api keys in google cloud console

Here's the link that was generated:

https://XXXXXXXXXX.firebaseapp.com/__/auth/action?mode=resetPassword&oobCode=XXXXXXX&apiKey=AIzXXXXXXXXXXXXXXXKPQ&lang=en

notice it ends with KPQ, which is the old key. The link does not work, it says it's expired.

If I swap out the API Key with the new one in the link, then I'm able to continue the forget password flow.

Does anyone know how to fix this? I'm using the updated API key in the app's config.

1 Answers

Firebase support suggested waiting for changes to happen on the backend. What I ended up doing to fix the issue was creating a new credential/api key (not rotate the existing one), and deleting the old ones. The issue still persisted for the weekend, it is now working though.

Related