{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/ably.json",
        "name": "Ably",
        "score": 75,
        "shared": [
          "notify.push"
        ],
        "slug": "ably"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/customer-io.json",
        "name": "Customer.io",
        "score": 74.5,
        "shared": [
          "notify.push"
        ],
        "slug": "customer-io"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/amazon-sns.json",
        "name": "Amazon SNS",
        "score": 72.8,
        "shared": [
          "notify.push"
        ],
        "slug": "amazon-sns"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/suprsend.json",
        "name": "SuprSend",
        "score": 72.6,
        "shared": [
          "notify.push"
        ],
        "slug": "suprsend"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/courier.json",
        "name": "Courier",
        "score": 70.5,
        "shared": [
          "notify.push"
        ],
        "slug": "courier"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/onesignal.json",
        "name": "OneSignal",
        "score": 69.3,
        "shared": [
          "notify.push"
        ],
        "slug": "onesignal"
      }
    ],
    "tool": {
      "slug": "firebase-cloud-messaging",
      "name": "Firebase Cloud Messaging",
      "vendor": "Google",
      "vendorUrl": "https://firebase.google.com/products/cloud-messaging",
      "kind": "http-api",
      "category": "notifications",
      "summary": "Google's push messaging service for Android, Apple and web apps. A server sends notification or data messages to devices, topics or conditions through the HTTP v1 API or the Firebase Admin SDKs.",
      "url": "https://www.anchorterminal.com/tools/firebase-cloud-messaging",
      "markdownUrl": "https://www.anchorterminal.com/tools/firebase-cloud-messaging.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/firebase-cloud-messaging.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/firebase-cloud-messaging.json",
      "repo": "https://github.com/firebase/firebase-admin-node",
      "license": "Proprietary service under the Google APIs Terms of Service. The Firebase Admin SDKs are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://fcm.googleapis.com",
      "packages": [
        {
          "registry": "npm",
          "name": "firebase-admin"
        },
        {
          "registry": "pypi",
          "name": "firebase-admin"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 bearer token minted from a service account key or Application Default Credentials, with the scope `https://www.googleapis.com/auth/firebase.messaging`. Sending needs the IAM permission `cloudmessaging.messages.create` on the project. Access is self-serve. A person creates the Firebase project and the service account in the console, with no review or sales step.",
      "pricing": "free",
      "pricingNotes": "No charge. The pricing page lists Cloud Messaging as no-cost on the Spark and Blaze plans, and Spark needs no billing account or card, so an agent's owner can start without a contract. The optional BigQuery export of delivery data is billed by BigQuery (https://firebase.google.com/pricing, checked 2026-10-08).",
      "priceSummary": "Free",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the FCM docs, the Discovery document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 11536195,
        "pypiWeekly": 3790113,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://firebase.google.com/docs/cloud-messaging",
      "llmsTxt": "https://firebase.google.com/docs/llms.txt",
      "openapi": "https://fcm.googleapis.com/$discovery/rest?version=v1",
      "capabilities": [
        "notify.push"
      ],
      "tags": [
        "hosted",
        "free",
        "push",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "java",
        "go",
        "dotnet",
        "mcp",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.8,
        "grade": "B",
        "agentReady": false,
        "rank": 162,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 40,
          "reliability": 66,
          "schema": 86,
          "security": 68,
          "transparency": 81
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 66,
            "points": 13.2,
            "reason": "Hosted reading. Firebase status dashboard with a page and a JSON incident feed per product (20). The feed lists one Cloud Messaging incident between 10 July and 8 October 2026, low availability and higher latency in North America on 1 September from 08:40 to 12:31 UTC, 3 hours 51 minutes, read as one major incident (10). Limits are published with numbers, 600,000 messages a minute per project, 240 a minute and 5,000 an hour to one Android device, 3,000 topic subscription changes a second and 1,000 concurrent fanouts (15). 429 and 503 handling is documented with `retry-after`, a 60 second default, exponential backoff with jitter and a 10 second timeout, but `messages:send` takes no idempotency key and the Admin SDK release notes record timeouts raised to avoid duplicate notifications (11 of 15). The Firebase SLA of 9 April 2020 does not name Cloud Messaging and pays credits as a share of fees, and FCM has no fee, so no SLA (0). The HTTP v1 API is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 86,
            "points": 13.98,
            "reason": "A public Discovery document at `fcm.googleapis.com/$discovery/rest?version=v1`, revision 20261006, with 6 methods and 16 schemas (25). `firebase.google.com/docs/llms.txt` indexes the docs and every page has a `.md.txt` twin (10). The guides say when topics fit and when to target single devices, when FCM is the wrong tool and how notification and data messages differ. The reference itself is terse (16 of 20). 79 typed properties with 4 enums, but `data`, the APNs `payload` and `headers` and the web push `notification` are free-form objects, and `ttl` and `condition` are strings with their own grammar (9 of 15). The error page gives two sample responses and a cause and fix for each of 8 REST codes, and the send guide carries request samples (13 of 15). Versioned `v1` path and dated Firebase release notes, though server API changes appear there mostly through the Admin SDK entries (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "API reading, graded on the HTTP v1 API. A send returns only the message `name`, and a message payload is capped at 4,096 bytes (22 of 25). Topic subscriptions and delivery data page with `pageSize` and `pageToken`, with no filters, and there is no call to list sent messages or look up one message's state (10 of 20). Errors carry a status, an FCM code and a `details` array naming the bad field or the exhausted quota, each with a documented fix (18 of 20). No idempotency key on send. `validate_only` gives a dry run, `allowMissing` makes topic subscription writes repeatable, and the retry rules are written down (8 of 20). A send needs only a project and one target, and Admin SDKs exist for Node.js, Python, Java, Go and .NET. Plain HTTP callers send one request per message and mint their own OAuth token (12 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 68,
            "points": 11.9,
            "reason": "OAuth 2.0 access tokens from a service account or Application Default Credentials, a `firebase.messaging` scope, and IAM permissions per action (30), less 10 because the Discovery document lists `access_token` and `key` as query parameters (20). A custom role can hold `cloudmessaging.messages.create` alone and `validate_only` tests without sending. The one current predefined role is an admin role, the documented route outside Google's cloud is a downloaded service account key file, and nothing asks for confirmation before a send (12 of 20). Responses carry no third-party content (10). Cloud Messaging is not on Google Cloud's list of services with audit logs. Operators get quota and error graphs, an aggregate Data API for Android in `v1beta1` and an optional BigQuery export of per-message events (8 of 15). google.com publishes a security.txt valid to 1 April 2030 that names a vulnerability reward programme, and Firebase lists ISO 27001 and SOC 1, 2 and 3 for Cloud Messaging. firebase.google.com has no security.txt of its own (18 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). The pricing page lists Cloud Messaging as no-cost on both plans, without a login (20). It is free on the Spark plan, which needs no billing account or card (20). A person signs in with a Google account, accepts the Firebase terms and creates the project and service account in a browser (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 83,
