Firebase를 사용한 이메일 및 전화번호 인증
이메일과 비밀번호를 사용한 가입 및 로그인을 구현하고, SMS OTP를 사용한 전화번호 인증을 추가하며, onAuthStateChanged 관찰자를 수신하여 내비게이션 접근을 제어합니다.
Firebase를 사용한 이메일 및 전화번호 인증은(는) CoddyKit의 무료 React Native Academy 강의입니다. 이것은 4개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 React Native Academy 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. React Native Academy 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
Firebase Auth Overview
Firebase Authentication provides ready-made sign-in flows for email/password, phone OTP, and social providers like Google and Apple. All authentication methods are accessed through the auth() singleton from @react-native-firebase/auth.
Firebase Auth manages tokens, refreshes them automatically, and persists the user session in native storage. The onAuthStateChanged observer is the single source of truth for authentication state in your app — always drive navigation from this callback rather than from individual sign-in function results.
Listening to Auth State Changes
Register an onAuthStateChanged observer early in your app's lifecycle, typically in the root layout component. It fires once with the current user on mount, and again whenever the user signs in or out.
The observer returns an unsubscribe function — always call it in the useEffect cleanup to prevent memory leaks. The observer's user parameter is null when no one is signed in and a FirebaseAuthTypes.User object when authenticated.
import auth from '@react-native-firebase/auth';
import { useEffect, useState } from 'react';
export function useFirebaseAuth() {
const [user, setUser] = useState(null);
const [initializing, setInitializing] = useState(true);
useEffect(() => {
const unsubscribe = auth().onAuthStateChanged((user) => {
setUser(user);
if (initializing) setInitializing(false);
});
return unsubscribe; // auto-cleanup on unmount
}, []);
return { user, initializing };
}Email and Password Sign-Up
To register a new user with email and password, call auth().createUserWithEmailAndPassword(email, password). Firebase validates the email format and enforces the minimum password length (6 characters by default) on the server.
After successful sign-up, Firebase automatically signs in the new user — the onAuthStateChanged observer fires immediately with the new user object. You can then prompt the user to verify their email by calling user.sendEmailVerification().
import auth from '@react-native-firebase/auth';
async function signUpWithEmail(email: string, password: string) {
try {
const { user } = await auth().createUserWithEmailAndPassword(email, password);
await user.sendEmailVerification();
console.log('Sign-up successful, verification email sent to', email);
} catch (error: any) {
if (error.code === 'auth/email-already-in-use') {
Alert.alert('Error', 'That email address is already in use.');
} else if (error.code === 'auth/invalid-email') {
Alert.alert('Error', 'That email address is invalid.');
}
}
}Email and Password Sign-In
Returning users sign in with auth().signInWithEmailAndPassword(email, password). This returns a UserCredential object, but in most cases you do not need to handle the return value — the onAuthStateChanged observer already handles navigation.
Wrap sign-in calls in a try/catch and check the error.code property to display user-friendly messages. Firebase uses error codes like auth/wrong-password and auth/user-not-found that you can map to readable messages.
async function signInWithEmail(email: string, password: string) {
try {
await auth().signInWithEmailAndPassword(email, password);
// onAuthStateChanged will fire and handle navigation
} catch (error: any) {
const messages: Record<string, string> = {
'auth/wrong-password': 'Incorrect password.',
'auth/user-not-found': 'No account found with this email.',
'auth/too-many-requests': 'Too many failed attempts. Try again later.',
};
Alert.alert('Sign In Failed', messages[error.code] ?? 'An error occurred.');
}
}Signing Out
Call auth().signOut() to sign out the current user. This clears the local session and triggers onAuthStateChanged with null. If you are driving navigation from the observer, the app will automatically redirect to the sign-in screen.
Sign out is synchronous in behavior but returns a Promise that resolves when the local session is cleared. You do not need to await it unless you want to confirm completion before performing additional actions.
async function handleSignOut() {
try {
await auth().signOut();
// onAuthStateChanged fires with null, navigator switches to auth stack
} catch (error) {
console.error('Sign out error:', error);
}
}Phone Authentication Overview
Firebase Phone Authentication works by sending a one-time SMS code to the user's phone number and verifying it. The flow has two steps: (1) call signInWithPhoneNumber to trigger the SMS, and (2) confirm the code the user enters.
On iOS, Firebase may silently verify the phone using APNs silent push notifications, bypassing the manual code entry step for known devices. This requires Push Notification capability in your app. On Android, Firebase uses the Play Integrity API to auto-verify codes on trusted devices.
Step 1: Sending the SMS Code
Call auth().signInWithPhoneNumber(phoneNumber) where phoneNumber is in E.164 format (e.g., +14155552671). The method returns a confirmation object that you store in state to use in the second step.
