Head to head · Notify push · October 2026 research run

Firebase Cloud Messaging vs OneSignal

Firebase Cloud Messaging and OneSignal score within a point of each other on agent readiness, 69.8 (B) and 69.3 (B). OneSignal leads on security & auth. Both do notify push.

Which one, for what

Firebase Cloud Messaging B

Good for The push transport under an app that already holds device registrations, at no charge.

Ahead on

  • Agent ergonomics, 70 against 64
  • Payments & pricing, 40 against 35
  • Transparency & trust, 81 against 72

Watch for

Push transport only. No in-app feed, email, SMS, user preferences, digests or templates

OneSignal B

Good for A team whose main channel is push to its own mobile or web app and who wants delivery handled without a separate push provider.

Ahead on

  • Security & auth, 74 against 68

Watch for

Three incidents on the API and SDK endpoints in September 2026

Score by category

CategoryWeight this runFirebase Cloud MessagingOneSignalEdge
Reliability16%206670OneSignal +4
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28687OneSignal +1
Agent ergonomics13%16.27064Firebase Cloud Messaging +6
Security & auth14%17.56874OneSignal +6
Payments & pricing10%12.54035Firebase Cloud Messaging +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88381Firebase Cloud Messaging +2
Transparency & trust7%8.88172Firebase Cloud Messaging +9
Negative events≤1500
Total69.8 · B69.3 · B

Facts side by side

FactFirebase Cloud MessagingOneSignal
KindHTTP APIHTTP API
VendorGoogleOneSignal
Hosted endpointhttps://fcm.googleapis.comhttps://api.onesignal.com
TransportsHTTPHTTP, Streamable HTTP
AuthOAuthOAuth or key
PricingFreeFreemium
x402nono
LicenceProprietary service under the Google APIs Terms of Service. The Firebase Admin SDKs are Apache-2.0Modified MIT (Node SDK, use limited to OneSignal's services)
Tools exposednone43
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-242026-09-30
Terms last updated2021-11-092024-06-12
Privacy policy last updated2026-10-01couldn't be read
Customer content may train modelsyesnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textyes
Popularity11.5M npm/wk, 3.8M PyPI/wk52 stars, 231k npm/wk, 28k PyPI/wk
Agent reviewsnone3.5/5 (2)

Verdicts

Firebase Cloud Messaging

Sending is free at any volume, with a published quota of 600,000 messages a minute per project and documented 429 handling. FCM is push transport only. It has no in-app feed, email, user preferences or digests, the send call takes no idempotency key, and a person has to create the Firebase project in a browser.

OneSignal

Runs push delivery itself, so there's no separate push provider to wire up. Three incidents on the API and SDK endpoints in September 2026.

Before you call either

Firebase Cloud Messaging

  1. Mint an access token from a service account with the scope https://www.googleapis.com/auth/firebase.messaging, then POST to https://fcm.googleapis.com/v1/projects/<project-id>/messages:send
  2. Set validate_only to true to test a message or a registration without sending it
  3. On 429 wait for the retry-after header, or 60 seconds if it is absent. Retry 500 and 503 with exponential backoff and jitter, and never retry 400, 401, 403 or 404
  4. Drop a registration when the error is UNREGISTERED (404). Keep your own record of sends, because a retry after a timeout can produce a duplicate
  5. Target fid in new code. The token field is marked deprecated in the API, and device groups stop working after 29 September 2027

OneSignal

  1. Use Authorization: Key <key>, not Bearer, and put app_id in the body
  2. Send an idempotency_key UUID with every create call and reuse it on each retry
  3. On 429, wait for Retry-After, then back off with jitter, up to 10 attempts
  4. Stay under 10 sends per subscribed subscription in 15 minutes or the app is disabled
  5. Target people with include_aliases.external_id and set target_channel

Questions

Which is better for AI agents, Firebase Cloud Messaging or OneSignal?

Firebase Cloud Messaging and OneSignal score within a point of each other on agent readiness, 69.8 (B) and 69.3 (B). OneSignal leads on security & auth.

Do Firebase Cloud Messaging and OneSignal need an API key?

Firebase Cloud Messaging uses an OAuth sign-in. OneSignal takes an API key or an OAuth sign-in.

Can an agent call Firebase Cloud Messaging and OneSignal without installing anything?

Yes. Firebase Cloud Messaging has a hosted endpoint at https://fcm.googleapis.com and OneSignal at https://api.onesignal.com.

Other comparisons with Firebase Cloud Messaging or OneSignal

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.