Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

FireCMS Cloud

NPM · @FIRECMS/MCP-SERVER · 2 COMPONENTS · SCANNED OCT 1

Manage FireCMS Cloud from an AI agent: Firestore data, collections, schemas and users.

82 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 90 of 273 dependencies flagged as unhealthy (1 deprecated). View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to firecmsco/firecms). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 0 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability82
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 3977 tokens (~88/item across 45 items; 45 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 46 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the FireCMS Cloud MCP server?

FireCMS Cloud runs locally as an npm package, launched with npx -y @firecms/mcp-server. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @firecms/mcp-server

# add to Claude Code
claude mcp add co-firecms-mcp -- npx -y @firecms/mcp-server
// .cursor/mcp.json
{
  "mcpServers": {
    "co-firecms-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "co-firecms-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add co-firecms-mcp -- npx -y @firecms/mcp-server
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "co-firecms-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@firecms/mcp-server"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add co-firecms-mcp --command npx --arg -y --arg @firecms/mcp-server
# ~/.hermes/config.yaml
mcp_servers:
  co-firecms-mcp:
    command: "npx"
    args: ["-y", "@firecms/mcp-server"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "co-firecms-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
# add to Vellum
assistant mcp add co-firecms-mcp -t stdio -c npx -a -y @firecms/mcp-server
// mcp.json
{
  "mcpServers": {
    "co-firecms-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 1 Oct 26 +25
    • Malware scan: unverified → pass ▲ security
    • Known CVEs: unverified → pass ▲ security
    • Dependency health: unverified → 0.85 ▲ functional
  • 30 Sept 26 57

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 1 Oct 2026 · Analysed npm/@firecms/mcp-server@3.5.1

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem npm
Reason Verified
Discovered via Registry attestation endpoint
Source repo firecmsco/firecms
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/firecmsco/firecms/.github/workflows/publish.yml@refs/tags/v3.5.1
Rekor log index 3019539354
Predicate type SLSA build provenance https://slsa.dev/provenance/v1
Subject digest sha512:638a9a61dcfa7cea8923f0d64d7d7d831bb95c7491c4f4c1610ec8dd59d91a3724b4a0424998efd99224688d95b94b4391e9de676895b67b1cda4151c

Background: How many MCP packages publish verified provenance →

Dependencies 273 packages
Packages resolved 273
Deprecated 1
Stale 89
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 45 exposed · ~3,917 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_user ~81

Invite a new user to a FireCMS project. Sends an invitation email. Admin-only. If the email already belongs to a user of the project, their roles are replaced by these.

NameTypeReqDescription
emailstringyesEmail address of the user to invite
projectIdstringyesThe Firebase project ID
rolesarrayyesRoles to assign

No output schema declared.

No examples provided.

apply_firestore_security_rules ~191

Add FireCMS's access rule to a project's Firestore and Storage security rules. Requires admin. FireCMS Cloud reads the customer's Firestore from the browser using the signed-in user's own token, so it needs a rule granting access to users carrying the `fireCMSUser` claim: match /{document=**} { allow read, write: if request.auth.token.fireCMSUser; } Without it the CMS shows "Missing Firestore Security Rules" and no collection opens, although this server keeps working: it reads through the backend's service account, which bypasses security rules. The rule is injected into the existing ruleset rather than replacing it, and a project that already has it is left alone, so it is safe to run again. Connecting a project applies it already; this repairs projects connected earlier, or where that step failed.

NameTypeReqDescription
projectIdstringyesThe Firebase project ID

No output schema declared.

No examples provided.

connect_project_to_firecms ~196

Connect an existing Firebase project to FireCMS Cloud. It creates a delegated service account in the project with the permissions FireCMS needs, registers the signed-in user as an admin, creates the FireCMS project on the free plan, and by default adds FireCMS's access rule to the project's Firestore and Storage security rules. Firebase, Firestore and Firebase Authentication must already be enabled on the project. Authentication cannot be enabled through any API: it is switched on once in the Firebase console. Fails if the project is already connected.

NameTypeReqDescription
applySecurityRulesboolean–Add FireCMS's Firestore and Storage access rule as part of connecting (default true). The CMS cannot open any collection without it.
creationTypestring–'existing' (default) for a project that already has data; 'new' for a freshly created one
projectIdstringyesThe Firebase project ID to connect

No output schema declared.

No examples provided.

count_documents ~64

Count the total number of documents in a Firestore collection.

NameTypeReqDescription
collectionPathstringyesCollection path (e.g., 'products')
databaseIdstring–Firestore database ID (default: '(default)')
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

create_document ~116

Create a new document in a Firestore collection. Provide the field values as a JSON object.

