
FirebaseAuth Framework Reference


@available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
open class User : NSObject, UserInfo
extension User: NSSecureCoding

Represents a user.

Firebase Auth does not attempt to validate users when loading them from the keychain. Invalidated users (such as those whose passwords have been changed on another client) are automatically logged out when an auth-dependent operation is attempted or when the ID token is automatically refreshed.

This class is thread-safe.

  • Indicates the user represents an anonymous user.



    public internal(set) var isAnonymous: Bool { get }
  • Indicates the user represents an anonymous user.



    open func anonymous() -> Bool
  • Indicates the email address associated with this user has been verified.



    public private(set) var isEmailVerified: Bool { get }
  • Indicates the email address associated with this user has been verified.



    open func emailVerified() -> Bool
  • Profile data for each identity provider, if any.

    This data is cached on sign-in and updated when linking or unlinking.



    open var providerData: [UserInfo] { get }
  • Metadata associated with the Firebase user in question.



    public private(set) var metadata: UserMetadata { get }
  • The tenant ID of the current user. nil if none is available.



    public private(set) var tenantID: String? { get }
  • Multi factor object associated with the user.

    This property is available on iOS only.



    public private(set) var multiFactor: MultiFactor { get }
  • [Deprecated] Updates the email address for the user.

    On success, the cached user profile data is updated. Returns an error when Email Enumeration Protection is enabled.

    May fail if there is already an account with this email address that was created using email and password authentication.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeInvalidRecipientEmail - Indicates an invalid recipient email was sent in the request.
    • AuthErrorCodeInvalidSender - Indicates an invalid sender email is set in the console for this action.
    • AuthErrorCodeInvalidMessagePayload - Indicates an invalid email template for sending update email.
    • AuthErrorCodeEmailAlreadyInUse - Indicates the email is already in use by another account.
    • AuthErrorCodeInvalidEmail - Indicates the email address is malformed.
    • AuthErrorCodeRequiresRecentLogin - Updating a user’s email is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    @available(*, deprecated, message: "`updateEmail` is deprecated and will be removed in a future release. Use sendEmailVerification(beforeUpdatingEmail:﹚ instead.")
    open func updateEmail(to email: String, completion: ((Error?) -> Void)? = nil)



    The email address for the user.


    Optionally; the block invoked when the user profile change has finished.

  • [Deprecated] Updates the email address for the user.

    On success, the cached user profile data is updated. Throws when Email Enumeration Protection is enabled.

    May fail if there is already an account with this email address that was created using email and password authentication.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeInvalidRecipientEmail - Indicates an invalid recipient email was sent in the request.
    • AuthErrorCodeInvalidSender - Indicates an invalid sender email is set in the console for this action.
    • AuthErrorCodeInvalidMessagePayload - Indicates an invalid email template for sending update email.
    • AuthErrorCodeEmailAlreadyInUse - Indicates the email is already in use by another account.
    • AuthErrorCodeInvalidEmail - Indicates the email address is malformed.
    • AuthErrorCodeRequiresRecentLogin - Updating a user’s email is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    @available(*, deprecated, message: "`updateEmail` is deprecated and will be removed in a future release. Use sendEmailVerification(beforeUpdatingEmail:﹚ instead.")
    open func updateEmail(to email: String) async throws



    The email address for the user.

  • Updates the password for the user. On success, the cached user profile data is updated.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeOperationNotAllowed - Indicates the administrator disabled sign in with the specified identity provider.
    • AuthErrorCodeRequiresRecentLogin - Updating a user’s password is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).
    • AuthErrorCodeWeakPassword - Indicates an attempt to set a password that is considered too weak. The NSLocalizedFailureReasonErrorKey field in the userInfo dictionary object will contain more detailed explanation that can be shown to the user.



    open func updatePassword(to password: String, completion: ((Error?) -> Void)? = nil)



    The new password for the user.


    Optionally; the block invoked when the user profile change has finished.

  • Updates the password for the user. On success, the cached user profile data is updated.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeOperationNotAllowed - Indicates the administrator disabled sign in with the specified identity provider.
    • AuthErrorCodeRequiresRecentLogin - Updating a user’s password is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).
    • AuthErrorCodeWeakPassword - Indicates an attempt to set a password that is considered too weak. The NSLocalizedFailureReasonErrorKey field in the userInfo dictionary object will contain more detailed explanation that can be shown to the user.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func updatePassword(to password: String) async throws



    The new password for the user.

