
FireCMS Cloud
co.firecmsv3.5.0更新於 Sep 30, 2026
Manage FireCMS Cloud from an AI agent: Firestore data, collections, schemas and users.
概覽
讓助理把 Firebase 專案接入 FireCMS Cloud,並管理其 Firestore 資料、集合結構、設定與使用者。
- 功能
- FireCMS Cloud 的 MCP 伺服器提供 Firestore 文件增刪改查工具(列出、取得、建立、更新、刪除、計數)、集合結構管理(儲存、更新、刪除結構與屬性)、專案設定以及使用者與角色管理。它能從現有 Firestore 文件推斷集合結構,包括非破壞性的預覽,也能依提示用 AI 產生或修改結構。引導工具可列出 Google Cloud 專案、啟用 API、建立 Firestore 資料庫並把專案接入 FireCMS。它還能將集合資料匯出為 JSON,並批次匯入文件。
- 適用情境
- 當你希望助理把現有 Firebase 專案接入 FireCMS、從 Firestore 既有資料推斷集合,或透過對話瀏覽與編輯 Firestore 文件及 CMS 結構時使用。它也適合日常 CMS 管理,例如重新命名專案、調整品牌顏色、開關功能以及管理專案使用者。
- 執行需求
- 可使用託管遠端端點(瀏覽器 OAuth 登入,無需安裝),或透過 stdio 執行本機 npm 套件 @firecms/mcp-server,後者需要 Node.js 並透過 firecms_login 登入 Google 帳號。本機權杖保存在 ~/.firecms/tokens.json,與 FireCMS CLI 共用。接入專案前必須在 Firebase 主控台手動啟用 Firebase Authentication。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 FireCMS Cloud,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"mcp": {
"type": "http",
"url": "https://api.firecms.co/mcp"
}
}
}README
@firecms/mcp-server
MCP server for FireCMS Cloud. Lets AI assistants connect a Firebase project to FireCMS, infer collections from the data already in Firestore, and then manage the CMS — browse and edit data, shape collection schemas and properties, configure the project, and manage users.
Admin-only: All write operations require the authenticated user to have the
adminrole on the target project. Read operations are available to any authenticated project member. Onboarding tools run before a project exists, so they are gated by Google Cloud access instead.
The same server runs in two places:
- Hosted, at
https://api.firecms.co/mcp, for everyone. Clients sign in with OAuth in the browser; nothing to install. It holds no Google Cloud credentials, so connecting a new Firebase project is handed off to the web app. The FireCMS backend mounts it through the@firecms/mcp-server/hostedentry point. - Local, over stdio (
npx @firecms/mcp-server). It signs in with your Google account (firecms_login), so it can also enable APIs, create Firestore databases and connect projects end to end.
Hosted server
In Claude (claude.ai or Claude Desktop): Settings → Connectors → Add custom connector, and paste https://api.firecms.co/mcp.
In Claude Code:
Any other client that takes remote servers by URL:
Local server
Setup
Claude Desktop
Add to claude_desktop_config.json:
Or use npx (no build required):
Use firecms_login to sign in when prompted. Tokens are shared with the FireCMS CLI (~/.firecms/tokens.json).
Connecting an existing Firebase project
The typical first session. Everything here is driven by the Google account you logged in with.
Firebase Authentication must be enabled on the project before step 5 — it is the one prerequisite with no API, so turn it on in the Firebase console. Step 5 then adds FireCMS's access rule to the project's Firestore and Storage rules; without it the CMS reports "Missing Firestore Security Rules" and opens nothing, and no tool here would notice, because they all read through the backend's service account, which bypasses security rules.
Step 6 is where an existing project becomes a working CMS: FireCMS samples the documents at each root collection, infers the property types, and uses an LLM to pick display names, a singular name, an icon and a navigation group.
Building collections from existing data
preview_inferred_schema is the non-destructive option: it samples up to 200 documents, infers types, enums and validation locally, and hands back a draft you can edit and then persist with save_collection_schema. It also works for subcollections and any path the bulk tools skip.
infer_collections_from_data and setup_all_collections go through the backend, which adds the LLM pass and writes the result straight into the project. Both skip paths that already map to a collection, so they are safe to re-run as the database grows.
