Tooliqo templates come with a built-in sign-in tool powered by Firebase. Once it's on, visitors can create an account on your Blogger site in one click, using their Google account or a passwordless sign-in link sent to their email. Signing in unlocks two members-only features: protected download links that only signed-in members can open, and post ratings limited to one vote per member. Setup takes 10–20 minutes, starts free on Firebase's no-cost plan, and requires no changes to your template code.
Which parts do you need?
| What you want | Parts to complete |
|---|---|
| Sign-in only (Google and email link) | Parts 1 and 2 |
| Members-only post ratings | Parts 1, 2, 3 and 5 |
| Protected download links | Parts 1, 2, 3 and 4 |
The newsletter is a separate feature: it runs on Google Sheets and has its own setup guide.
Prefer a shorter, guided version?
The simplified setup guide takes you through the same 14 steps in a compact format, and it's available in six languages.
How the Firebase sign-in tool works
- Firebase Authentication confirms who the visitor is, either through their Google account or with a one-time sign-in link sent to their email. There are no passwords for you to store and none for your visitors to forget.
- Members stay signed in. After signing in, the person icon in your site's header turns into the member's profile photo, and the session survives closed browsers and return visits until the member clicks Sign out.
- Cloud Firestore is a small database inside your Firebase account, where the template keeps protected download links and post ratings. The security rules you publish block anyone who isn't signed in from reading those links or posting a rating, and that check runs on Google's servers, not in the visitor's browser.
- You own the data. Members, links and ratings all live in your own Firebase account, where you can view, export or delete them at any time.
Part 1: Create your Firebase project
Required. Done once per site.
Setting up Firebase for the first time? Keep the simplified setup guide open in another tab and follow it alongside this tutorial.
Open the guideCreate a Firebase project
Open the Firebase console and sign in with the Google account that should own your members' data.
Click Create a project and enter a name that identifies your site. When asked about Google Analytics, turn it off: the sign-in tool doesn't use it. Skip any other optional extras, click Create project, wait a few seconds, then click Continue.
Register a web app and copy four config values
On the project overview page, click the Web icon
</>. If you don't see it, go to:⚙️ Project settings › General › Your apps › Add app › Web
Enter any nickname, leave Firebase Hosting unchecked, and click Register app.
Firebase now shows some setup code. Ignore the
npmandimportinstructions: they're meant for developers, and your template already handles that part. From thefirebaseConfigobject, you only need these four values:apiKey: "AIza…" authDomain: "your-project.firebaseapp.com" projectId: "your-project" appId: "1:…:web:…"
Copy each value without the quotation marks and keep them in a note for Part 2. You can skip the other values, such as
storageBucket, and you can find all of them again later under Project settings › General.Enable Google and email-link sign-in
Security › Authentication › Get started › Sign-in method
In older versions of the Firebase console, Authentication and Firestore are listed under Build.
Google: click Google, switch on Enable, choose your address under Support email, then click Save.
Email link: click Email/Password. Two toggles appear, one above the other:
- Turn on the first toggle, Email/Password.
- Then turn on the second one, Email link (passwordless sign-in).
Click Save.
Don't skip the second toggle
It's the most common setup mistake: the Google button works, but every email sign-in fails with
auth/operation-not-allowed.Add your blog's domain to Authorized domains
Authentication › Settings › Authorized domains › Add domain
Enter your blog's address without
https://and without a trailing slash:my-blog.blogspot.com
If your blog uses a custom domain, add it too, in both forms if you use both:
example.comandwww.example.com. Without this step, sign-ins from your site are rejected withauth/unauthorized-domain.
Part 2: Connect Firebase to your Blogger template
Required. Done from Blogger's Layout page, without opening the HTML editor.
Paste the keys into the Layout widget
Blogger › Layout › “Login Tool — Firebase Keys” › ✎
The widget already contains four rows with the right names. Leave each name unchanged and paste the matching value into its URL field:
Name (keep as is) URL (paste the value here) apiKeyAIza…authDomainyour-project.firebaseapp.comprojectIdyour-projectappId1:…:web:…Three checks that prevent most errors
- A
#means the field is empty: replace it, don't keep it. - No spaces or quotation marks before or after a value.