NameTypeReqDescription
collectionPathstringyesCollection path (e.g., 'products')
dataobjectyesDocument fields as a JSON object
databaseIdstring–Firestore database ID (default: '(default)')
documentIdstring–Optional document ID. If not provided, Firestore generates one. If a document with this ID exists, it is replaced.
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

create_firecms_webapp ~61

Create the FireCMS web app inside the client's Firebase project, or reuse the one already there. Connecting a project normally does this; this repairs a project where that step failed. Requires admin.

NameTypeReqDescription
projectIdstringyesThe Firebase project ID

No output schema declared.

No examples provided.

delete_collection_schema ~74

Delete a collection schema from FireCMS. This removes the collection configuration from the CMS — it does NOT delete the underlying Firestore data. The collection will simply no longer appear in the FireCMS UI.

NameTypeReqDescription
collectionIdstringyesCollection ID to delete
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

delete_document ~76

Delete a document from Firestore. This action is permanent.

NameTypeReqDescription
collectionPathstringyesCollection path (e.g., 'products')
databaseIdstring–Firestore database ID (default: '(default)')
documentIdstringyesDocument ID to delete
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

delete_property ~85

Remove a property from a collection schema. This removes the field definition from the CMS configuration — it does NOT delete the field from existing Firestore documents.

NameTypeReqDescription
collectionIdstringyesCollection ID
namespacestring–Dot-separated namespace for nested properties
projectIdstringyesFirebase project ID
propertyKeystringyesProperty key to remove

No output schema declared.

No examples provided.

enable_firestore ~75

Create the default Firestore database in a Google Cloud project, in the given location. The location is permanent and cannot be changed later.

NameTypeReqDescription
locationIdstringyesFirestore location, e.g. 'eur3' or 'us-central'. Permanent.
projectIdstringyesThe Google Cloud / Firebase project ID

No output schema declared.

No examples provided.

enable_project_apis ~56

Enable the Google Cloud APIs that FireCMS requires on a project (reported as `apisEnabled` in its setup status). Safe to run more than once.

NameTypeReqDescription
projectIdstringyesThe Google Cloud / Firebase project ID

No output schema declared.

No examples provided.

export_collection ~104

Export documents from a Firestore collection as JSON. Useful for data backups, analysis, or migration. For large collections, use the limit parameter.

NameTypeReqDescription
collectionPathstringyesCollection path to export (e.g., 'products')
databaseIdstring–Firestore database ID (default: '(default)')
limitnumber–Max documents to export (default: 100, max: 500)
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

firecms_get_current_user ~19

Get the currently authenticated FireCMS user

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

firecms_login ~32

Sign in to FireCMS Cloud. Opens a browser window for Google OAuth authentication. Required before using any other tools.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

firecms_logout ~22

Sign out of FireCMS Cloud. Revokes the current session.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

generate_collection ~91

Generate a new FireCMS collection schema using AI. Provide a natural language description of the collection you want (e.g., "A blog with posts that have title, body, author, tags, and a featured image"). Returns a complete FireCMS collection configuration.

NameTypeReqDescription
existingCollectionsarray–Optional existing collection schemas for context
promptstringyesNatural language description of the collection to generate

No output schema declared.

No examples provided.

get_collection_schema ~70

Get the full schema definition for a specific collection, including all properties, validation rules, display configuration, and subcollection definitions.

NameTypeReqDescription
collectionIdstringyesCollection ID (usually same as the Firestore path, e.g., 'products')
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

get_document ~83

Get a specific document by its collection path and ID. Returns all fields of the document.

NameTypeReqDescription
collectionPathstringyesCollection path (e.g., 'products', 'users')
databaseIdstring–Firestore database ID (default: '(default)')
documentIdstringyesDocument ID
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

get_project_config ~78

Get the full configuration for a FireCMS project, including: - Project name, logo, and brand colors (primary/secondary) - Subscription plan and trial status - Feature toggles (text search, entity history, App Check) - Default locale settings - Customization revision info

NameTypeReqDescription
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

get_project_setup_status ~67

Get the detailed FireCMS readiness status of a single Google Cloud project: whether Firebase, Firestore, Storage, Auth and the required APIs are enabled, and so what is still missing before it can be connected.

NameTypeReqDescription
projectIdstringyesThe Google Cloud / Firebase project ID

No output schema declared.

No examples provided.

get_root_collections ~76

List all Firestore root-level collections in a FireCMS project — the paths that can be turned into CMS collections. Read live from Firestore, so collections created moments ago are included.

