feat: print the API's keyless signup link as-is and send X-Origin: cli - #291
Conversation
The API now links keyless prompts to the caller's own opaque signup link, https://firecrawl.dev/k/<id>, issued per keyless identity and surface. The CLI no longer rewrites utm_medium=api to cli in those messages (there is nothing to rewrite), and instead identifies itself so the API issues a CLI link: keyless requests send X-Origin: cli, which covers the requests without a body (GET research and developer lookups, interact stop) and multipart parse, whose options are parsed after auth. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
No issues found across 5 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Shadow auto-approve: would auto-approve. Client-side change confined to keyless headers and error messages: stops rewriting signup URLs, sends X-Origin: cli on keyless requests, with tests updated; rollout depends on the documented API change shipping first.
Re-trigger cubic
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
0 issues found across 1 file (changes from recent commits).
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Shadow auto-approve: would auto-approve. Bounded client-side keyless change: sends X-Origin: cli and prints the API's signup links as-is, with tests updated; delta since prior approval is only the 1.25.0 version bump, and the documented API-first rollout remains the merge condition.
Re-trigger cubic
The API now links keyless prompts to the caller's own
https://firecrawl.dev/k/<token>signup link: a 12-character encrypted token that carries the keyless identity, the surface (read from theX-Origin: cliheader this PR sends) and the prompt reason. So the CLI no longer rewritesutm_medium=apitocli, and prints the API's link as-is (including the regular signup link the API sends when it has no token).X-Origin: cli, so the API issues a CLI link even for requests without a body (GET research and developer lookups, interact stop) and for multipart parse.Release after the API change. Before it, CLI signups from the old link would be tagged
api.🤖 Generated with Claude Code
Summary by cubic
The CLI now prints the API's keyless signup links as-is and sends
X-Origin: cliheaders so the API attributes the link to the CLI.withCliSignupTag, which rewroteutm_medium=apitocliin keyless error messages.X-Origin: clion all keyless requests, including GET requests and multipart parse, where no body carried the origin before.Requires the corresponding API change deployed first; before it, CLI signups from the old link are tagged
api.Written for commit 96a6932. Summary will update on new commits.
Release: this PR bumps the version to firecrawl-cli 1.25.0, so merging it publishes to npm right away. Merge only after firecrawl/firecrawl#4856 is live.
Rollout order (ship in this order)
/k/<token>route (must be live before the API ships, or new links 404; web and API must shareKEYLESS_SIGNUP_LINK_KEYS)🤖 Generated with Claude Code