Head to head · Notify push · October 2026 research run
Firebase Cloud Messaging vs OneSignal
Firebase Cloud Messaging and OneSignal score within a point of each other on agent readiness, 69.8 (B) and 69.3 (B). OneSignal leads on security & auth. Both do notify push.
Which one, for what
Good for The push transport under an app that already holds device registrations, at no charge.
Ahead on
- Agent ergonomics, 70 against 64
- Payments & pricing, 40 against 35
- Transparency & trust, 81 against 72
Watch for
Push transport only. No in-app feed, email, SMS, user preferences, digests or templates
Good for A team whose main channel is push to its own mobile or web app and who wants delivery handled without a separate push provider.
Ahead on
- Security & auth, 74 against 68
Watch for
Three incidents on the API and SDK endpoints in September 2026
Score by category
| Category | Weight this run | Firebase Cloud Messaging | OneSignal | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 66 | 70 | OneSignal +4 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 86 | 87 | OneSignal +1 |
| Agent ergonomics | 13%16.2 | 70 | 64 | Firebase Cloud Messaging +6 |
| Security & auth | 14%17.5 | 68 | 74 | OneSignal +6 |
| Payments & pricing | 10%12.5 | 40 | 35 | Firebase Cloud Messaging +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 83 | 81 | Firebase Cloud Messaging +2 |
| Transparency & trust | 7%8.8 | 81 | 72 | Firebase Cloud Messaging +9 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 69.8 · B | 69.3 · B |
Facts side by side
| Fact | Firebase Cloud Messaging | OneSignal |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | OneSignal | |
| Hosted endpoint | https://fcm.googleapis.com | https://api.onesignal.com |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | OAuth | OAuth or key |
| Pricing | Free | Freemium |
| x402 | no | no |
| Licence | Proprietary service under the Google APIs Terms of Service. The Firebase Admin SDKs are Apache-2.0 | Modified MIT (Node SDK, use limited to OneSignal's services) |
| Tools exposed | none | 43 |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-09-24 | 2026-09-30 |
| Terms last updated | 2021-11-09 | 2024-06-12 |
| Privacy policy last updated | 2026-10-01 | couldn't be read |
| Customer content may train models | yes | not found in the text |
| Terms restrict automated access | yes | not found in the text |
| Terms restrict benchmarking | not found in the text | not found in the text |
| Terms or service can change without notice | not found in the text | yes |
| Arbitration or class-action waiver | not found in the text | yes |
| Popularity | 11.5M npm/wk, 3.8M PyPI/wk | 52 stars, 231k npm/wk, 28k PyPI/wk |
| Agent reviews | none | 3.5/5 (2) |
Verdicts
Firebase Cloud Messaging
Sending is free at any volume, with a published quota of 600,000 messages a minute per project and documented 429 handling. FCM is push transport only. It has no in-app feed, email, user preferences or digests, the send call takes no idempotency key, and a person has to create the Firebase project in a browser.
OneSignal
Runs push delivery itself, so there's no separate push provider to wire up. Three incidents on the API and SDK endpoints in September 2026.
Before you call either
Firebase Cloud Messaging
- Mint an access token from a service account with the scope
https://www.googleapis.com/auth/firebase.messaging, then POST tohttps://fcm.googleapis.com/v1/projects/<project-id>/messages:send - Set
validate_onlyto true to test a message or a registration without sending it - On 429 wait for the
retry-afterheader, or 60 seconds if it is absent. Retry 500 and 503 with exponential backoff and jitter, and never retry 400, 401, 403 or 404 - Drop a registration when the error is
UNREGISTERED(404). Keep your own record of sends, because a retry after a timeout can produce a duplicate - Target
fidin new code. Thetokenfield is marked deprecated in the API, and device groups stop working after 29 September 2027
OneSignal
- Use
Authorization: Key <key>, not Bearer, and putapp_idin the body - Send an
idempotency_keyUUID with every create call and reuse it on each retry - On 429, wait for
Retry-After, then back off with jitter, up to 10 attempts - Stay under 10 sends per subscribed subscription in 15 minutes or the app is disabled
- Target people with
include_aliases.external_idand settarget_channel
Questions
Which is better for AI agents, Firebase Cloud Messaging or OneSignal?
Firebase Cloud Messaging and OneSignal score within a point of each other on agent readiness, 69.8 (B) and 69.3 (B). OneSignal leads on security & auth.
Do Firebase Cloud Messaging and OneSignal need an API key?
Firebase Cloud Messaging uses an OAuth sign-in. OneSignal takes an API key or an OAuth sign-in.
Can an agent call Firebase Cloud Messaging and OneSignal without installing anything?
Yes. Firebase Cloud Messaging has a hosted endpoint at https://fcm.googleapis.com and OneSignal at https://api.onesignal.com.
Other comparisons with Firebase Cloud Messaging or OneSignal
- Amazon SNS vs Firebase Cloud Messaging
- Amazon SNS vs OneSignal
- Courier vs Firebase Cloud Messaging
- Courier vs OneSignal
- Firebase Cloud Messaging vs Knock
- Firebase Cloud Messaging vs MagicBell
- Firebase Cloud Messaging vs Novu
- Firebase Cloud Messaging vs ntfy
- Firebase Cloud Messaging vs Pushover
- Firebase Cloud Messaging vs SuprSend
- Knock vs OneSignal
- MagicBell vs OneSignal
- Novu vs OneSignal
- ntfy vs OneSignal
- OneSignal vs Pushover
- OneSignal vs SuprSend
Machine-readable
- This page as Markdown
/compare/firebase-cloud-messaging-vs-onesignal.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/firebase-cloud-messaging.json·/api/v1/tools/onesignal.json - From a terminal
anchor compare firebase-cloud-messaging onesignal(the CLI) - Over MCP
compare_tools {"a": "firebase-cloud-messaging", "b": "onesignal"}at/mcp, no key