# @firecms/mcp-server

MCP server for FireCMS Cloud — manage projects, collections, users, and AI features via the Model Context Protocol

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 3.5.1
- **Author:** Unknown
- **License:** MIT
- **npm:** @firecms/mcp-server
- **Endpoints:** streamable-http https://api.firecms.co/mcp
- **Source:** https://github.com/firecmsco/firecms
- **Endpoint health:** reachable (last checked 2026-10-06T23:49:29.606Z, 1 sample) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-06T23:49:08.125Z
- **Version scanned:** 3.5.1
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `firecms_login` — Sign in to FireCMS Cloud. Opens a browser window for Google OAuth authentication. Required before using any other tools.
- `firecms_logout` — Sign out of FireCMS Cloud. Revokes the current session.
- `list_collection_schemas` — List all persisted collection schemas for a FireCMS project. Returns the collection configurations (name, path, properties, etc.) that define how data is displa
- `get_collection_schema` — Get the full schema definition for a specific collection, including all properties, validation rules, display configuration, and subcollection definitions.
- `save_collection_schema`
- `update_collection_schema` — Partially update an existing collection schema. Only the top-level fields given are changed (merged with the existing schema): for example the name, group, disp
- `delete_collection_schema` — Delete a collection schema from FireCMS. This removes the collection configuration from the CMS — it does NOT delete the underlying Firestore data. The collecti
- `save_property` — Add or update a single property in a collection schema, leaving the other properties as they are. A new property is added at the end of the display order.
- `delete_property` — Remove a property from a collection schema. This removes the field definition from the CMS configuration — it does NOT delete the field from existing Firestore 
- `generate_collection` — Generate a new FireCMS collection schema using AI. Provide a natural language description of the collection you want (e.g., "A blog with posts that have title, 
- `modify_collection` — Modify an existing FireCMS collection schema using AI. Describe the changes you want (e.g., "Add a priority enum with low/medium/high" or "Make title required w
- `firecms_get_current_user` — Get the currently authenticated FireCMS user
- `list_documents` — List documents from a Firestore collection, with optional filters, ordering and a limit.
- `get_document` — Get a specific document by its collection path and ID. Returns all fields of the document.
- `create_document` — Create a new document in a Firestore collection. Provide the field values as a JSON object.
- `update_document` — Update fields of an existing document. Only the specified fields are modified (partial update / merge).
- `delete_document` — Delete a document from Firestore. This action is permanent.
- `count_documents` — Count the total number of documents in a Firestore collection.
- `export_collection` — Export documents from a Firestore collection as JSON. Useful for data backups, analysis, or migration. For large collections, use the limit parameter.
- `import_documents` — Bulk import documents into a Firestore collection, for seeding data, migrations or restoring a backup. Each document can specify an ID; without one, Firestore g
- `list_databases` — List the Firestore databases of a project. Only needed for projects using more
- `preview_inferred_schema` — Read a sample of real documents from a Firestore path and infer a FireCMS collection schema from them, without saving anything. Works for any path, subcollectio
- `infer_collections_from_data` — Infer collections from the existing Firestore data at the given paths, and save them to the project. Requires admin.
- `setup_all_collections` — Discover every Firestore root collection in the project that is not yet mapped to a collection, infer a collection schema for each (display names and widgets pi
- `connect_project_to_firecms` — Get the link to connect a Firebase project to FireCMS Cloud.
- `list_firebase_projects` — List the Google Cloud / Firebase projects the signed-in user can access, and whether each one is ready to be connected to FireCMS Cloud.
- `get_project_setup_status` — Get the detailed FireCMS readiness status of a single Google Cloud project: whether Firebase, Firestore, Storage, Auth and the required APIs are enabled, and so
- `list_firestore_locations` — List the locations available for a new Firestore database, as location IDs such as 'eur3' or 'us-central'.
- `enable_project_apis` — Enable the Google Cloud APIs that FireCMS requires on a project (reported as `apisEnabled` in its setup status). Safe to run more than once.
- `enable_firestore` — Create the default Firestore database in a Google Cloud project, in the given location. The location is permanent and cannot be changed later.
- `apply_firestore_security_rules` — Add FireCMS's access rule to a project's Firestore and Storage security rules. Requires admin.
- `create_firecms_webapp` — Create the FireCMS web app inside the client's Firebase project, or reuse the one already there. Connecting a project normally does this; this repairs a project
- `get_project_config` — Get the full configuration for a FireCMS project, including: - Project name, logo, and brand colors (primary/secondary) - Subscription plan and trial status - F
- `update_project_name` — Update the display name of a FireCMS project.
- `update_project_colors` — Update the primary and/or secondary brand colors for the CMS UI. Colors should be hex values (e.g., '#0070F4').
- `update_default_locale` — Change the default locale for the CMS (affects date formatting, etc.).
- `toggle_text_search` — Enable or disable the local text search feature for a project.
- `toggle_entity_history` — Enable or disable entity history tracking (audit log of document changes) for a project.
- `list_projects` — List all FireCMS Cloud projects accessible by the authenticated user
- `get_root_collections` — List all Firestore root-level collections in a FireCMS project — the

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp-server\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@firecms/mcp-server\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs locally and hosted.
- Floor 42, ceiling 66 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40firecms%2Fmcp-server
- Install plan: https://forgeregistry.com/api/v1/packages/%40firecms%2Fmcp-server/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40firecms%2Fmcp-server
- HTML page: https://forgeregistry.com/registry/%40firecms%2Fmcp-server
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
