Pure C# Firebase Auth, Firestore, Storage, callable Functions, Realtime Database and App Check, with 25 game services, Security Rules packs, editor tools and drop-in panels.
What you get, how long it takes, and what you need.
About 10 minutes to configure a project, sign in, save data and read a leaderboard, following the package quick start.
Unity 6.3 LTS (6000.3) or newer. Bring a Firebase project, its Web API key and Project ID; enable your sign-in method and publish the matching Rules pack. Cloud Storage requires Firebase's Blaze plan.
The official Firebase Unity SDK cannot run on WebGL.
Its native plugins cannot execute in a browser, so a WebGL build has nothing to link against. If you ship to the browser, you need a different path to the same backend.
The official SDK is built on native libraries. A WebAssembly build cannot link or execute them, so the browser gets nothing at runtime.
Android and iOS libraries grow the build, the binary and the surface you have to keep working across every platform you ship to.
Anything you ship to the browser has to work inside WebAssembly, over the network, without native code. That is the path this toolkit takes.
Everything the native SDK covers, over HTTP.
Six systems on one client, sharing one signed-in session, one retry policy and one transport.
Email and password, anonymous guests, custom tokens, and identity-provider sign-in and linking. Password reset, verification, profile changes and account deletion. Sessions persist and refresh through GetValidIdTokenAsync().
Typed document CRUD, a fluent query builder, pagination and aggregations. Batches commit up to 500 operations atomically with server-side transforms, RunInTransactionAsync covers read-modify-write, and vector search uses Firestore's native findNearest.
Uploads, downloads, metadata, listings and token-authorized public URLs, plus the resumable session protocol for large files. Texture2D, Sprite and AudioClip loaders included.
Call Cloud Functions with bearer auth and plain-JSON payloads; HttpsError status and details surface on typed exceptions.
REST reads and writes plus SSE streaming listeners: chunk-safe parsing, reconnection that honours server retry hints, and events raised on the main thread.
Debug-provider tokens ride on Firestore, Storage and Functions calls, cached and single-flight. The interface is pluggable for native attestation providers.
EnableOfflineCache and Firestore writes survive a lost connection. They are queued durably (IndexedDB on WebGL) and replayed oldest-first on reconnect, with a pending count for sync badges.Twenty-five services, each with its rules and its limits written down.
Each service documents its Firestore layout, the Security Rules it expects, and what a modified client can still cheat. Most hang off FirebaseClient.Instance; crash telemetry is constructed by your game.
Economy and progression · 9
- Cloud Save — multi-slot JSON saves, private per player, with versioned conflict resolution.
- Leaderboard — personal best, owner-only writes, public top-N reads.
- Economy — wallet, catalog, transactional purchases, append-only ledger.
- Inventory — one document per stack, so Increment handles stacking safely.
- Achievements — definitions joined to progress, with an Unlocked event.
- Daily Rewards — streaks decided against the server clock, never the device clock.
- Quests — claiming kept separate from completion, so an offline finish still pays out.
- Battle Pass — tiers derived from XP, so retuning a curve re-derives everyone.
- IAP Validation — forwards store receipts to your
validatePurchasefunction, whose shipped template verifies against Google Play and the App Store before granting.
Live ops · 7
- Remote Config — flags and tuning with code defaults that survive a failed fetch.
- Experiments — deterministic assignment that survives reinstalls, with no stored bucket.
- Announcements — scheduling, platform targeting and per-player dismissal.
- Localization — over-the-air strings, so a typo or a new language skips the store release.
- Analytics — your own events into your Firestore, batched; not Google Analytics for Firebase.
- Push Tokens — owner-only device tokens; sending belongs in a Cloud Function.
- Crash Telemetry — bounded breadcrumbs, error and fatal events, an offline queue and redaction before storage. Writes only to your project, and your game switches it on.
Social · 6
- Guilds — atomic creation, roles and a self-healing membership pointer.
- Friends — friends, requests and invites in one fetch, plus add-by-id.
- Presence — Realtime Database heartbeats with a staleness window, because a force-quit cannot write offline.
- Chat — paged history, polling followers, local mutes and a write-only report queue.
- Mailbox — rewards, compensation and gifts; claiming is one transaction into wallet and inventory.
- Moderation — client-side reports; bans and resolutions go through the
moderatePlayerfunction.
Multiplayer-adjacent · 3
- Matchmaking — skill-banded pairing with a widening band and one-match-or-abort transactions.
- Matchmaking Queue — roster matchmaking by region and skill, widening with wait time, claimed in one transaction that cannot seat a player twice.
- Lobbies — create, transactional join, ready and host start, with a host heartbeat for liveness.
For turn-based games, TurnSessionService runs an ordered roster over the Realtime Database with per-turn deadlines, fenced move submission, forfeits and spectators. Netcode still belongs to your networking library.
A 48-screen workspace instead of a console round trip.
Tools → ShipIt → Firebase Toolkit opens a searchable workspace (Ctrl+K) with light and dark themes. Most day-to-day work happens without leaving Unity.
Setup Wizard
Validates your credentials against Identity Toolkit and probes every configured service.
