# FireCMS Cloud (npm · @firecms/mcp-server)

Manage FireCMS Cloud from an AI agent: Firestore data, collections, schemas and users.

- Trust score: 82/100 (high trust)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-01

## Components

- remote · `api.firecms.co`: 36/100, [markdown](https://verifymcp.io/servers/co-firecms-mcp/api.md), [page](https://verifymcp.io/servers/co-firecms-mcp/api)
- npm · `@firecms/mcp-server`: 82/100 (this document), [markdown](https://verifymcp.io/servers/co-firecms-mcp/firecms-mcp-server.md), [page](https://verifymcp.io/servers/co-firecms-mcp/firecms-mcp-server)

## Channel facts

- Registry: `npm`
- Package: `@firecms/mcp-server`
- Version: `3.5.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-01.

- **Supply Chain Security**: 98/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 90 of 273 dependencies flagged as unhealthy (1 deprecated).
- **Provenance & Transparency**: 100/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to firecmsco/firecms).
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 0 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 82/100
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 3977 tokens (~88/item across 45 items; 45 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 46 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the FireCMS Cloud MCP server?

FireCMS Cloud runs locally as an npm package, launched with npx -y @firecms/mcp-server. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add co-firecms-mcp -- npx -y @firecms/mcp-server
```

### Cursor

```json
{
  "mcpServers": {
    "co-firecms-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "co-firecms-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add co-firecms-mcp -- npx -y @firecms/mcp-server
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "co-firecms-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@firecms/mcp-server"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add co-firecms-mcp --command npx --arg -y --arg @firecms/mcp-server
```

### Hermes

```yaml
mcp_servers:
  co-firecms-mcp:
    command: "npx"
    args: ["-y", "@firecms/mcp-server"]
```

### Netclaw

```json
{
  "McpServers": {
    "co-firecms-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add co-firecms-mcp -t stdio -c npx -a -y @firecms/mcp-server
```

### Other

```json
{
  "mcpServers": {
    "co-firecms-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@firecms/mcp-server"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-01 (score 82, +25)

- [security improvement] Malware scan: unverified → pass
- [security improvement] Known CVEs: unverified → pass
- [functional improvement] Dependency health: unverified → 0.85

### 2026-09-30 (score 57)

First indexed and scored.

## MCP tools (45)

### `firecms_get_current_user` (~19 tokens)

Current user

Get the currently authenticated FireCMS user

### `list_firebase_projects` (~99 tokens)

List Firebase projects

List the Google Cloud / Firebase projects the signed-in user can access, and whether each one is ready to be connected to FireCMS Cloud.

Each entry reports:
\- `fireCMSProject`: true if it is already connected to FireCMS Cloud
\- `cloudProjectConfigurationStatus.firebaseEnabled` / `firestoreEnabled` / `apisEnabled` / `authEnabled`: what connecting requires

Connecting needs Firebase, Firestore and Firebase Authentication enabled.

### `get_project_setup_status` (~67 tokens)

Check project setup

Get the detailed FireCMS readiness status of a single Google Cloud project: whether Firebase, Firestore, Storage, Auth and the required APIs are enabled, and so what is still missing before it can be connected.

Input parameters:

- `projectId` (string, required): The Google Cloud / Firebase project ID

### `list_firestore_locations` (~34 tokens)

List Firestore locations

List the locations available for a new Firestore database, as location IDs such as 'eur3' or 'us-central'.

### `enable_project_apis` (~56 tokens)

Enable required APIs

Enable the Google Cloud APIs that FireCMS requires on a project (reported as `apisEnabled` in its setup status). Safe to run more than once.

Input parameters:

- `projectId` (string, required): The Google Cloud / Firebase project ID

### `enable_firestore` (~75 tokens)

Create Firestore database

Create the default Firestore database in a Google Cloud project, in the given location. The location is permanent and cannot be changed later.

Input parameters:

- `locationId` (string, required): Firestore location, e.g. 'eur3' or 'us-central'. Permanent.
- `projectId` (string, required): The Google Cloud / Firebase project ID

### `connect_project_to_firecms` (~196 tokens)

Connect a Firebase project

Connect an existing Firebase project to FireCMS Cloud.

