# Firebase Cloud Messaging > Google's push messaging service for Android, Apple and web apps. A server sends notification or data messages to devices, topics or conditions through the HTTP v1 API or the Firebase Admin SDKs. - Canonical: https://www.anchorterminal.com/tools/firebase-cloud-messaging - Markdown: https://www.anchorterminal.com/tools/firebase-cloud-messaging.md (~8,550 tokens) - Slim: https://www.anchorterminal.com/tools/firebase-cloud-messaging.min.md (~1,530 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/firebase-cloud-messaging.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 69.8/100 · rank #162 of 842 · #4 in Notifications · not agent-ready · confidence medium** More from Google, listed separately because each is its own product: [Gemini Developer API](https://www.anchorterminal.com/tools/gemini-api.md) (Model APIs & inference), [Gemini Embedding](https://www.anchorterminal.com/tools/gemini-embedding.md) (Embeddings & rerankers), [Vertex AI Gemini tuning](https://www.anchorterminal.com/tools/vertex-ai-tuning.md) (Fine-tuning), [Google Cloud Model Armor](https://www.anchorterminal.com/tools/google-model-armor.md) (Guardrails & safety filters), [Google Imagen](https://www.anchorterminal.com/tools/google-imagen.md) (Image generation), [Google Veo](https://www.anchorterminal.com/tools/google-veo.md) (Video generation), [Google Lyria](https://www.anchorterminal.com/tools/google-lyria.md) (Music generation), [Google Cloud Speech-to-Text](https://www.anchorterminal.com/tools/google-speech-to-text.md) (Speech-to-text), [Gemini Live API](https://www.anchorterminal.com/tools/gemini-live.md) (Conversational voice agents), [Agent Development Kit (ADK)](https://www.anchorterminal.com/tools/google-adk.md) (Agent frameworks & SDKs), [Google Cloud Secret Manager](https://www.anchorterminal.com/tools/google-secret-manager.md) (Secrets & credential vaults), [Google Weather API (Maps Platform)](https://www.anchorterminal.com/tools/google-weather-api.md) (Weather & climate data), [Chrome DevTools MCP](https://www.anchorterminal.com/tools/chrome-devtools-mcp.md) (Browser automation), [Google Maps Platform + Grounding Lite MCP](https://www.anchorterminal.com/tools/google-maps-platform.md) (Maps, geocoding & places), [Google Cloud Translation](https://www.anchorterminal.com/tools/google-cloud-translation.md) (Translation), [Google Calendar API](https://www.anchorterminal.com/tools/google-calendar-api.md) (Calendars & scheduling), [Google Drive API + MCP](https://www.anchorterminal.com/tools/google-drive-api.md) (File storage & sharing), [Gemini CLI](https://www.anchorterminal.com/tools/gemini-cli.md) (Agent harnesses), [Google Search Console API](https://www.anchorterminal.com/tools/google-search-console.md) (SEO & search visibility), [Google Ads API](https://www.anchorterminal.com/tools/google-ads-api.md) (Advertising & campaign operations), [Google Forms API](https://www.anchorterminal.com/tools/google-forms.md) (Forms, surveys & structured intake), [Google Sheets API](https://www.anchorterminal.com/tools/google-sheets-api.md) (Spreadsheets & operational tables), [Gmail API](https://www.anchorterminal.com/tools/gmail-api.md) (Mailbox access). ## Assessment Sending is free at any volume, with a published quota of 600,000 messages a minute per project and documented 429 handling. FCM is push transport only. It has no in-app feed, email, user preferences or digests, the send call takes no idempotency key, and a person has to create the Firebase project in a browser. ## Facts | Field | Value | | --- | --- | | Vendor | Google (https://firebase.google.com/products/cloud-messaging) | | Kind | HTTP API | | Category | Notifications (https://www.anchorterminal.com/categories/notifications) | | Transport | HTTP | | Endpoint | `https://fcm.googleapis.com` | | Auth | OAuth · OAuth 2.0 bearer token minted from a service account key or Application Default Credentials, with the scope `https://www.googleapis.com/auth/firebase.messaging`. Sending needs the IAM permission `cloudmessaging.messages.create` on the project. Access is self-serve. A person creates the Firebase project and the service account in the console, with no review or sales step. | | Pricing | Free (Free) · No charge. The pricing page lists Cloud Messaging as no-cost on the Spark and Blaze plans, and Spark needs no billing account or card, so an agent's owner can start without a contract. The optional BigQuery export of delivery data is billed by BigQuery (https://firebase.google.com/pricing, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the