Firetool

Home / Features / Security rules editor

Security rules

A Firestore security rules editor on your desktop

Open the rules Firebase has for a Firestore database or a Storage bucket, check them for errors, and deploy a change, with the same production checks as your data and the old rules kept so you can put them back.

Why here

Rules next to the data they protect

Security rules decide who can read and write every document and file, so a wrong line can lock out your app or open your data to anyone. Firetool shows the rules that are live right now, in the same window as the collections they cover, and treats a deploy like any other change to production: it is checked, confirmed and written to the audit log.

Edit and check

Firebase checks the rules before anything goes live

Right-click a database in the sidebar and choose Security rules…, or use Tools, Security rules…. Edit the rules, then choose Check: Firebase compiles them and lists every error and warning with its line and column. Click one to go there. Checking saves nothing.

  • Firestore rules for each database, including named ones
  • Storage rules for each bucket
  • Shows since when the rules have been live
The security rules editor in Firetool with Firestore rules for users, orders and products, and the message that Firebase found no errors

Deploy safely

The checks a production change deserves

Production asks first

On a project marked production, Firetool asks you to type the project ID before the rules go live, and asks for a reason when your policy says so.

No overwriting someone else

If the rules were changed in the Firebase console or with the CLI after you opened them, the deploy is refused until you reload, so their change isn't lost.

Put the old rules back

Every deploy goes in the audit log with the rules it replaced. Put back these rules… opens them in the editor, ready to check and deploy again.

Roles and read-only

A Viewer, a read-only project or the Free edition can open and check rules but not deploy them.

Questions

Security rules in Firetool: common questions

Does Firetool change my firestore.rules file?

No. Firetool works with the rules that are live in Firebase. If you also deploy from a file with the Firebase CLI, copy your change into the file, or the next CLI deploy puts the file's version back.

Can I test a request against my rules?

Not yet. Check finds errors in the rules themselves. To try requests, use the Rules Playground in the Firebase console or the emulators.

What access does my Google account need?

Firebase Rules Viewer to open the rules, and Firebase Rules Admin (or Owner or Editor) to deploy them.

Does deploying rules need Pro?

Yes. Opening and checking rules works in the Free edition; deploying needs Pro, which every computer can try free for 30 days.

Try it on your own data

Free for Windows, macOS and Linux, with every Pro feature for the first 30 days.