It creates a delegated service account in the project with the permissions FireCMS needs, registers the signed-in user as an admin, creates the FireCMS project on the free plan, and by default adds FireCMS's access rule to the project's Firestore and Storage security rules.

Firebase, Firestore and Firebase Authentication must already be enabled on the project. Authentication cannot be enabled through any API: it is switched on once in the Firebase console. Fails if the project is already connected.

Input parameters:

- `applySecurityRules` (boolean): Add FireCMS's Firestore and Storage access rule as part of connecting (default true). The CMS cannot open any collection without it.
- `creationType` (string): 'existing' (default) for a project that already has data; 'new' for a freshly created one
- `projectId` (string, required): The Firebase project ID to connect

### `apply_firestore_security_rules` (~191 tokens)

Apply FireCMS security rules

Add FireCMS's access rule to a project's Firestore and Storage security rules. Requires admin.

FireCMS Cloud reads the customer's Firestore from the browser using the signed-in user's own token, so it needs a rule granting access to users carrying the `fireCMSUser` claim:
    match /{document=**} { allow read, write: if request.auth.token.fireCMSUser; }

Without it the CMS shows "Missing Firestore Security Rules" and no collection opens, although this server keeps working: it reads through the backend's service account, which bypasses security rules.

The rule is injected into the existing ruleset rather than replacing it, and a project that already has it is left alone, so it is safe to run again. Connecting a project applies it already; this repairs projects connected earlier, or where that step failed.

Input parameters:

- `projectId` (string, required): The Firebase project ID

### `create_firecms_webapp` (~61 tokens)

Create FireCMS web app

Create the FireCMS web app inside the client's Firebase project, or reuse the one already there. Connecting a project normally does this; this repairs a project where that step failed. Requires admin.

Input parameters:

- `projectId` (string, required): The Firebase project ID

### `list_projects` (~20 tokens)

List projects

List all FireCMS Cloud projects accessible by the authenticated user

### `get_root_collections` (~76 tokens)

List root collections

List all Firestore root-level collections in a FireCMS project — the paths that can be turned into CMS collections. Read live from Firestore, so collections created moments ago are included.

Input parameters:

- `databaseId` (string): Firestore database ID, if not '(default)'
- `projectId` (string, required): The Firebase project ID

### `list_subcollections` (~86 tokens)

List subcollections

List the subcollections of a specific document, with their full paths: nested data that can be turned into CMS collections.

Input parameters:

- `databaseId` (string): Firestore database ID, if not '(default)'
- `parentDocumentPath` (string, required): Full path of the parent document, e.g. 'users/abc123'
- `projectId` (string, required): The Firebase project ID

### `list_users` (~42 tokens)

List users

List all users that have access to a FireCMS project, including their roles (admin, editor, viewer)

Input parameters:

- `projectId` (string, required): The Firebase project ID

### `add_user` (~81 tokens)

Invite a user

Invite a new user to a FireCMS project. Sends an invitation email. Admin-only. If the email already belongs to a user of the project, their roles are replaced by these.

Input parameters:

- `email` (string, required): Email address of the user to invite
- `projectId` (string, required): The Firebase project ID
- `roles` (array, required): Roles to assign

### `update_user_roles` (~59 tokens)

Change user roles

Update the roles of an existing user in a FireCMS project. Admin-only.

Input parameters:

- `projectId` (string, required): The Firebase project ID
- `roles` (array, required): New roles
- `userId` (string, required): The user ID to update

### `remove_user` (~50 tokens)

Remove a user

Remove a user from a FireCMS project, revoking their access. Admin-only.

Input parameters:

- `projectId` (string, required): The Firebase project ID
- `userId` (string, required): The user ID to remove

### `list_databases` (~58 tokens)

List Firestore databases

List the Firestore databases of a project. Only needed for projects using more than the '(default)' database — the resulting database IDs can be passed to the other introspection and document tools.

Input parameters:

- `projectId` (string, required): Firebase project ID

### `preview_inferred_schema` (~165 tokens)

Preview inferred schema

Read a sample of real documents from a Firestore path and infer a FireCMS collection schema from them, without saving anything. Works for any path, subcollections included.

Inference is structural only: it derives data types, enum candidates and validation from the sampled values. The result is a complete collection schema that can be edited and saved as it is.