FCM docs, the Discovery document or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under the Google APIs Terms of Service. The Firebase Admin SDKs are Apache-2.0 | | Packages | npm: `firebase-admin`; pypi: `firebase-admin` | | Source | https://github.com/firebase/firebase-admin-node | | Docs | https://firebase.google.com/docs/cloud-messaging | | llms.txt | https://firebase.google.com/docs/llms.txt | | Last release | 2026-09-24 | | npm downloads / week | 11,536,195 | | PyPI downloads / week | 3,790,113 | | API | HTTP v1 at `https://fcm.googleapis.com/v1/projects//messages:send`, plus five topic subscription methods. Discovery revision 20261006 | | Targets | A Firebase installation ID or registration token, a topic, or a condition over topics. Device groups are deprecated and stop on 29 September 2027 | | Platforms | Android, Apple platforms through APNs, and web push | | Payload | Up to 4,096 bytes, or 2,048 bytes for a topic message | | Quota | 600,000 messages a minute per project. 240 a minute and 5,000 an hour to one Android device. 3,000 topic subscription changes a second. 1,000 concurrent fanouts | | Retries | 429 with `retry-after` (60 seconds if absent). Exponential backoff with jitter on 500 and 503. No idempotency key | | Credentials | OAuth 2.0 token from a service account, scope `firebase.messaging`, IAM permission `cloudmessaging.messages.create` | | Admin SDKs | Node.js, Python, Java, Go and .NET. Up to 500 messages or targets per SDK call, sent as separate requests | | Delivery data | Aggregate Data API for Android (`v1beta1`) and an optional BigQuery export of per-message events | | Message storage | Up to four weeks for undelivered messages, or the `ttl` given | | Price | No charge on the Spark and Blaze plans | | Capabilities | notify.push | | Tags | hosted, free, push, oauth, llms-txt, typescript, python, java, go, dotnet, mcp, status-page, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/firebase-cloud-messaging.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 66 | 13.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 86 | 14.0 | | Agent ergonomics | 13% | 16.2 | 70 | 11.4 | | Security & auth | 14% | 17.5 | 68 | 11.9 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 83 | 7.3 | | Transparency & trust (editorial 68, provenance 94) | 7% | 8.8 | 81 | 7.1 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **69.8 → B** | ### Why each score - Reliability 66: Hosted reading. Firebase status dashboard with a page and a JSON incident feed per product (20). The feed lists one Cloud Messaging incident between 10 July and 8 October 2026, low availability and higher latency in North America on 1 September from 08:40 to 12:31 UTC, 3 hours 51 minutes, read as one major incident (10). Limits are published with numbers, 600,000 messages a minute per project, 240 a minute and 5,000 an hour to one Android device, 3,000 topic subscription changes a second and 1,000 concurrent fanouts (15). 429 and 503 handling is documented with `retry-after`, a 60 second default, exponential backoff with jitter and a 10 second timeout, but `messages:send` takes no idempotency key and the Admin SDK release notes record timeouts raised to avoid duplicate notifications (11 of 15). The Firebase SLA of 9 April 2020 does not name Cloud Messaging and pays credits as a share of fees, and FCM has no fee, so no SLA (0). The HTTP v1 API is generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 86: A public Discovery document at `fcm.googleapis.com/$discovery/rest?version=v1`, revision 20261006, with 6 methods and 16 schemas (25). `firebase.google.com/docs/llms.txt` indexes the docs and every page has a `.md.txt` twin (10). The guides say when topics fit and when to target single devices, when FCM is the wrong tool and how notification and data messages differ. The reference itself is terse (16 of 20). 