            "points": 7.26,
            "reason": "Read as a closed service with official SDKs. The Admin SDKs for Node.js and Go shipped on 23 September 2026 and for Java and .NET on 24 September, each moving topic subscriptions to the v1 API, and the Discovery document is revision 20261006 (30). Firebase's release notes carry Cloud Messaging entries on 19, 25 and 27 August and 9, 23 and 24 September 2026 (20). Public release notes, Firebase Support and a bug report form. We could not read the SDK issue trackers, so half marks on answers (10 of 15). Current official Admin SDKs in five languages, `firebase-admin` 14.5.0 on npm and 7.7.0 on PyPI (15). The Node SDK's CI builds and tests on Node 22, 24 and 26, with dependency updates merged on 8 October. We did not see the run results (8 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 81,
            "points": 7.09,
            "note": "editorial 68, provenance 94",
            "reason": "Closed service under the Google APIs Terms of Service and the Firebase Data Processing and Security Terms, with Apache-2.0 Admin SDKs (15 of 30). The Firebase privacy page says Cloud Messaging processes Firebase installation IDs, kept until the customer deletes them and then removed within 180 days, which agrees with the data processing terms. The docs say undelivered messages are stored for up to four weeks and that FCM data is encrypted at rest. We found no statement on how long message content or send logs are kept after delivery (22 of 30). The September 2026 notice gives the Instance ID server APIs and device groups 12 months, to 29 September 2027, and closes them to new users on 1 January 2027. No standing deprecation policy for FCM was found (17 of 20). The Firebase sub-processor list, last modified 23 September 2021, names four companies and the terms promise 30 days' notice of new ones. Cloud Messaging is a global service with no data location choice (14 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "API reading, graded on the HTTP v1 API. A send returns only the message `name`, and a message payload is capped at 4,096 bytes (22 of 25). Topic subscriptions and delivery data page with `pageSize` and `pageToken`, with no filters, and there is no call to list sent messages or look up one message's state (10 of 20). Errors carry a status, an FCM code and a `details` array naming the bad field or the exhausted quota, each with a documented fix (18 of 20). No idempotency key on send. `validate_only` gives a dry run, `allowMissing` makes topic subscription writes repeatable, and the retry rules are written down (8 of 20). A send needs only a project and one target, and Admin SDKs exist for Node.js, Python, Java, Go and .NET. Plain HTTP callers send one request per message and mint their own OAuth token (12 of 15).",
            "maintenance": "Read as a closed service with official SDKs. The Admin SDKs for Node.js and Go shipped on 23 September 2026 and for Java and .NET on 24 September, each moving topic subscriptions to the v1 API, and the Discovery document is revision 20261006 (30). Firebase's release notes carry Cloud Messaging entries on 19, 25 and 27 August and 9, 23 and 24 September 2026 (20). Public release notes, Firebase Support and a bug report form. We could not read the SDK issue trackers, so half marks on answers (10 of 15). Current official Admin SDKs in five languages, `firebase-admin` 14.5.0 on npm and 7.7.0 on PyPI (15). The Node SDK's CI builds and tests on Node 22, 24 and 26, with dependency updates merged on 8 October. We did not see the run results (8 of 10).",
            "payments": "No x402, MPP or L402 (0). The pricing page lists Cloud Messaging as no-cost on both plans, without a login (20). It is free on the Spark plan, which needs no billing account or card (20). A person signs in with a Google account, accepts the Firebase terms and creates the project and service account in a browser (0).",
            "reliability": "Hosted reading. Firebase status dashboard with a page and a JSON incident feed per product (20). The feed lists one Cloud Messaging incident between 10 July and 8 October 2026, low availability and higher latency in North America on 1 September from 08:40 to 12:31 UTC, 3 hours 51 minutes, read as one major incident (10). Limits are published with numbers, 600,000 messages a minute per project, 240 a minute and 5,000 an hour to one Android device, 3,000 topic subscription changes a second and 1,000 concurrent fanouts (15). 429 and 503 handling is documented with `retry-after`, a 60 second default, exponential backoff with jitter and a 10 second timeout, but `messages:send` takes no idempotency key and the Admin SDK release notes record timeouts raised to avoid duplicate notifications (11 of 15). The Firebase SLA of 9 April 2020 does not name Cloud Messaging and pays credits as a share of fees, and FCM has no fee, so no SLA (0). The HTTP v1 API is generally available (10).",
            "schema": "A public Discovery document at `fcm.googleapis.com/$discovery/rest?version=v1`, revision 20261006, with 6 methods and 16 schemas (25). `firebase.google.com/docs/llms.txt` indexes the docs and every page has a `.md.txt` twin (10). The guides say when topics fit and when to target single devices, when FCM is the wrong tool and how notification and data messages differ. The reference itself is terse (16 of 20). 79 typed properties with 4 enums, but `data`, the APNs `payload` and `headers` and the web push `notification` are free-form objects, and `ttl` and `condition` are strings with their own grammar (9 of 15). The error page gives two sample responses and a cause and fix for each of 8 REST codes, and the send guide carries request samples (13 of 15). Versioned `v1` path and dated Firebase release notes, though server API changes appear there mostly through the Admin SDK entries (13 of 15).",
            "security": "OAuth 2.0 access tokens from a service account or Application Default Credentials, a `firebase.messaging` scope, and IAM permissions per action (30), less 10 because the Discovery document lists `access_token` and `key` as query parameters (20). A custom role can hold `cloudmessaging.messages.create` alone and `validate_only` tests without sending. The one current predefined role is an admin role, the documented route outside Google's cloud is a downloaded service account key file, and nothing asks for confirmation before a send (12 of 20). Responses carry no third-party content (10). Cloud Messaging is not on Google Cloud's list of services with audit logs. Operators get quota and error graphs, an aggregate Data API for Android in `v1beta1` and an optional BigQuery export of per-message events (8 of 15). google.com publishes a security.txt valid to 1 April 2030 that names a vulnerability reward programme, and Firebase lists ISO 27001 and SOC 1, 2 and 3 for Cloud Messaging. firebase.google.com has no security.txt of its own (18 of 20).",
            "transparency": "Closed service under the Google APIs Terms of Service and the Firebase Data Processing and Security Terms, with Apache-2.0 Admin SDKs (15 of 30). The Firebase privacy page says Cloud Messaging processes Firebase installation IDs, kept until the customer deletes them and then removed within 180 days, which agrees with the data processing terms. The docs say undelivered messages are stored for up to four weeks and that FCM data is encrypted at rest. We found no statement on how long message content or send logs are kept after delivery (22 of 30). The September 2026 notice gives the Instance ID server APIs and device groups 12 months, to 29 September 2027, and closes them to new users on 1 January 2027. No standing deprecation policy for FCM was found (17 of 20). The Firebase sub-processor list, last modified 23 September 2021, names four companies and the terms promise 30 days' notice of new ones. Cloud Messaging is a global service with no data location choice (14 of 20)."