  • Updates the phone number for the user. On success, the cached user profile data is updated.

    Invoked asynchronously on the main thread in the future.

    This method is available on iOS only.

    Possible error codes:

    • AuthErrorCodeRequiresRecentLogin - Updating a user’s phone number is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    open func updatePhoneNumber(_ credential: PhoneAuthCredential,
                                completion: ((Error?) -> Void)? = nil)



    The new phone number credential corresponding to the phone number to be added to the Firebase account, if a phone number is already linked to the account this new phone number will replace it.


    Optionally; the block invoked when the user profile change has finished.

  • Updates the phone number for the user. On success, the cached user profile data is updated.

    Invoked asynchronously on the main thread in the future.

    This method is available on iOS only.

    Possible error codes:

    • AuthErrorCodeRequiresRecentLogin - Updating a user’s phone number is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func updatePhoneNumber(_ credential: PhoneAuthCredential) async throws



    The new phone number credential corresponding to the phone number to be added to the Firebase account, if a phone number is already linked to the account this new phone number will replace it.

  • Creates an object which may be used to change the user’s profile data.

    Set the properties of the returned object, then call UserProfileChangeRequest.commitChanges() to perform the updates atomically.



    open func createProfileChangeRequest() -> UserProfileChangeRequest

    Return Value

    An object which may be used to change the user’s profile data atomically.

  • A refresh token; useful for obtaining new access tokens independently.

    This property should only be used for advanced scenarios, and is not typically needed.



    open var refreshToken: String? { get }
  • Reloads the user’s profile data from the server.

    May fail with an AuthErrorCodeRequiresRecentLogin error code. In this case you should call reauthenticate(with:) before re-invoking updateEmail(to:).



    open func reload(completion: ((Error?) -> Void)? = nil)



    Optionally; the block invoked when the reload has finished. Invoked asynchronously on the main thread in the future.

  • Reloads the user’s profile data from the server.

    May fail with an AuthErrorCodeRequiresRecentLogin error code. In this case you should call reauthenticate(with:) before re-invoking updateEmail(to:).



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func reload() async throws
  • Renews the user’s authentication tokens by validating a fresh set of credentials supplied by the user and returns additional identity provider data.

    If the user associated with the supplied credential is different from the current user, or if the validation of the supplied credentials fails; an error is returned and the current user remains signed in.

    Possible error codes:

    • AuthErrorCodeInvalidCredential - Indicates the supplied credential is invalid. This could happen if it has expired or it is malformed.
    • AuthErrorCodeOperationNotAllowed - Indicates that accounts with the identity provider represented by the credential are not enabled. Enable them in the Auth section of the Firebase console.
    • AuthErrorCodeEmailAlreadyInUse - Indicates the email asserted by the credential (e.g. the email in a Facebook access token) is already in use by an existing account, that cannot be authenticated with this method. This error will only be thrown if the “One account per email address” setting is enabled in the Firebase console, under Auth settings. Please note that the error code raised in this specific situation may not be the same on Web and Android.
    • AuthErrorCodeUserDisabled - Indicates the user’s account is disabled.
    • AuthErrorCodeWrongPassword - Indicates the user attempted reauthentication with an incorrect password, if credential is of the type EmailPasswordAuthCredential.
    • AuthErrorCodeUserMismatch - Indicates that an attempt was made to reauthenticate with a user which is not the current user.
    • AuthErrorCodeInvalidEmail - Indicates the email address is malformed.



    open func reauthenticate(with credential: AuthCredential,
                             completion: ((AuthDataResult?, Error?) -> Void)? = nil)



    A user-supplied credential, which will be validated by the server. This can be a successful third-party identity provider sign-in, or an email address and password.


    Optionally; the block invoked when the re-authentication operation has finished. Invoked asynchronously on the main thread in the future.

  • Renews the user’s authentication tokens by validating a fresh set of credentials supplied by the user and returns additional identity provider data.

    If the user associated with the supplied credential is different from the current user, or if the validation of the supplied credentials fails; an error is returned and the current user remains signed in.

