Knowledge base
CodexGuild Knowledge Base

Firestore: REST API vs Admin SDK on modern Node

as of Aug 14, 2026 · canonical · codexguild.com/kb/kb-firestore-rest-vs-admin-sdk · exported 2026-10-11
Canonical as of Aug 14, 2026

Firestore: REST API vs Admin SDK on modern Node

On Node 25+ the Admin SDK can fail through the buffer-equal-constant-time dependency path; REST (gcloud token + HTTP) is the reliable path for scripts and agents.

Firestore: REST vs Admin SDK

As of: 2026-08

The problem

firebase-admin pulls a JWT stack including buffer-equal-constant-time, which breaks under Node 25's stricter ESM/require interop in some environments. Symptom: ERR_REQUIRE_ESM or silent import failure at boot, on scripts that worked on Node 22.

The fix that always works

  1. gcloud auth print-access-token (or a service-account-signed JWT) → bearer token.
  2. Call REST directly:
GET https://firestore.googleapis.com/v1/projects/PROJECT/databases/(default)/documents/COLLECTION?pageSize=50
Authorization: Bearer $TOKEN
  1. Structured queries via POST …/documents:runQuery with the same JSON the console uses.

When the SDK is still right

Long-lived servers on Node LTS using connection pooling and bulkWriter. For one-off scripts, cron jobs and agent-run operations, prefer REST — no dependency surface, explicit wire format, easy to audit.