79 typed properties with 4 enums, but `data`, the APNs `payload` and `headers` and the web push `notification` are free-form objects, and `ttl` and `condition` are strings with their own grammar (9 of 15). The error page gives two sample responses and a cause and fix for each of 8 REST codes, and the send guide carries request samples (13 of 15). Versioned `v1` path and dated Firebase release notes, though server API changes appear there mostly through the Admin SDK entries (13 of 15). - Agent ergonomics 70: API reading, graded on the HTTP v1 API. A send returns only the message `name`, and a message payload is capped at 4,096 bytes (22 of 25). Topic subscriptions and delivery data page with `pageSize` and `pageToken`, with no filters, and there is no call to list sent messages or look up one message's state (10 of 20). Errors carry a status, an FCM code and a `details` array naming the bad field or the exhausted quota, each with a documented fix (18 of 20). No idempotency key on send. `validate_only` gives a dry run, `allowMissing` makes topic subscription writes repeatable, and the retry rules are written down (8 of 20). A send needs only a project and one target, and Admin SDKs exist for Node.js, Python, Java, Go and .NET. Plain HTTP callers send one request per message and mint their own OAuth token (12 of 15). - Security & auth 68: OAuth 2.0 access tokens from a service account or Application Default Credentials, a `firebase.messaging` scope, and IAM permissions per action (30), less 10 because the Discovery document lists `access_token` and `key` as query parameters (20). A custom role can hold `cloudmessaging.messages.create` alone and `validate_only` tests without sending. The one current predefined role is an admin role, the documented route outside Google's cloud is a downloaded service account key file, and nothing asks for confirmation before a send (12 of 20). Responses carry no third-party content (10). Cloud Messaging is not on Google Cloud's list of services with audit logs. Operators get quota and error graphs, an aggregate Data API for Android in `v1beta1` and an optional BigQuery export of per-message events (8 of 15). google.com publishes a security.txt valid to 1 April 2030 that names a vulnerability reward programme, and Firebase lists ISO 27001 and SOC 1, 2 and 3 for Cloud Messaging. firebase.google.com has no security.txt of its own (18 of 20). - Payments & pricing 40: No x402, MPP or L402 (0). The pricing page lists Cloud Messaging as no-cost on both plans, without a login (20). It is free on the Spark plan, which needs no billing account or card (20). A person signs in with a Google account, accepts the Firebase terms and creates the project and service account in a browser (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 83: Read as a closed service with official SDKs. The Admin SDKs for Node.js and Go shipped on 23 September 2026 and for Java and .NET on 24 September, each moving topic subscriptions to the v1 API, and the Discovery document is revision 20261006 (30). Firebase's release notes carry Cloud Messaging entries on 19, 25 and 27 August and 9, 23 and 24 September 2026 (20). Public release notes, Firebase Support and a bug report form. We could not read the SDK issue trackers, so half marks on answers (10 of 15). Current official Admin SDKs in five languages, `firebase-admin` 14.5.0 on npm and 7.7.0 on PyPI (15). The Node SDK's CI builds and tests on Node 22, 24 and 26, with dependency updates merged on 8 October. We did not see the run results (8 of 10). - Transparency & trust 81: Closed service under the Google APIs Terms of Service and the Firebase Data Processing and Security Terms, with Apache-2.0 Admin SDKs (15 of 30). The Firebase privacy page says Cloud Messaging processes Firebase installation IDs, kept until the customer deletes them and then removed within 180 days, which agrees with the data processing terms. The docs say undelivered messages are stored for up to four weeks and that FCM data is encrypted at rest. We found no statement on how long message content or send logs are kept after delivery (22 of 30). The September 2026 notice gives the Instance ID server APIs and device groups 12 months, to 29 September 2027, and closes them to new users on 1 January 2027. No standing deprecation policy for FCM was found (17 of 20). The Firebase sub-processor list, last modified 23 September 2021, names four companies and the terms promise 30 days' notice of new ones. Cloud Messaging is a global service with no data location choice (14 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/firebase-cloud-messaging.md (JSON https://www.anchorterminal.com/fixes/firebase-cloud-messaging.json) ### What we couldn't check - unchecked: GitHub stars and the open issues of the Admin SDK repositories. api.github.com answered with its rate limit, so `githubStars` is empty and issue handling is scored at half - unchecked: whether CI passes on the default branch of firebase/firebase-admin-node. We read the workflow file from a clone, not the run results - unchecked: the tool definition of `messaging_send_message` in the Firebase MCP server. The