Input parameters:

- `databaseId` (string): Firestore database ID, if not '(default)'
- `path` (string, required): Firestore collection path, e.g. 'products' or 'users/{userId}/orders'
- `projectId` (string, required): Firebase project ID
- `sampleSize` (number): How many documents to sample (default 30, max 200). More samples give better enum and optionality detection.

### `infer_collections_from_data` (~113 tokens)

Create collections from data

Infer collections from the existing Firestore data at the given paths, and save them to the project. Requires admin.

For each path the backend samples documents, infers the property types, then uses an LLM to pick display names, a singular name, an icon, a navigation group and field widgets. Paths already mapped to a collection, and paths with no documents, are skipped.

Input parameters:

- `paths` (array, required): The collection paths to infer and save
- `projectId` (string, required): Firebase project ID

### `setup_all_collections` (~121 tokens)

Set up all collections

Discover every Firestore root collection in the project that is not yet mapped to a collection, infer a collection schema for each (display names and widgets picked by an LLM), and save them all. Requires admin.

Covers every database of the project. Collections that already exist are left alone, so it is safe to run again later to pick up new Firestore collections. Can take a while on large projects.

Input parameters:

- `databaseId` (string): Firestore database ID, if not '(default)'
- `projectId` (string, required): Firebase project ID

### `get_project_config` (~78 tokens)

Get project settings

Get the full configuration for a FireCMS project, including:
\- Project name, logo, and brand colors (primary/secondary)
\- Subscription plan and trial status
\- Feature toggles (text search, entity history, App Check)
\- Default locale settings
\- Customization revision info

Input parameters:

- `projectId` (string, required): Firebase project ID

### `update_project_name` (~40 tokens)

Rename project

Update the display name of a FireCMS project.

Input parameters:

- `name` (string, required): New project name
- `projectId` (string, required): Firebase project ID

### `update_project_colors` (~88 tokens)

Change brand colors

Update the primary and/or secondary brand colors for the CMS UI. Colors should be hex values (e.g., '#0070F4').

Input parameters:

- `primaryColor` (string): Primary color hex (e.g., '#0070F4')
- `projectId` (string, required): Firebase project ID
- `secondaryColor` (string): Secondary color hex (e.g., '#FF5B79')

### `update_default_locale` (~62 tokens)

Change default locale

Change the default locale for the CMS (affects date formatting, etc.).

Input parameters:

- `locale` (string, required): Locale code (e.g., 'en', 'es', 'de', 'fr', 'it')
- `projectId` (string, required): Firebase project ID

### `toggle_text_search` (~46 tokens)

Turn text search on or off

Enable or disable the local text search feature for a project.

Input parameters:

- `enabled` (boolean, required): true to enable, false to disable
- `projectId` (string, required): Firebase project ID

### `toggle_entity_history` (~51 tokens)

Turn entity history on or off

Enable or disable entity history tracking (audit log of document changes) for a project.

Input parameters:

- `enabled` (boolean, required): true to enable, false to disable
- `projectId` (string, required): Firebase project ID

### `list_collection_schemas` (~59 tokens)

List collections

List all persisted collection schemas for a FireCMS project. Returns the collection 
configurations (name, path, properties, etc.) that define how data is displayed and edited in the CMS.

Input parameters:

- `projectId` (string, required): Firebase project ID

### `get_collection_schema` (~70 tokens)

Get a collection

Get the full schema definition for a specific collection, including all properties, 
validation rules, display configuration, and subcollection definitions.

Input parameters:

- `collectionId` (string, required): Collection ID (usually same as the Firestore path, e.g., 'products')
- `projectId` (string, required): Firebase project ID

### `save_collection_schema` (~279 tokens)

Save a collection

Create or fully replace a collection schema. This defines how a Firestore collection 
is displayed and edited in FireCMS. Requires at minimum: id, path, and name. 