          },
          "sources": [
            {
              "what": "product overview",
              "url": "https://firebase.google.com/docs/cloud-messaging.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "send guide for the HTTP v1 API",
              "url": "https://firebase.google.com/docs/cloud-messaging/send/v1-api.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "send method reference",
              "url": "https://firebase.google.com/docs/reference/fcm/rest/v1/projects.messages/send.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Discovery document",
              "url": "https://fcm.googleapis.com/$discovery/rest?version=v1",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://firebase.google.com/docs/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "throttling and quotas",
              "url": "https://firebase.google.com/docs/cloud-messaging/throttling-and-quotas.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "sending at scale and retries",
              "url": "https://firebase.google.com/docs/cloud-messaging/scale-fcm.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "error codes",
              "url": "https://firebase.google.com/docs/cloud-messaging/error-codes.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "topic messaging limits",
              "url": "https://firebase.google.com/docs/cloud-messaging/topic-messaging.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "topic subscription management",
              "url": "https://firebase.google.com/docs/cloud-messaging/manage-topic-subscriptions.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "deprecation FAQ",
              "url": "https://firebase.google.com/docs/cloud-messaging/troubleshooting.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "device group migration",
              "url": "https://firebase.google.com/docs/cloud-messaging/migrate-off-device-groups.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "message lifespan",
              "url": "https://firebase.google.com/docs/cloud-messaging/customize-messages/setting-message-lifespan.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "delivery data and BigQuery export",
              "url": "https://firebase.google.com/docs/cloud-messaging/understand-delivery.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Data API reference",
              "url": "https://firebase.google.com/docs/reference/fcmdata/rest/v1beta1/projects.androidApps.deliveryData/list.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "status incident feed",
              "url": "https://status.firebase.google.com/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "incident of 1 September 2026",
              "url": "https://status.firebase.google.com/incidents/efSHTx8oFZ4CH8XsqZuy",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://firebase.google.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "terms by Firebase service",
              "url": "https://firebase.google.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "Google APIs Terms of Service",
              "url": "https://developers.google.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "Firebase Data Processing and Security Terms",
              "url": "https://firebase.google.com/terms/data-processing-terms",
              "seen": "2026-10-08"
            },
            {
              "what": "Firebase SLA",
              "url": "https://firebase.google.com/terms/service-level-agreement",
              "seen": "2026-10-08"
            },
            {
              "what": "Firebase sub-processors",
              "url": "https://firebase.google.com/terms/subprocessors",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy and security in Firebase",
              "url": "https://firebase.google.com/support/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "Google privacy policy",
              "url": "https://policies.google.com/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "IAM roles",
              "url": "https://firebase.google.com/docs/projects/iam/roles-predefined-product.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "IAM permissions",
              "url": "https://firebase.google.com/docs/projects/iam/permissions.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Google Cloud services with audit logs",
              "url": "https://docs.cloud.google.com/logging/docs/audit/services",
              "seen": "2026-10-08"
            },
            {
              "what": "Firebase release notes",
              "url": "https://firebase.google.com/support/releases",
              "seen": "2026-10-08"
            },
            {
              "what": "Admin Node.js SDK release notes",
              "url": "https://firebase.google.com/support/release-notes/admin/node",
              "seen": "2026-10-08"
            },
            {
              "what": "Admin Node.js SDK repository",
              "url": "https://github.com/firebase/firebase-admin-node",
              "seen": "2026-10-08"
            },
            {
              "what": "npm registry",
              "url": "https://registry.npmjs.org/firebase-admin/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI",
              "url": "https://pypi.org/pypi/firebase-admin/json",
              "seen": "2026-10-08"
            },
            {
              "what": "Firebase MCP server",
              "url": "https://firebase.google.com/docs/ai-assistance/mcp-server.md.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.google.com/.well-known/security.txt",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: GitHub stars and the open issues of the Admin SDK repositories. api.github.com answered with its rate limit, so `githubStars` is empty and issue handling is scored at half",
            "unchecked: whether CI passes on the default branch of firebase/firebase-admin-node. We read the workflow file from a clone, not the run results",
            "unchecked: the tool definition of `messaging_send_message` in the Firebase MCP server. The listing is graded on the HTTP v1 API",
            "The Discovery document lists `access_token` and `key` as query parameters on every method. We took the checklist's 10 points for it, as the Gmail and Google Sheets dossiers did and the Drive and Calendar dossiers did not",
            "The Firebase SLA text names no services. We read it as not covering Cloud Messaging because credits are a share of fees and FCM has none",
            "No statement was found on how long FCM keeps message content or send logs after delivery",
            "The lead was right on the interface. The docs now also describe a v1 topic subscription API and a `fid` target that replaces registration tokens"
          ]
        },
        "negative": 0,
        "verdict": "Sending is free at any volume, with a published quota of 600,000 messages a minute per project and documented 429 handling. FCM is push transport only. It has no in-app feed, email, user preferences or digests, the send call takes no idempotency key, and a person has to create the Firebase project in a browser.",
        "bestFor": "The push transport under an app that already holds device registrations, at no charge.",
        "strengths": [
          "No charge for sending on either Firebase plan, and no billing account needed (https://firebase.google.com/pricing)",
          "Default quota of 600,000 messages a minute per project, with 429 responses that carry `retry-after` and written backoff guidance",
          "Short-lived OAuth 2.0 tokens with a `firebase.messaging` scope, and IAM permissions per action such as `cloudmessaging.messages.create`",
          "Public Discovery document (revision 20261006), a docs `llms.txt` and a Markdown twin of every docs page",
          "Dated deprecation notice in September 2026 that gives 12 months before the Instance ID server APIs and device groups stop on 29 September 2027"
        ],
        "weaknesses": [
          "Push transport only. No in-app feed, email, SMS, user preferences, digests or templates",
          "No idempotency key on `messages:send`, so a retried request can reach the device twice",
          "One HTTP request per message. Only the Admin SDKs group up to 500 sends in a call",
          "FCM is absent from Google Cloud's list of services with audit logs, and per-message delivery data needs a BigQuery export",
          "One incident on 1 September 2026 lowered availability in North America for 3 hours 51 minutes, and no SLA names FCM"
        ],
        "agentNotes": [
          "Mint an access token from a service account with the scope `https://www.googleapis.com/auth/firebase.messaging`, then POST to `https://fcm.googleapis.com/v1/projects/\u003cproject-id\u003e/messages:send`",
          "Set `validate_only` to true to test a message or a registration without sending it",
          "On 429 wait for the `retry-after` header, or 60 seconds if it is absent. Retry 500 and 503 with exponential backoff and jitter, and never retry 400, 401, 403 or 404",
          "Drop a registration when the error is `UNREGISTERED` (404). Keep your own record of sends, because a retry after a timeout can produce a duplicate",
          "Target `fid` in new code. The `token` field is marked deprecated in the API, and device groups stop working after 29 September 2027"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.8
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 40,
          "reliability": 66,
          "schema": 86,
          "security": 68,
          "transparency": 68
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm install firebase-admin   # or: pip install firebase-admin",
        "http": "curl -X POST \"https://fcm.googleapis.com/v1/projects/$FIREBASE_PROJECT_ID/messages:send\" \\\n  -H \"Authorization: Bearer $ACCESS_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"message\":{\"topic\":\"news\",\"notification\":{\"title\":\"Build finished\",\"body\":\"All tests passed\"}}}'",
        "claudeCode": "claude mcp add firebase npx -- -y firebase-tools@latest mcp"
      },
      "letme": {
        "capability": "https://letme.dev/notify.push",
        "tool": "https://letme.dev/firebase-cloud-messaging"
      },
      "sameCompany": [
        "gemini-api",
        "gemini-embedding",
        "vertex-ai-tuning",
        "google-model-armor",
        "google-imagen",
        "google-veo",
        "google-lyria",
        "google-speech-to-text",
        "gemini-live",
        "google-adk",
        "google-secret-manager",
        "google-weather-api",
        "chrome-devtools-mcp",
        "google-maps-platform",
        "google-cloud-translation",
        "google-calendar-api",
        "google-drive-api",
        "gemini-cli",
        "google-search-console",
        "google-ads-api",
        "google-forms",
        "google-sheets-api",
        "gmail-api"
      ],
      "notable": [
        "The default quota is 600,000 messages a minute per project. It counts messages, not requests, and client errors other than 429 count against it (https://firebase.google.com/docs/cloud-messaging/throttling-and-quotas)",
