Missing or insufficient permissions ☁️ Google Cloud / Firebase

Firestore: FirebaseError: [code=permission-denied]: Missing or insufficient permissions

Firestore Security Rules denied the read/write — the user isn’t signed in, the rule conditions don’t match, or test-mode rules expired.

Seen on: Google Cloud

Meaning

Client SDK requests are evaluated against Security Rules. Test-mode rules expire after 30 days; queries must be constrained in ways the rules can verify (rules aren’t filters).

Common causes

  • Test-mode rules expired (allow until timestamp)
  • Request made before auth state is ready (request.auth null)
  • Query not filtered to match rule conditions
  • Rules deployed to another project/database

⚡ Quick fix

  1. Write rules for your data model and deploy them
  2. Wait for onAuthStateChanged before querying
  3. Add where clauses matching rule conditions (e.g. userId == uid)

Detailed fix by platform

JavaScript

  1. javascript
    rules_version = '2';
    service cloud.firestore {
      match /databases/{db}/documents {
        match /notes/{id} {
          allow read, write: if request.auth != null && request.auth.uid == resource.data.userId;
        }
      }
    }

How to diagnose

  1. Rules — Rules Playground with the same request
  2. Auth — Signed in at request time?
  3. Query — Constrained like the rule?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.