Adds live web search/scrape/crawl to any agent via the firecrawl-py SDK, wired to Firecrawl's clo...
140
Adds live web search/scrape/crawl to any agent via the firecrawl-py SDK, wired to Firecrawl's cloud API. Needs a key: `sbx secret set -g firecrawl` (the kit holds no key).
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 4.44.0 | firecrawl-py release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Required | Firecrawl API key (fc-...) from https://www.firecrawl.dev/app/api-keys | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit sbx/firecrawl:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
A kind: mixin kit that gives any Docker Sandboxes agent live web access through
Firecrawl: search the web, scrape a page to clean markdown, crawl a site,
and reach structured third-party data through Alexandria. It installs the firecrawl-py SDK as the agent
user and wires the API key through the sbx proxy, so the key never enters the sandbox.
Firecrawl maintains this kit at firecrawl/firecrawl-docker-sandbox,
which also publishes it as docker.io/firecrawl/firecrawl-docker-sandbox. The copy here tracks that
repository so the kit is discoverable alongside the other community kits.
Store a Firecrawl API key once (get one at https://www.firecrawl.dev/app/api-keys):
sbx secret set -g firecrawl
Then layer the kit onto any agent. From the image published by this repo:
sbx run --kit "docker.io/sbx/firecrawl:latest" claude
From this repo over git:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=firecrawl" claude
From a local clone:
sbx run --kit ./firecrawl/ claude
On the first run sbx asks you to approve sending the firecrawl credential to api.firecrawl.dev. Accept
the defaults; the value already lives in the secret store. The agent can then call the SDK directly:
from firecrawl import Firecrawl
fc = Firecrawl() # key handled by the proxy
fc.scrape("https://example.com", formats=["markdown"]) # one page -> clean markdown
fc.search("docker sandboxes mixin kit", limit=5) # search the web, get page content
fc.crawl("https://docs.example.com", limit=20) # crawl a site/section
fc.search("flight prices", sources=["alexandria"]) # Alexandria (beta): discover providers/tools
pip install --user firecrawl-py==<pinned> as user 1000, followed by an import check, so a
broken install fails sandbox creation instead of surfacing as a missing module mid-task. The pin lives in
firecrawl.yaml, once: a build-phase version arg that the descriptor's own version: (the published
tag), its provides entry and the install hook all resolve from.apiKey credential, proxyManaged, injected as a bearer token on api.firecrawl.dev
only. In-container FIRECRAWL_API_KEY is the proxy-managed sentinel.pypi.org and files.pythonhosted.org during the install phase, api.firecrawl.dev at
runtime. Nothing else is reachable, which the agent context explains to the agent (for example, URLs found
in a scrape result must be fetched through Firecrawl, not with curl).Most kits in this repo moved their v2 install hooks into a build-time overlay, because a v3 kit is an image and content that reads nothing from sandbox-create time belongs in a layer. This one did not.
pip install --user lands the SDK under ~/.local/lib/python3.<minor>/site-packages, and firecrawl-py
pulls in pydantic-core, a compiled wheel selected for the interpreter's ABI. Baking that into an overlay
would pin the kit to the Python version of whichever base it was built on — and this is a mixin, so the
base is chosen by whoever composes it, later. Installing at create time resolves against the Python that is
actually present, which is the property that has to hold.
The kit writes nothing to the host. Remove the stored key with sbx secret rm firecrawl if you no longer
need it.