Firestore: FirebaseError: [code=permission-denied]: Missing or insufficient permissions
Firestore Security Rules denied the read/write — the user isn’t signed in, the rule conditions don’t match, or test-mode rules expired.
Seen on:
Google Cloud
Meaning
Client SDK requests are evaluated against Security Rules. Test-mode rules expire after 30 days; queries must be constrained in ways the rules can verify (rules aren’t filters).
Common causes
- Test-mode rules expired (allow until timestamp)
- Request made before auth state is ready (request.auth null)
- Query not filtered to match rule conditions
- Rules deployed to another project/database
⚡ Quick fix
- Write rules for your data model and deploy them
- Wait for onAuthStateChanged before querying
- Add where clauses matching rule conditions (e.g. userId == uid)
Detailed fix by platform
JavaScript
- javascript
rules_version = '2'; service cloud.firestore { match /databases/{db}/documents { match /notes/{id} { allow read, write: if request.auth != null && request.auth.uid == resource.data.userId; } } }
How to diagnose
- Rules — Rules Playground with the same request
- Auth — Signed in at request time?
- Query — Constrained like the rule?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- Container failed to start Cloud Run: The user-provided container failed to start and listen on the port defined provided by the PORT=8080 environment variable
- Could not load the default credentials Google Cloud: Error: Could not load the default credentials. Browse to https://cloud.google.com/docs/authentication/getting-started
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026