NameTypeReqDescription
databaseIdstring–Firestore database ID, if not '(default)'
projectIdstringyesThe Firebase project ID

No output schema declared.

No examples provided.

import_documents ~155

Bulk import documents into a Firestore collection, for seeding data, migrations or restoring a backup. Each document can specify an ID; without one, Firestore generates it. By default a document with an existing ID is overwritten; with merge: true its fields are merged instead. At most 500 documents per call.

NameTypeReqDescription
collectionPathstringyesTarget collection path (e.g., 'products')
databaseIdstring–Firestore database ID (default: '(default)')
documentsarrayyesArray of documents to import (max 500)
mergeboolean–If true, merge with existing documents instead of overwriting (default: false)
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

infer_collections_from_data ~113

Infer collections from the existing Firestore data at the given paths, and save them to the project. Requires admin. For each path the backend samples documents, infers the property types, then uses an LLM to pick display names, a singular name, an icon, a navigation group and field widgets. Paths already mapped to a collection, and paths with no documents, are skipped.

NameTypeReqDescription
pathsarrayyesThe collection paths to infer and save
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

list_collection_schemas ~59

List all persisted collection schemas for a FireCMS project. Returns the collection configurations (name, path, properties, etc.) that define how data is displayed and edited in the CMS.

NameTypeReqDescription
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

list_databases ~58

List the Firestore databases of a project. Only needed for projects using more than the '(default)' database — the resulting database IDs can be passed to the other introspection and document tools.

NameTypeReqDescription
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

list_documents ~127

List documents from a Firestore collection, with optional filters, ordering and a limit.

NameTypeReqDescription
collectionPathstringyesCollection path (e.g., 'products', 'users', 'blog/posts')
databaseIdstring–Firestore database ID (default: '(default)')
filtersarray–Optional filters to apply
limitnumber–Max number of documents to return (default: 20)
orderBystring–Field to order by
orderDirectionstring–Sort direction
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

list_firebase_projects ~99

List the Google Cloud / Firebase projects the signed-in user can access, and whether each one is ready to be connected to FireCMS Cloud. Each entry reports: - `fireCMSProject`: true if it is already connected to FireCMS Cloud - `cloudProjectConfigurationStatus.firebaseEnabled` / `firestoreEnabled` / `apisEnabled` / `authEnabled`: what connecting requires Connecting needs Firebase, Firestore and Firebase Authentication enabled.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_firestore_locations ~34

List the locations available for a new Firestore database, as location IDs such as 'eur3' or 'us-central'.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_projects ~20

List all FireCMS Cloud projects accessible by the authenticated user

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_subcollections ~86

List the subcollections of a specific document, with their full paths: nested data that can be turned into CMS collections.

NameTypeReqDescription
databaseIdstring–Firestore database ID, if not '(default)'
parentDocumentPathstringyesFull path of the parent document, e.g. 'users/abc123'
projectIdstringyesThe Firebase project ID

No output schema declared.

No examples provided.

list_users ~42

List all users that have access to a FireCMS project, including their roles (admin, editor, viewer)

NameTypeReqDescription
projectIdstringyesThe Firebase project ID

No output schema declared.

No examples provided.

modify_collection ~101

Modify an existing FireCMS collection schema using AI. Describe the changes you want (e.g., "Add a priority enum with low/medium/high" or "Make title required with max 100 chars"). Returns the updated schema and a list of operations performed.

NameTypeReqDescription
existingCollectionobjectyesThe current collection schema to modify
existingCollectionsarray–Optional list of all collection schemas for context
promptstringyesDescription of the modifications

No output schema declared.

No examples provided.

preview_inferred_schema ~165

Read a sample of real documents from a Firestore path and infer a FireCMS collection schema from them, without saving anything. Works for any path, subcollections included. Inference is structural only: it derives data types, enum candidates and validation from the sampled values. The result is a complete collection schema that can be edited and saved as it is.

NameTypeReqDescription
databaseIdstring–Firestore database ID, if not '(default)'
pathstringyesFirestore collection path, e.g. 'products' or 'users/{userId}/orders'
projectIdstringyesFirebase project ID
sampleSizenumber–How many documents to sample (default 30, max 200). More samples give better enum and optionality detection.

No output schema declared.

No examples provided.

remove_user ~50

Remove a user from a FireCMS project, revoking their access. Admin-only.

NameTypeReqDescription
projectIdstringyesThe Firebase project ID
userIdstringyesThe user ID to remove

No output schema declared.