        "The Instance ID server APIs and device groups were deprecated in September 2026, close to new users on 1 January 2027 and stop on 29 September 2027 (https://firebase.google.com/docs/cloud-messaging/troubleshooting)",
        "The API's `Message` type now takes a Firebase installation ID in `fid` and marks the registration `token` field as deprecated (https://fcm.googleapis.com/$discovery/rest?version=v1)",
        "Topic subscriptions have their own v1 resource, `projects.registrations.topicSubscriptions`, and Admin SDKs moved to it on 23 and 24 September 2026 (https://firebase.google.com/support/releases)",
        "Undelivered messages are stored for up to four weeks unless `ttl` sets a shorter life (https://firebase.google.com/docs/cloud-messaging/customize-messages/setting-message-lifespan)",
        "The local Firebase MCP server in `firebase-tools` includes a `messaging_send_message` tool that sends to a registration token or topic (https://firebase.google.com/docs/ai-assistance/mcp-server)",
        "Firebase lists ISO 27001 and SOC 1, 2 and 3 for Cloud Messaging, and not ISO 27017 or 27018 (https://firebase.google.com/support/privacy)"
      ],
      "area": "everyday",
      "details": [
        {
          "label": "API",
          "value": "HTTP v1 at `https://fcm.googleapis.com/v1/projects/\u003cproject-id\u003e/messages:send`, plus five topic subscription methods. Discovery revision 20261006"
        },
        {
          "label": "Targets",
          "value": "A Firebase installation ID or registration token, a topic, or a condition over topics. Device groups are deprecated and stop on 29 September 2027"
        },
        {
          "label": "Platforms",
          "value": "Android, Apple platforms through APNs, and web push"
        },
        {
          "label": "Payload",
          "value": "Up to 4,096 bytes, or 2,048 bytes for a topic message"
        },
        {
          "label": "Quota",
          "value": "600,000 messages a minute per project. 240 a minute and 5,000 an hour to one Android device. 3,000 topic subscription changes a second. 1,000 concurrent fanouts"
        },
        {
          "label": "Retries",
          "value": "429 with `retry-after` (60 seconds if absent). Exponential backoff with jitter on 500 and 503. No idempotency key"
        },
        {
          "label": "Credentials",
          "value": "OAuth 2.0 token from a service account, scope `firebase.messaging`, IAM permission `cloudmessaging.messages.create`"
        },
        {
          "label": "Admin SDKs",
          "value": "Node.js, Python, Java, Go and .NET. Up to 500 messages or targets per SDK call, sent as separate requests"
        },
        {
          "label": "Delivery data",
          "value": "Aggregate Data API for Android (`v1beta1`) and an optional BigQuery export of per-message events"
        },
        {
          "label": "Message storage",
          "value": "Up to four weeks for undelivered messages, or the `ttl` given"
        },
        {
          "label": "Price",
          "value": "No charge on the Spark and Blaze plans"
        }
      ],
      "provenance": {
        "legalEntity": "Google LLC",
        "domain": "google.com",
        "domainRegistered": "1997-09-15",
        "domainNote": "The endpoint is on googleapis.com, Google's API domain. The docs are on firebase.google.com.",
        "endpointOnVendorDomain": true,
        "terms": "https://developers.google.com/terms",
        "privacy": "https://policies.google.com/privacy",
        "statusPage": "https://status.firebase.google.com",
        "changelog": "https://firebase.google.com/support/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "firebase.google.com/terms, last modified 24 September 2026, places Cloud Messaging under the Google APIs Terms of Service and the Firebase Data Processing and Security Terms.",
          "The Google APIs Terms of Service were last modified on 9 November 2021, name Google LLC of Mountain View, California, and choose California law.",
          "Google's privacy policy is effective 1 October 2026. Firebase's own privacy and security page, last modified 15 September 2026, gives the per-service data and retention table.",
          "www.google.com/.well-known/security.txt expires on 2030-04-01. firebase.google.com/.well-known/security.txt returns 404.",
          "The registration date of google.com is taken from our earlier Google listings and was not looked up again today."
        ],
        "score": 94,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Google LLC",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "google.com, registered 1997-09-15 (29 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "fcm.googleapis.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 7.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 7.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.firebase.google.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://developers.google.com/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2021-11-09",
            "words": 3831,
            "points": 7.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last modified: November 9, 2021 (see previous version)",
                "says": "Last updated 2021-11-09"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Except as set forth below: (i) the laws of California, U.S.A., excluding California's conflict of laws rules, will apply to any disputes arising out of or related to the Terms or the APIs and (ii) ALL CLAIMS ARISING OUT OF OR RELATING TO THE TERMS OR THE APIS WILL BE LITIGATED EXCLUSIVELY IN THE FEDERAL OR STATE COURT…",
                "says": "The law of California, with disputes in the courts of Santa Clara County, California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…ITS SUPPLIERS AND DISTRIBUTORS, FOR ANY CLAIM UNDER THE TERMS, INCLUDING FOR ANY IMPLIED WARRANTIES, IS LIMITED TO THE AMOUNT YOU PAID US TO USE THE APPLICABLE APIS (OR, IF WE CHOOSE, TO SUPPLYING YOU THE APIS AGAIN) DURING THE SIX MONTHS PRIOR TO THE EVENT GIVING RISE TO THE LIABILITY.",
                "says": "Capped at the fees paid in the 6 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Google may suspend access to the APIs by you or your API Client without notice if we reasonably believe that you are in violation of the Terms."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "We'll post notice of modifications to the Terms within the documentation of each applicable API, to this website, and/or in the Google developers console.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You may not use the APIs and may not accept the Terms if (a) you are not of legal age to form a binding contract with Google, or (b) you are a person barred from using or receiving the APIs under the applicable laws of the United States or other countries including the country in which you are resident or from which y…"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Scrape, build databases, or otherwise create permanent copies of such content, or keep cached copies longer than permitted by the cache header;",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Google reserves the right to terminate the Terms with you or discontinue the APIs or any portion or feature or your access thereto for any reason and at any time without liability or other obligation to you."
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last modified: November 9, 2021 (see previous version)"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Content submitted through the APIs is licensed to Google on a perpetual, irrevocable and sublicensable basis, for the stated sole purpose of enabling Google to provide, secure and improve the APIs.",
                "quote": "For the sole purpose of enabling Google to provide, secure, and improve the APIs (and the related service(s)) and only in accordance with the applicable Google privacy policies, you give Google a perpetual, irrevocable, worldwide, sublicensable, royalty-free, and non-exclusive license to Use content"
              },
              {
                "date": "2026-10-08",
                "text": "A developer may not misrepresent or mask its own identity or the identity of its API client when using the APIs or developer accounts.",
                "quote": "You will not misrepresent or mask either your identity or your API Client's identity when using the APIs or developer accounts."
              },
              {
                "date": "2026-10-08",
                "text": "Google may use the developer's company or product name, and screenshots or video of its API client, when promoting or demonstrating the APIs.",
                "quote": "In the course of promoting, marketing, or demonstrating the APIs you are using and the associated Google products, Google may produce and distribute incidental depictions, including screenshots, video, or other content from your API Client, and may use your company or product name."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://policies.google.com/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-10-01",
            "words": 14332,
            "points": 7.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective October 1, 2026 | Archived versions | Download PDF",
                "says": "Last updated 2026-10-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "The types of location data we collect and how long we store it depend in part on your device and account settings."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "For example, we use service providers to help operate our data centers, deliver our products and services, improve our internal business processes, and offer additional support to customers and users."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "If Google is involved in a merger, acquisition, or sale of assets, we’ll continue to ensure the confidentiality of your personal information and give affected users notice before personal information is transferred or becomes subject to a different privacy policy."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If European Union or United Kingdom data protection law applies to the processing of your information, you can review the European requirements section below to learn more about your rights and Google’s compliance with these laws."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "And if you have any questions about this Privacy Policy, you can contact us."
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "We use your interactions with AI models and technologies like Gemini Apps to develop, train, fine-tune, and improve these models to better handle your requests, and update their classifiers and filters including for safety, language understanding, and factuality.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Members of organisations using Google Workspace or Google Cloud Platform are referred to the separate Google Cloud Privacy Notice for how those services collect and use personal information.",
                "quote": "If you’re a member of an organization that uses Google Workspace or Google Cloud Platform, learn how these services collect and use your personal information in the Google Cloud Privacy Notice."
