Provider REST API

Data

Connect Claude to Firecrawl

Extract clean, LLM-ready content from a web page. Toolspoke puts 8 of its actions behind one MCP endpoint that Claude, Cursor, and Codex all speak.

Connection
Provider REST API
Authentication
API key
Actions exposed
8
Cost per call (typical)
1 credit
Adapter
Maintained by Toolspoke

Connected in three steps

  1. 1

    Install Firecrawl

    Open the marketplace in your workspace, add Firecrawl to the project your agents work in, and it appears on the gateway immediately.

  2. 2

    Connect the credential

    Authenticate with api key. Where to get one, and what it has to be able to reach, is the next section.

  3. 3

    Point your agent at the gateway

    Give your client one address, https://toolspoke.com/mcp. Claude Code takes it as a command, Claude and Claude Desktop add it as a custom connector, and Cursor, Codex and VS Code each read it from a config file of their own.

.mcp.json
{
  "mcpServers": {
    "toolspoke": {
      "type": "http",
      "url": "https://toolspoke.com/mcp"
    }
  }
}

One block covers every tool you have installed. Firecrawl shows up in the client as soon as your policy allows it, and so does everything else you install later.

Where the address goes, per client

Claude Code

Run it in your project, then /mcp to sign in

claude mcp add --transport http toolspoke https://toolspoke.com/mcp
Claude and Claude Desktop

Settings, then Connectors, then Add custom connector

https://toolspoke.com/mcp
Cursor

~/.cursor/mcp.json, or .cursor/mcp.json for one project

{ "mcpServers": { "toolspoke": { "url": "https://toolspoke.com/mcp" } } }
Codex

~/.codex/config.toml

[mcp_servers.toolspoke]
url = "https://toolspoke.com/mcp"
VS Code

.vscode/mcp.json, or the MCP: Add Server command

{ "servers": { "toolspoke": { "type": "http", "url": "https://toolspoke.com/mcp" } } }

What Firecrawl asks for

API key. You provide it once, when you install the connector. Toolspoke encrypts it at rest and decrypts it only for the length of a single call, and the gateway attaches it to the outbound request itself, so it is never part of the arguments an agent sends.

API keyRequired
firecrawl.dev → Dashboard → API Keys
fc-…
Instance URLOptional
Only for a self-hosted Firecrawl; leave blank for the hosted cloud
https://firecrawl.internal

What Claude can do in Firecrawl

8 actions, each one declared and named by the connector rather than discovered at runtime. A workspace policy grants a person all of them, a hand-picked selection, everything on the read side, everything on the write side, or none.

Reads
5Reads
Writes
3Writes
Destructive
0Destructive

Reads

5

Fetches data and changes nothing.

  • scrape

    Scrape one URL and return clean, LLM-ready content. The default markdown format is what you want for reading a page; add "links", "html", "summary", or "screenshot" when you need them. Use map or crawl instead when you need more than one page.

  • map

    Discover the URLs on a site in a single fast call, without scraping their content. Use this first to decide what is worth scraping, or to check whether a site has the pages you expect. Pass `search` to rank the results by relevance.

  • search

    Run a web search and optionally scrape the results in the same call. Use this when you need current information but do not already know which URLs to read. Set scrapeOptions to get page content back with each hit.

  • crawl_status

    Check a crawl started by `crawl` and read the pages scraped so far. `status` is scraping, completed, or failed - poll every few seconds while it is scraping. Page content is trimmed: only `limit` pages come back, each cut to max_chars.

  • extract_status

    Check an extraction started by `extract` and read its result. `status` is processing, completed, failed, or cancelled; the structured data arrives under `data` once it is completed.

Writes

3

Creates or updates something on the other side.

  • crawl

    Start an asynchronous crawl of a whole site or section. Returns a job id immediately - poll crawl_status with it, do not expect content here. Crawls bill one credit per page, so keep `limit` tight; it defaults to 25 rather than Firecrawl's 10000.

  • cancel_crawl

    Stop a running crawl started by `crawl`, so it stops consuming credits. Pages already scraped stay readable through crawl_status until the job expires; this does not delete anything else.

  • extract

    Start an asynchronous job that pulls structured data matching a JSON schema out of one or more pages. Returns a job id - poll extract_status with it. Use this instead of scrape when you want fields, not prose; a wildcard URL such as https://example.com/* extracts across a whole site.

What it will not do

Enforced by the gateway rather than left to convention, which is why each of these can be stated flatly.

It cannot call anything else
The 8 actions above are the whole of it. A call to any other name is refused before it reaches Firecrawl rather than forwarded on, and connecting your account does not add to the list: it is fixed by the connector, not discovered at run time.
Nothing here deletes
This connector writes to Firecrawl, but nothing in it deletes or permanently alters anything.
It reaches no further than your credential
Toolspoke holds no access to Firecrawl of its own. Every call carries the credential you stored and nothing besides, so whatever that credential cannot reach, this connector cannot reach either.
It never hears from Firecrawl
Nothing is pushed to it. There is no webhook, no subscription and no polling, so this connector cannot notice by itself that something changed in Firecrawl. An agent has to ask.
It does not smooth over provider limits
Toolspoke does not retry, queue or back off around Firecrawl's own rate limits. A call that Firecrawl refuses comes back to the agent as a failed call.

Before you connect it

What can Claude do in Firecrawl?

8 named actions: 5 that only read and 3 that write. They include scrape, map and search. Nothing outside that list is reachable: the connector declares each operation by name rather than proxying whatever an agent asks for.

What credentials does the Firecrawl connector need?

API key. The connector asks for api key, and optionally instance url. Values are encrypted at rest and attached to the outbound request by the gateway, so they are never part of the arguments an agent sends and never reach the audit log.

Does the Firecrawl connector work with Cursor and Codex, or only Claude?

Any client that speaks MCP, and every one of them gets the same 8 actions. There is a single address, https://toolspoke.com/mcp. Claude Code adds it with claude mcp add --transport http, Claude and Claude Desktop take it as a custom connector in settings, Cursor reads it from .cursor/mcp.json, Codex from ~/.codex/config.toml, and VS Code from .vscode/mcp.json. Each of them signs in to the gateway itself, so there is no key to paste.

What does the Firecrawl connector not do?

The 8 actions above are the whole of it. A call to any other name is refused before it reaches Firecrawl rather than forwarded on, and connecting your account does not add to the list: it is fixed by the connector, not discovered at run time. This connector writes to Firecrawl, but nothing in it deletes or permanently alters anything. Toolspoke holds no access to Firecrawl of its own. Every call carries the credential you stored and nothing besides, so whatever that credential cannot reach, this connector cannot reach either. Nothing is pushed to it. There is no webhook, no subscription and no polling, so this connector cannot notice by itself that something changed in Firecrawl. An agent has to ask. Toolspoke does not retry, queue or back off around Firecrawl's own rate limits. A call that Firecrawl refuses comes back to the agent as a failed call.

Can I limit which actions an agent can call?

Yes, in two places. The project switches Firecrawl's actions on and off one at a time, for everyone in the project at once, and the screen groups them by read, write and destructive so turning off everything that deletes is one click. An individual agent key can then be narrowed further, to particular toolkits in a project and to particular actions in a toolkit. Whatever it was granted, a key never reaches a project its owner cannot.

What gets recorded when an agent calls Firecrawl?

Every attempt, with the agent that made it and the person that agent belongs to, the full request payload, the response payload, the status, the duration, and the credits spent. Values whose key names a secret are masked out before the record is shown to anyone. An operation the connector marks as not retained never has its response body written at all, so the gateway keeps no second copy of what was read.