← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionHeimdall MCP ServerOne tool standing watch over your entire App Store Connect accountContext7Upstash's official server providing up-to-date third-party library docs for AI coding assistantsNPM Sentinel MCP ServerAI-powered NPM package analysis MCP server
FMRS61 / 100 · C80 / 100 · B79 / 100 · B
Reliability8 / 2014 / 2012 / 20
Security and permissions14 / 2016 / 2016 / 20
Maintenance12 / 2017 / 2018 / 20
Documentation14 / 2015 / 2018 / 20
Setup experience13 / 2018 / 2015 / 20
Best for
  • iOS/macOS developers and release teams needing every App Store Connect endpoint
  • Anyone working with subscriptions, IAP, StoreKit 2 transactions and refunds
  • Users who want confirm-before-write safety and local key custody
  • Teams using multiple MCP clients (Claude, Codex, Cursor) wanting one-step registration
  • Developers using fast-moving frameworks/libraries worried about the AI suggesting stale code
  • Scenarios wanting zero-config documentation lookup
  • Developers auditing NPM dependencies within AI workflows
  • Teams performing supply chain security assessments
  • Users of Claude Desktop, Cursor, or VS Code
Not for
  • Users who won't install Node locally or prefer remote HTTP servers
  • Those expecting the server itself to generate marketing/reply text (your own model writes it)
  • Anyone seeking a Fastlane replacement for scripted CI pipelines (it's positioned as the interactive complement)
  • Users looking for an official Apple tool — this project is unaffiliated with Apple
  • Looking up internal/private codebase documentation (Context7 targets publicly published open-source libraries)
  • Cases needing very high coverage of obscure, niche libraries (coverage depends on what Context7's platform has indexed)
  • Projects outside the NPM ecosystem (e.g., pure Python/Go)
  • Environments without network access to deps.dev, OSV.dev, and the npm registry
  • Scenarios requiring maintenance by an official upstream vendor
Required permissions
  • Reads App Store Connect API credentials (Key ID, Issuer ID, .p8 private key)
  • Accesses the Apple App Store Connect and App Store Server APIs
  • StoreKit 2 transaction tools need the app's Bundle ID
  • Optional write access: writes confirm by default; ASC_CONFIRM_WRITES=0 disables confirmation and --read-only removes mutating tools entirely
  • Usable without an API key (subject to a free-tier rate limit); CONTEXT7_API_KEY is an optional credential for higher quota
  • Read-only documentation lookup — no code execution or local filesystem access involved
  • Network access to the NPM registry and external services (deps.dev, OSV.dev, OpenSSF, npms.io, GitHub)
  • Read access to workspace lockfiles (pnpm-lock.yaml, package-lock., yarn.lock) for cache invalidation
Risks and side effects
  • A leaked .p8 key grants signing power over your App Store account at whatever role was granted; use Keychain storage, not plain-text config
  • Write-capable tools can change prices, submit for review or delete resources; a misread instruction could still execute after confirmation
  • 2.x is a breaking release; 1.x profile names in configs may have changed
  • The full tool surface exceeds 100k tokens of definitions if profiles aren't narrowed
  • No telemetry and local-only operation means you track version updates yourself
  • The free tier has limited quota — high-frequency use may hit rate limits
  • Documentation content comes from Context7's platform index, so its accuracy and freshness depend on that platform's crawl cadence
  • Third-party READMEs and changelogs are untrusted external content; they are wrapped in tags with _meta flags but should still be handled cautiously
  • Depends on availability and accuracy of external services
  • Batch requests are capped at 25 packages to prevent registry enumeration; larger sets require batching
  • Third-party open source project, not officially maintained by NPM or Anthropic
Supported clientsClaude Desktop, Claude, Codex, Cursor, Windsurf, VS Code, AntigravityClaude Code, VS Code, Cursor, Cline, AmpClaude Desktop, VS Code, Cursor, Smithery.ai
Tools1219