Genkit Dart setup and Firebase endpoint security

Learn to build a Genkit Dart flow and protect a virtual try-on endpoint with App Check, user claims, request limits and cached images.

Player not loading? Watch on YouTube

Nohe introduces Genkit support for Dart through a virtual clothing try-on app. The setup starts with a Shelf server project, adds dependencies, and defines a flow with input and output schemas, model plugins and business logic. The backend implementation happens off screen, so the tutorial focuses on its structure and endpoint protection.

For device verification, the speaker uses Firebase App Check limited-use tokens, described as valid for five minutes and usable once. A Shelf handler extracts the request header and verifies the token. The suggested attestation providers are reCAPTCHA Enterprise for web, Play Integrity for Android and App Attest for iOS, with a custom provider as an option for desktop apps.

User authorization checks a verified token for custom claims, such as premium access. Nohe also proposes recording requests to enforce a limit, using five try-ons per hour as an example rather than a fixed requirement. Saving generated images in a storage bucket lets the endpoint return an existing result before starting another flow.

The final example replaces caller-supplied product image URLs with a product ID. The backend retrieves the matching information from Firestore and storage, and rejects missing products. Nohe presents this restriction as a way to reduce prompt injection risk. The example uses Firebase services; it does not demonstrate running models locally.