No examples provided.

save_collection_schema ~279

Create or fully replace a collection schema. This defines how a Firestore collection is displayed and edited in FireCMS. Requires at minimum: id, path, and name. Example schema: { "id": "products", "path": "products", "name": "Products", "singularName": "Product", "icon": "ShoppingCart", "description": "Product catalog", "group": "Shop", "properties": { "name": { "dataType": "string", "name": "Name", "validation": { "required": true } }, "price": { "dataType": "number", "name": "Price", "validation": { "required": true, "min": 0 } }, "status": { "dataType": "string", "name": "Status", "enumValues": [ { "id": "draft", "label": "Draft" }, { "id": "published", "label": "Published" } ]} }, "propertiesOrder": ["name", "price", "status"] }

NameTypeReqDescription
collectionIdstringyesCollection ID (e.g., 'products')
projectIdstringyesFirebase project ID
schemaobjectyesComplete collection schema definition

No output schema declared.

No examples provided.

save_property ~166

Add or update a single property in a collection schema, leaving the other properties as they are. A new property is added at the end of the display order. Example property: { "dataType": "string", "name": "Description", "description": "Product description", "multiline": true, "validation": { "required": true, "max": 500 } }

NameTypeReqDescription
collectionIdstringyesCollection ID
namespacestring–Dot-separated namespace for nested properties in maps (e.g., 'address' for address.street)
projectIdstringyesFirebase project ID
propertyobjectyesProperty definition
propertyKeystringyesProperty field key (e.g., 'description', 'price')

No output schema declared.

No examples provided.

setup_all_collections ~121

Discover every Firestore root collection in the project that is not yet mapped to a collection, infer a collection schema for each (display names and widgets picked by an LLM), and save them all. Requires admin. Covers every database of the project. Collections that already exist are left alone, so it is safe to run again later to pick up new Firestore collections. Can take a while on large projects.

NameTypeReqDescription
databaseIdstring–Firestore database ID, if not '(default)'
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

toggle_entity_history ~51

Enable or disable entity history tracking (audit log of document changes) for a project.

NameTypeReqDescription
enabledbooleanyestrue to enable, false to disable
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

toggle_text_search ~46

Enable or disable the local text search feature for a project.

NameTypeReqDescription
enabledbooleanyestrue to enable, false to disable
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

update_collection_schema ~82

Partially update an existing collection schema. Only the top-level fields given are changed (merged with the existing schema): for example the name, group, display settings or properties.

NameTypeReqDescription
collectionIdstringyesCollection ID to update
dataobjectyesFields to update (merged with existing schema)
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

update_default_locale ~62

Change the default locale for the CMS (affects date formatting, etc.).

NameTypeReqDescription
localestringyesLocale code (e.g., 'en', 'es', 'de', 'fr', 'it')
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

update_document ~97

Update fields of an existing document. Only the specified fields are modified (partial update / merge).

NameTypeReqDescription
collectionPathstringyesCollection path (e.g., 'products')
dataobjectyesFields to update as a JSON object
databaseIdstring–Firestore database ID (default: '(default)')
documentIdstringyesDocument ID to update
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

update_project_colors ~88

Update the primary and/or secondary brand colors for the CMS UI. Colors should be hex values (e.g., '#0070F4').

NameTypeReqDescription
primaryColorstring–Primary color hex (e.g., '#0070F4')
projectIdstringyesFirebase project ID
secondaryColorstring–Secondary color hex (e.g., '#FF5B79')

No output schema declared.

No examples provided.

update_project_name ~40

Update the display name of a FireCMS project.

NameTypeReqDescription
namestringyesNew project name
projectIdstringyesFirebase project ID

No output schema declared.

No examples provided.

update_user_roles ~59

Update the roles of an existing user in a FireCMS project. Admin-only.

NameTypeReqDescription
projectIdstringyesThe Firebase project ID
rolesarrayyesNew roles
userIdstringyesThe user ID to update

No output schema declared.

No examples provided.

Common questions

What is the FireCMS Cloud MCP server?

FireCMS Cloud is an MCP server listed in the public MCP registry as co.firecms/mcp. Manage FireCMS Cloud from an AI agent: Firestore data, collections, schemas and users. This page covers its npm package (@firecms/mcp-server).

Is the FireCMS Cloud MCP server safe to use?

FireCMS Cloud scores 82 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 1 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the FireCMS Cloud MCP server expose?

FireCMS Cloud exposes 45 tools: firecms_get_current_user, list_firebase_projects, get_project_setup_status, list_firestore_locations, enable_project_apis, and 40 more. Their descriptions and schemas cost roughly 3,917 tokens of context every time the server is loaded.

Is the FireCMS Cloud MCP server still maintained?

FireCMS Cloud is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the FireCMS Cloud MCP server under?

FireCMS Cloud declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.