← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionApple Health MCP ServerQuery your Apple Health export locally with SQLHevy MCPManage your Hevy workout data from AI assistants via MCP.Firecrawl MCP ServerFirecrawl's official MCP server for web search, scraping, and structured extraction for AI agents
FMRS67 / 100 · C77 / 100 · B75 / 100 · B
Reliability11 / 2012 / 2013 / 20
Security and permissions15 / 2016 / 2012 / 20
Maintenance12 / 2016 / 2016 / 20
Documentation15 / 2018 / 2017 / 20
Setup experience14 / 2015 / 2017 / 20
Best for
  • Users who want health data to stay local rather than pass through a third-party server
  • Users who already have an Apple Health CSV export from Simple Health Export CSV
  • Quantified-self practitioners who are comfortable with SQL and DuckDB
  • Claude Desktop users working from a trusted MCP client
  • Hevy PRO users who want AI assistants to directly access their workout data
  • People who prefer using MCP clients like Claude, Cursor, Codex for fitness tracking
  • Anyone needing summaries and insights from their training data
  • Scenarios needing clean, structured web context fed to an AI assistant
  • Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
Not for
  • Users who only have the native Apple Health export.xml and have not converted it to CSV
  • Users who do not want query results potentially sent to the model provider configured in their MCP client
  • Anyone treating health reports as medical advice or diagnosis
  • Users who need persistent incremental import or a database reused across processes
  • Users without a Hevy PRO subscription (API key required)
  • Users who want to use the server without an API key
  • Those needing delete workflows (Hevy API does not expose delete endpoints)
  • Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
  • Sites that explicitly disallow automated access (robots.txt)
Required permissions
  • Read the Apple Health CSV export files in the directory given by HEALTH_DATA_DIR
  • DuckDB processes data in memory, bounded by MAX_MEMORY_MB
  • The server itself makes no network requests and does not upload the export; however, query results returned to your MCP client may be sent to that client's configured model provider
  • Requires HEVY_API_KEY environment variable for Hevy API authentication
  • Can create, update, and replace workouts, routines, folders, templates, and body measurements via tools
  • Read operations can fetch workouts, routines, folders, templates, history, and user info
  • Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
  • firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
Risks and side effects
  • Every tool can reach the whole configured history, so only start this server from an MCP client you trust with that data
  • Health data is sensitive; once query results are sent to a model provider they leave the local environment
  • The first request that needs a table loads that table's full CSV history, with no date window
  • Tables are held in memory; an export that does not fit within MAX_MEMORY_MB fails with an explicit error instead of spilling to disk
  • Device overlap can produce duplicate-looking measurements, so queries may need to account for sourceName
  • Health reports summarize recorded data and are not medical advice
  • API key can be misused if leaked; do not expose in URLs, logs, or screenshots
  • Create operations may produce duplicates on retry; update operations replace existing records
  • The server sends data to the Hevy API and may send telemetry to external services unless disabled
  • Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
  • firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
Supported clientsClaude DesktopClaude Desktop, Cursor, Codex, Google AntigravityClaude Desktop, VS Code, Cursor, Windsurf, Zed, Amp
Tools32611