enabled: true url: https://www.google.com/preferences/source title: subtitle: button: where: post
ca-pub-1234567890123456
title: Biz Pro Reimagined text: Biz Pro – Built for Business. Designed to Impress. link: /2026/09/biz-pro-free.html button: icon: fa-solid fa-arrow-up-right-from-square style: outline badge: tlq-badge-bell-ring button2: link2: icon2:

Firebase Sign-in Tool for Tooliqo Blogger Templates

Tooliqo templates come with a built-in sign-in tool powered by Firebase. Once it's on, visitors can create an account on your Blogger site in one click, using their Google account or a passwordless sign-in link sent to their email. Signing in unlocks two members-only features: protected download links that only signed-in members can open, and post ratings limited to one vote per member. Setup takes 10–20 minutes, starts free on Firebase's no-cost plan, and requires no changes to your template code.

Sign-in buttonGoogle or email link
FirebaseAuthentication + Firestore
Member list
Protected downloads
Post ratings ★
One sign-in connects the visitor to Firebase, which powers your member list, protected downloads and members-only ratings.
Setup time10–20 minutes
CostFree (Spark plan)
Template code editsNone
What you needA Google account

Which parts do you need?

What you wantParts to complete
Sign-in only (Google and email link)Parts 1 and 2
Members-only post ratingsParts 1, 2, 3 and 5
Protected download linksParts 1, 2, 3 and 4

The newsletter is a separate feature: it runs on Google Sheets and has its own setup guide.

14steps

Prefer a shorter, guided version?

The simplified setup guide takes you through the same 14 steps in a compact format, and it's available in six languages.

Open the setup guide
Firebase sign-in for Blogger in Tooliqo templates, with Google and email-link login

How the Firebase sign-in tool works

  • Firebase Authentication confirms who the visitor is, either through their Google account or with a one-time sign-in link sent to their email. There are no passwords for you to store and none for your visitors to forget.
  • Members stay signed in. After signing in, the person icon in your site's header turns into the member's profile photo, and the session survives closed browsers and return visits until the member clicks Sign out.
  • Cloud Firestore is a small database inside your Firebase account, where the template keeps protected download links and post ratings. The security rules you publish block anyone who isn't signed in from reading those links or posting a rating, and that check runs on Google's servers, not in the visitor's browser.
  • You own the data. Members, links and ratings all live in your own Firebase account, where you can view, export or delete them at any time.

Part 1: Create your Firebase project

Required. Done once per site.

Setting up Firebase for the first time? Keep the simplified setup guide open in another tab and follow it alongside this tutorial.

Open the guide
  1. Create a Firebase project

    Open the Firebase console and sign in with the Google account that should own your members' data.

    Click Create a project and enter a name that identifies your site. When asked about Google Analytics, turn it off: the sign-in tool doesn't use it. Skip any other optional extras, click Create project, wait a few seconds, then click Continue.

  2. Register a web app and copy four config values

    On the project overview page, click the Web icon </>. If you don't see it, go to:

    ⚙️ Project settings › General › Your apps › Add app › Web

    Enter any nickname, leave Firebase Hosting unchecked, and click Register app.

    Firebase now shows some setup code. Ignore the npm and import instructions: they're meant for developers, and your template already handles that part. From the firebaseConfig object, you only need these four values:

    apiKey:     "AIza…"
    authDomain: "your-project.firebaseapp.com"
    projectId:  "your-project"
    appId:      "1:…:web:…"

    Copy each value without the quotation marks and keep them in a note for Part 2. You can skip the other values, such as storageBucket, and you can find all of them again later under Project settings › General.

    Are these keys secret?

    No. Firebase web config values are public by design and appear in the source code of every site that uses Firebase. Your real protection comes from the authorized-domains list (step 4) and, above all, the Firestore security rules (step 10).

  3. Enable Google and email-link sign-in

    Security › Authentication › Get started › Sign-in method

    In older versions of the Firebase console, Authentication and Firestore are listed under Build.

    Google: click Google, switch on Enable, choose your address under Support email, then click Save.

    Email link: click Email/Password. Two toggles appear, one above the other:

    • Turn on the first toggle, Email/Password.
    • Then turn on the second one, Email link (passwordless sign-in).

    Click Save.

    Don't skip the second toggle

    It's the most common setup mistake: the Google button works, but every email sign-in fails with auth/operation-not-allowed.

  4. Add your blog's domain to Authorized domains

    Authentication › Settings › Authorized domains › Add domain

    Enter your blog's address without https:// and without a trailing slash:

    my-blog.blogspot.com

    If your blog uses a custom domain, add it too, in both forms if you use both: example.com and www.example.com. Without this step, sign-ins from your site are rejected with auth/unauthorized-domain.