Example schema:
{
  "id": "products",
  "path": "products",
  "name": "Products",
  "singularName": "Product",
  "icon": "ShoppingCart",
  "description": "Product catalog",
  "group": "Shop",
  "properties": {
    "name": { "dataType": "string", "name": "Name", "validation": { "required": true } },
    "price": { "dataType": "number", "name": "Price", "validation": { "required": true, "min": 0 } },
    "status": { "dataType": "string", "name": "Status", "enumValues": [
      { "id": "draft", "label": "Draft" },
      { "id": "published", "label": "Published" }
    ]}
  },
  "propertiesOrder": ["name", "price", "status"]
}

Input parameters:

- `collectionId` (string, required): Collection ID (e.g., 'products')
- `projectId` (string, required): Firebase project ID
- `schema` (object, required): Complete collection schema definition

### `update_collection_schema` (~82 tokens)

Update a collection

Partially update an existing collection schema. Only the top-level fields given are changed (merged with the existing schema): for example the name, group, display settings or properties.

Input parameters:

- `collectionId` (string, required): Collection ID to update
- `data` (object, required): Fields to update (merged with existing schema)
- `projectId` (string, required): Firebase project ID

### `delete_collection_schema` (~74 tokens)

Delete a collection

Delete a collection schema from FireCMS. This removes the collection configuration 
from the CMS — it does NOT delete the underlying Firestore data. The collection will simply 
no longer appear in the FireCMS UI.

Input parameters:

- `collectionId` (string, required): Collection ID to delete
- `projectId` (string, required): Firebase project ID

### `save_property` (~166 tokens)

Save a property

Add or update a single property in a collection schema, leaving the other properties as they are. A new property is added at the end of the display order.

Example property:
{
  "dataType": "string",
  "name": "Description",
  "description": "Product description",
  "multiline": true,
  "validation": { "required": true, "max": 500 }
}

Input parameters:

- `collectionId` (string, required): Collection ID
- `namespace` (string): Dot-separated namespace for nested properties in maps (e.g., 'address' for address.street)
- `projectId` (string, required): Firebase project ID
- `property` (object, required): Property definition
- `propertyKey` (string, required): Property field key (e.g., 'description', 'price')

### `delete_property` (~85 tokens)

Delete a property

Remove a property from a collection schema. This removes the field definition from 
the CMS configuration — it does NOT delete the field from existing Firestore documents.

Input parameters:

- `collectionId` (string, required): Collection ID
- `namespace` (string): Dot-separated namespace for nested properties
- `projectId` (string, required): Firebase project ID
- `propertyKey` (string, required): Property key to remove

### `generate_collection` (~91 tokens)

Generate a collection with AI

Generate a new FireCMS collection schema using AI. Provide a natural language description 
of the collection you want (e.g., "A blog with posts that have title, body, author, tags, 
and a featured image"). Returns a complete FireCMS collection configuration.

Input parameters:

- `existingCollections` (array): Optional existing collection schemas for context
- `prompt` (string, required): Natural language description of the collection to generate

### `modify_collection` (~101 tokens)

Modify a collection with AI

Modify an existing FireCMS collection schema using AI. Describe the changes you want 
(e.g., "Add a priority enum with low/medium/high" or "Make title required with max 100 chars").
Returns the updated schema and a list of operations performed.

Input parameters:

- `existingCollection` (object, required): The current collection schema to modify
- `existingCollections` (array): Optional list of all collection schemas for context
- `prompt` (string, required): Description of the modifications

### `list_documents` (~127 tokens)

List documents

List documents from a Firestore collection, with optional filters, ordering and a limit.

Input parameters:

- `collectionPath` (string, required): Collection path (e.g., 'products', 'users', 'blog/posts')
- `databaseId` (string): Firestore database ID (default: '(default)')
- `filters` (array): Optional filters to apply
- `limit` (number): Max number of documents to return (default: 20)
- `orderBy` (string): Field to order by
- `orderDirection` (string): Sort direction
- `projectId` (string, required): Firebase project ID

### `get_document` (~83 tokens)

Get a document

Get a specific document by its collection path and ID. Returns all fields of the document.

Input parameters:

- `collectionPath` (string, required): Collection path (e.g., 'products', 'users')
- `databaseId` (string): Firestore database ID (default: '(default)')
- `documentId` (string, required): Document ID
- `projectId` (string, required): Firebase project ID

### `create_document` (~116 tokens)

Create a document

Create a new document in a Firestore collection. Provide the field values as a JSON object.