              },
              {
                "date": "2026-10-08",
                "text": "Google says it uses publicly available information from the web and other public sources to help train machine learning models behind products such as Google Translate, Gemini Apps and Cloud AI.",
                "quote": "We use publicly available information online or from other public sources to help train new machine learning models and build foundational technologies that power various Google products such as Google Translate, Gemini Apps, and Cloud AI capabilities."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/firebase-cloud-messaging.json",
      "live": {
        "slug": "firebase-cloud-messaging",
        "probe": {
          "target": "https://fcm.googleapis.com",
          "method": "get",
          "lastAt": "2026-10-09T09:26:50.167166367Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 99,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 39,
          "p95ms24h": 99,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.firebase.google.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:54.993043607Z"
        },
        "updatedAt": "2026-10-09T09:26:50.167166367Z"
      }
    },
    "verify": {
      "accepts": "a page on google.com or one of its subdomains, or the README of github.com/firebase/firebase-admin-node",
      "badgeUrl": "https://www.anchorterminal.com/badges/firebase-cloud-messaging.svg",
      "body": {
        "slug": "firebase-cloud-messaging",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/firebase-cloud-messaging",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/firebase-cloud-messaging\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/firebase-cloud-messaging.svg\" alt=\"Firebase Cloud Messaging on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Firebase Cloud Messaging on Anchor Terminal](https://www.anchorterminal.com/badges/firebase-cloud-messaging.svg)](https://www.anchorterminal.com/tools/firebase-cloud-messaging)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/firebase-cloud-messaging\"\u003eFirebase Cloud Messaging on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/firebase-cloud-messaging",
    "json": "https://www.anchorterminal.com/tools/firebase-cloud-messaging.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/firebase-cloud-messaging.md",
    "slim": "https://www.anchorterminal.com/tools/firebase-cloud-messaging.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 69.8/100 · rank #162 of 842 · #4 in Notifications · not agent-ready · confidence medium**\n\n\nMore from Google, listed separately because each is its own product: [Gemini Developer API](https://www.anchorterminal.com/tools/gemini-api.md) (Model APIs \u0026 inference), [Gemini Embedding](https://www.anchorterminal.com/tools/gemini-embedding.md) (Embeddings \u0026 rerankers), [Vertex AI Gemini tuning](https://www.anchorterminal.com/tools/vertex-ai-tuning.md) (Fine-tuning), [Google Cloud Model Armor](https://www.anchorterminal.com/tools/google-model-armor.md) (Guardrails \u0026 safety filters), [Google Imagen](https://www.anchorterminal.com/tools/google-imagen.md) (Image generation), [Google Veo](https://www.anchorterminal.com/tools/google-veo.md) (Video generation), [Google Lyria](https://www.anchorterminal.com/tools/google-lyria.md) (Music generation), [Google Cloud Speech-to-Text](https://www.anchorterminal.com/tools/google-speech-to-text.md) (Speech-to-text), [Gemini Live API](https://www.anchorterminal.com/tools/gemini-live.md) (Conversational voice agents), [Agent Development Kit (ADK)](https://www.anchorterminal.com/tools/google-adk.md) (Agent frameworks \u0026 SDKs), [Google Cloud Secret Manager](https://www.anchorterminal.com/tools/google-secret-manager.md) (Secrets \u0026 credential vaults), [Google Weather API (Maps Platform)](https://www.anchorterminal.com/tools/google-weather-api.md) (Weather \u0026 climate data), [Chrome DevTools MCP](https://www.anchorterminal.com/tools/chrome-devtools-mcp.md) (Browser automation), [Google Maps Platform + Grounding Lite MCP](https://www.anchorterminal.com/tools/google-maps-platform.md) (Maps, geocoding \u0026 places), [Google Cloud Translation](https://www.anchorterminal.com/tools/google-cloud-translation.md) (Translation), [Google Calendar API](https://www.anchorterminal.com/tools/google-calendar-api.md) (Calendars \u0026 scheduling), [Google Drive API + MCP](https://www.anchorterminal.com/tools/google-drive-api.md) (File storage \u0026 sharing), [Gemini CLI](https://www.anchorterminal.com/tools/gemini-cli.md) (Agent harnesses), [Google Search Console API](https://www.anchorterminal.com/tools/google-search-console.md) (SEO \u0026 search visibility), [Google Ads API](https://www.anchorterminal.com/tools/google-ads-api.md) (Advertising \u0026 campaign operations), [Google Forms API](https://www.anchorterminal.com/tools/google-forms.md) (Forms, surveys \u0026 structured intake), [Google Sheets API](https://www.anchorterminal.com/tools/google-sheets-api.md) (Spreadsheets \u0026 operational tables), [Gmail API](https://www.anchorterminal.com/tools/gmail-api.md) (Mailbox access).\n\n## Assessment\n\nSending is free at any volume, with a published quota of 600,000 messages a minute per project and documented 429 handling. FCM is push transport only. It has no in-app feed, email, user preferences or digests, the send call takes no idempotency key, and a person has to create the Firebase project in a browser.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Google (https://firebase.google.com/products/cloud-messaging) |\n| Kind | HTTP API |\n| Category | Notifications (https://www.anchorterminal.com/categories/notifications) |\n| Transport | HTTP |\n| Endpoint | `https://fcm.googleapis.com` |\n| Auth | OAuth · OAuth 2.0 bearer token minted from a service account key or Application Default Credentials, with the scope `https://www.googleapis.com/auth/firebase.messaging`. Sending needs the IAM permission `cloudmessaging.messages.create` on the project. Access is self-serve. A person creates the Firebase project and the service account in the console, with no review or sales step. |\n| Pricing | Free (Free) · No charge. The pricing page lists Cloud Messaging as no-cost on the Spark and Blaze plans, and Spark needs no billing account or card, so an agent's owner can start without a contract. The optional BigQuery export of delivery data is billed by BigQuery (https://firebase.google.com/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the FCM docs, the Discovery document or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under the Google APIs Terms of Service. The Firebase Admin SDKs are Apache-2.0 |\n| Packages | npm: `firebase-admin`; pypi: `firebase-admin` |\n| Source | https://github.com/firebase/firebase-admin-node |\n| Docs | https://firebase.google.com/docs/cloud-messaging |\n| llms.txt | https://firebase.google.com/docs/llms.txt |\n| Last release | 2026-09-24 |\n| npm downloads / week | 11,536,195 |\n| PyPI downloads / week | 3,790,113 |\n| API | HTTP v1 at `https://fcm.googleapis.com/v1/projects/\u003cproject-id\u003e/messages:send`, plus five topic subscription methods. Discovery revision 20261006 |\n| Targets | A Firebase installation ID or registration token, a topic, or a condition over topics. Device groups are deprecated and stop on 29 September 2027 |\n| Platforms | Android, Apple platforms through APNs, and web push |\n| Payload | Up to 4,096 bytes, or 2,048 bytes for a topic message |\n| Quota | 600,000 messages a minute per project. 240 a minute and 5,000 an hour to one Android device. 3,000 topic subscription changes a second. 1,000 concurrent fanouts |\n| Retries | 429 with `retry-after` (60 seconds if absent). Exponential backoff with jitter on 500 and 503. No idempotency key |\n| Credentials | OAuth 2.0 token from a service account, scope `firebase.messaging`, IAM permission `cloudmessaging.messages.create` |\n| Admin SDKs | Node.js, Python, Java, Go and .NET. Up to 500 messages or targets per SDK call, sent as separate requests |\n| Delivery data | Aggregate Data API for Android (`v1beta1`) and an optional BigQuery export of per-message events |\n| Message storage | Up to four weeks for undelivered messages, or the `ttl` given |\n| Price | No charge on the Spark and Blaze plans |\n| Capabilities | notify.push |\n| Tags | hosted, free, push, oauth, llms-txt, typescript, python, java, go, dotnet, mcp, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/firebase-cloud-messaging.