← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

Dimensiondeja-vuOne local memory shared by twenty-five coding agents, built from the session history already on disk.Context7Upstash's official server providing up-to-date third-party library docs for AI coding assistantsNPM Sentinel MCP ServerAI-powered NPM package analysis MCP server
FMRS72 / 100 · B80 / 100 · B79 / 100 · B
Reliability11 / 2014 / 2012 / 20
Security and permissions14 / 2016 / 2016 / 20
Maintenance15 / 2017 / 2018 / 20
Documentation18 / 2015 / 2018 / 20
Setup experience14 / 2018 / 2015 / 20
Best for
  • Developers who run several coding agents (Claude Code, Codex, Cursor, Copilot CLI, OpenClaw, opencode, Gemini CLI, Qwen Code, Kimi Code, Zed and more) and want them to share one history
  • Users who want memory to stay entirely local, with no LLM or embedding key required for default search
  • Engineers who need to reach back into months-old sessions to reuse prior fixes and decisions
  • Developers using fast-moving frameworks/libraries worried about the AI suggesting stale code
  • Scenarios wanting zero-config documentation lookup
  • Developers auditing NPM dependencies within AI workflows
  • Teams performing supply chain security assessments
  • Users of Claude Desktop, Cursor, or VS Code
Not for
  • Users looking for a hosted or cloud knowledge base rather than local session history
  • Users unwilling to send (redacted, truncated) indexed text to a remote embedding endpoint, unless they configure a local Ollama or LM Studio runtime
  • Organizations that need a managed, multi-tenant, centrally administered memory service
  • Users expecting semantic recall with zero configuration, since it requires setting DEJA_EMBED_URL and related variables explicitly
  • Looking up internal/private codebase documentation (Context7 targets publicly published open-source libraries)
  • Cases needing very high coverage of obscure, niche libraries (coverage depends on what Context7's platform has indexed)
  • Projects outside the NPM ecosystem (e.g., pure Python/Go)
  • Environments without network access to deps.dev, OSV.dev, and the npm registry
  • Scenarios requiring maintenance by an official upstream vendor
Required permissions
  • Reads the session-history directories of the agents on this machine (for example Claude Code's `~/.claude/projects`, Codex's `~/.codex/sessions`, Cursor's state.vscdb)
  • Writes a local inverted index and vector sidecar (.vectors.bin) under `~/.cache/deja`
  • `deja install` writes user-level guidance files (or a marked block inside them) for each harness it detects; `--no-guidance` opts out
  • Some harness parsers rely on local tooling: Cursor, Grok Build, Hermes, opencode, Crush and Zed need sqlite3; DeepSeek Harness and Zed need zstd
  • Network access is used only by `deja update`, `deja sync ssh`, and the version check in `deja doctor`; a remote endpoint receives redacted indexed text only after DEJA_EMBED_URL is configured
  • Usable without an API key (subject to a free-tier rate limit); CONTEXT7_API_KEY is an optional credential for higher quota
  • Read-only documentation lookup — no code execution or local filesystem access involved
  • Network access to the NPM registry and external services (deps.dev, OSV.dev, OpenSSF, npms.io, GitHub)
  • Read access to workspace lockfiles (pnpm-lock.yaml, package-lock., yarn.lock) for cache invalidation
Risks and side effects
  • Redaction is pattern matching, not secret detection: a shape it does not recognize can pass through into digests, share output or sync exports
  • Secrets already present in the original harness files stay in those files; deja-vu does not modify the sources
  • With a remote embedding endpoint configured, redacted indexed text (truncated to about 2k characters) leaves the machine; Ollama or LM Studio keeps embedding local
  • `deja forget` removes sessions from a rebuilt index and writes tombstones, but does not delete the underlying harness files
  • Session formats vary per harness and can change across versions, affecting parser completeness
  • The free tier has limited quota — high-frequency use may hit rate limits
  • Documentation content comes from Context7's platform index, so its accuracy and freshness depend on that platform's crawl cadence
  • Third-party READMEs and changelogs are untrusted external content; they are wrapped in tags with _meta flags but should still be handled cautiously
  • Depends on availability and accuracy of external services
  • Batch requests are capped at 25 packages to prevent registry enumeration; larger sets require batching
  • Third-party open source project, not officially maintained by NPM or Anthropic
Supported clientsClaude Code, Codex CLI, Cursor, Copilot CLI, VS Code Copilot Chat, Gemini CLI, Qwen Code, opencode, Zed, Cline, Goose, Kimi Code, OpenClaw, Roo Code, Continue, Crush, aiderClaude Code, VS Code, Cursor, Cline, AmpClaude Desktop, VS Code, Cursor, Smithery.ai
Tools1219