Skip to content

feat: print the API's keyless signup link as-is and send X-Origin: cli - #291

Merged
rakshith48 merged 2 commits into
mainfrom
rak/keyless-short-links
Sep 30, 2026
Merged

rakshith48 merged 2 commits into
mainfrom
rak/keyless-short-links

Conversation

@rakshith48

@rakshith48 rakshith48 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The API now links keyless prompts to the caller's own https://firecrawl.dev/k/<token> signup link: a 12-character encrypted token that carries the keyless identity, the surface (read from the X-Origin: cli header this PR sends) and the prompt reason. So the CLI no longer rewrites utm_medium=api to cli, and prints the API's link as-is (including the regular signup link the API sends when it has no token).

  • Keyless error messages are printed exactly as the API sends them.
  • Keyless requests send X-Origin: cli, so the API issues a CLI link even for requests without a body (GET research and developer lookups, interact stop) and for multipart parse.

Release after the API change. Before it, CLI signups from the old link would be tagged api.

🤖 Generated with Claude Code


Summary by cubic

The CLI now prints the API's keyless signup links as-is and sends X-Origin: cli headers so the API attributes the link to the CLI.

  • Removes withCliSignupTag, which rewrote utm_medium=api to cli in keyless error messages.
  • Sends X-Origin: cli on all keyless requests, including GET requests and multipart parse, where no body carried the origin before.
  • Legacy UTM links from older API versions are printed unchanged instead of rewritten.
  • Bumps the CLI version to 1.25.0.

Requires the corresponding API change deployed first; before it, CLI signups from the old link are tagged api.

Written for commit 96a6932. Summary will update on new commits.

Review in cubic

Release: this PR bumps the version to firecrawl-cli 1.25.0, so merging it publishes to npm right away. Merge only after firecrawl/firecrawl#4856 is live.

Rollout order (ship in this order)

  1. firecrawl/firecrawl-db#310: migrations
  2. firecrawl/firecrawl-web#3849: /k/<token> route (must be live before the API ships, or new links 404; web and API must share KEYLESS_SIGNUP_LINK_KEYS)
  3. feat(api): link keyless prompts to opaque per-identity /k links firecrawl#4856: API issues the links
  4. feat: relay the caller's own keyless signup link from the API firecrawl-mcp-server#467: MCP relays them
  5. feat: print the API's keyless signup link as-is and send X-Origin: cli #291: CLI release

🤖 Generated with Claude Code

The API now links keyless prompts to the caller's own opaque signup link,
https://firecrawl.dev/k/<id>, issued per keyless identity and surface. The CLI
no longer rewrites utm_medium=api to cli in those messages (there is nothing to
rewrite), and instead identifies itself so the API issues a CLI link:
keyless requests send X-Origin: cli, which covers the requests without a body
(GET research and developer lookups, interact stop) and multipart parse, whose
options are parsed after auth.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Shadow auto-approve: would auto-approve. Client-side change confined to keyless headers and error messages: stops rewriting signup URLs, sends X-Origin: cli on keyless requests, with tests updated; rollout depends on the documented API change shipping first.

Re-trigger cubic

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Shadow auto-approve: would auto-approve. Bounded client-side keyless change: sends X-Origin: cli and prints the API's signup links as-is, with tests updated; delta since prior approval is only the 1.25.0 version bump, and the documented API-first rollout remains the merge condition.

Re-trigger cubic

@rakshith48
rakshith48 merged commit bceea7f into main Sep 30, 2026
8 checks passed
@rakshith48
rakshith48 deleted the rak/keyless-short-links branch September 30, 2026 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants