7.3 KiB
Google provider inventory
Verified read-only on 2026-08-28 against the authenticated Google Cloud and
Firebase consoles, the local Dev .env, the installed Test and Prod .env
files over SSH, and the repository environment validators. No secret values
were read into this document. This is an inventory, not a source of secrets.
Environment contract
Who Need Help has exactly three deployment environments:
| Environment | Public origin | Android build/package | Google project |
|---|---|---|---|
| Dev | https://whoneedhelp.imalto.site |
development / org.whoneedhelp.mobile.development |
Who Need Help Development / who-need-help-development / 299749044449 |
| Test | https://test.whoneedhelp.com |
staging / org.whoneedhelp.mobile.staging |
Who Need Help Staging / who-need-help-staging / 340523338913 |
| Prod | https://whoneedhelp.com |
release / org.whoneedhelp.mobile |
Who Need Help Production / who-need-help-production / 184178014037 |
staging is only the existing Google display name and Android build/package
label for Test. It is not a fourth environment. Reuse the three project IDs
above; do not create another Google Cloud or Firebase project for these
environments.
The repository enforces this mapping in
scripts/validate-android-environment.sh.
The installed runtime identifiers match the table: Dev points to
who-need-help-development, Prod points to who-need-help-production, and
Test has its own Web OAuth client while all Firebase/FCM values remain empty.
Current registrations
Dev
- Google OAuth clients
- Web:
Who Need Help Development Web(299749044449-j364ndp46h83r6mmtrj2qrlleas05an0.apps.googleusercontent.com) - origin:
https://whoneedhelp.imalto.site - callback:
https://whoneedhelp.imalto.site/auth/google/callback - Android:
Who Need Help Development Android(299749044449-e39l1h560kot97bj2mjjat70or2sn00n.apps.googleusercontent.com)
- Web:
- Firebase project:
Spark, shown as
No-cost ($0/month)at verification time. - Firebase Android app:
Who Need Help Development, packageorg.whoneedhelp.mobile.development, app ID1:299749044449:android:284bfd48e072ca29e307a0. - IAM service accounts:
wnh-dev-fcm-sender@who-need-help-development.iam.gserviceaccount.comis enabled for FCM HTTP v1;- the Firebase Admin SDK service account exists and has no user-managed key.
Test
- Google OAuth clients
- Web:
Who Need Help Staging Web(340523338913-8qjj8vtnamq44mtl7eg5fv60o8cfnts5.apps.googleusercontent.com) - origin:
https://test.whoneedhelp.com - callback:
https://test.whoneedhelp.com/auth/google/callback - Android:
Who Need Help Staging Android(340523338913-4634ev1onnv8a5q092pncpocj9smfvvg.apps.googleusercontent.com), packageorg.whoneedhelp.mobile.staging.
- Web:
- Firebase is not connected to
who-need-help-staging; the current Firebase project list contains only Dev and Prod. - IAM service accounts: no service accounts were present, so Test has no FCM sender registration.
- The Google Cloud project has a billing account linked. The console showed
$0.00estimated charges for 2026-08-01 through 2026-08-28; this observation is not a pricing guarantee. - The Web OAuth client also contains the old callback
https://staging.whoneedhelp.com/auth/google/callback. It is not part of the three-environment contract. Do not rely on or remove it until the owner explicitly chooses the cleanup.
Prod
- Google OAuth clients
- Web:
Who Need Help Production Web(184178014037-elt40fdgum1umln6440fgmb6h7o7dskr.apps.googleusercontent.com) - origin:
https://whoneedhelp.com - callback:
https://whoneedhelp.com/auth/google/callback - Android clients:
Who Need Help Android Upload,Who Need Help Android Play RSA 1,Who Need Help Android Play RSA 2, andWho Need Help Android Play ML-DSA.
- Web:
- Firebase project:
Spark, shown as
No-cost ($0/month)at verification time. - Firebase Android app:
Who Need Help Production, packageorg.whoneedhelp.mobile, app ID1:184178014037:android:18b3996444c3bebce361dc. - IAM service accounts:
who-need-help-fcm@who-need-help-production.iam.gserviceaccount.comis enabled for FCM HTTP v1;- the Firebase Admin SDK service account exists and has no user-managed key.
- Google Play app is the production Android application.
- Four Android OAuth clients currently exist while the local Play identity inventory records three Play signing identities. The purpose of the fourth client has not been verified; do not delete or merge any of them based only on their similar names.
Configuration ownership
Each checkout keeps one ignored .env. Provider secrets must remain there or
in the ignored provider files consumed by the import scripts; never copy them
into this document or commit them.
| Capability | Runtime configuration |
|---|---|
| Web Google sign-in | GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET |
| Android Google sign-in | GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS |
| Public Firebase Android config | four WNH_FIREBASE_* values |
| Server-side FCM | FCM_PROJECT_ID and exactly one service-account source |
| Android App Links | ANDROID_APP_LINKS_PACKAGE_NAME, ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS |
Relevant validated importers:
scripts/import-firebase-android-config.shscripts/import-fcm-service-account.shscripts/import-play-android-config.sh
The Dev and Prod FCM sender accounts being present proves registration only; delivery still requires the matching environment configuration and an actual device smoke test. Test currently has OAuth but no Firebase/FCM registration.
The ignored tmp/environment-access/*.env files are historical snapshots, not
live configuration. In particular, its old Dev snapshot still references the
historical who-need-help-dev-firebase setup and must not be used to recreate or
overwrite the current Dev configuration.
Do not recreate
- Do not create a fourth environment called Staging.
- Do not create another Firebase project for Dev or Prod.
- Do not place OAuth client secrets, Firebase API keys, service-account JSON, private keys, or key IDs in documentation.
- Do not delete an OAuth client, callback, Firebase app, fingerprint, or service account until its active environment and signing identity have been verified.