It should be considered confidential . The json file that is generated contains an api_key that you can use to send push notifications. As you can see in this post, the api key just identifies your Firebase project on the Google servers. It is not a security risk for someone to know it.