Prompt
Why does Firebase Authentication create duplicate accounts with Google sign in?
Latest observation
Firebase Authentication can end up creating what look like “duplicate accounts” with Google sign-in when the same person is signed in through Google in a way that Firebase treats as a different identity. The most common reasons are:
1. Different Firebase sign-in methods are being used for the same user
If a user first signs up with:
- email/password, and later
- Google Sign-In,
Firebase creates two separate Firebase user records unless you link those providers to the same account.
2. The Google account is not being linked to an existing Firebase user
To avoid duplicates, after a user signs in with one provider, you need to call account linking, e.g.:
- link Google credential to existing email/password account
- or link email/password to existing Google account
Without linking, Firebase assumes it’s a new account.
3. Different Google accounts are actually being used
Sometimes users have:
- multiple Google accounts in the browser
- a personal account vs work account
- one Gmail account and one Google Workspace account
If the Google sub/UID differs, Firebase sees them as different users and creates separate accounts.
4. Same email, but different provider identity
Firebase identifies users by the provider’s unique ID, not just the email address.
Even if two sign-ins use the same email, if they come from different auth providers and aren’t linked, Firebase may create separate users.
5. Missing account collision handling
If you allow users to sign in with multiple providers, you need to handle cases where:
- the email already exists with another provider
- Firebase returns
auth/account-exists-with-different-credential
If you ignore this and just retry sign-in, it may look like a duplicate was created.
How to prevent duplicates
Link providers
If the user already has an account, link the new credential to it:
- Sign in with the first provider
- Then use
linkWithCredential()/linkWithPopup()/linkWithRedirect()
Handle email conflicts
When Firebase says the email already exists with another provider:
- ask the user to sign in with the existing provider
- then link the new provider
Use one account creation flow
Pick a consistent rule:
- either always start with Google
- or always start with email/password and then link Google
Example scenario
User signs up with email/password using alice@example.com.
Later they click “Sign in with Google” and choose the same email address.
If the Google account is not linked to the original Firebase user, Firebase creates a second user because:
- the email may match
- but the provider identity is different
In short
Firebase creates duplicate accounts with Google sign-in when you don’t link auth providers or don’t properly handle account collisions. The fix is usually to link the Google credential to the existing Firebase user and handle the account-exists-with-different-credential case.
If you want, I can show you the exact Firebase code for linking Google sign-in to an existing account in Web, Android, or iOS.