| FMRS | 75 / 100 · B | 77 / 100 · B | 75 / 100 · B |
| Reliability | 12 / 20 | 12 / 20 | 13 / 20 |
|---|
| Security and permissions | 16 / 20 | 16 / 20 | 12 / 20 |
|---|
| Maintenance | 14 / 20 | 16 / 20 | 16 / 20 |
|---|
| Documentation | 18 / 20 | 18 / 20 | 17 / 20 |
|---|
| Setup experience | 15 / 20 | 15 / 20 | 17 / 20 |
| Best for | - Individuals or teams who prioritise privacy and offline operation and do not want data leaving the machine
- Users who share memory across multiple MCP clients such as Claude Code, Claude Desktop, Hermes Agent, OpenClaw, Cursor, Codex and Gemini CLI
- Scenarios that need encrypted storage, a hash-chained audit log and verifiable vault migration
- Users who want low-latency recall, a bundled embedding model and no extra LLM calls inside the memory layer
| - Hevy PRO users who want AI assistants to directly access their workout data
- People who prefer using MCP clients like Claude, Cursor, Codex for fitness tracking
- Anyone needing summaries and insights from their training data
| - Scenarios needing clean, structured web context fed to an AI assistant
- Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
|
| Not for | - Users who need cloud multi-device sync or a hosted team memory service; moving between machines means locking the vault and copying the file
- Users who expect the server itself to run an LLM that extracts facts and decides what to remember; Compartment explicitly keeps no LLM inside and leaves that to the host model
- Users who cannot keep a passphrase safe or who need a recovery path if it is lost, since Compartment never generates a password, seed or recovery phrase
- Deployments that require network transports such as SSE or streamable-http; this server is stdio only and opens no ports
| - Users without a Hevy PRO subscription (API key required)
- Users who want to use the server without an API key
- Those needing delete workflows (Hevy API does not expose delete endpoints)
| - Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
- Sites that explicitly disallow automated access (robots.txt)
|
| Required permissions | - Read and write the vault file under the user's home directory, by default ~/.compartment/memory.vault, and its sibling settings file
- Access the session directory holding the unlock credential (configurable with COMPARTMENT_SESSION_DIR), which also carries the shared embedding process's Unix socket
- Optionally use the macOS keychain (compartment unlock --keychain is an explicit opt-in, and it survives reboots)
- Write or merge an mcpServers entry into each MCP client's own configuration file, taking a byte-exact backup first
- Install a PostToolUse hook for Claude Code that captures memory files the agent writes
- Serve a read-only dashboard on 127.0.0.1 behind a one-time random URL token
| - Requires HEVY_API_KEY environment variable for Hevy API authentication
- Can create, update, and replace workouts, routines, folders, templates, and body measurements via tools
- Read operations can fetch workouts, routines, folders, templates, history, and user info
| - Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
- firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
|
| Risks and side effects | - A leaked passphrase means the encrypted content can be decrypted; Compartment generates no recovery phrase and cannot recover a lost passphrase
- Enabling the memory_unlock tool places the passphrase in the model's context, which is why it is off by default
- If a 2FA keyfile is lost, for example a USB stick, the vault cannot be opened even with the passphrase
- `export --plaintext` writes the vault as unencrypted JSONL, so that file must be handled carefully
- Memory content can come from untrusted sources; recall wraps memories with a notice that they are stored data and content can be marked quarantined, but the host agent must still treat memory as data to limit prompt-injection risk
- The capture hook and client integration write into the user's own settings files, although the implementation backs up and merges rather than replacing
| - API key can be misused if leaked; do not expose in URLs, logs, or screenshots
- Create operations may produce duplicates on retry; update operations replace existing records
- The server sends data to the Hevy API and may send telemetry to external services unless disabled
| - Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
- firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
|
| Supported clients | Claude Desktop, Claude Code, Hermes Agent, OpenClaw, Cursor, VS Code, Codex CLI, Gemini CLI, Cline, Roo Code, Zed, OpenCode, LM Studio, AnythingLLM, BoltAI, goose, Kiro | Claude Desktop, Cursor, Codex, Google Antigravity | Claude Desktop, VS Code, Cursor, Windsurf, Zed, Amp |
| Tools | 14 | 26 | 11 |