Part 2: Connect Firebase to your Blogger template

Required. Done from Blogger's Layout page, without opening the HTML editor.

  1. Paste the keys into the Layout widget

    Blogger › Layout › “Login Tool — Firebase Keys” › ✎

    The widget already contains four rows with the right names. Leave each name unchanged and paste the matching value into its URL field:

    Name (keep as is)URL (paste the value here)
    apiKeyAIza…
    authDomainyour-project.firebaseapp.com
    projectIdyour-project
    appId1:…:web:…

    Three checks that prevent most errors

    • A # means the field is empty: replace it, don't keep it.
    • No spaces or quotation marks before or after a value.
    • A single missing character in apiKey breaks the tool, so compare it with the original after pasting.

    Save the widget, then save the Layout.

  2. Test both sign-in methods

    Open your blog at its live address, not Blogger's preview, and do a hard refresh: Ctrl + F5 on Windows or Cmd + Shift + R on Mac.

    • A person icon now appears in your site's header, next to the language icon.
    • Click it, then Continue with Google. You're signed in immediately, and the icon turns into your profile photo.
    • Sign out, type your email address and click Sign in with a magic link. Open the email you receive and click the link: you land back on your site, signed in.

    Two things to know about email sign-in

    • Open the link on the same device. The link is meant for the browser that requested it. Opened anywhere else, the site asks for the email address again to confirm. That's standard security behaviour, not an error.
    • Every email counts toward a daily limit. On the free Spark plan, Firebase sends at most 5 sign-in link emails per day for your whole project, tests included. See Is Firebase's free plan enough?
  3. Manage members and brand your sign-in emails

    Authentication › Users

    This table lists every member with their email address, sign-in method, sign-up date and last sign-in. You can disable or delete any account from here.

    To brand the sign-in email, open Authentication › Templates: set Sender name to your site's name, enter your address under Reply to, and choose the email language under Template language.

    Two limits to know

    • Firebase doesn't let you edit the body of the sign-in email. It's a Google safeguard against phishing.
    • The first emails may land in the spam folder, so remind your visitors to check it.
  4. Pause the tool without losing anything

    In Layout, click the eye icon on the keys widget to hide it. The sign-in icon and window disappear and no Firebase files load, so your page speed is unaffected. Make the widget visible again and everything comes back, with no need to re-enter the keys.

Part 3: Set up the Firestore database

Needed for protected downloads and post ratings. A one-time setup.

  1. Create a Firestore database in production mode

    Databases & Storage › Firestore › Create database

    Older consoles: Build › Firestore Database › Create database.

    • Edition: if the console asks, choose Standard edition.
    • Database ID: keep (default).
    • Location: pick the one closest to your audience, such as nam5 (United States) for North America or eur3 (europe-west) for Europe and North Africa. It can't be changed later.
    • Rules: choose Start in production mode, not test mode.

    Why production mode?

    Test mode leaves your database open to anyone, then locks it automatically after 30 days, and the tool suddenly stops working. Production mode starts fully locked; in the next step you open exactly what the template needs and nothing more.

  2. Publish the security rules

    Firestore › Rules

    Delete everything in the editor, paste the full contents of the firestore-rules.txt file supplied with your template, and click Publish.

    How to confirm: the last-published date shows today.

    In plain terms, these rules tell Google's servers:

    • Download links: only signed-in members can read them, and nobody can change them from your site.
    • Ratings: everyone can see them, only signed-in members can submit them, and nobody can rate in someone else's name.

    This step is the protection itself

    Without it, neither protected downloads nor ratings will work, because production mode refuses every request until the rules are published. Don't write your own rules or copy rules from another site: the supplied file matches exactly what the template expects.

Part 4: Protect download links for members

Optional. For files and links that visitors should sign in to reach.

Each download button or link in your posts can work in one of three modes. You choose per link, and all three can sit in the same post.

Mode 1: Fully protected with Firestore

Best for paid files, templates, private group invites and members-only pages. The real link never appears on your page.

<a class="tq-btn" data-tq-file="my-file">Download</a>

The button has no href, only an ID. The real link is stored in Firestore under that ID and is released only to a signed-in member: for anyone else, Google's servers refuse the request before any data is sent. The lock icon and the short Preparing… state are added automatically, so you don't write anything for them.

Mode 2: Members first, with no setup

A quick way to encourage sign-ups, ready to use immediately.