- A single missing character in
apiKeybreaks the tool, so compare it with the original after pasting.
Save the widget, then save the Layout.
- A
Test both sign-in methods
Open your blog at its live address, not Blogger's preview, and do a hard refresh: Ctrl + F5 on Windows or Cmd + Shift + R on Mac.
- A person icon now appears in your site's header, next to the language icon.
- Click it, then Continue with Google. You're signed in immediately, and the icon turns into your profile photo.
- Sign out, type your email address and click Sign in with a magic link. Open the email you receive and click the link: you land back on your site, signed in.
Two things to know about email sign-in
- Open the link on the same device. The link is meant for the browser that requested it. Opened anywhere else, the site asks for the email address again to confirm. That's standard security behaviour, not an error.
- Every email counts toward a daily limit. On the free Spark plan, Firebase sends at most 5 sign-in link emails per day for your whole project, tests included. See Is Firebase's free plan enough?
Manage members and brand your sign-in emails
Authentication › Users
This table lists every member with their email address, sign-in method, sign-up date and last sign-in. You can disable or delete any account from here.
To brand the sign-in email, open Authentication › Templates: set Sender name to your site's name, enter your address under Reply to, and choose the email language under Template language.
Two limits to know
- Firebase doesn't let you edit the body of the sign-in email. It's a Google safeguard against phishing.
- The first emails may land in the spam folder, so remind your visitors to check it.
Pause the tool without losing anything
In Layout, click the eye icon on the keys widget to hide it. The sign-in icon and window disappear and no Firebase files load, so your page speed is unaffected. Make the widget visible again and everything comes back, with no need to re-enter the keys.
Part 3: Set up the Firestore database
Needed for protected downloads and post ratings. A one-time setup.
Create a Firestore database in production mode
Databases & Storage › Firestore › Create database
Older consoles: Build › Firestore Database › Create database.
- Edition: if the console asks, choose Standard edition.
- Database ID: keep
(default). - Location: pick the one closest to your audience, such as
nam5 (United States)for North America oreur3 (europe-west)for Europe and North Africa. It can't be changed later. - Rules: choose Start in production mode, not test mode.
Why production mode?
Test mode leaves your database open to anyone, then locks it automatically after 30 days, and the tool suddenly stops working. Production mode starts fully locked; in the next step you open exactly what the template needs and nothing more.
Publish the security rules
Firestore › Rules
Delete everything in the editor, paste the full contents of the
firestore-rules.txtfile supplied with your template, and click Publish.How to confirm: the last-published date shows today.
In plain terms, these rules tell Google's servers:
- Download links: only signed-in members can read them, and nobody can change them from your site.
- Ratings: everyone can see them, only signed-in members can submit them, and nobody can rate in someone else's name.
This step is the protection itself
Without it, neither protected downloads nor ratings will work, because production mode refuses every request until the rules are published. Don't write your own rules or copy rules from another site: the supplied file matches exactly what the template expects.
Part 4: Protect download links for members
Optional. For files and links that visitors should sign in to reach.
Each download button or link in your posts can work in one of three modes. You choose per link, and all three can sit in the same post.
Mode 1: Fully protected with Firestore
Best for paid files, templates, private group invites and members-only pages. The real link never appears on your page.
<a class="tq-btn" data-tq-file="my-file">Download</a>The button has no href, only an ID. The real link is stored in Firestore under that ID and is released only to a signed-in member: for anyone else, Google's servers refuse the request before any data is sent. The lock icon and the short Preparing… state are added automatically, so you don't write anything for them.
Mode 2: Members first, with no setup
A quick way to encourage sign-ups, ready to use immediately.
<a class="tq-btn" data-tq-lock href="https://…/file.zip">Download</a>The link stays in your post, and the template asks visitors to sign in before opening it. Be aware: the link is still in the page source, so anyone who views the source (Ctrl + U) can find it. Treat this mode as an incentive, not as protection.
Mode 3: Open to everyone
<a class="tq-btn" href="https://…/file.zip">Free download</a>
| Protected | Members first | Open | |
|---|---|---|---|
| Link in the page source | Hidden | Visible | Visible |
| Who enforces access | Google's servers | The visitor's browser | No one |
| Bypassed by turning off JavaScript? | No | Yes | — |
| Work per link | One Firestore document | None | None |
What visitors see in modes 1 and 2
A small lock appears on the button. When a visitor clicks it, the sign-in window opens, and the download continues automatically once they're signed in, even if they signed in through the email link and came back from their inbox. The lock disappears when they sign in and returns when they sign out.
