An ESP32 can connect a smart-home prototype to Firebase Realtime Database by sending HTTPS requests to the database’s REST API. Plan the data paths and access rules first, then have the ESP32 report device state separately from the commands it receives. This is a practical maker architecture—not a wiring plan or proof that a particular appliance circuit is safe.
What this setup does—and what it does not decide
The ESP32 is the networked controller: it can send sensor readings or reported device state to Firebase and retrieve commands stored there. Realtime Database stores data as JSON and synchronizes changes to connected clients. With REST, the device communicates with a database path over HTTPS by appending .json to the endpoint.
This describes the software architecture, not a finished construction specification. The board variant, framework, sensors, power supply, pin assignments, switching hardware, and authentication identity depend on the actual project. Do not choose components or copy wiring based only on the phrase “ESP32 smart home.”
Plan the device and data model
Choose the board and framework
Start by identifying the exact ESP32 development board and the framework used to build its firmware. Espressif’s ESP-IDF User Guide for ESP32, SDK v5.3.5, documents ESP-IDF as Espressif’s framework and covers getting started with ESP32 development boards. That versioned guide is a reference, not a claim that v5.3.5 is the latest release. If you use Arduino tooling instead, the code, libraries, board selection, and pin mapping must match that stack; the available documentation here does not establish a particular Arduino library or board as the right choice.
#1 Best Overall
- 2.4GHz Dual Mode WiFi + Bluetooth Development Board
- Support LWIP protocol, Freertos
- SupportThree Modes: AP, STA, and AP+STA
- Ultra-Low power consumption, Compatible with Arduino IDE
- ESP32 is a safe, reliable, and scalable to a variety of applications
Separate commands, reported state, and readings
Use distinct branches for desired actions and what the device says it has actually done. This example is an illustrative schema, not an official Firebase requirement:
homes/{homeId}/devices/{deviceId}/command: { "desiredOn": true }
homes/{homeId}/devices/{deviceId}/reported: { "isOn": true }
homes/{homeId}/devices/{deviceId}/readings/{readingId}: { "temperature": 21.5 }
Assign a writer and reader for each branch before implementing firmware. A command records intent; it is not evidence that an appliance changed state. The device should update its reported branch only after it has applied the command and can report the resulting state. A reading path can hold sensor values, while a generated child key is useful when appending individual records.
Rank #2
- Dual-Core Performance Up to 240 MHz: Run sensor processing, wireless communication, automation logic and connected-device tasks on a 32-bit dual-core ESP32 platform designed for responsive embedded and IoT projects
- Built-in Wi-Fi and Bluetooth 4.2: Connect to 2.4 GHz Wi-Fi networks or use Bluetooth Classic and BLE for wireless sensors, smart devices, remote controls, home automation and other connected projects
- Flexible Power-Saving Modes: ESP32 power-management features support dynamic clock scaling and low-power operating modes, helping developers reduce energy use in compatible sensing, monitoring and connected-device applications, suitable for battery-powered Internet of Things (IoT) devices.
- USB-C Programming with CP2102: Connect through USB-C for power, sketch uploads and serial monitoring, while GPIO, UART, SPI and I2C interfaces support sensors, displays, motor drivers and other modules (USB-C cable not included)
- Over-the-Air Update Support: Configure OTA functionality through a compatible ESP-32 software framework to update deployed firmware over Wi-Fi without reconnecting the board by USB for every revision
Connect the ESP32 to Firebase
- Create or select the Firebase project and Realtime Database. Use the database URL shown for that project. Firebase URL formats vary by location: the
us-central1form usesDATABASE_NAME.firebaseio.com; other locations use a regionalfirebasedatabase.appform. Do not substitute a sample URL for the project’s own endpoint. - Decide the database paths and permissions. Define which authenticated user or device can read and write each path before connecting the board. Keep commands, reported state, and readings separated as appropriate for your application.
- Connect the board to its network and send an HTTPS request. For REST, address the intended path with
.jsonappended. The firmware must handle JSON encoding and decoding, HTTP status results, network failures, and any authentication-token lifecycle it uses. - Test one operation at a time. First read a known path, then write a harmless test value under the intended device branch, and confirm the resulting JSON in the database. Next, test command retrieval and device-reported state separately. Remove test data when it is no longer needed.