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 66 | 13.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 86 | 14.0 |\n| Agent ergonomics | 13% | 16.2 | 70 | 11.4 |\n| Security \u0026 auth | 14% | 17.5 | 68 | 11.9 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 83 | 7.3 |\n| Transparency \u0026 trust (editorial 68, provenance 94) | 7% | 8.8 | 81 | 7.1 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **69.8 → B** |\n\n### Why each score\n\n- Reliability 66: Hosted reading. Firebase status dashboard with a page and a JSON incident feed per product (20). The feed lists one Cloud Messaging incident between 10 July and 8 October 2026, low availability and higher latency in North America on 1 September from 08:40 to 12:31 UTC, 3 hours 51 minutes, read as one major incident (10). Limits are published with numbers, 600,000 messages a minute per project, 240 a minute and 5,000 an hour to one Android device, 3,000 topic subscription changes a second and 1,000 concurrent fanouts (15). 429 and 503 handling is documented with `retry-after`, a 60 second default, exponential backoff with jitter and a 10 second timeout, but `messages:send` takes no idempotency key and the Admin SDK release notes record timeouts raised to avoid duplicate notifications (11 of 15). The Firebase SLA of 9 April 2020 does not name Cloud Messaging and pays credits as a share of fees, and FCM has no fee, so no SLA (0). The HTTP v1 API is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 86: A public Discovery document at `fcm.googleapis.com/$discovery/rest?version=v1`, revision 20261006, with 6 methods and 16 schemas (25). `firebase.google.com/docs/llms.txt` indexes the docs and every page has a `.md.txt` twin (10). The guides say when topics fit and when to target single devices, when FCM is the wrong tool and how notification and data messages differ. The reference itself is terse (16 of 20). 79 typed properties with 4 enums, but `data`, the APNs `payload` and `headers` and the web push `notification` are free-form objects, and `ttl` and `condition` are strings with their own grammar (9 of 15). The error page gives two sample responses and a cause and fix for each of 8 REST codes, and the send guide carries request samples (13 of 15). Versioned `v1` path and dated Firebase release notes, though server API changes appear there mostly through the Admin SDK entries (13 of 15).\n- Agent ergonomics 70: API reading, graded on the HTTP v1 API. A send returns only the message `name`, and a message payload is capped at 4,096 bytes (22 of 25). Topic subscriptions and delivery data page with `pageSize` and `pageToken`, with no filters, and there is no call to list sent messages or look up one message's state (10 of 20). Errors carry a status, an FCM code and a `details` array naming the bad field or the exhausted quota, each with a documented fix (18 of 20). No idempotency key on send. `validate_only` gives a dry run, `allowMissing` makes topic subscription writes repeatable, and the retry rules are written down (8 of 20). A send needs only a project and one target, and Admin SDKs exist for Node.js, Python, Java, Go and .NET. Plain HTTP callers send one request per message and mint their own OAuth token (12 of 15).\n- Security \u0026 auth 68: OAuth 2.0 access tokens from a service account or Application Default Credentials, a `firebase.messaging` scope, and IAM permissions per action (30), less 10 because the Discovery document lists `access_token` and `key` as query parameters (20). A custom role can hold `cloudmessaging.messages.create` alone and `validate_only` tests without sending. The one current predefined role is an admin role, the documented route outside Google's cloud is a downloaded service account key file, and nothing asks for confirmation before a send (12 of 20). Responses carry no third-party content (10). Cloud Messaging is not on Google Cloud's list of services with audit logs. Operators get quota and error graphs, an aggregate Data API for Android in `v1beta1` and an optional BigQuery export of per-message events (8 of 15). google.com publishes a security.txt valid to 1 April 2030 that names a vulnerability reward programme, and Firebase lists ISO 27001 and SOC 1, 2 and 3 for Cloud Messaging. firebase.google.com has no security.txt of its own (18 of 20).\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). The pricing page lists Cloud Messaging as no-cost on both plans, without a login (20). It is free on the Spark plan, which needs no billing account or card (20). A person signs in with a Google account, accepts the Firebase terms and creates the project and service account in a browser (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 83: Read as a closed service with official SDKs. The Admin SDKs for Node.js and Go shipped on 23 September 2026 and for Java and .NET on 24 September, each moving topic subscriptions to the v1 API, and the Discovery document is revision 20261006 (30). Firebase's release notes carry Cloud Messaging entries on 19, 25 and 27 August and 9, 23 and 24 September 2026 (20). Public release notes, Firebase Support and a bug report form. We could not read the SDK issue trackers, so half marks on answers (10 of 15). Current official Admin SDKs in five languages, `firebase-admin` 14.5.0 on npm and 7.7.0 on PyPI (15). The Node SDK's CI builds and tests on Node 22, 24 and 26, with dependency updates merged on 8 October. We did not see the run results (8 of 10).\n- Transparency \u0026 trust 81: Closed service under the Google APIs Terms of Service and the Firebase Data Processing and Security Terms, with Apache-2.0 Admin SDKs (15 of 30). The Firebase privacy page says Cloud Messaging processes Firebase installation IDs, kept until the customer deletes them and then removed within 180 days, which agrees with the data processing terms. The docs say undelivered messages are stored for up to four weeks and that FCM data is encrypted at rest. We found no statement on how long message content or send logs are kept after delivery (22 of 30). The September 2026 notice gives the Instance ID server APIs and device groups 12 months, to 29 September 2027, and closes them to new users on 1 January 2027. No standing deprecation policy for FCM was found (17 of 20). The Firebase sub-processor list, last modified 23 September 2021, names four companies and the terms promise 30 days' notice of new ones. Cloud Messaging is a global service with no data location choice (14 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/firebase-cloud-messaging.md (JSON https://www.anchorterminal.com/fixes/firebase-cloud-messaging.json)\n\n### What we couldn't check\n\n- unchecked: GitHub stars and the open issues of the Admin SDK repositories. api.github.com answered with its rate limit, so `githubStars` is empty and issue handling is scored at half\n- unchecked: whether CI passes on the default branch of firebase/firebase-admin-node. We read the workflow file from a clone, not the run results\n- unchecked: the tool definition of `messaging_send_message` in the Firebase MCP server. The listing is graded on the HTTP v1 API\n- The Discovery document lists `access_token` and `key` as query parameters on every method. We took the checklist's 10 points for it, as the Gmail and Google Sheets dossiers did and the Drive and Calendar dossiers did not\n- The Firebase SLA text names no services. We read it as not covering Cloud Messaging because credits are a share of fees and FCM has none\n- No statement was found on how long FCM keeps message content or send logs after delivery\n- The lead was right on the interface. The docs now also describe a v1 topic subscription API and a `fid` target that replaces registration tokens\n\n### Sources\n\n- product overview: \u003chttps://firebase.google.com/docs/cloud-messaging.md.txt\u003e (seen 2026-10-08)\n- send guide for the HTTP v1 API: \u003chttps://firebase.google.com/docs/cloud-messaging/send/v1-api.md.txt\u003e (seen 2026-10-08)\n- send method reference: \u003chttps://firebase.google.com/docs/reference/fcm/rest/v1/projects.messages/send.md.txt\u003e (seen 2026-10-08)\n- Discovery document: \u003chttps://fcm.googleapis.com/$discovery/rest?version=v1\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://firebase.google.com/docs/llms.txt\u003e (seen 