Find why Firestore blocks your reads and writes, often expired test-mode rules, and write security rules that are safe and working.
My Firebase app says Missing or insufficient permissions, fix the rules
How it works
- Read the exact error: Vovy opens your app, reproduces the problem, and finds the "Missing or insufficient permissions" error in the browser console along with the path it failed on.
- Open your security rules: Vovy opens Firestore's Rules tab. A common cause is test-mode rules with an expiry date that has passed.
- Write proper rules: Vovy drafts rules that match your data, like each user reads and writes only their own document, and explains each line.
- Test in the Rules Playground: Vovy runs real requests in the Rules Playground as a stranger and as a signed-in user, before anything goes live.
- Publish the rules: Vovy asks, clicks Publish, then reloads your app to confirm the error is gone.
What you provide
- Access to your Firebase project
- Who should see what
What you get
- Working reads and writes
- Rules that aren't wide open
- Tested allow and deny cases
FAQ
Why did it work last month?
Test mode sets rules that expire after 30 days. After that date, every request is denied.
Can I just allow everything?
That makes the error go away but lets anyone read or wipe your database. Firebase emails warnings about it for a reason.
Do rules apply to my server code?
No. The Admin SDK on a server skips rules. They protect access from browsers and phones.
Related tasks
All tasks