TL;DR: The key file is corrupt or is not a service account key at all. Re-download a fresh JSON key from the Firebase console (Project settings, Service accounts) and point Certificate() at it.

```text
ValueError: Failed to initialize a certificate credential. Caused by: "Could not deserialize key data. ..."
```

## Fix it

1. Inspect the file: head -c 300 [key].json. Expected: {"type": "service_account", ...}. If it is HTML or truncated, that is the bug.
2. Re-download: Firebase console, Project settings, Service accounts, Generate new private key. Expected: a fresh JSON file.
3. Point your code at the new file and retry. Expected: initializes.
4. Keep the file out of git; load the path from an env var.

## When this applies
- Certificate() raises Could not deserialize key data.

## When it doesn't
- The file does not exist: fix the path (different error).
- The error is about permissions at call time: IAM roles, not the key file.

## Compatibility
- firebase-admin 4.x/5.x/6.x.

## Why it happens
Key downloads get truncated, saved as the wrong file, or replaced by an HTML login page. The crypto layer then fails to parse it and reports this generic error.

## Edge cases
- One key per service account is plenty; generating many keys is a rotation smell.
- On GCP, prefer ApplicationDefault() over key files entirely.