2026-10-08)\n- throttling and quotas: \u003chttps://firebase.google.com/docs/cloud-messaging/throttling-and-quotas.md.txt\u003e (seen 2026-10-08)\n- sending at scale and retries: \u003chttps://firebase.google.com/docs/cloud-messaging/scale-fcm.md.txt\u003e (seen 2026-10-08)\n- error codes: \u003chttps://firebase.google.com/docs/cloud-messaging/error-codes.md.txt\u003e (seen 2026-10-08)\n- topic messaging limits: \u003chttps://firebase.google.com/docs/cloud-messaging/topic-messaging.md.txt\u003e (seen 2026-10-08)\n- topic subscription management: \u003chttps://firebase.google.com/docs/cloud-messaging/manage-topic-subscriptions.md.txt\u003e (seen 2026-10-08)\n- deprecation FAQ: \u003chttps://firebase.google.com/docs/cloud-messaging/troubleshooting.md.txt\u003e (seen 2026-10-08)\n- device group migration: \u003chttps://firebase.google.com/docs/cloud-messaging/migrate-off-device-groups.md.txt\u003e (seen 2026-10-08)\n- message lifespan: \u003chttps://firebase.google.com/docs/cloud-messaging/customize-messages/setting-message-lifespan.md.txt\u003e (seen 2026-10-08)\n- delivery data and BigQuery export: \u003chttps://firebase.google.com/docs/cloud-messaging/understand-delivery.md.txt\u003e (seen 2026-10-08)\n- Data API reference: \u003chttps://firebase.google.com/docs/reference/fcmdata/rest/v1beta1/projects.androidApps.deliveryData/list.md.txt\u003e (seen 2026-10-08)\n- status incident feed: \u003chttps://status.firebase.google.com/incidents.json\u003e (seen 2026-10-08)\n- incident of 1 September 2026: \u003chttps://status.firebase.google.com/incidents/efSHTx8oFZ4CH8XsqZuy\u003e (seen 2026-10-08)\n- pricing: \u003chttps://firebase.google.com/pricing\u003e (seen 2026-10-08)\n- terms by Firebase service: \u003chttps://firebase.google.com/terms\u003e (seen 2026-10-08)\n- Google APIs Terms of Service: \u003chttps://developers.google.com/terms\u003e (seen 2026-10-08)\n- Firebase Data Processing and Security Terms: \u003chttps://firebase.google.com/terms/data-processing-terms\u003e (seen 2026-10-08)\n- Firebase SLA: \u003chttps://firebase.google.com/terms/service-level-agreement\u003e (seen 2026-10-08)\n- Firebase sub-processors: \u003chttps://firebase.google.com/terms/subprocessors\u003e (seen 2026-10-08)\n- privacy and security in Firebase: \u003chttps://firebase.google.com/support/privacy\u003e (seen 2026-10-08)\n- Google privacy policy: \u003chttps://policies.google.com/privacy\u003e (seen 2026-10-08)\n- IAM roles: \u003chttps://firebase.google.com/docs/projects/iam/roles-predefined-product.md.txt\u003e (seen 2026-10-08)\n- IAM permissions: \u003chttps://firebase.google.com/docs/projects/iam/permissions.md.txt\u003e (seen 2026-10-08)\n- Google Cloud services with audit logs: \u003chttps://docs.cloud.google.com/logging/docs/audit/services\u003e (seen 2026-10-08)\n- Firebase release notes: \u003chttps://firebase.google.com/support/releases\u003e (seen 2026-10-08)\n- Admin Node.js SDK release notes: \u003chttps://firebase.google.com/support/release-notes/admin/node\u003e (seen 2026-10-08)\n- Admin Node.js SDK repository: \u003chttps://github.com/firebase/firebase-admin-node\u003e (seen 2026-10-08)\n- npm registry: \u003chttps://registry.npmjs.org/firebase-admin/latest\u003e (seen 2026-10-08)\n- PyPI: \u003chttps://pypi.org/pypi/firebase-admin/json\u003e (seen 2026-10-08)\n- Firebase MCP server: \u003chttps://firebase.google.com/docs/ai-assistance/mcp-server.md.txt\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.google.com/.well-known/security.txt\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 94/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Google LLC | 20/20 |\n| Domain age | google.com, registered 1997-09-15 (29 years) | 15/15 |\n| Endpoint on the vendor's domain | fcm.googleapis.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects, and has 1 clause that costs points | 7.3/10 |\n| Status page | status.firebase.google.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe endpoint is on googleapis.com, Google's API domain. The docs are on firebase.google.com.\n\nfirebase.google.com/terms, last modified 24 September 2026, places Cloud Messaging under the Google APIs Terms of Service and the Firebase Data Processing and Security Terms.\n\nThe Google APIs Terms of Service were last modified on 9 November 2021, name Google LLC of Mountain View, California, and choose California law.\n\nGoogle's privacy policy is effective 1 October 2026. Firebase's own privacy and security page, last modified 15 September 2026, gives the per-service data and retention table.\n\nwww.google.com/.well-known/security.txt expires on 2030-04-01. firebase.google.com/.well-known/security.txt returns 404.\n\nThe registration date of google.com is taken from our earlier Google listings and was not looked up again today.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://developers.google.com/terms), read 2026-10-08, dated 2021-11-09, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"Scrape, build databases, or otherwise create permanent copies of such content, or keep cached copies longer than permitted by the cache header;\"\n- To know. Says access can be ended without notice or for any reason. \"Google reserves the right to terminate the Terms with you or discontinue the APIs or any portion or feature or your access thereto for any reason and at any time without liability or other obligation to you.\"\n- To know. Has not been updated for three years or more. \"Last modified: November 9, 2021 (see previous version)\"\n- Gives the date it was last updated. Last updated 2021-11-09.\n- Names the governing law or courts. The law of California, with disputes in the courts of Santa Clara County, California.\n- States a limit on its liability. Capped at the fees paid in the 6 months before the claim.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Content submitted through the APIs is licensed to Google on a perpetual, irrevocable and sublicensable basis, for the stated sole purpose of enabling Google to provide, secure and improve the APIs. \"For the sole purpose of enabling Google to provide, secure, and improve the APIs (and the related service(s)) and only in accordance with the applicable Google privacy policies, you give Google a perpetual, irrevocable, worldwide, sublicensable, royalty-free, and non-exclusive license to Use content\"\n- Also in the text (2026-10-08). A developer may not misrepresent or mask its own identity or the identity of its API client when using the APIs or developer accounts. \"You will not misrepresent or mask either your identity or your API Client's identity when using the APIs or developer accounts.\"\n- Also in the text (2026-10-08). Google may use the developer's company or product name, and screenshots or video of its API client, when promoting or demonstrating the APIs. \"In the course of promoting, marketing, or demonstrating the APIs you are using and the associated Google products, Google may produce and distribute incidental depictions, including screenshots, video, or other content from your API Client, and may use your company or product name.\"\n\n**Privacy policy** (https://policies.google.com/privacy), read 2026-10-08, dated 2026-10-01, states 7 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"We use your interactions with AI models and technologies like Gemini Apps to develop, train, fine-tune, and improve these models to better handle your requests, and update their classifiers and filters including for safety, language understanding, and factuality.\"\n- Gives the date it was last updated. Last updated 2026-10-01.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). Members of organisations using Google Workspace or Google Cloud Platform are referred to the separate Google Cloud Privacy Notice for how those services collect and use personal information. \"If you’re a member of an organization that uses Google Workspace or Google Cloud Platform, learn how these services collect and use your personal information in the Google Cloud Privacy Notice.\"\n- Also in the text (2026-10-08). Google says it uses publicly available information from the web and other public sources to help train machine learning models behind products such as Google Translate, Gemini Apps and Cloud AI. \"We use publicly available information online or from other public sources to help train new machine learning models and build foundational technologies that power various Google products such as Google Translate, Gemini Apps, and Cloud AI capabilities.