Input parameters:

- `collectionPath` (string, required): Collection path (e.g., 'products')
- `data` (object, required): Document fields as a JSON object
- `databaseId` (string): Firestore database ID (default: '(default)')
- `documentId` (string): Optional document ID. If not provided, Firestore generates one. If a document with this ID exists, it is replaced.
- `projectId` (string, required): Firebase project ID

### `update_document` (~97 tokens)

Update a document

Update fields of an existing document. Only the specified fields are modified (partial update / merge).

Input parameters:

- `collectionPath` (string, required): Collection path (e.g., 'products')
- `data` (object, required): Fields to update as a JSON object
- `databaseId` (string): Firestore database ID (default: '(default)')
- `documentId` (string, required): Document ID to update
- `projectId` (string, required): Firebase project ID

### `delete_document` (~76 tokens)

Delete a document

Delete a document from Firestore. This action is permanent.

Input parameters:

- `collectionPath` (string, required): Collection path (e.g., 'products')
- `databaseId` (string): Firestore database ID (default: '(default)')
- `documentId` (string, required): Document ID to delete
- `projectId` (string, required): Firebase project ID

### `count_documents` (~64 tokens)

Count documents

Count the total number of documents in a Firestore collection.

Input parameters:

- `collectionPath` (string, required): Collection path (e.g., 'products')
- `databaseId` (string): Firestore database ID (default: '(default)')
- `projectId` (string, required): Firebase project ID

### `export_collection` (~104 tokens)

Export a collection

Export documents from a Firestore collection as JSON. Useful for data backups,
analysis, or migration. For large collections, use the limit parameter.

Input parameters:

- `collectionPath` (string, required): Collection path to export (e.g., 'products')
- `databaseId` (string): Firestore database ID (default: '(default)')
- `limit` (number): Max documents to export (default: 100, max: 500)
- `projectId` (string, required): Firebase project ID

### `import_documents` (~155 tokens)

Import documents

Bulk import documents into a Firestore collection, for seeding data, migrations or restoring a backup. Each document can specify an ID; without one, Firestore generates it. By default a document with an existing ID is overwritten; with merge: true its fields are merged instead. At most 500 documents per call.

Input parameters:

- `collectionPath` (string, required): Target collection path (e.g., 'products')
- `databaseId` (string): Firestore database ID (default: '(default)')
- `documents` (array, required): Array of documents to import (max 500)
- `merge` (boolean): If true, merge with existing documents instead of overwriting (default: false)
- `projectId` (string, required): Firebase project ID

### `firecms_login` (~32 tokens)

Sign in to FireCMS

Sign in to FireCMS Cloud. Opens a browser window for Google OAuth authentication. Required before using any other tools.

### `firecms_logout` (~22 tokens)

Sign out of FireCMS

Sign out of FireCMS Cloud. Revokes the current session.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/co-firecms-mcp/firecms-mcp-server#diagnostics

## Score history

- 2026-10-01: 82
- 2026-09-30: 57

## Common questions

### What is the FireCMS Cloud MCP server?

FireCMS Cloud is an MCP server listed in the public MCP registry as co.firecms/mcp. Manage FireCMS Cloud from an AI agent: Firestore data, collections, schemas and users. This page covers its npm package (@firecms/mcp-server).

### Is the FireCMS Cloud MCP server safe to use?

FireCMS Cloud scores 82 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 1 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the FireCMS Cloud MCP server expose?

FireCMS Cloud exposes 45 tools: firecms_get_current_user, list_firebase_projects, get_project_setup_status, list_firestore_locations, enable_project_apis, and 40 more. Their descriptions and schemas cost roughly 3,917 tokens of context every time the server is loaded.

### Is the FireCMS Cloud MCP server still maintained?

FireCMS Cloud is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the FireCMS Cloud MCP server under?

FireCMS Cloud declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/@firecms/mcp-server
- Socket report: https://socket.dev/npm/package/@firecms/mcp-server
- Repository: https://github.com/firecmsco/firecms
- Website: https://firecms.co/docs/cloud/mcp_server
- Changelog RSS feed: https://verifymcp.io/servers/co-firecms-mcp/firecms-mcp-server.xml
- Changelog JSON feed: https://verifymcp.io/servers/co-firecms-mcp/firecms-mcp-server.json
- HTML version of this page: https://verifymcp.io/servers/co-firecms-mcp/firecms-mcp-server