    Possible error codes:

    • AuthErrorCodeInvalidCredential - Indicates the supplied credential is invalid. This could happen if it has expired or it is malformed.
    • AuthErrorCodeOperationNotAllowed - Indicates that accounts with the identity provider represented by the credential are not enabled. Enable them in the Auth section of the Firebase console.
    • AuthErrorCodeEmailAlreadyInUse - Indicates the email asserted by the credential (e.g. the email in a Facebook access token) is already in use by an existing account, that cannot be authenticated with this method. This error will only be thrown if the “One account per email address” setting is enabled in the Firebase console, under Auth settings. Please note that the error code raised in this specific situation may not be the same on Web and Android.
    • AuthErrorCodeUserDisabled - Indicates the user’s account is disabled.
    • AuthErrorCodeWrongPassword - Indicates the user attempted reauthentication with an incorrect password, if credential is of the type EmailPasswordAuthCredential.
    • AuthErrorCodeUserMismatch - Indicates that an attempt was made to reauthenticate with a user which is not the current user.
    • AuthErrorCodeInvalidEmail - Indicates the email address is malformed.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func reauthenticate(with credential: AuthCredential) async throws -> AuthDataResult



    A user-supplied credential, which will be validated by the server. This can be a successful third-party identity provider sign-in, or an email address and password.

    Return Value

    The AuthDataResult after the reauthentication.

  • Renews the user’s authentication using the provided auth provider instance.

    This method is available on iOS only.



    open func reauthenticate(with provider: FederatedAuthProvider,
                             uiDelegate: AuthUIDelegate?,
                             completion: ((AuthDataResult?, Error?) -> Void)? = nil)



    An instance of an auth provider used to initiate the reauthenticate flow.


    Optionally an instance of a class conforming to the AuthUIDelegate protocol, used for presenting the web context. If nil, a default AuthUIDelegate will be used.


    Optionally; a block which is invoked when the reauthenticate flow finishes, or is canceled. Invoked asynchronously on the main thread in the future.

  • Renews the user’s authentication using the provided auth provider instance.

    This method is available on iOS only.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func reauthenticate(with provider: FederatedAuthProvider,
                             uiDelegate: AuthUIDelegate?) async throws -> AuthDataResult



    An instance of an auth provider used to initiate the reauthenticate flow.


    Optionally an instance of a class conforming to the AuthUIDelegate protocol, used for presenting the web context. If nil, a default AuthUIDelegate will be used.

    Return Value

    The AuthDataResult after the reauthentication.

  • Retrieves the Firebase authentication token, possibly refreshing it if it has expired.



    open func getIDToken(completion: ((String?, Error?) -> Void)?)



    Optionally; the block invoked when the token is available. Invoked asynchronously on the main thread in the future.

  • Retrieves the Firebase authentication token, possibly refreshing it if it has expired.

    The authentication token will be refreshed (by making a network request) if it has expired, or if forceRefresh is true.



    open func getIDTokenForcingRefresh(_ forceRefresh: Bool,
                                       completion: ((String?, Error?) -> Void)?)



    Forces a token refresh. Useful if the token becomes invalid for some reason other than an expiration.


    Optionally; the block invoked when the token is available. Invoked asynchronously on the main thread in the future.

  • Retrieves the Firebase authentication token, possibly refreshing it if it has expired.

    The authentication token will be refreshed (by making a network request) if it has expired, or if forceRefresh is true.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func getIDToken(forcingRefresh forceRefresh: Bool = false) async throws -> String



    Forces a token refresh. Useful if the token becomes invalid for some reason other than an expiration.

    Return Value

    The Firebase authentication token.

  • API included for compatibility with a mis-named Firebase 10 API. Use getIDToken(forcingRefresh forceRefresh: Bool = false) instead.



    open func idTokenForcingRefresh(_ forceRefresh: Bool) async throws -> String
  • Retrieves the Firebase authentication token, possibly refreshing it if it has expired.



    open func getIDTokenResult(completion: ((AuthTokenResult?, Error?) -> Void)?)



    Optionally; the block invoked when the token is available. Invoked asynchronously on the main thread in the future.

  • Retrieves the Firebase authentication token, possibly refreshing it if it has expired.

    The authentication token will be refreshed (by making a network request) if it has expired, or if forcingRefresh is true.



    open func getIDTokenResult(forcingRefresh: Bool,
                               completion: ((AuthTokenResult?, Error?) -> Void)?)



