auth/too-many-requests 🔐 Authentication

Firebase Auth: auth/too-many-requests — Access to this account has been temporarily disabled due to many failed login attempts

Firebase throttled sign-in or SMS verification because of too many attempts from the device/IP or for the account.

Seen on: REST API

Meaning

Repeated wrong passwords, automated tests hitting real auth, or SMS OTP abuse protection trigger it. It clears after a while; resetting the password unlocks the account sooner.

Common causes

  • Many failed password attempts
  • Automated tests or scripts using production Auth
  • Phone auth SMS quota/abuse protection

⚡ Quick fix

  1. Wait and retry later; offer password reset
  2. Use the Auth emulator or test phone numbers in tests
  3. Add App Check/reCAPTCHA for phone auth

Detailed fix by platform

JavaScript

  1. connectAuthEmulator(auth, "http://127.0.0.1:9099"); // tests/dev

How to diagnose

  1. Source — Tests or users?
  2. Flow — Password or phone?
  3. IP — Shared NAT?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.