What App Check does and why you might remove it
App Check is a Firebase security feature that verifies requests are coming from your legitimate app, not from a bot or someone reverse-engineering your API. It works by having your app prove its identity before Firebase processes requests. If you built App Check into your project and now want to turn it off — whether because you're testing, switching to a different security method, or the overhead isn't worth it for your use case — you need to remove it from both your Firebase console and your app code.
Removing App Check is straightforward but requires changes in two places: your Firebase project settings and your application code. If you skip either step, your app will either stop working or the protection will remain active even though you think you've disabled it.
Key Takeaways
- App Check must be removed from your Firebase console under Project Settings, then from your app code — doing only one leaves your app broken or partially protected.
- In your app code, you need to remove the App Check initialization lines and any enforcement rules that block requests without a valid token.
- If you're using App Check with specific services like Realtime Database or Cloud Storage, you must remove the enforcement rules for each one separately.
- After removing App Check, test your app thoroughly because requests that were previously blocked will now go through to your backend.
Disable App Check in the Firebase Console
Start by logging into the Firebase Console and opening your project. Navigate to Project Settings (the gear icon in the top left), then select the App Check tab. You'll see a list of apps registered in your project, each with an App Check status.
For each app where you want to remove App Check, click the three-dot menu next to it and select Delete. Firebase will ask you to confirm. Once you confirm, App Check is no longer active for that app in the console. This step stops Firebase from expecting App Check tokens, but your app code may still be trying to send them, so you need to clean up your code next.
Remove App Check initialization from your app code
Open your app's main code file where you initialize Firebase. In a web app, this is usually your index.js or main.js. In a mobile app, it's your main activity or app delegate. Look for lines that initialize App Check — they typically look like this in a web app:
initializeAppCheck(app, { provider: new ReCaptchaV3Provider('YOUR_RECAPTCHA_KEY'), isTokenAutoRefreshEnabled: true });
Delete these initialization lines entirely. If you're using a mobile app (iOS or Android), find the equivalent App Check setup code and remove it. In iOS, this is usually in your AppDelegate. In Android, it's in your Application class or MainActivity. Once you remove the initialization, your app will no longer attempt to generate or send App Check tokens.
Remove App Check enforcement from your services
If you set up App Check enforcement on specific Firebase services — like Realtime Database, Cloud Storage, or Cloud Functions — you need to turn that off separately. Go back to the Firebase Console and navigate to the service where you enabled enforcement. For Realtime Database, go to Database and find the Rules tab. For Cloud Storage, go to Storage and find Rules.
Look for rules that reference app.check.token. These rules block requests that don't include a valid App Check token. Remove or comment out these rules so requests are no longer rejected. A rule that enforces App Check might look like this:
match /documents/{document=**} { allow read, write: if request.auth != null && request.appCheck.token != null; }
Change it to allow requests without App Check, or remove the App Check condition entirely. Publish your updated rules when you're done.
Test your app after removal
Before you consider App Check fully removed, test your app in a real environment. Open your app on a device or in a browser and perform actions that make requests to Firebase — loading data, uploading files, or running functions. Watch your browser console (web) or logcat (Android) or console output (iOS) for errors. If you see messages about missing App Check tokens or failed requests, you may have missed removing initialization code somewhere.
If your app works normally and data flows to and from Firebase without errors, App Check is successfully removed. If you see errors, search your codebase for any remaining references to App Check, App Check provider, or token refresh, and remove those as well.
What to do if you want App Check back later
Removing App Check is not permanent. If you decide later that you want the protection again, you can re-enable it by going back to the Firebase Console, adding App Check to your project, and re-adding the initialization code to your app. You'll need to register your app's signing certificate (for Android) or App ID (for iOS or web) again, but the process is the same as the first time you set it up.
Keep in mind that if you remove App Check and then add it back, any users running old versions of your app without App Check code will get errors when they try to use services that enforce App Check. Plan your rollout carefully if you're re-enabling it.
Frequently Asked Questions
Will my app break if I only remove App Check from the console but not from my code?
Your app will likely continue to work, but it will waste resources generating and sending App Check tokens that Firebase no longer expects. You won't see errors, but you're doing unnecessary work. Remove it from your code to clean up.
Do I need to remove App Check from every service separately?
Yes. App Check enforcement is set per service through security rules. Disabling App Check in the console stops new tokens from being issued, but you must update the rules for Realtime Database, Cloud Storage, and Cloud Functions individually if you set enforcement on them.
What happens to users who have my app installed when I remove App Check?
If your app code still has App Check initialization, it will keep trying to send tokens. Since Firebase no longer expects them, the requests will still go through. If you removed App Check enforcement from your rules, requests work fine. If you didn't update the rules, requests will fail.
Can I remove App Check from one app but keep it on another in the same Firebase project?
Yes. You can delete App Check for specific apps in the console while leaving it active for others. However, your security rules apply to the entire service, so if you remove enforcement from your Realtime Database rules, it affects all apps in that project.
Where do I find my app's signing certificate if I need to re-enable App Check later?
For Android, generate it from your keystore file using the keytool command. For iOS, get it from your provisioning profile. For web, you don't need a certificate — just your reCAPTCHA key. The Firebase Console will guide you through this when you re-add App Check.