    Forces a token refresh. Useful if the token becomes invalid for some reason other than an expiration.


    Optionally; the block invoked when the token is available. Invoked asynchronously on the main thread in the future.

  • Retrieves the Firebase authentication token, possibly refreshing it if it has expired.

    The authentication token will be refreshed (by making a network request) if it has expired, or if forceRefresh is true.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func getIDTokenResult(forcingRefresh forceRefresh: Bool = false) async throws
      -> AuthTokenResult



    Forces a token refresh. Useful if the token becomes invalid for some reason other than an expiration.

    Return Value

    The Firebase authentication token.

  • Associates a user account from a third-party identity provider with this user and returns additional identity provider data.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeProviderAlreadyLinked - Indicates an attempt to link a provider of a type already linked to this account.
    • AuthErrorCodeCredentialAlreadyInUse - Indicates an attempt to link with a credential that has already been linked with a different Firebase account.
    • AuthErrorCodeOperationNotAllowed - Indicates that accounts with the identity provider represented by the credential are not enabled. Enable them in the Auth section of the Firebase console.

    This method may also return error codes associated with updateEmail(to:) and updatePassword(to:) on User.



    open func link(with credential: AuthCredential,
                   completion: ((AuthDataResult?, Error?) -> Void)? = nil)



    The credential for the identity provider.


    Optionally; the block invoked when the unlinking is complete, or fails.

  • Associates a user account from a third-party identity provider with this user and returns additional identity provider data.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeProviderAlreadyLinked - Indicates an attempt to link a provider of a type already linked to this account.
    • AuthErrorCodeCredentialAlreadyInUse - Indicates an attempt to link with a credential that has already been linked with a different Firebase account.
    • AuthErrorCodeOperationNotAllowed - Indicates that accounts with the identity provider represented by the credential are not enabled. Enable them in the Auth section of the Firebase console.

    This method may also return error codes associated with updateEmail(to:) and updatePassword(to:) on User.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func link(with credential: AuthCredential) async throws -> AuthDataResult



    The credential for the identity provider.

    Return Value

    An AuthDataResult.

  • Link the user with the provided auth provider instance.

    This method is available on iOSonly.



    open func link(with provider: FederatedAuthProvider,
                   uiDelegate: AuthUIDelegate?,
                   completion: ((AuthDataResult?, Error?) -> Void)? = nil)



    An instance of an auth provider used to initiate the link flow.


    Optionally an instance of a class conforming to the AuthUIDelegate protocol used for presenting the web context. If nil, a default AuthUIDelegate will be used.


    Optionally; a block which is invoked when the link flow finishes, or is canceled. Invoked asynchronously on the main thread in the future.

  • Link the user with the provided auth provider instance.

    This method is available on iOSonly.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func link(with provider: FederatedAuthProvider,
                   uiDelegate: AuthUIDelegate?) async throws -> AuthDataResult



    An instance of an auth provider used to initiate the link flow.


    Optionally an instance of a class conforming to the AuthUIDelegate protocol used for presenting the web context. If nil, a default AuthUIDelegate will be used.


    Optionally; a block which is invoked when the link flow finishes, or is canceled. Invoked asynchronously on the main thread in the future.

    Return Value

    An AuthDataResult.

  • Disassociates a user account from a third-party identity provider with this user.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeNoSuchProvider - Indicates an attempt to unlink a provider that is not linked to the account.
    • AuthErrorCodeRequiresRecentLogin - Updating email is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    open func unlink(fromProvider provider: String,
                     completion: ((User?, Error?) -> Void)? = nil)



    The provider ID of the provider to unlink.


    Optionally; the block invoked when the unlinking is complete, or fails.

  • Disassociates a user account from a third-party identity provider with this user.

    Invoked asynchronously on the main thread in the future.

    Possible error codes:

    • AuthErrorCodeNoSuchProvider - Indicates an attempt to unlink a provider that is not linked to the account.
    • AuthErrorCodeRequiresRecentLogin - Updating email is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func unlink(fromProvider provider: String) async throws -> User



    The provider ID of the provider to unlink.

    Return Value

    The user.

  • Initiates email verification for the user.

