| FMRS | 70 / 100 · B | 75 / 100 · B | 73 / 100 · B |
| Reliability | 9 / 20 | 13 / 20 | 12 / 20 |
|---|
| Security and permissions | 14 / 20 | 12 / 20 | 13 / 20 |
|---|
| Maintenance | 18 / 20 | 16 / 20 | 16 / 20 |
|---|
| Documentation | 17 / 20 | 17 / 20 | 16 / 20 |
|---|
| Setup experience | 12 / 20 | 17 / 20 | 16 / 20 |
| Best for | - Privacy-conscious researchers and developers who want to run LLMs and search fully locally
- Users already running local models via Ollama, LM Studio, or llama.cpp
- People who want to give Claude multi-engine academic search and structured report generation
- Local, STDIO-based integration into Claude Desktop or Claude Code
| - Scenarios needing clean, structured web context fed to an AI assistant
- Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
| - Q&A and research scenarios that need real-time, clean web content
- Users with an existing Exa account who want a zero-deployment remote option
|
| Not for | - Multi-user or network-exposed deployments — this MCP server has no built-in authentication or rate limiting and is documented as local-use only
- Users wanting a zero-config tool — it requires configuring an LLM provider and a search engine, and sometimes deploying SearXNG
- Teams needing real-time multi-user collaboration features
| - Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
- Sites that explicitly disallow automated access (robots.txt)
| - Scenarios requiring a strict allowlist of search sources that can't use a third-party search service
- Budget-sensitive, high-volume search scenarios (remote/API calls may incur cost)
|
| Required permissions | - Access to a configured LLM (local endpoint or cloud API key)
- Outbound network access to call configured search engines (arXiv, PubMed, SearXNG, Brave, etc.), unless restricted to local documents only
- Local filesystem read access for analyze_documents to work with private documents
- Read/write access to the local encrypted (SQLCipher) database
| - Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
- firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
| - Requires an Exa API key for full functionality; OAuth login is optional in remote mode
- web_fetch_exa retrieves content from a specified URL; agent_run performs multi-step autonomous actions and needs the user to have clear expectations of Agent behavior
|
| Risks and side effects | - The docs explicitly warn this MCP server is designed for local use only via STDIO transport, has no built-in authentication or rate limiting, and should not be exposed over a network without additional security controls
- Credentials (e.g. API keys) are held in process memory during active sessions, a routine runtime risk the project mitigates with session-scoped credential lifetimes and core dump exclusion
- Research queries are sent to whichever search engines are configured, and cloud LLM providers (OpenAI, Anthropic, Google, etc.) receive query/document content when selected
- Docker's --network host mode can silently fail to expose ports or misroute localhost on Windows/WSL2/Mac
| - Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
- firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
| - The API key should be stored carefully — avoid leaving it in plaintext in client config files on untrusted machines
- agent_run is a multi-step autonomous tool with a longer action chain — try it on low-risk tasks first
|
| Supported clients | Claude Desktop, Claude Code | Claude Desktop, VS Code, Cursor, Windsurf, Zed, Amp | Claude Desktop, Claude Code, VS Code, Cursor, Windsurf, Zed, Amp, Kiro, LM Studio, Antigravity |
| Tools | 8 | 11 | 4 |