Collection Browser
Pages live collections as an anonymous caller, so what you see is what a signed-out client sees.
Query Console
Composes structured queries, runs them, and emits the equivalent C#.
Code Generator
Infers typed [Serializable] models from real documents, with explicit skip reporting for unmappable fields.
Vector Search
Ranked results with distances, and the vector index snippet your query needs, ready to copy.
Pentest
Sweeps your project as an anonymous caller and finds world-writable collections before someone else does.
Rules Generator and Simulator
Composes default-deny rules from per-collection access models, then probes a real path signed out and signed in.
Function Templates
Eight deployable Cloud Functions for the operations a client must never be trusted with.
Diagnostics
p95 latency beside the mean, a credential-free support bundle, a request inspector that redacts credentials at capture, and an error explainer.
firestore.indexes.json export, seven drop-in Security Rules packs, a Storage rules generator, C# to TypeScript model sync, emulator targeting, seed data, JSON and CSV import and export, offline simulation, and an AI context export.19 runtime panels, built in code. No prefabs.
GameObject → ShipIt → Firebase places a working panel into the open scene in one click. Every panel builds its own uGUI layout at runtime: no prefab GUIDs, no serialized font references, nothing to break on import.
Three playable sample scenes
Auth + Cloud Save
Sign in, round-trip a save, read the leaderboard top three.
Realtime Room
Stream a Realtime Database path over SSE and push messages.
Panel Tour
Every drop-in panel, one at a time from a toolbar.
How the numbers are checked.
The v0.23.0 release run on Unity 6000.3.11f1, September 20, 2026. Nothing here is more than one build or one test run away.
| Check | Result | How it is verified |
|---|---|---|
| EditMode tests | 776 passed, 0 failed | Unity Test Runner; a compile gate runs on every push |
| PlayMode tests | 17 passed | Unity Test Runner, headless |
| WebGL build | 0 errors, 0 warnings, about 10.1 MB | Batch build of the Panel Tour scene |
| WebGL player boot | Pass, no page errors | ci/webgl-proof.cjs boots the built player in headless Chromium |
| Windows IL2CPP build | 0 errors, 0 warnings | The same batch build with the IL2CPP scripting backend |
| Package contents | 25 services · 48 screens · 19 panels · 7 rules packs · 8 function templates · 3 samples | Generated from the shipped source into the package's feature matrix |
Initialize, sign in, save, post a score.
- Configure. Tools → ShipIt → Firebase Toolkit → Setup Wizard. Paste your Web API key and project ID, press Test Connection, then Save.
- Initialize. Drop the Bootstrapper into your scene, or call
FirebaseClient.InitializeFromResources()yourself. - Lock it down. Publish a rules pack before you ship. The Web API key is public by design; authorization lives in Security Rules and App Check.
[Serializable] public class SaveData { public int level; public string hero; }
await FirebaseClient.Instance.CloudSave
.SaveAsync("slot1",
new SaveData { level = 3, hero = "Ada" });
var state = await FirebaseClient.Instance.CloudSave
.LoadAsync<SaveData>("slot1");
await FirebaseClient.Instance.Leaderboard
.SubmitScoreAsync(score);
What it does not do.
- No Firestore realtime listeners. Upstream realtime is gRPC-only and REST has no documented stream. Use the Realtime Database, which streams over SSE, or poll Firestore queries.
- No OAuth popup or redirect sign-in on WebGL. There is deliberately no JavaScript bridge. Use email and password, anonymous, custom tokens, or a provider token obtained natively.
- App Check ships the debug provider. Native attestation (Play Integrity, DeviceCheck) needs platform plugins; implement
IAppCheckTokenProviderto add one. - No Query Explain. It accepts only IAM server credentials, and service accounts must never ship in a client.
- It does not host anything. Your Firebase project holds your data. Cloud Storage needs the Blaze plan.
Firebase on WebGL, without the native SDK.
The Asset Store listing is not live yet. Read the documentation first, or ask about release timing.
Before you connect Firebase.
Is this the official Firebase Unity SDK?
No. It is an independent, pure C# integration over Firebase's documented REST APIs. It avoids native plugins and JavaScript bridges, which lets it run in WebGL.
Does every Firebase feature work in WebGL?
No. The runtime supports WebGL, but Firestore realtime listeners and browser popup or redirect flows for OAuth and phone reCAPTCHA are not supported. Realtime Database uses SSE.
Do I need to configure Security Rules?
Yes. Publish the Rules pack for each feature you use. The toolkit supplies rules and tools to inspect them; it does not replace your project's authorization rules.
Can I use Cloud Storage on Firebase's free plan?
The package documentation says Cloud Storage requires the Blaze plan. Other services have their own Firebase project and billing requirements.
Running a different backend?
The same playbook, with full C# source and WebGL support: the Unity Supabase Toolkit for Postgres, Row Level Security and live-ops, and the Unity AWS Toolkit for Cognito, S3, DynamoDB and Lambda.
Trademarks
Firebase and Google Play are trademarks of Google LLC. App Store is a service mark of Apple Inc. This is an independent, third-party integration and is not affiliated with, endorsed by, or sponsored by Google or Apple. "Unity" is a trademark of Unity Technologies.