Tools
Auth
Onboarding
Projects & Root Collections
Project Configuration 🔒
Users 🔒
Collection Schemas 🔒
AI Schema Generation
Documents (Firestore CRUD)
Data Import & Export
🔒 = Admin-only operation · 💻 = local server only
Every tool declares a title and a readOnlyHint, plus a destructiveHint when it writes: false for tools that only add (create a document, invite a user), true for anything that can overwrite or delete.
Resources
Example Workflows
Bring an existing Firebase project into FireCMS
Create a collection from scratch
Shape a schema before committing to it
AI-assisted schema creation
Architecture
Sessions: local and hosted
Nothing reads credentials from process-wide state. Every API call goes through a FireCMSSession (session.ts) — the user's email, a Firebase ID token on firecms-backend, and a Google access token when there is one — passed to createFireCMSMcpServer():
- Local (
cli.ts):localSessionreads the CLI's tokens file and exchanges the Google ID token for a backend token (below). The login/logout tools are registered by the CLI only. - Hosted (
hosted.ts): the backend resolves each request's OAuth bearer token to a user and passes a session that mints that user's backend ID token. There is no Google token, so the Google Cloud tools are replaced by aconnect_project_to_firecmsthat links to the web app. Every request gets its own server and transport (stateless Streamable HTTP), so nothing of one person's session outlives their request.hosted.tsnever imports the CLI's login flow; a test walks its import graph to keep it that way.
Authentication
The FireCMS Cloud API expects two different tokens, and the server sends both — the same pair the web app sends:
firecms login only produces the Google credentials. The Google ID token is not a Firebase ID token — it is issued by accounts.google.com for the Google OAuth client, so verifyIdToken() rejects it. backend-auth.ts therefore exchanges it for a real firecms-backend token through Identity Toolkit signInWithIdp, which is the headless equivalent of the web app's signInWithPopup(auth, GoogleAuthProvider). The exchanged token is cached in memory until shortly before it expires.
Where collection configurations live
FireCMS Cloud reads collection configurations from the backend Firestore, at projects/{projectId}/collections/{collectionId} — see useFirestoreCollectionsConfigController in FireCMSCloudApp.tsx. That is not the client project's __FIRECMS/config/collections, which is the self-hosted layout and is never read by Cloud.
The backend exposes no REST endpoints for that store — the web app writes to it directly with the Firebase SDK — so backend-firestore.ts talks to the Firestore REST API with the exchanged Firebase token. The backend's security rules apply unchanged.
Document CRUD is different: it is proxied by the backend into the client's Firestore using the project's delegated service account.
Cache-aware collection discovery
The backend's firestore_root_collections endpoint caches its answer for 5 minutes per project, so it misses collections created since the last lookup — including every collection of a project connected moments ago. Discovery therefore goes through the uncached admin/collections/list endpoint, and setup_all_collections resolves the paths itself rather than delegating to initial_setup, which resolves them through that same cache.
infer_collections_from_data also refuses paths with no documents. The backend runs its LLM pass regardless, and with nothing to sample the model invents a schema from the path name alone — an empty articles path yields plausible title/slug/status/author fields that exist nowhere in the data.
stdout is reserved
On a stdio transport, stdout carries the JSON-RPC stream, so cli.ts routes every console channel to stderr before starting. Dependencies do log — @firecms/schema_inference logs while inferring properties — and a single stray console.log would corrupt the protocol stream.
Security
- Hosted authentication: OAuth 2.1 with PKCE against the FireCMS backend; the person approves each client in the web app. The backend stores tokens only as hashes, rotates refresh tokens, and never holds Google Cloud credentials
- Local authentication: Google OAuth via browser, same as
firecms loginCLI - Authorization: Write operations enforce admin role check per project
- Token storage:
~/.firecms/tokens.json(shared with CLI); the exchanged backend token is held in memory only and dropped on logout - Admin cache: Role checks are cached for 5 minutes per project
- Credential hygiene:
list_projectsstrips each project's service account from its output, so credentials are never serialised into the model's context
來源:packages/mcp_server/README.md,提交 74bd4a2
工具
0版本歷史
1- v3.5.0最新Sep 30, 2026