    Possible error codes:

    • AuthErrorCodeInvalidRecipientEmail - Indicates an invalid recipient email was sent in the request.
    • AuthErrorCodeInvalidSender - Indicates an invalid sender email is set in the console for this action.
    • AuthErrorCodeInvalidMessagePayload - Indicates an invalid email template for sending update email.
    • AuthErrorCodeUserNotFound - Indicates the user account was not found.



    open func __sendEmailVerification(withCompletion completion: ((Error?) -> Void)?)



    Optionally; the block invoked when the request to send an email verification is complete, or fails. Invoked asynchronously on the main thread in the future.

  • Initiates email verification for the user.

    Possible error codes:

    • AuthErrorCodeInvalidRecipientEmail - Indicates an invalid recipient email was sent in the request.
    • AuthErrorCodeInvalidSender - Indicates an invalid sender email is set in the console for this action.
    • AuthErrorCodeInvalidMessagePayload - Indicates an invalid email template for sending update email.
    • AuthErrorCodeUserNotFound - Indicates the user account was not found.



    open func sendEmailVerification(with actionCodeSettings: ActionCodeSettings? = nil,
                                    completion: ((Error?) -> Void)? = nil)



    An ActionCodeSettings object containing settings related to handling action codes.


    Optionally; the block invoked when the request to send an email verification is complete, or fails. Invoked asynchronously on the main thread in the future.

  • Initiates email verification for the user.

    Possible error codes:

    • AuthErrorCodeInvalidRecipientEmail - Indicates an invalid recipient email was sent in the request.
    • AuthErrorCodeInvalidSender - Indicates an invalid sender email is set in the console for this action.
    • AuthErrorCodeInvalidMessagePayload - Indicates an invalid email template for sending update email.
    • AuthErrorCodeUserNotFound - Indicates the user account was not found.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func sendEmailVerification(with actionCodeSettings: ActionCodeSettings? = nil) async throws



    An ActionCodeSettings object containing settings related to handling action codes. The default value is nil.

  • Deletes the user account (also signs out the user, if this was the current user).

    Possible error codes:

    • AuthErrorCodeRequiresRecentLogin - Updating email is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    open func delete(completion: ((Error?) -> Void)? = nil)



    Optionally; the block invoked when the request to delete the account is complete, or fails. Invoked asynchronously on the main thread in the future.

  • Deletes the user account (also signs out the user, if this was the current user).

    Possible error codes:

    • AuthErrorCodeRequiresRecentLogin - Updating email is a security sensitive operation that requires a recent login from the user. This error indicates the user has not signed in recently enough. To resolve, reauthenticate the user by calling reauthenticate(with:).



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func delete() async throws
  • Send an email to verify the ownership of the account then update to the new email.



    open func __sendEmailVerificationBeforeUpdating(email: String, completion: ((Error?) -> Void)?)



    The email to be updated to.


    Optionally; the block invoked when the request to send the verification email is complete, or fails.

  • Send an email to verify the ownership of the account then update to the new email.



    open func sendEmailVerification(beforeUpdatingEmail email: String,
                                    actionCodeSettings: ActionCodeSettings? = nil,
                                    completion: ((Error?) -> Void)? = nil)



    The email to be updated to.


    An ActionCodeSettings object containing settings related to handling action codes.


    Optionally; the block invoked when the request to send the verification email is complete, or fails.

  • Send an email to verify the ownership of the account then update to the new email.



    @available(iOS 13, tvOS 13, macOS 10.15, watchOS 7, *)
    open func sendEmailVerification(beforeUpdatingEmail newEmail: String,
                                    actionCodeSettings: ActionCodeSettings? = nil) async throws



    The email to be updated to.


    An ActionCodeSettings object containing settings related to handling action codes.

  • Declaration


    open var providerID: String { get }
  • uid

    The provider’s user ID for the user.



    open var uid: String
  • The name of the user.



    open var displayName: String?
  • The URL of the user’s profile photo.



    open var photoURL: URL?
  • The user’s email address.



    open var email: String?
  • A phone number associated with the user.

    This property is only available for users authenticated via phone number auth.



    open var phoneNumber: String?
  • Undocumented



    public static var supportsSecureCoding: Bool { get }
  • Undocumented



    public func encode(with coder: NSCoder)
  • Undocumented



    public required init?(coder: NSCoder)