Install
Get the installer for your system from the download page: choose your system and Download now (no email needed), or have the link emailed to you.
Windows 10 and 11
Run Firetool-…-windows-x64-setup.exe (or …-windows-x86-setup.exe on 32-bit Windows). It installs for your Windows account only, needs no administrator rights, and adds Firetool to the Start menu. Firetool isn't code-signed yet, so Windows may show "Windows protected your PC": choose More info, then Run anyway. The Microsoft Store version, once it's live, installs without that warning.
macOS 11 or newer
When your download is ready, the page shows a one-line Terminal command. Paste it into Terminal and press Return: it downloads Firetool, checks its SHA-256, installs it in Applications and opens it. (A zip opened from the browser is called "damaged" by macOS because Firetool isn't notarized by Apple yet.)
Linux
sudo apt install ./Firetool-2.24.1-linux-x64.deb
On Ubuntu, Debian and Mint, or unpack the .tar.gz and run its install.sh for a per-user install. Start it from your applications menu or with the firetool command.
Connect to Firestore
Open Firetool and choose Add account (at the bottom of the sidebar, or the + button at its top). Nothing connects until you choose one of these:
- Continue with Google: sign in on Google's page in your browser, so you see every Firebase project your account can open. Firetool uses the Google Cloud CLI for this; if it isn't installed, the app tells you how to get it.
- Google Cloud CLI: if you've already signed in with
gcloud auth application-default login, Firetool shows that account and uses it only if you choose it. On the first start it asks. - Add service account: choose a service account key file (JSON) from Google Cloud Console. The key is encrypted on your computer. Give the service account the
Cloud Datastore Userrole to read and write, orCloud Datastore Viewerfor read-only. - Connect to emulator: enter the Firestore emulator address (for example
127.0.0.1:8080), the Authentication emulator address if you use it, and your project IDs.
Browse and query
Expand a project in the sidebar and click a collection: it opens in a tab. In the query bar:
- Filter adds conditions (
==,in,>,array-containsand the rest); choose whether all or any must match. - Sort orders by any field, and # sets how many documents to read.
- Group queries every collection with that name (a collection group).
- Totals counts, sums or averages everything the query matches without loading it.
- The project button in the query bar moves the same query to another project or database.
Switch between Table, Tree and JSON views; click a row to open the document.
Edit and import
Edit a field right in the table, or edit the whole document in the JSON editor and choose Save. Only the fields you changed are sent, types are kept exactly, and if someone else saved the document since you opened it you're asked first.
To change a field in many documents, right-click its column header and choose Set a value, Rename field or Delete field. You see how many documents will change before anything is written. Import reads CSV or JSON, with a type for each CSV column.
Export and back up
Choose Export, then CSV or JSON, for the rows you see or everything the query matches. CSV opens cleanly in Excel, with nested fields as their own columns.
Right-click a collection and choose Back up collection (or right-click the database for every collection). A backup keeps subcollections, exact numbers and timestamps. Restore a backup puts it back in the same or another project.
Transfer data between projects
- Choose Tools, Data transfer (Ctrl+Shift+T), or right-click a database and choose Transfer collections.
- Pick the source and target project and database.
- Tick the collections. Optionally: custom target paths, empty the target collections first, or a limit per collection.
- Under If a document already exists, choose Keep it: add only new documents or Replace it.
- Choose Start transfer. Stop at any time; Resume carries on without duplicates.
If the target is marked production, you're asked for its project ID once before the transfer starts. A read-only target is refused before anything is read.
JS queries
Switch a tab to JS Query and write JavaScript in the style of the Firebase Admin SDK. Return a query or any value, and the result is shown as a table or JSON.
// Paid orders over 5,000, newest first
return db.collection("orders")
.where("status", "==", "paid")
.where("total", ">", 5000)
.orderBy("createdAt", "desc")
.limit(50)
.get();
// Count and total without reading every document
const agg = await db.collection("orders").where("status", "==", "paid")
.aggregate({ orders: AggregateField.count(), revenue: AggregateField.sum("total") }).get();
return agg.data();
Batches, transactions, FieldValue, findNearest() and explain() work as in the Admin SDK, and auth.getUserByEmail() and friends reach Firebase Authentication. Scripts run in a separate process that can't read your files, and every write passes the same checks as the rest of the app.
Firebase Authentication
Click Authentication under a project in the sidebar. Find users by email, phone number or UID, or list them page by page; then create, disable, delete, edit custom claims, make password reset or verification links, or sign a user out everywhere.
Production and read-only
Right-click a project and choose Project settings (or right-click a database and choose Settings):
- Production: deletes, scripts, bulk changes and new indexes ask for the project ID to be typed, once per operation. Editing one document doesn't ask.
- Read-only: nothing in that project or database can be changed from Firetool, whatever someone's role. Browsing, queries and exports still work.
The sidebar shows prod and read-only tags, and tabs show a badge. More rules (a reason for every change, protected collections, delete limits, roles per Google account) are in Tools, Policy and roles.
Audit log
Tools, Audit log lists every change with who, when, what and why. Changes with a saved copy show restorable: open one and choose Restore. Verify integrity checks that no entry was edited or removed, and Export CSV saves the log.
Scheduled exports
Tools, Scheduled exports runs an export daily, weekly or hourly through Windows Task Scheduler, launchd on macOS or cron on Linux, even when Firetool is closed. Each file gets a .sha256 checksum, and old files can be removed after a number of days.
For IT teams
The Windows installer installs per user with no admin rights. Install silently with:
Firetool-2.24.1-windows-x64-setup.exe /S
To apply the same rules on every PC, save a policy from Tools, Policy and roles, Save policy file for IT, then copy it to:
| System | Policy file |
|---|---|
| Windows | C:\ProgramData\Firetool\policy.json |
| macOS | /Library/Application Support/Firetool/policy.json |
| Linux | /etc/firetool/policy.json |
Make it read-only for standard users. Firetool then uses it and can't change it. For example:
{
"defaultRole": "viewer",
"users": { "lead@yourcompany.com": "editor" },
"projects": {
"shop-production": { "production": true, "requireReason": true, "noDeleteCollections": ["orders"] }
},
"updateChecks": false
}
Licences
The first time Firetool opens, it offers a 30-day Pro trial: enter your email, then the 6-digit code we email you. One trial per person and per computer; Continue with Free skips it, and Help, Licence starts it later. To add a licence, choose Help, Licence and enter your email and key. One licence is for one person on one computer; Move it to this computer takes it to a new PC, and Email me my key resends it. See pricing.
Troubleshooting
- Windows protected your PC: choose More info, then Run anyway. The installer isn't code-signed yet.
- macOS says the app is damaged: install with the Terminal command from the download page instead of opening the zip.
- Can't connect from an office network: Firetool follows the system proxy; set one in Settings, Network proxy if yours needs it.
- A query needs an index: the error offers to create it; or see Tools, Composite indexes.
- Anything else: Help, Report a problem sends us a message, with the diagnostics if you choose, or contact us.