| FMRS | 52 / 100 · D | 77 / 100 · B | 75 / 100 · B |
| Reliability | 7 / 20 | 12 / 20 | 13 / 20 |
|---|
| Security and permissions | 9 / 20 | 16 / 20 | 12 / 20 |
|---|
| Maintenance | 13 / 20 | 16 / 20 | 16 / 20 |
|---|
| Documentation | 13 / 20 | 18 / 20 | 17 / 20 |
|---|
| Setup experience | 10 / 20 | 15 / 20 | 17 / 20 |
| Best for | - Small and mid-sized businesses that sell on WhatsApp and are willing to maintain their own VPS
- Teams that need multi-tenant isolation and data sovereignty
- Operators comfortable configuring Supabase, WAHA and an AI provider following the docs
- Service businesses (clinics, real estate, e-commerce, infoproducts) that need audit, RBAC and LGPD features
| - Hevy PRO users who want AI assistants to directly access their workout data
- People who prefer using MCP clients like Claude, Cursor, Codex for fitness tracking
- Anyone needing summaries and insights from their training data
| - Scenarios needing clean, structured web context fed to an AI assistant
- Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
|
| Not for | - Non-technical users who expect a turnkey product without provisioning a server and a Supabase project
- Scenarios requiring an official SLA or vendor-hosted support (the project is community-run and as-is)
- Teams unwilling to configure third-party services (Supabase, AI provider, WAHA, Upstash, Resend and others)
- Users who need fully automatic updates (updates are triggered by a click or by running the update script)
| - Users without a Hevy PRO subscription (API key required)
- Users who want to use the server without an API key
- Those needing delete workflows (Hevy API does not expose delete endpoints)
| - Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
- Sites that explicitly disallow automated access (robots.txt)
|
| Required permissions | - Root or equivalent access on a VPS (Docker, cron, ports 80/443)
- Supabase project database and auth credentials (4 credentials plus the Session pooler connection string)
- An API key from an AI provider (OpenRouter, Anthropic or OpenAI)
- A WhatsApp number connected by QR code, or credentials for the official Meta Cloud API channel
- Optional: Upstash Redis, Sentry DSN, Resend, and Nuvemshop integration credentials
| - Requires HEVY_API_KEY environment variable for Hevy API authentication
- Can create, update, and replace workouts, routines, folders, templates, and body measurements via tools
- Read operations can fetch workouts, routines, folders, templates, history, and user info
| - Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
- firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
|
| Risks and side effects | - Self-hosting makes you the data controller for the instance, carrying LGPD compliance, backup and maintenance duties
- If the cron (event-log-drain) is not installed and running, automations are created but never execute
- Connecting WhatsApp through a non-official engine (WAHA) carries a risk of account ban, mitigated by throttling and jitter
- The Supabase free plan does not back up automatically, so you must schedule backup.sh yourself
- Updates only target published release tags; reverting to an older version requires the explicit --force flag
- Optional Sentry telemetry sends error reports, with CPF, phone and email scrubbed, and can be turned off with SENTRY_DSN=off
| - API key can be misused if leaked; do not expose in URLs, logs, or screenshots
- Create operations may produce duplicates on retry; update operations replace existing records
- The server sends data to the Hevy API and may send telemetry to external services unless disabled
| - Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
- firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
|
| Supported clients | | Claude Desktop, Cursor, Codex, Google Antigravity | Claude Desktop, VS Code, Cursor, Windsurf, Zed, Amp |
| Tools | 0 | 26 | 11 |