\"\n\n## Live (updated 2026-10-09 09:26 UTC)\n\n- Right now: up, HTTP 404, 99 ms, checked 2026-10-09 09:26 UTC (get on `https://fcm.googleapis.com`)\n- Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 39 ms · p95 99 ms\n- Vendor status page: unknown, no machine-readable status found\n- Always current: https://www.anchorterminal.com/api/v1/live/firebase-cloud-messaging.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- No charge for sending on either Firebase plan, and no billing account needed (https://firebase.google.com/pricing)\n- Default quota of 600,000 messages a minute per project, with 429 responses that carry `retry-after` and written backoff guidance\n- Short-lived OAuth 2.0 tokens with a `firebase.messaging` scope, and IAM permissions per action such as `cloudmessaging.messages.create`\n- Public Discovery document (revision 20261006), a docs `llms.txt` and a Markdown twin of every docs page\n- Dated deprecation notice in September 2026 that gives 12 months before the Instance ID server APIs and device groups stop on 29 September 2027\n\n## Weaknesses\n\n- Push transport only. No in-app feed, email, SMS, user preferences, digests or templates\n- No idempotency key on `messages:send`, so a retried request can reach the device twice\n- One HTTP request per message. Only the Admin SDKs group up to 500 sends in a call\n- FCM is absent from Google Cloud's list of services with audit logs, and per-message delivery data needs a BigQuery export\n- One incident on 1 September 2026 lowered availability in North America for 3 hours 51 minutes, and no SLA names FCM\n\n## Before you call it (notes for agents)\n\n1. Mint an access token from a service account with the scope `https://www.googleapis.com/auth/firebase.messaging`, then POST to `https://fcm.googleapis.com/v1/projects/\u003cproject-id\u003e/messages:send`\n2. Set `validate_only` to true to test a message or a registration without sending it\n3. On 429 wait for the `retry-after` header, or 60 seconds if it is absent. Retry 500 and 503 with exponential backoff and jitter, and never retry 400, 401, 403 or 404\n4. Drop a registration when the error is `UNREGISTERED` (404). Keep your own record of sends, because a retry after a timeout can produce a duplicate\n5. Target `fid` in new code. The `token` field is marked deprecated in the API, and device groups stop working after 29 September 2027\n\n## Connect\n\nInstall:\n\n```bash\nnpm install firebase-admin   # or: pip install firebase-admin\n```\n\nFirst request:\n\n```bash\ncurl -X POST \"https://fcm.googleapis.com/v1/projects/$FIREBASE_PROJECT_ID/messages:send\" \\\n  -H \"Authorization: Bearer $ACCESS_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"message\":{\"topic\":\"news\",\"notification\":{\"title\":\"Build finished\",\"body\":\"All tests passed\"}}}'\n```\n\nClaude Code:\n\n```bash\nclaude mcp add firebase npx -- -y firebase-tools@latest mcp\n```\n\nThrough letme (picks today, calling later): https://letme.dev/firebase-cloud-messaging. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Ably | BB | 75 | 58 | notify.push | no | https://www.anchorterminal.com/tools/ably.md |\n| Customer.io | BB | 74.5 | 68 | notify.push | no | https://www.anchorterminal.com/tools/customer-io.md |\n| Amazon SNS | BB | 72.8 | 96 | notify.push | no | https://www.anchorterminal.com/tools/amazon-sns.md |\n| SuprSend | BB | 72.6 | 99 | notify.push | no | https://www.anchorterminal.com/tools/suprsend.md |\n| Courier | BB | 70.5 | 146 | notify.push | no | https://www.anchorterminal.com/tools/courier.md |\n| OneSignal | B | 69.3 | 180 | notify.push | no | https://www.anchorterminal.com/tools/onesignal.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The default quota is 600,000 messages a minute per project. It counts messages, not requests, and client errors other than 429 count against it (source: \u003chttps://firebase.google.com/docs/cloud-messaging/throttling-and-quotas\u003e)\n- The Instance ID server APIs and device groups were deprecated in September 2026, close to new users on 1 January 2027 and stop on 29 September 2027 (source: \u003chttps://firebase.google.com/docs/cloud-messaging/troubleshooting\u003e)\n- The API's `Message` type now takes a Firebase installation ID in `fid` and marks the registration `token` field as deprecated (source: \u003chttps://fcm.googleapis.com/$discovery/rest?version=v1\u003e)\n- Topic subscriptions have their own v1 resource, `projects.registrations.topicSubscriptions`, and Admin SDKs moved to it on 23 and 24 September 2026 (source: \u003chttps://firebase.google.com/support/releases\u003e)\n- Undelivered messages are stored for up to four weeks unless `ttl` sets a shorter life (source: \u003chttps://firebase.google.com/docs/cloud-messaging/customize-messages/setting-message-lifespan\u003e)\n- The local Firebase MCP server in `firebase-tools` includes a `messaging_send_message` tool that sends to a registration token or topic (source: \u003chttps://firebase.google.com/docs/ai-assistance/mcp-server\u003e)\n- Firebase lists ISO 27001 and SOC 1, 2 and 3 for Cloud Messaging, and not ISO 27017 or 27018 (source: \u003chttps://firebase.google.com/support/privacy\u003e)\n\n## Compare\n\n- [Amazon SNS vs Firebase Cloud Messaging](https://www.anchorterminal.com/compare/amazon-sns-vs-firebase-cloud-messaging.md): BB 72.8 vs B 69.8\n- [Courier vs Firebase Cloud Messaging](https://www.anchorterminal.com/compare/courier-vs-firebase-cloud-messaging.md): BB 70.5 vs B 69.8\n- [Firebase Cloud Messaging vs Knock](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-knock.md): B 69.8 vs B 66.5\n- [Firebase Cloud Messaging vs MagicBell](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-magicbell.md): B 69.8 vs C 58.8\n- [Firebase Cloud Messaging vs Novu](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-novu.md): B 69.8 vs B 64.2\n- [Firebase Cloud Messaging vs ntfy](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-ntfy.md): B 69.8 vs C 61.5\n- [Firebase Cloud Messaging vs OneSignal](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-onesignal.md): B 69.8 vs B 69.3\n- [Firebase Cloud Messaging vs Pushover](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-pushover.md): B 69.8 vs D 53.1\n- [Firebase Cloud Messaging vs SuprSend](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-suprsend.md): B 69.8 vs BB 72.6\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on google.com or one of its subdomains, or the README of github.com/firebase/firebase-admin-node. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"firebase-cloud-messaging\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/firebase-cloud-messaging\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/firebase-cloud-messaging.svg\" alt=\"Firebase Cloud Messaging on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Firebase Cloud Messaging on Anchor Terminal](https://www.anchorterminal.com/badges/firebase-cloud-messaging.svg)](https://www.anchorterminal.com/tools/firebase-cloud-messaging)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/firebase-cloud-messaging\"\u003eFirebase Cloud Messaging on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Firebase Cloud Messaging is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/firebase-cloud-messaging-dark.png\n- Light: https://www.anchorterminal.com/assets/share/firebase-cloud-messaging-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Notifications",
        "url": "https://www.anchorterminal.com/categories/notifications"
      },
      {
        "name": "Firebase Cloud Messaging",
        "url": ""
      }
    ],
    "description": "Google's push messaging service for Android, Apple and web apps. A server sends notification or data messages to devices, topics or conditions through the HTTP v1 API or the Firebase Admin SDKs.",
    "facts": [
      "rank #162 of 842",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Firebase Cloud Messaging",
    "image": "https://www.anchorterminal.com/assets/og/tools-firebase-cloud-messaging.png",
    "path": "/tools/firebase-cloud-messaging",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Firebase Cloud Messaging review for AI agents, grade B (69.8/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/firebase-cloud-messaging"
  },
  "tokens": {
    "markdown": 8550,
    "slim": 1530
  },
  "version": 1
}