Each protected link is one small document in Firestore. Steps 11 to 14 show you how to add it.
Create the downloads collection and your first link
Firestore › Data › Start collection
Collection ID: type
downloadsin lowercase, then click Next. On the first-document screen, fill in:Field What to enter Document ID An ID of your choice, such as my-file. Don't click Auto-ID.Field url, in lowercaseType stringValue The full link, starting with https://Click Save, then add a button with the same ID to your post:
<a class="tq-btn" data-tq-file="my-file">Download</a>The ID in the button must match the Document ID exactly, character for character.
Use a direct-download link
The value must open the file directly, not a preview page:
Source What to change Google Drive Turn …/file/d/ID/viewintohttps://drive.google.com/uc?export=download&id=ID, and set sharing to Anyone with the link.Dropbox Change the end of the link from dl=0todl=1.GitHub Use a Releases download link or the file's Raw link. A web page or an invite link Use it as is. This mode works with any link, not just files. The honest limits of protection
Firestore hides the link from anyone who isn't signed in. Once a member opens it, though, they can see the link and share it. Make sure important files can't be found anywhere else, and never publish their link on a public page.
Add more protected links
Don't create the collection again. Open
downloads, click Add document, enter a new ID, add theurlfield and paste the link. It takes about 30 seconds.Faster: open an existing document, choose ⋮ › Duplicate document, and change only the ID and the link.
Naming IDs: use lowercase English letters, numbers and hyphens only, with no spaces or accented characters, for example
seo-guide-2026. To replace a file later, edit theurlvalue in its document: every post that uses that ID updates automatically.Test the protection in a private window
This test is your proof that the gate really works. Open your post in a private window (Ctrl + Shift + N in Chrome or Edge):
- The button shows a small lock, and clicking it opens the sign-in window without downloading anything.
- View the page source (Ctrl + U, or Cmd + Option + U on Mac) and search for your file's link: you shouldn't find it.
- After you sign in, the file downloads automatically.
If the file downloads without signing in, the security rules weren't published. Go back to step 10.
Lock the download, not the article
Gate only the download button and keep your post text public. Hiding the text behind sign-in leaves search engines little to index, or shows them different content from what visitors see, and both can hurt your rankings.
Part 5: Members-only post ratings
Works automatically once Parts 1 to 3 are done. Nothing to add to your posts.
Star ratings appear at the end of every post, along with the average score and the number of votes. Everyone can see the results, but only signed-in members can vote.
What happens when someone clicks a star
| Visitor | What happens |
|---|---|
| Not signed in | The sign-in window opens and nothing is counted. Once signed in, they click a star and their rating is saved. |
| Signed in, hasn't rated yet | The rating is saved instantly, and the average and vote count update on the spot. |
| Signed in, has already rated | Their earlier rating is highlighted and they can change it. No second vote is added: the new rating replaces the first. |
Why ratings require sign-in
- One vote per member: each rating is tied to the member's account, not to the browser, so reloading, switching to a private window or clearing cookies won't allow a second vote.
- Ratings you can trust: bots and passing visitors can't flood your posts with fake votes, because Google's servers reject any rating from someone who isn't signed in.
- A reason to sign up: readers who want to rate a post become members of your site.
Check that ratings work
- In a private window, click a star: the sign-in window should open.
- Sign in and rate: the average and the vote count update.
- Change your rating: the average changes, but the vote count stays the same.
The template creates the rating data in Firestore automatically with the first vote. Don't edit it by hand, except to delete abusive ratings.
What if I pause the sign-in tool?
If you hide the keys widget with the eye icon, the tool stops, and protected downloads and ratings stop with it. Existing ratings stay saved in your Firebase account and return exactly as they were when you turn the tool back on.
Is Firebase's free plan enough?
For most blogs, yes. Firebase's free Spark plan needs no payment card and includes about 50,000 Firestore reads and 20,000 writes per day, enough for thousands of downloads and ratings daily. If you go over on a given day, those operations pause until the quota resets the next day, and you're never charged.
