Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Search the live web, a 43-million-paper research index and public GitHub history.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Firecrawl connector gives Claude, ChatGPT and any MCP client live web search, a research index of roughly 43 million paper abstracts, and search over public GitHub issues and READMEs. Anthropic's directory lists six read-only tools. This is Firecrawl's deliberately narrowed search surface — it cannot scrape, crawl or extract a page you name.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
firecrawl:global names no object and no verb. It cannot exclude anything: granting it grants whatever the server implements, now and in future. The boundary protecting you here is the tool allowlist in code, not the consent screen — and those are different guarantees with different failure modes.https://mcp.firecrawl.dev/v2/mcp-oauth reaches 27 tools including firecrawl_crawl and firecrawl_monitor_delete. Nothing on this page assesses that surface.tools/list response we received. Source and directory agree exactly.ignoreRobotsTxt all require an enterprise plan or account-team enablement.robots.txt by default.No. It is Firecrawl's search-only surface at the /v2/mcp-search path, which exposes six read tools and nothing else. Firecrawl's own design note states registration on that instance is filtered against a fixed allowlist, so scrape, crawl, map, extract, agent, interact, parse and monitor are never registered there. The full surface lives at a different URL you would have to add yourself.
Not through this connector. The search surface's firecrawl_search takes no scrapeOptions, its schema rejects unknown fields, and Firecrawl states the outbound request body is built from an explicit allowed-field list rather than spread from raw arguments. Firecrawl's separate /v2/mcp endpoint does expose firecrawl_scrape and firecrawl_crawl, but that is a different server you add deliberately.
Yes, by design, and that is the main risk to plan for. Search highlights are on by default and replace each result's description with passages taken from the page itself, so third-party Markdown enters the model's context. Paper passages and GitHub issue text arrive the same way. Anyone who controls a page that ranks for your query controls text your agent reads.
Two credits per ten results, rounded up, so eleven results cost four. Firecrawl documents this rate for both web search and developer search. Every firecrawl_search response returns a creditsUsed field, so the spend is observable inline on each call rather than only in a dashboard. Firecrawl publishes no separate rate for the research paper endpoints.
It cannot delete anything, and spending does not necessarily stop. None of the six tools writes or deletes; the only delete in Firecrawl's MCP codebase, firecrawl_monitor_delete, is not registered on this surface. But Firecrawl's Smart Upgrade moves an exhausted account up one paid credit tier automatically and bills the pro-rated difference, so a zero balance is a purchase rather than a halt.
One wildcard scope called firecrawl:global. Firecrawl's RFC 9728 descriptor for the search resource advertised exactly that single scope on 2026-08-23, and its authorization server advertises the same scope plus offline_access. The name states no object and no verb, so consent cannot separate searching from anything else the server implements now or later.
Not through this connector, because it has no tool that fetches a URL you supply. The search surface accepts a query, never a target address. On Firecrawl's scraping endpoints, its open-source code does block loopback, RFC 1918 and link-local addresses at the resolved socket address, covering the cloud metadata endpoint. Firecrawl documents none of that anywhere, and we did not test it.
Yes to both, under two different licences. Firecrawl's core engine is AGPL-3.0, while the MCP server repository and the SDKs are MIT, and Firecrawl's README states SDKs and some UI components carry MIT terms. The MCP server can run locally over stdio or HTTP against either Firecrawl Cloud or a self-hosted API, though Agent, Browser and Interact are cloud-only.
firecrawl/firecrawl-mcp-server at branch main, MIT — · src/index.ts · src/research.ts (retrieved 2026-08-23). All 27 registered tool names were read from source. · retrieved 2026-08-23llms.txt (retrieved 2026-08-23). docs.firecrawl.dev/robots.txt carries Content-Signal: ai-train=yes, search=yes, ai-input=yes — synthesis expressly permitted by the publisher. · retrieved 2026-08-23initialize to the endpoint returned HTTP 401 with a www-authenticate Bearer challenge; RFC 9728 metadata read at https://mcp.firecrawl.dev/.well-known/oauth-protected-resource/v2/mcp-search; authorization server metadata at https://www.firecrawl.dev/.well-known/oauth-authorization-server. Three control paths returned matching 404s with identical body hashes, so the descriptor is genuine rather than a catch-all. · retrieved 2026-08-23Connect Firecrawl once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.