- Test failure and recovery behavior. Decide how the device responds when Wi-Fi is unavailable, a request fails, a token expires, or a response cannot be parsed. Retrying policy and safe behavior during a cloud outage are application decisions; they are not supplied automatically by the REST endpoint.
Use the REST method that matches the change
Firebase’s REST API uses standard HTTP methods, but their effects differ. Choose the operation based on whether you are reading, replacing, updating, appending, or removing data.
| Method | Effect at the selected path | Smart-home example |
|---|---|---|
GET |
Reads data. | Retrieve the command branch the device is permitted to read. |
PUT |
Replaces data at the target path. | Write a complete reported-state object when replacement is intended. |
PATCH |
Updates named children without deleting omitted children. | Change one reported field while retaining other children at that path. |
POST |
Adds an item under a generated key. | Append a new reading or event record. |
DELETE |
Removes data at the target path. | Delete a test record or a branch your rules allow the client to remove. |
For example, use PATCH when changing one child should preserve other children. A PUT to that same parent replaces its data, so omitted children may be removed. Confirm the path as well as the method before sending writes.
Rank #3
- Powerful ESP-32 Board: Unlock the world of Internet of Things (IoT) and advanced electronics with the heart of this kit: the ESP-32 board. It features a powerful dual-core processor, integrated Wi-Fi and Bluetooth 4.2, making it perfect for building connected, smart devices that communicate with your phone or the cloud. It's fully compatible with the Arduino IDE for easy programming.
- Super Starter Kit: This kit contains over 35 different modules and electronic components, including sensors, displays, motors, and input devices. From LEDs and buttons to an OLED screen, servo motor, and keypad, you have everything needed to explore a vast range of projects in one box.
- Step by Step Online Tutorial: Jump right in with our detailed, beginner-friendly tutorial. Access 30+ projects with complete code, clear circuit diagrams, and step-by-step instructions. Learn the fundamentals of electronics, coding, and how to utilize the ESP-32's unique capabilities without any prior experience.
- Hands-on Learning for All Skill Levels: Perfect for students, makers, engineers, and hobbyists. Start with basic circuits and coding, then progress to intermediate and advanced IoT applications. Build practical projects like weather stations, smart home controllers, remote-controlled devices, and interactive gadgets. The skills you learn are the foundation for real-world innovation.
- Quality & Great Support: Elegoo is committed to quality. We provide a clear, detailed tutorial guide, refined code, and a well-organized component kit. All modules are carefully selected for reliability and ease of use. Our dedicated technical support team and active online community are ready to help you succeed in your learning journey.
Choose REST or a supported Firebase SDK
Firebase’s SDKs handle authentication and database communication automatically in supported client environments. Direct REST can be useful when the chosen firmware environment does not have a suitable SDK or when an HTTP integration is preferred, but it moves more responsibility into the device software.
| Approach | What it provides | What to assess for this build |
|---|---|---|
| Firebase SDK | Automatic authentication and database communication for supported environments, according to Firebase documentation. | Whether an SDK supports the selected ESP32 framework and fits the project’s connection and memory needs. |
| REST over HTTPS | Path-based database operations using HTTP methods; the REST API also supports Server-Sent Events for streamed changes. | Firmware responsibility for requests, authentication, status handling, retries, JSON, and stream event and redirect handling if streaming is used. |
For a small prototype, a request/response flow can be easier to reason about than a persistent stream. If you need the device to receive changes continuously, assess Server-Sent Events and implement its event and redirect behavior rather than assuming a basic HTTP request is a live subscription. The right choice depends on SDK availability, connection needs, authentication lifecycle, and maintenance burden.