<a class="tq-btn" data-tq-lock href="https://…/file.zip">Download</a>

The link stays in your post, and the template asks visitors to sign in before opening it. Be aware: the link is still in the page source, so anyone who views the source (Ctrl + U) can find it. Treat this mode as an incentive, not as protection.

Mode 3: Open to everyone

<a class="tq-btn" href="https://…/file.zip">Free download</a>
 ProtectedMembers firstOpen
Link in the page sourceHiddenVisibleVisible
Who enforces accessGoogle's serversThe visitor's browserNo one
Bypassed by turning off JavaScript?NoYes—
Work per linkOne Firestore documentNoneNone

What visitors see in modes 1 and 2

A small lock appears on the button. When a visitor clicks it, the sign-in window opens, and the download continues automatically once they're signed in, even if they signed in through the email link and came back from their inbox. The lock disappears when they sign in and returns when they sign out.

Each protected link is one small document in Firestore. Steps 11 to 14 show you how to add it.

  1. Create the downloads collection and your first link

    Firestore › Data › Start collection

    Collection ID: type downloads in lowercase, then click Next. On the first-document screen, fill in:

    FieldWhat to enter
    Document IDAn ID of your choice, such as my-file. Don't click Auto-ID.
    Fieldurl, in lowercase
    Typestring
    ValueThe full link, starting with https://

    Click Save, then add a button with the same ID to your post:

    <a class="tq-btn" data-tq-file="my-file">Download</a>

    The ID in the button must match the Document ID exactly, character for character.

  2. Use a direct-download link

    The value must open the file directly, not a preview page:

    SourceWhat to change
    Google DriveTurn …/file/d/ID/view into https://drive.google.com/uc?export=download&id=ID, and set sharing to Anyone with the link.
    DropboxChange the end of the link from dl=0 to dl=1.
    GitHubUse a Releases download link or the file's Raw link.
    A web page or an invite linkUse it as is. This mode works with any link, not just files.

    The honest limits of protection

    Firestore hides the link from anyone who isn't signed in. Once a member opens it, though, they can see the link and share it. Make sure important files can't be found anywhere else, and never publish their link on a public page.

  3. Add more protected links

    Don't create the collection again. Open downloads, click Add document, enter a new ID, add the url field and paste the link. It takes about 30 seconds.

    Faster: open an existing document, choose ⋮ › Duplicate document, and change only the ID and the link.

    Naming IDs: use lowercase English letters, numbers and hyphens only, with no spaces or accented characters, for example seo-guide-2026. To replace a file later, edit the url value in its document: every post that uses that ID updates automatically.

  4. Test the protection in a private window

    This test is your proof that the gate really works. Open your post in a private window (Ctrl + Shift + N in Chrome or Edge):

    • The button shows a small lock, and clicking it opens the sign-in window without downloading anything.
    • View the page source (Ctrl + U, or Cmd + Option + U on Mac) and search for your file's link: you shouldn't find it.
    • After you sign in, the file downloads automatically.

    If the file downloads without signing in, the security rules weren't published. Go back to step 10.

Lock the download, not the article

Gate only the download button and keep your post text public. Hiding the text behind sign-in leaves search engines little to index, or shows them different content from what visitors see, and both can hurt your rankings.

Part 5: Members-only post ratings

Works automatically once Parts 1 to 3 are done. Nothing to add to your posts.

Star ratings appear at the end of every post, along with the average score and the number of votes. Everyone can see the results, but only signed-in members can vote.

What happens when someone clicks a star

VisitorWhat happens
Not signed inThe sign-in window opens and nothing is counted. Once signed in, they click a star and their rating is saved.
Signed in, hasn't rated yetThe rating is saved instantly, and the average and vote count update on the spot.
Signed in, has already ratedTheir earlier rating is highlighted and they can change it. No second vote is added: the new rating replaces the first.

Why ratings require sign-in

  • One vote per member: each rating is tied to the member's account, not to the browser, so reloading, switching to a private window or clearing cookies won't allow a second vote.
  • Ratings you can trust: bots and passing visitors can't flood your posts with fake votes, because Google's servers reject any rating from someone who isn't signed in.
  • A reason to sign up: readers who want to rate a post become members of your site.

Check that ratings work

  • In a private window, click a star: the sign-in window should open.
  • Sign in and rate: the average and the vote count update.
  • Change your rating: the average changes, but the vote count stays the same.

The template creates the rating data in Firestore automatically with the first vote. Don't edit it by hand, except to delete abusive ratings.

What if I pause the sign-in tool?

If you hide the keys widget with the eye icon, the tool stops, and protected downloads and ratings stop with it. Existing ratings stay saved in your Firebase account and return exactly as they were when you turn the tool back on.

Is Firebase's free plan enough?

