Start watching free

Error library · Firebase refuses a read or write

FirebaseError: Missing or insufficient permissions

Your Firebase database refused something the app tried to read or save. Firebase has security rules that decide who may touch which data, and they don't allow this request, so it fails.

Who it affects

People doing this see it fail or see nothing load — 5 sessions so far.

Numbers here are from an example app where 5 visitors hit it. How serious: High — an important part of the app is broken for some people.

How to fix it

Give this to the AI that builds your app. It’s the prompt Vigilia writes for this error — shown here for an example app (an orders table, a /checkout page); for your app, Vigilia fills in the real details from what your visitors hit.

For Lovable
Lovable: Bug: Firebase rejects a read or write with "Missing or insufficient permissions".

Evidence: "FirebaseError: Missing or insufficient permissions." — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Find the read or write that fails (the page is /checkout) and the collection or path it touches.
2. Update the Firebase security rules (firestore.rules / storage rules) so signed-in users can do exactly that on the data they own, e.g. allow it when request.auth.uid matches the document's owner field.
3. Do not open the rules to everyone (no "allow read, write: if true").
4. Check the user is actually signed in before the request runs, and show a clear message if the rules refuse it.

Acceptance criteria: a signed-in user can do this with their own data, others still can't, and there are no more permission-denied errors on /checkout.
For Bolt
Bolt: Bug: Firebase rejects a read or write with "Missing or insufficient permissions".

Evidence: "FirebaseError: Missing or insufficient permissions." — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Find the read or write that fails (the page is /checkout) and the collection or path it touches.
2. Update the Firebase security rules (firestore.rules / storage rules) so signed-in users can do exactly that on the data they own, e.g. allow it when request.auth.uid matches the document's owner field.
3. Do not open the rules to everyone (no "allow read, write: if true").
4. Check the user is actually signed in before the request runs, and show a clear message if the rules refuse it.

Acceptance criteria: a signed-in user can do this with their own data, others still can't, and there are no more permission-denied errors on /checkout.
For Cursor
Cursor: Bug: Firebase rejects a read or write with "Missing or insufficient permissions".

Evidence: "FirebaseError: Missing or insufficient permissions." — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Find the read or write that fails (the page is /checkout) and the collection or path it touches.
2. Update the Firebase security rules (firestore.rules / storage rules) so signed-in users can do exactly that on the data they own, e.g. allow it when request.auth.uid matches the document's owner field.
3. Do not open the rules to everyone (no "allow read, write: if true").
4. Check the user is actually signed in before the request runs, and show a clear message if the rules refuse it.

Acceptance criteria: a signed-in user can do this with their own data, others still can't, and there are no more permission-denied errors on /checkout.
For Claude Code
Claude Code: Bug: Firebase rejects a read or write with "Missing or insufficient permissions".

Evidence: "FirebaseError: Missing or insufficient permissions." — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Find the read or write that fails (the page is /checkout) and the collection or path it touches.
2. Update the Firebase security rules (firestore.rules / storage rules) so signed-in users can do exactly that on the data they own, e.g. allow it when request.auth.uid matches the document's owner field.
3. Do not open the rules to everyone (no "allow read, write: if true").
4. Check the user is actually signed in before the request runs, and show a clear message if the rules refuse it.

Acceptance criteria: a signed-in user can do this with their own data, others still can't, and there are no more permission-denied errors on /checkout.
For any other tool
Bug: Firebase rejects a read or write with "Missing or insufficient permissions".

Evidence: "FirebaseError: Missing or insufficient permissions." — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Find the read or write that fails (the page is /checkout) and the collection or path it touches.
2. Update the Firebase security rules (firestore.rules / storage rules) so signed-in users can do exactly that on the data they own, e.g. allow it when request.auth.uid matches the document's owner field.
3. Do not open the rules to everyone (no "allow read, write: if true").
4. Check the user is actually signed in before the request runs, and show a clear message if the rules refuse it.

Acceptance criteria: a signed-in user can do this with their own data, others still can't, and there are no more permission-denied errors on /checkout.

Vigilia catches this automatically

When this happens on your live app, Vigilia recognises it at once — no waiting, no AI credits — tells you who it affects, hands your AI the fix, and confirms it held with real visitors.

More errors, explained