listing is graded on the HTTP v1 API - The Discovery document lists `access_token` and `key` as query parameters on every method. We took the checklist's 10 points for it, as the Gmail and Google Sheets dossiers did and the Drive and Calendar dossiers did not - The Firebase SLA text names no services. We read it as not covering Cloud Messaging because credits are a share of fees and FCM has none - No statement was found on how long FCM keeps message content or send logs after delivery - The lead was right on the interface. The docs now also describe a v1 topic subscription API and a `fid` target that replaces registration tokens ### Sources - product overview: (seen 2026-10-08) - send guide for the HTTP v1 API: (seen 2026-10-08) - send method reference: (seen 2026-10-08) - Discovery document: (seen 2026-10-08) - docs index for agents: (seen 2026-10-08) - throttling and quotas: (seen 2026-10-08) - sending at scale and retries: (seen 2026-10-08) - error codes: (seen 2026-10-08) - topic messaging limits: (seen 2026-10-08) - topic subscription management: (seen 2026-10-08) - deprecation FAQ: (seen 2026-10-08) - device group migration: (seen 2026-10-08) - message lifespan: (seen 2026-10-08) - delivery data and BigQuery export: (seen 2026-10-08) - Data API reference: (seen 2026-10-08) - status incident feed: (seen 2026-10-08) - incident of 1 September 2026: (seen 2026-10-08) - pricing: (seen 2026-10-08) - terms by Firebase service: (seen 2026-10-08) - Google APIs Terms of Service: (seen 2026-10-08) - Firebase Data Processing and Security Terms: (seen 2026-10-08) - Firebase SLA: (seen 2026-10-08) - Firebase sub-processors: (seen 2026-10-08) - privacy and security in Firebase: (seen 2026-10-08) - Google privacy policy: (seen 2026-10-08) - IAM roles: (seen 2026-10-08) - IAM permissions: (seen 2026-10-08) - Google Cloud services with audit logs: (seen 2026-10-08) - Firebase release notes: (seen 2026-10-08) - Admin Node.js SDK release notes: (seen 2026-10-08) - Admin Node.js SDK repository: (seen 2026-10-08) - npm registry: (seen 2026-10-08) - PyPI: (seen 2026-10-08) - Firebase MCP server: (seen 2026-10-08) - security.txt: (seen 2026-10-08) ## Who's behind it (provenance 94/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Google LLC | 20/20 | | Domain age | google.com, registered 1997-09-15 (29 years) | 15/15 | | Endpoint on the vendor's domain | fcm.googleapis.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects, and has 1 clause that costs points | 7.3/10 | | Status page | status.firebase.google.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The endpoint is on googleapis.com, Google's API domain. The docs are on firebase.google.com. firebase.google.com/terms, last modified 24 September 2026, places Cloud Messaging under the Google APIs Terms of Service and the Firebase Data Processing and Security Terms. The Google APIs Terms of Service were last modified on 9 November 2021, name Google LLC of Mountain View, California, and choose California law. Google's privacy policy is effective 1 October 2026. Firebase's own privacy and security page, last modified 15 September 2026, gives the per-service data and retention table. www.google.com/.well-known/security.txt expires on 2030-04-01. firebase.google.com/.well-known/security.txt returns 404. The registration date of google.com is taken from our earlier Google listings and was not looked up again today. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://developers.google.com/terms), read 2026-10-08, dated 2021-11-09, states 6 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Scrape, build databases, or otherwise create permanent copies of such content, or keep cached copies longer than permitted by the cache header;" - To know. Says access can be ended without notice or for any reason. "Google reserves the right to terminate the Terms with you or discontinue the APIs or any portion or feature or your access thereto for any reason and at any time without liability or other obligation to you." - To know. Has not been updated for three years or more. "Last modified: November 9, 2021 (see previous version)" - Gives the date it was last updated. Last updated 2021-11-09. - Names the governing law or courts. The law of California, with disputes in the courts of Santa Clara County, California. - States a limit on its liability. Capped at the fees paid in the 6 months before the claim. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Content submitted through the APIs is licensed to Google on a perpetual, irrevocable and sublicensable basis, for the stated sole purpose of enabling Google to provide, secure and improve the APIs. "For the sole purpose of enabling Google to provide, secure, and improve the APIs (and the related service(s)) and only in accordance with the applicable Google privacy policies, you give Google a perpetual, irrevocable, worldwide, sublicensable, royalty-free, and non-exclusive license to Use content" - Also in the text (2026-10-08). A developer may not misrepresent or mask its own identity or the identity of its API client when using the APIs or developer accounts. "You will not misrepresent or mask either your identity or your API Client's identity when using the APIs or developer accounts." - Also in the text (2026-10-08). Google may use the developer's company or product name, and screenshots or video of its API client, when promoting or demonstrating the APIs. "In the course of promoting, marketing, or demonstrating the APIs you are using and the associated Google products, Google may produce and distribute incidental depictions, including screenshots, video, or other content from your API Client, and may use your company or product name." **Privacy policy** (https://policies.google.com/privacy), read 2026-10-08, dated 2026-10-01, states 7 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "We use your interactions with AI models and technologies like Gemini Apps to develop, train, fine-tune, and improve these models to better handle your requests, and update their classifiers and filters including for safety, language understanding, and factuality." - Gives the date it was last updated. Last updated 2026-10-01. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Members of organisations using Google Workspace or Google Cloud Platform are referred to the separate Google Cloud Privacy Notice for how those services collect and use personal information. "If you’re a member of an organization that uses Google Workspace or Google Cloud Platform, learn how these services collect and use your personal information in the Google Cloud Privacy Notice." - Also in the text (2026-10-08). Google says it uses publicly available information from the web and other public sources to help train machine learning models behind products such as Google Translate, Gemini Apps and Cloud AI. "We use publicly available information online or from other public sources to help train new machine learning models and build foundational technologies that power various Google products such as Google Translate, Gemini Apps, and Cloud AI capabilities." ## Live (updated 2026-10-09 10:14 UTC) - Right now: up, HTTP 404, 37 ms, checked 2026-10-09 10:14 UTC (get on `https://fcm.googleapis.com`) - Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 39 ms · p95 99 ms - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/firebase-cloud-messaging.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - No charge for sending on either Firebase plan, and no billing account needed (https://firebase.google.com/pricing) - Default quota of 600,000 messages a minute per project, with 429 responses that carry `retry-after` and written backoff guidance - Short-lived OAuth 2.0 tokens with a `firebase.messaging` scope, and IAM permissions per action such as `cloudmessaging.messages.create` - Public Discovery document (revision 20261006), a docs `llms.txt` and a Markdown twin of every docs page - Dated deprecation notice in September 2026 that gives 12 months before the Instance ID server APIs and device groups stop on 29 September 2027 ## Weaknesses - Push transport only. No in-app feed, email, SMS, user preferences, digests or templates - No idempotency key on `messages:send`, so a retried request can reach the device twice - One HTTP request per message. Only the Admin SDKs group up to 500 sends in a call - FCM is absent from Google Cloud's list of services with audit logs, and per-message delivery data needs a BigQuery export - One incident on 1 September 2026 lowered availability in North America for 3 hours 51 minutes, and no SLA names FCM ## Before you call it (notes for agents) 1. Mint an access token from a service account with the scope `https://www.googleapis.com/auth/firebase.messaging`, then POST to `https://fcm.googleapis.com/v1/projects//messages:send` 2. Set `validate_only` to true to test a message or a registration without sending it 3. On 429 wait for the `retry-after` header, or 60 seconds if it is absent. Retry 500 and 503 with exponential backoff and jitter, and never