Rank #4
- 2.4GHz Dual Mode WiFi + Bluetooth Development Board
- Support LWIP protocol, Freertos;ESP32 is a safe, reliable, and scalable to a variety of applications
- SupportThree Modes: AP, STA, and AP+STA
- Ultra-Low power consumption, Compatible with Arduino IDE
- 1PCS 30Pin ESP32 Development Board 2.4GHz WiFi Dual Cores Microcontroller Integrated with Antenna RF Low Noise Amplifiers Filters
Protect database access with rules and authentication
Firebase Realtime Database Security Rules are enforced on the server. Google Firebase’s “Understand Firebase Realtime Database Security Rules” explains that, by default, the rules do not allow anyone access to the database. Set access for the intended authenticated identities and data paths instead of relying on secrecy of the database URL.
- Scope reads and writes narrowly. A rule can compare a path key with
auth.uidto grant a user access to that user’s own data. Plan access around the actual user and device identity model. - Validate the data shape. Firebase’s rules support
.validatechecks for incoming values, including type or required-child constraints. Use validation to reject malformed writes rather than treating every JSON object as acceptable. - Account for rule inheritance. Firebase documents that
.readand.writepermissions cascade to descendants; validation rules do not cascade in the same way. Review parent-path grants carefully. - Do not deploy open test rules. Firebase warns that test mode can let anyone read and overwrite database data. Replace permissive test rules before connecting real devices or making a project public.
- Keep privileged credentials off the device. REST requests can use Firebase Authentication ID tokens or OAuth access tokens. Do not put service-account keys or other privileged server credentials in ESP32 firmware, mobile or web clients, or a public repository. Firebase warns that exposed service-account credentials can compromise project security; privileged OAuth service-account access belongs in a protected server environment.
An unauthenticated REST request succeeds only if the rules allow public access. That is not a safe shortcut for a deployed smart-home database. For a device acting under user/device rules, use an appropriate Firebase Authentication identity and ID token, and plan how the firmware obtains and refreshes credentials.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesBest Value
- 2.4GHz Dual Mode WiFi + Bluetooth Development Board
- Ultra-Low power consumption, works perfectly with the Arduino IDE
- Support LWIP protocol, Freertos
- SupportThree Modes: AP, STA, and AP+STA
- ESP32 is a safe, reliable, and scalable to a variety of applications
Keep hardware selection and electrical safety specific
The software architecture does not specify a sensor, relay, supply, wire gauge, enclosure, or appliance. Choose these from the actual electrical and mechanical requirements of the installation, including the board’s pinout and the peripherals’ voltage and current needs. A generic ESP32 board and relay module do not, by themselves, establish that switching household mains is safe.
For a low-voltage prototype, keep the circuit within the documented ratings of its components. For mains applications, use an appropriately certified, enclosed switching device and qualified electrical guidance. Espressif’s ESP32 security documentation describes platform security capabilities; those capabilities do not establish that a particular circuit, firmware configuration, or installation is safe or secure.
Troubleshoot by separating the layers
- The endpoint cannot be reached: confirm the board has network access and that firmware uses the exact database URL and location-specific domain shown in Firebase.
- A request is rejected: inspect the HTTP result and check the path, method, authentication token, and applicable server rules. A database URL alone does not grant permission.
- A write removes fields unexpectedly: check whether the request used
PUTat a parent path wherePATCHwas intended. - The database changes but the device does not: distinguish data synchronization from the device’s ability to retrieve and apply a command. Check command reads, firmware parsing, and the separate reported-state update.
- Updates stop after authentication changes: check token validity and renewal logic in the REST client. Unlike a supported SDK’s automatic handling, a direct REST implementation must manage the relevant authentication lifecycle.
- A stream disconnects or redirects: verify that the REST client handles Server-Sent Events, events, and redirects rather than treating the connection as an ordinary one-shot request.
Documentation to consult
Use Google Firebase’s official documentation for “Firebase Database REST API,” “Authenticate REST Requests,” “Installation & Setup for REST API,” “Understand Firebase Realtime Database Security Rules,” and “Firebase Realtime Database Security Rules API.” For the hardware platform and framework, consult Espressif Systems’ “ESP-IDF User Guide for ESP32, SDK v5.3.5” and its versioned “Security – ESP32 – ESP-IDF Programming Guide v5.1.” Those guides describe platform capabilities and APIs; the specific project still needs its own board, firmware, rules, and electrical design.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




