MCP Directory

Firebase MCP Setup: CLI Credentials and the Right Project

Use the official Firebase MCP server from firebase-tools, authenticate the Firebase CLI, and verify the active project before reading or changing application data.

MCPtrove·October 7, 2026·6 min read
An extreme close-up of colorful programming code on a computer screen, showcasing development and software debugging.
Photo by Markus Spiske on Pexels

Use the official Firebase MCP server from firebase-tools, authenticate the Firebase CLI, and verify the active project before reading or changing application data. The most important setup decision is project context: a correctly connected assistant can still be pointed at the wrong Firebase project.

This guide follows official documentation checked on October 7, 2026. The Firebase directory entry currently links to a community implementation. Its package and credential instructions are separate from the official CLI route described here; check the publisher before copying a configuration.

Table of contents

Which Firebase MCP package should you use?

Choose firebase-tools when you want the official Firebase MCP implementation. Firebase-branded community packages are different software, and their capabilities, credentials, and maintenance practices should not be inferred from Google's documentation.

The official MCP guide describes a local stdio server that uses the credentials available to the Firebase CLI. It also warns that some tools interact with remote services. Local execution therefore does not mean every operation is offline or every data read stays on your computer.

Before installing anything, identify the job: inspecting a development project's configuration, retrieving a known document, or investigating an application error. Those are sensible starting points. “Build my entire backend” makes it difficult to separate a successful connection from a series of unreviewed infrastructure decisions.

Record the chosen package and client configuration location. If a community Firebase server is already enabled, disable it during the official connection test so the assistant cannot silently choose between similarly named tools. Keep its configuration recoverable without retaining credentials in version control.

How do you establish the CLI identity?

Authenticate the Firebase CLI and confirm which projects the identity can access before asking an editor to use that identity. An editor connection should inherit an understood credential context, rather than becoming the place where you discover which Google account was active.

Following the Firebase CLI reference, use a working Node.js and npm installation, then run:

npx -y firebase-tools@latest login
npx -y firebase-tools@latest projects:list

Complete the browser flow with the account intended for the project. Compare a project ID in the list with the Firebase console. A friendly display name is useful, but the immutable identifier is the safer thing to carry into later checks.

In managed environments, authentication may come from Application Default Credentials instead of an interactive login. Treat that as a separate identity source to inspect. Do not copy a service-account private key into your editor configuration simply because another tutorial uses one.

Firebase's IAM overview explains project access through roles assigned to principals. Start from the access the task actually requires. If a read operation fails, identify the missing permission before granting a broader role; an owner role is not a general-purpose connection repair.

A laptop screen shows a coding application with a calculator design in a tech office setting.
Photo by Eduardo Rosas on Pexels

How do you configure the MCP client?

Configure a local stdio process that launches firebase-tools mcp, using the schema your client expects. The command can be the same across editors while the surrounding configuration object differs, so do not copy an entire file from a different client.

For Cursor, the official guide documents:

{
  "mcpServers": {
    "firebase": {
      "command": "npx",
      "args": ["-y", "firebase-tools@latest", "mcp"]
    }
  }
}

Merge this entry into .cursor/mcp.json for a project-specific connection. Our Cursor guide covers configuration placement. Use the configuration validator before reloading the client so a missing comma does not get mistaken for an authentication failure.

The Firebase MCP instructions also document --dir for an absolute project directory and --only for selected feature groups. Core tools remain available. A feature filter reduces the tools shown to the assistant; it is not a read-only permission boundary.

For a desktop application, remember that its process may have a different working directory or executable path from your terminal. Confirm the project directory deliberately rather than assuming the repository visible in another window determines the MCP process's context.

How do you confirm project and database context?

Ask the connected assistant to identify its active Firebase environment and project, then compare those details with the console before requesting application data. Directory context, project selection, and database selection should all be explicit when a task could affect more than one backend.

Use a verification request such as: “Inspect the current Firebase environment and active project. Report the project ID and local directory without changing either. Do not deploy, create resources, or modify users.” Inspect the returned tool result rather than accepting a guessed project name in the final answer.

The CLI reference explains project aliases and project selection. Check the repository's Firebase configuration and selected alias when moving between development and production. A directory containing an application's source code is not, by itself, proof that its selected cloud project is the development one.

ContextWhat you should recordWhat can go wrong
Local directoryThe intended app directoryEditor starts from another location
Authenticated identityIntended user or workload identityCached credentials belong to another account
Firebase projectExact project IDAlias points at production
Data targetDatabase and document pathFamiliar collection name exists elsewhere

Stop the verification sequence if these disagree. Correct the specific selection, then repeat the read check rather than trying to compensate with a more restrictive natural-language prompt.

What does a useful first read test prove?

A useful first test retrieves one known, non-sensitive record or configuration item and reproduces what you can see in the Firebase console. It establishes targeting and access without requiring a write or a broad export of user data.

Choose a document that your team already uses for development checks. Ask for its identifier, a small set of expected fields, and the selected project. Compare values with the console. Do not ask the assistant to list every user or scan an entire collection just to prove connectivity.

For local application testing, the Firebase Emulator Suite overview describes tools for developing and testing against emulated services. However, an emulator running in one terminal does not establish that every MCP operation uses it. Confirm the target used by the particular operation before treating a test as isolated.

Keep a small acceptance record: project, data target, operation, expected result, observed result, and date. Omit personal information and credentials. If the result is empty, distinguish “the requested record is absent” from “the query used the wrong project or database.”

Our recommendation is to finish this read test before enabling any workflow that edits Authentication users, changes rules, sends messages, or deploys. Each of those requires its own outcome check, beyond a healthy server connection.

How do you diagnose failures without widening access?

Work through startup, credentials, project context, and permissions in that order. It is faster and safer than reinstalling packages, changing accounts, and granting new roles simultaneously, because each step preserves evidence about the actual cause.

If the client cannot launch npx, inspect the local runtime and process path. If tools load but authentication fails, compare the credential context with the working CLI session. If the wrong project appears, fix selection before investigating individual database permissions.

The IAM documentation is the authority for project access. Configuration tools cannot validate an account's effective permissions. Use Config Doctor to inspect the client configuration layer, then preserve a redacted service error for an administrator when the failure is authorization-related.

Do not weaken application security rules as a generic MCP repair. First establish which identity and API are making the request and which permission failed. Finally, repeat the original narrow read test after the fix. A different successful operation may hide the fact that the intended workflow still does not work.

FAQ

Does local MCP mean the data stays local?

No. The process runs locally, but tools can interact with cloud-hosted Firebase services. Inspect the operation and its target before assuming it is an offline action.

Is --only firestore a read-only mode?

No. Feature selection changes which tool groups are exposed, and core tools remain available. Use appropriate permissions and review controls to limit consequential actions.

Does Firebase Studio use the same config file as Cursor?

No. Firebase Studio documents .idx/mcp.json, while Cursor uses its own MCP configuration locations. Follow the instructions for the client you are actually running.

Can the server replace IAM permissions?

No. A configured connection does not grant missing project access. Resolve the relevant identity and role assignment instead of expecting the assistant to bypass authorization.

Put this into practice

Browse MCP servers by capability, or check your own setup's tool budget and security.

More in Integrations

Browse all integrations articles.