The one limit to plan for: email-link sign-ins
On the Spark plan, Firebase sends at most 5 sign-in link emails per day for your whole project. Google sign-in doesn't send emails, so it isn't affected. If you expect more email sign-ins, upgrade the project to the pay-as-you-go Blaze plan: the limit rises to 25,000 emails per day, the free quotas still apply, and you only pay for usage beyond them. Blaze requires a payment card, so set a budget alert in Google Cloud Billing to stay informed.
You can follow your usage under Firestore › Usage.
Troubleshooting sign-in errors
Most setup problems come from a skipped toggle or a mistyped key. Find what you're seeing in the table below.
| What you see | Cause and fix |
|---|---|
| The sign-in icon doesn't appear | The keys are empty or still contain #, the widget is hidden with the eye icon, or the Layout wasn't saved. Fix it, then hard-refresh the page. |
auth/unauthorized-domain | Your blog's domain isn't in Authorized domains. See step 4. |
auth/invalid-api-key or auth/api-key-not-valid | The apiKey was copied incorrectly. Copy it again with the copy button and paste it in full, without quotation marks. |
auth/operation-not-allowed | A sign-in method isn't enabled, usually the Email link toggle. See step 3. |
auth/quota-exceeded | The Spark plan's limit of 5 sign-in link emails per day has been reached. Sign in with Google, wait for the daily reset, or upgrade to Blaze. See the free plan. |
| The Google window doesn't open | A pop-up blocker is active. The tool switches automatically to a full-page sign-in, so click the button again. |
| The sign-in email didn't arrive | Check the spam folder. If it isn't there, the Email link toggle is off (step 3) or the daily email limit has been reached. |
| It asks to retype the email | The link was opened on a different device or browser. This is normal security behaviour. |
| It asks for a code on the phone | That's 2-Step Verification on the visitor's own Google account, unrelated to the tool. The email-link option doesn't use the Google account at all. |
| “This file is not available” | The data-tq-file ID doesn't match the Document ID, the field isn't named url, or the collection isn't named downloads. |
| The download button doesn't respond | The button probably has an href as well as data-tq-file. Remove the href. |
| The file downloads without signing in | The security rules aren't published. See step 10. |
| Stars don't save a rating after signing in | Firestore wasn't created or the rules aren't published. See steps 9 and 10. |
| “Missing or insufficient permissions” | The published rules aren't the complete firestore-rules.txt file. Clear the editor and paste the whole file again. |
Still stuck? Compare each screen with the simplified setup guide, which covers the same steps in a shorter format.
Open the guideFrequently asked questions
Can I add a login system to Blogger without coding?
Yes. In Tooliqo templates the sign-in tool is already built in: you create a free Firebase project, paste four keys into a Layout widget, and you're done. No template code changes are needed.
Which sign-in methods does the tool support?
Google accounts and passwordless email links. Visitors never create a password, and you never have to store one.
Is it safe to have Firebase keys in my blog's code?
Yes. Firebase web keys are public by design. What protects your data is the authorized-domains list and, above all, the Firestore security rules you publish in step 10.
Is the sign-in tool free to use?
Yes, on Firebase's Spark plan. Its Firestore quotas cover most blogs; the main limit is 5 sign-in link emails per day, which doesn't affect Google sign-in.
Will members-only downloads hurt my SEO?
No, as long as you lock only the download button. Your post text stays public and indexable; only the file link requires sign-in.
Quick setup checklist
- A Firebase project exists, with a web app registered in it.
- Google sign-in is enabled, with a support email.
- Email/Password is enabled, together with the Email link toggle.
- Your blog's domain, and your custom domain if you have one, is listed under Authorized domains.
- The four keys are in the Layout widget with no
#left, and the Layout is saved. - Both Continue with Google and the email link sign you in.
- The sender name under Templates shows your site's name.
- For ratings and protected links: Firestore is created in production mode and the security rules are published.
- For protected links: the
downloadscollection has one document per link with aurlfield, and the private-window test passed. - For ratings: clicking a star in a private window opens the sign-in window.
Ready to set it up?
Open the simplified setup guide in a new tab and work through its 14 steps next to your Firebase console.
