FCM access token vs device token

Two different tokens with similar names: one authenticates the sender, the other identifies the recipient.

Two different "tokens" in FCM

Developers new to Firebase Cloud Messaging often mix up two unrelated values that both get called a "token": the access token, which proves who is sending the message, and the device (registration) token, which identifies which app installation should receive it.

What is an FCM access token

An access token is a short-lived OAuth 2.0 bearer token, valid for about an hour, minted from a Firebase service account's private key. It goes in the Authorization: Bearer ... header of the HTTP v1 send request. You never type this token in manually — it is generated by signing a JWT with the service account's private key and exchanging it at Google's OAuth token endpoint for the Firebase Messaging scope.

What is an FCM device (registration) token

A device token is generated on the client by the Firebase Messaging SDK, unique to one app installation on one device. It has nothing to do with authorization — it is simply the address a message is delivered to, and it is the value you paste into the FCM device token field of the tester.

How this tester gets an access token

Instead of a server-side script, the FCM notification tester signs the JWT and requests the access token directly in your browser using the Web Crypto API, from the service account JSON you provide. The private key is never sent anywhere except Google's own OAuth endpoint.

Common access token errors

If Google rejects the token exchange, you will typically see invalid_grant (wrong or revoked service account key) or an UNAUTHENTICATED status on the send itself. See the FCM error codes guide for the full list of what each status means.