Two different "tokens" in FCM
Developers new to Firebase Cloud Messaging often mix up two unrelated values that both get called a "token": the access token, which proves who is sending the message, and the device (registration) token, which identifies which app installation should receive it.
What is an FCM access token
An access token is a short-lived OAuth 2.0 bearer token, valid for about an hour, minted from a Firebase service account's private key. It goes in the Authorization: Bearer ... header of the HTTP v1 send request. You never type this token in manually — it is generated by signing a JWT with the service account's private key and exchanging it at Google's OAuth token endpoint for the Firebase Messaging scope.
What is an FCM device (registration) token
A device token is generated on the client by the Firebase Messaging SDK, unique to one app installation on one device. It has nothing to do with authorization — it is simply the address a message is delivered to, and it is the value you paste into the FCM device token field of the tester.
How this tester gets an access token
Instead of a server-side script, the FCM notification tester signs the JWT and requests the access token directly in your browser using the Web Crypto API, from the service account JSON you provide. The private key is never sent anywhere except Google's own OAuth endpoint.
Common access token errors
If Google rejects the token exchange, you will typically see invalid_grant (wrong or revoked service account key) or an UNAUTHENTICATED status on the send itself. See the FCM error codes guide for the full list of what each status means.