Firebase Ships a Codex Plugin That Provisions Your Backend Firebase released an official plugin for OpenAI's Codex on Sept. 28, 2026, bundling Firebase agent skills, the Firebase MCP server and the Firebase CLI so the coding agent can provision a Firebase project, database instance and schema, add Firebase Authentication and write starter Security Rules from a prompt. Firebase developer advocate Sumit Chandel wrote that the plugin installs via a Codex Plugins menu search for "Firebase" or the terminal commands `codex plugin marketplace add firebase/agent-skills` and `codex plugin add firebase@firebase`, with Claude Code, Cursor and Antigravity listed as supported agents. Independent Codex knowledge-base operator Daniel Vaughan warned that the MCP server inherits the Firebase CLI session and in `full-auto` mode "the agent can modify production data," recommending the `suggest` or `auto-edit` approval modes and the `--only` flag to trim the server's 50-plus tools; Firebase's post does not state whether the plugin ships with those guardrails. Firebase Ships a Codex Plugin That Provisions Your Backend Firebase's new Codex plugin bundles agent skills, the MCP server and the CLI so Codex can create projects, add Auth and write Security Rules from a prompt. Firebase released an official plugin for OpenAI’s Codex on Sept. 28, letting the coding agent provision a Firebase project, a database and Authentication from a plain prompt The Firebase plugin is now available in Codex, Firebase Blog, Sept. 2026 https://firebase.blog/posts/2026/09/firebase-plugin-for-codex . The plugin packages what developers previously wired up by hand. What’s in it Sumit Chandel, a Firebase developer advocate, wrote that the plugin bundles three pieces: Firebase agent skills, the Firebase MCP server and the Firebase CLI. The skills carry current documentation and Firebase’s recommended patterns. The MCP server handles database queries, user management and doc lookups. The CLI does project setup and deploys. With all three installed, the post says, Codex can provision a project plus a database instance and schema, add Firebase Authentication “usually by default,” write starter Security Rules and audit those rules before production. Install is a menu path: open a Codex project, go to Plugins, search “Firebase,” install. Firebase’s agent-skills docs also list a terminal route, codex plugin marketplace add firebase/agent-skills , followed by codex plugin add firebase@firebase . The same docs page lists Claude Code, Cursor and Antigravity as supported agents. Chandel’s post lists the catches. Users may need to accept Firebase’s terms in the console and sign in with a Google account. Firebase also recommends working through its launch checklist before production. The manual route it replaces Codex could already talk to Firebase. Daniel Vaughan, who runs an independent Codex knowledge base, documented the manual setup in a May 25 post: add the MCP server to ~/.codex/config.toml , then run npx skills add firebase/agent-skills --agent=codex . His warning is the part the plugin’s announcement skips. The MCP server, he wrote, inherits your Firebase CLI session, and in full-auto mode “the agent can modify production data.” He recommends the suggest or auto-edit approval modes for production projects and the --only flag to trim the server’s 50-plus tools. Whether the plugin ships with those guardrails isn’t stated in Firebase’s post. Firerun couldn’t confirm it. Firerun’s take One-click install removes the setup friction. It also removes the moment where a developer reads a config file and sees what access they’re granting. An agent that can write Security Rules and deploy them is holding the same credentials as the developer who invoked it. The rules audit is the useful part. Rules written by a model and shipped unread are how open databases happen. Treat the plugin’s rules output as a draft, run it against the Emulator Suite, and keep Codex out of full-auto on any project with real users.