Show a UI that asks the user to enter the 6-digit code they receive via SMS. Use a numeric TextInput with keyboardType='number-pad' and maxLength={6} for a clean code entry experience.
import auth from '@react-native-firebase/auth';
import { useState } from 'react';
export function PhoneAuthScreen() {
const [phoneNumber, setPhoneNumber] = useState('');
const [confirmation, setConfirmation] = useState(null);
async function sendCode() {
try {
const confirm = await auth().signInWithPhoneNumber(phoneNumber);
setConfirmation(confirm);
// Now show the code entry screen
} catch (error) {
Alert.alert('Error', 'Failed to send verification code.');
}
}
// ...
}Step 2: Confirming the Code
When the user enters the SMS code, call confirmation.confirm(code). If the code is correct, Firebase signs in the user and onAuthStateChanged fires with the authenticated user. If the code is wrong, the method throws with code auth/invalid-verification-code.
Each confirmation object can only be used once. If the code expires or the user requests a new one, you must call signInWithPhoneNumber again to get a new confirmation object.
async function confirmCode(code: string) {
try {
await confirmation.confirm(code);
// User is now signed in, onAuthStateChanged fires
} catch (error: any) {
if (error.code === 'auth/invalid-verification-code') {
Alert.alert('Error', 'The code you entered is incorrect.');
} else if (error.code === 'auth/code-expired') {
Alert.alert('Code Expired', 'Please request a new code.');
setConfirmation(null); // Reset to phone number entry
}
}
}Updating User Profile
After sign-up, you can update the user's display name and photo URL using auth().currentUser.updateProfile(). This stores the data directly on the Firebase Auth user object, making it available without a separate database query.
However, for rich user profiles (bio, address, etc.), it is better to store additional data in Firestore under a users collection, using the user's UID as the document ID. The Auth profile is for core identity data only.
async function updateUserProfile(displayName: string, photoURL: string) {
const user = auth().currentUser;
if (!user) return;
await user.updateProfile({ displayName, photoURL });
console.log('Profile updated:', auth().currentUser?.displayName);
}
// Also save extended data to Firestore:
await firestore().collection('users').doc(user.uid).set({
displayName,
bio: '',
createdAt: firestore.FieldValue.serverTimestamp(),
});Password Reset via Email
If a user forgets their password, call auth().sendPasswordResetEmail(email). Firebase sends an email with a link to reset their password. The link opens a Firebase-hosted web page where the user can enter a new password.
This flow does not require any additional native setup. The link is not a deep link into your app — it goes to Firebase's hosted page. If you want the reset flow to open inside your app, configure the Action URL in Firebase Authentication settings to point to your app's domain with dynamic links.
async function sendPasswordReset(email: string) {
try {
await auth().sendPasswordResetEmail(email);
Alert.alert(
'Email Sent',
'Check your inbox for a link to reset your password.'
);
} catch (error: any) {
if (error.code === 'auth/user-not-found') {
// For security, show the same message even if the email is not found
Alert.alert('Email Sent', 'If this email is registered, you will receive a reset link.');
}
}
}Checking Email Verification Status
After sign-up with email/password, you may want to prevent access to the main app until the user verifies their email. Check auth().currentUser?.emailVerified inside onAuthStateChanged.
Note that emailVerified is not updated in real time — the user must reload the token for the value to reflect verification. Call auth().currentUser?.reload() and then re-read the property after the user claims to have clicked the verification link.
async function checkEmailVerification() {
const user = auth().currentUser;
if (!user) return;
await user.reload(); // Refresh the user object
if (user.emailVerified) {
console.log('Email is verified — grant access');
navigation.replace('Main');
} else {
Alert.alert(
'Not Verified',
'Please click the link in your email. Tap Resend to get a new link.',
[
{ text: 'Resend', onPress: () => user.sendEmailVerification() },
{ text: 'OK' },
]
);
}
}Quick Check
Test your understanding of React Native Mobile Development concepts from this lesson.
Lesson Recap
In this lesson you learned: how to implement email/password sign-up and sign-in with Firebase Auth, the two-step phone OTP authentication flow using signInWithPhoneNumber and confirmation.confirm, and how to manage user profile updates and email verification. Next up we read and write documents in Cloud Firestore.
자주 묻는 질문
“Firebase를 사용한 이메일 및 전화번호 인증” 강의는 무료인가요?
네 — “Firebase를 사용한 이메일 및 전화번호 인증” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 React Native Academy 강의 전체를 잠금 해제할 수 있습니다. React Native Academy 강의에는 총 4개의 강의가 포함되어 있습니다.
“Firebase를 사용한 이메일 및 전화번호 인증”에서 뭘 배우나요?
이메일과 비밀번호를 사용한 가입 및 로그인을 구현하고, SMS OTP를 사용한 전화번호 인증을 추가하며, onAuthStateChanged 관찰자를 수신하여 내비게이션 접근을 제어합니다. 브라우저에서 직접 실행하는 실습 코드로 React Native Academy을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
React Native Academy을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 React Native Academy은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 2번째 강의입니다.
“Firebase를 사용한 이메일 및 전화번호 인증” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 React Native Academy 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 React Native Academy 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- React Native Firebase를 프로젝트에 연결하기
- Firebase를 사용한 이메일 및 전화번호 인증
- Firestore 문서 읽기 및 쓰기
- 실시간 리스너 및 오프라인 유지