For most blogs, yes. Firebase's free Spark plan needs no payment card and includes about 50,000 Firestore reads and 20,000 writes per day, enough for thousands of downloads and ratings daily. If you go over on a given day, those operations pause until the quota resets the next day, and you're never charged.

The one limit to plan for: email-link sign-ins

On the Spark plan, Firebase sends at most 5 sign-in link emails per day for your whole project. Google sign-in doesn't send emails, so it isn't affected. If you expect more email sign-ins, upgrade the project to the pay-as-you-go Blaze plan: the limit rises to 25,000 emails per day, the free quotas still apply, and you only pay for usage beyond them. Blaze requires a payment card, so set a budget alert in Google Cloud Billing to stay informed.

You can follow your usage under Firestore › Usage.

Troubleshooting sign-in errors

Most setup problems come from a skipped toggle or a mistyped key. Find what you're seeing in the table below.

What you seeCause and fix
The sign-in icon doesn't appearThe keys are empty or still contain #, the widget is hidden with the eye icon, or the Layout wasn't saved. Fix it, then hard-refresh the page.
auth/unauthorized-domainYour blog's domain isn't in Authorized domains. See step 4.
auth/invalid-api-key or auth/api-key-not-validThe apiKey was copied incorrectly. Copy it again with the copy button and paste it in full, without quotation marks.
auth/operation-not-allowedA sign-in method isn't enabled, usually the Email link toggle. See step 3.
auth/quota-exceededThe Spark plan's limit of 5 sign-in link emails per day has been reached. Sign in with Google, wait for the daily reset, or upgrade to Blaze. See the free plan.
The Google window doesn't openA pop-up blocker is active. The tool switches automatically to a full-page sign-in, so click the button again.
The sign-in email didn't arriveCheck the spam folder. If it isn't there, the Email link toggle is off (step 3) or the daily email limit has been reached.
It asks to retype the emailThe link was opened on a different device or browser. This is normal security behaviour.
It asks for a code on the phoneThat's 2-Step Verification on the visitor's own Google account, unrelated to the tool. The email-link option doesn't use the Google account at all.
“This file is not available”The data-tq-file ID doesn't match the Document ID, the field isn't named url, or the collection isn't named downloads.
The download button doesn't respondThe button probably has an href as well as data-tq-file. Remove the href.
The file downloads without signing inThe security rules aren't published. See step 10.
Stars don't save a rating after signing inFirestore wasn't created or the rules aren't published. See steps 9 and 10.
“Missing or insufficient permissions”The published rules aren't the complete firestore-rules.txt file. Clear the editor and paste the whole file again.

Still stuck? Compare each screen with the simplified setup guide, which covers the same steps in a shorter format.

Open the guide

Frequently asked questions

Can I add a login system to Blogger without coding?

Yes. In Tooliqo templates the sign-in tool is already built in: you create a free Firebase project, paste four keys into a Layout widget, and you're done. No template code changes are needed.

Which sign-in methods does the tool support?

Google accounts and passwordless email links. Visitors never create a password, and you never have to store one.

Is it safe to have Firebase keys in my blog's code?

Yes. Firebase web keys are public by design. What protects your data is the authorized-domains list and, above all, the Firestore security rules you publish in step 10.

Is the sign-in tool free to use?

Yes, on Firebase's Spark plan. Its Firestore quotas cover most blogs; the main limit is 5 sign-in link emails per day, which doesn't affect Google sign-in.

Will members-only downloads hurt my SEO?

No, as long as you lock only the download button. Your post text stays public and indexable; only the file link requires sign-in.

Quick setup checklist

  1. A Firebase project exists, with a web app registered in it.
  2. Google sign-in is enabled, with a support email.
  3. Email/Password is enabled, together with the Email link toggle.
  4. Your blog's domain, and your custom domain if you have one, is listed under Authorized domains.
  5. The four keys are in the Layout widget with no # left, and the Layout is saved.
  6. Both Continue with Google and the email link sign you in.
  7. The sender name under Templates shows your site's name.
  8. For ratings and protected links: Firestore is created in production mode and the security rules are published.
  9. For protected links: the downloads collection has one document per link with a url field, and the private-window test passed.
  10. For ratings: clicking a star in a private window opens the sign-in window.
14steps

Ready to set it up?

Open the simplified setup guide in a new tab and work through its 14 steps next to your Firebase console.

Start the setup guide
َAdmin
Written by َAdmin

As a digital content enthusiast, I dedicate myself to sharing my personal insights and documenting the knowledge I gain from the web. My goal is to create valuable, purpose-driven content that informs, inspires, and delivers real benefits to others.