retry 400, 401, 403 or 404 4. Drop a registration when the error is `UNREGISTERED` (404). Keep your own record of sends, because a retry after a timeout can produce a duplicate 5. Target `fid` in new code. The `token` field is marked deprecated in the API, and device groups stop working after 29 September 2027 ## Connect Install: ```bash npm install firebase-admin # or: pip install firebase-admin ``` First request: ```bash curl -X POST "https://fcm.googleapis.com/v1/projects/$FIREBASE_PROJECT_ID/messages:send" \ -H "Authorization: Bearer $ACCESS_TOKEN" -H "Content-Type: application/json" \ -d '{"message":{"topic":"news","notification":{"title":"Build finished","body":"All tests passed"}}}' ``` Claude Code: ```bash claude mcp add firebase npx -- -y firebase-tools@latest mcp ``` Through letme (picks today, calling later): https://letme.dev/firebase-cloud-messaging. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Ably | BB | 75 | 58 | notify.push | no | https://www.anchorterminal.com/tools/ably.md | | Customer.io | BB | 74.5 | 68 | notify.push | no | https://www.anchorterminal.com/tools/customer-io.md | | Amazon SNS | BB | 72.8 | 96 | notify.push | no | https://www.anchorterminal.com/tools/amazon-sns.md | | SuprSend | BB | 72.6 | 99 | notify.push | no | https://www.anchorterminal.com/tools/suprsend.md | | Courier | BB | 70.5 | 146 | notify.push | no | https://www.anchorterminal.com/tools/courier.md | | OneSignal | B | 69.3 | 180 | notify.push | no | https://www.anchorterminal.com/tools/onesignal.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The default quota is 600,000 messages a minute per project. It counts messages, not requests, and client errors other than 429 count against it (source: ) - The Instance ID server APIs and device groups were deprecated in September 2026, close to new users on 1 January 2027 and stop on 29 September 2027 (source: ) - The API's `Message` type now takes a Firebase installation ID in `fid` and marks the registration `token` field as deprecated (source: ) - Topic subscriptions have their own v1 resource, `projects.registrations.topicSubscriptions`, and Admin SDKs moved to it on 23 and 24 September 2026 (source: ) - Undelivered messages are stored for up to four weeks unless `ttl` sets a shorter life (source: ) - The local Firebase MCP server in `firebase-tools` includes a `messaging_send_message` tool that sends to a registration token or topic (source: ) - Firebase lists ISO 27001 and SOC 1, 2 and 3 for Cloud Messaging, and not ISO 27017 or 27018 (source: ) ## Compare - [Amazon SNS vs Firebase Cloud Messaging](https://www.anchorterminal.com/compare/amazon-sns-vs-firebase-cloud-messaging.md): BB 72.8 vs B 69.8 - [Courier vs Firebase Cloud Messaging](https://www.anchorterminal.com/compare/courier-vs-firebase-cloud-messaging.md): BB 70.5 vs B 69.8 - [Firebase Cloud Messaging vs Knock](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-knock.md): B 69.8 vs B 66.5 - [Firebase Cloud Messaging vs MagicBell](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-magicbell.md): B 69.8 vs C 58.8 - [Firebase Cloud Messaging vs Novu](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-novu.md): B 69.8 vs B 64.2 - [Firebase Cloud Messaging vs ntfy](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-ntfy.md): B 69.8 vs C 61.5 - [Firebase Cloud Messaging vs OneSignal](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-onesignal.md): B 69.8 vs B 69.3 - [Firebase Cloud Messaging vs Pushover](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-pushover.md): B 69.8 vs D 53.1 - [Firebase Cloud Messaging vs SuprSend](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-suprsend.md): B 69.8 vs BB 72.6 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on google.com or one of its subdomains, or the README of github.com/firebase/firebase-admin-node. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "firebase-cloud-messaging", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Firebase Cloud Messaging on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Firebase Cloud Messaging on Anchor Terminal](https://www.anchorterminal.com/badges/firebase-cloud-messaging.svg)](https://www.anchorterminal.com/tools/firebase-cloud-messaging) ``` Plain link: ```html Firebase Cloud Messaging on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Firebase Cloud Messaging is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/firebase-cloud-messaging-dark.png - Light: https://www.anchorterminal.com/assets/share/firebase-cloud-messaging-light.png