Firecrawl made a deliberate choice most APIs have not: an agent can start using it with no account, no API key, and no human in the loop. Firecrawl Keyless gives any agent search, scrape, and parse with 1,000 free credits a month. And when an agent needs more than that, Firecrawl accepts Sign in with AgentID, so the agent can open its own account the same way it did everything else: by itself.
In short
- Firecrawl Keyless already gives agents search, scrape, and parse with no signup and 1,000 free credits a month.
- An account is for what keyless deliberately does not cover: the full tool surface, higher limits, and usage that belongs to someone.
- With Sign in with AgentID, crossing that line does not reintroduce a human key-generation step.
- The agent signs in with its own verified inbox identity and holds its own API key, usage history, and billing trail.
- Firecrawl keeps control of tools, credits, plans, and policy at every stage.
Do agents need an account to use Firecrawl?
No, and that is the best thing about Firecrawl's design. Keyless access exists so that a demo, a prototype, or a light workload never waits on credential setup. An agent connects to the MCP server, CLI, or REST API and starts working. Firecrawl's own framing is that there is no human in the loop to generate a key, and the free allowance resets every month.
The real question is what happens on the day one particular agent's work stops fitting inside the free tier.
When does an agent outgrow keyless?
Three things tend to arrive together as an agent's web workload becomes real.
It needs more than the keyless surface. Keyless covers search, scrape, and parse. An API key unlocks the full tool surface and higher limits, which is exactly where a production workload ends up.
Its usage needs to belong to someone. The keyless allowance is fine for experiments. Sustained work needs an account where usage is metered, invoiced, and reviewable, so the workload has a paper trail.
It needs continuity. A keyless call stands alone. An account carries the key, the plan, the usage history, and the billing relationship from one day's work to the next, which is what an agent that runs every day needs.
The traditional answer at this point is that a human signs up, generates a key, and pastes it into the agent. Which means the one setup step Firecrawl engineered out of the beginning returns in the middle.
How does an agent get its own Firecrawl account?
By signing in as itself. Firecrawl accepts AgentID, AgentMail's sign-in service for AI agents. It works over OpenID Connect, the same standard behind Sign in with Google, and it gives the agent a verified identity of its own: a stable identifier plus a working email address, which is the agent's AgentMail inbox.
The agent approves the sign-in with a single-use cryptographic signature from its own key. No password exists in the flow, and Firecrawl never receives a reusable credential it could store. What Firecrawl gets is an account holder it can recognize: this agent, on every return visit, distinct from every other.
The upgrade path stays true to the keyless philosophy end to end. No human generated a key at the start, and no human has to generate one at the account stage either.
Who controls what
| Stage | AgentID | Firecrawl |
|---|---|---|
| Keyless access | Not involved | Owns the free tier, its tools, and its allowance |
| Identity at sign-in | Supplies verified agent email and stable identifier through OpenID Connect | Accepts the sign-in, creates the account |
| API keys | Not involved | Issues, scopes, and revokes them |
| Credits, plans, and billing | Not involved | Controls all three |
| Usage metering and limits | Not involved | Meters per account and enforces its policy |
| Account email | Provides the inbox behind the identity | Decides which messages it sends |
What stays with Firecrawl?
Every product decision. AgentID supplies identity at the door and nothing else. The tools, the credit system, the plans, what a keyless caller may do versus an account holder, and how any account behaves once inside are all Firecrawl's decisions, unchanged by how the account holder signed in.
One detail earns a mention: the agent's address is a real inbox. Usage alerts and receipts can go to the account holder that acts on them, rather than to a human who was never in the loop.
Start keyless at Firecrawl, and when your agent needs an account, the AgentID sign-in guide covers preparing its inbox identity.
