E-Mail and Password authentication: User Registration, Manage Login/Logout, Password Reset and E-Mail verification

Email and password authentication is the full account lifecycle: register a user, log them in and out, let them reset a forgotten password, and verify their email address, all through FirebaseAuth methods.

11 min read · 7 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

The whole life of an account

A real app does not just log users in. Over an account's life it must register new users, log them in and out, help them when they forget their password, and confirm they actually own their email address. Firebase Authentication provides a method for each, so you get the full lifecycle without building any of it yourself.

This lesson walks through email and password authentication end to end: registration, login, logout, password reset, and email verification. These are the everyday auth features FestConnect Mobile needs.

Theory

Register, log in, log out

The three basics you met with the SDK:

  • Register: createUserWithEmailAndPassword(email, password) creates the account (and signs the user in on success).
  • Log in: signInWithEmailAndPassword(email, password) for an existing user.
  • Log out: auth.signOut() ends the session, after which auth.currentUser is null.

Each networked call returns a Task you handle with a listener. With just these three, a user can create an account and come and go. But two more features make the experience complete and secure: resetting a forgotten password and verifying the email.

Practical

Password reset and email verification

val auth = Firebase.auth

// Password reset: Firebase emails a reset link to the address
auth.sendPasswordResetEmail(email)
    .addOnCompleteListener { task ->
        if (task.isSuccessful) { /* tell user to check their inbox */ }
    }

// Email verification: send a verification link to the signed-in user
auth.currentUser?.sendEmailVerification()

// Later, check whether they have verified:
val verified = auth.currentUser?.isEmailVerified ?: false

Formula

Firebase handles passwords; you never do

Notice what you do NOT do: you never store passwords, and you never reset them yourself. When a user forgets their password, you call sendPasswordResetEmail, and Firebase emails them a secure reset link; the user sets a new password through Firebase, not through your code.

Similarly, email verification is Firebase emailing a confirmation link; you just trigger it and later check isEmailVerified. This is a security win: sensitive credential handling stays inside Firebase's trusted system, so your app never touches raw passwords or builds risky reset flows. Trigger the feature, let Firebase do the sensitive part.

Quiz

A FestConnect user forgot their password. What is the correct Firebase approach?

  1. Read their old password from the database and show it to them
  2. Call auth.sendPasswordResetEmail(email); Firebase emails them a secure link to set a new password
  3. Ask them to create a whole new account
  4. Store passwords in plain text so you can look them up
Show the answer

Call auth.sendPasswordResetEmail(email); Firebase emails them a secure link to set a new password

The correct approach is auth.sendPasswordResetEmail(email): Firebase sends the user a secure link by email, through which they set a new password, all handled by Firebase, so your app never touches the password. Option A is impossible and insecure: Firebase does not store passwords in a readable form (they are securely hashed), so there is no 'old password' to show, and showing passwords would be a serious security flaw. Option C is unnecessary and bad UX: resetting the password keeps their existing account and data. Option D is a dangerous anti-pattern; never store passwords in plain text. Let Firebase handle credentials: trigger the reset email, and it does the rest securely.

Think first

Why bother verifying a user's email address?

The user already registered with an email. Why send a verification link and check isEmailVerified? Then tap.

Show the answer

Because registering with an email does NOT prove the user actually OWNS that address, and email verification is how you confirm they do, which matters for security, communication, and trust. When someone signs up, they can type any email, including one that is mistyped, or one belonging to someone else. Without verification, you might have accounts tied to addresses their owners never see: password-reset emails would go to the wrong place, important notifications would be lost, and a malicious user could register under someone else's email. Email verification closes this gap: Firebase emails a unique link to the address given, and only someone with access to that inbox can click it, proving ownership. Your app then checks isEmailVerified and can decide what unverified users may do, perhaps letting them browse but requiring verification before registering for an event or receiving notices. This protects the real owner of the address, ensures your emails reach a valid inbox, and reduces fake or mistaken accounts. It is a small step with big payoffs in reliability and security, which is why serious apps verify emails as part of onboarding. And, as with password reset, Firebase does the sensitive part, sending and validating the link, so you just trigger it and check the flag. Proving ownership of the address is the point; a typed email is only a claim until verified.

Summary

Key takeaways

  • Email/password authentication covers the whole account lifecycle through FirebaseAuth methods.
  • Register with createUserWithEmailAndPassword; log in with signInWithEmailAndPassword; log out with signOut().
  • Password reset: call sendPasswordResetEmail(email), and Firebase emails a secure reset link; you never store or reset passwords yourself.
  • Email verification: call currentUser.sendEmailVerification(), then check currentUser.isEmailVerified.
  • Firebase handles the sensitive credential work, keeping raw passwords out of your app.
  • Email verification confirms the user actually owns the address, improving security and reliable communication.
  • Memory hook: create, signIn, signOut, sendPasswordResetEmail, sendEmailVerification, Firebase does the risky parts.

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from FirebaseUI Auth authentication

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

E-Mail and Password authentication: User Registration, Manage Login/Logout, Password Reset and E-Mail verification · Advance Mobile Application Development - II (Major-15-02) · Gri-Learn