| FMRS | 71 / 100 · B | 75 / 100 · B |
| Reliability | 11 / 20 | 12 / 20 |
|---|
| Security and permissions | 14 / 20 | 16 / 20 |
|---|
| Maintenance | 16 / 20 | 14 / 20 |
|---|
| Documentation | 17 / 20 | 18 / 20 |
|---|
| Setup experience | 13 / 20 | 15 / 20 |
| Best for | - Developers building AI applications that need real geocoding, POI search, and routing data
- Logistics, travel, and site-selection workflows that need offline geometry operations (area, buffers, union/intersect/difference)
- Users on clients with MCP Apps support (Claude Desktop, VS Code Copilot, Claude Code, Goose) who want visual, interactive map output
| - Individuals or teams who prioritise privacy and offline operation and do not want data leaving the machine
- Users who share memory across multiple MCP clients such as Claude Code, Claude Desktop, Hermes Agent, OpenClaw, Cursor, Codex and Gemini CLI
- Scenarios that need encrypted storage, a hash-chained audit log and verifiable vault migration
- Users who want low-latency recall, a bundled embedding model and no extra LLM calls inside the memory layer
|
| Not for | - Users without a Mapbox account who don't want to obtain an access token
- Fully offline geocoding or routing needs, since most location APIs require live Mapbox connectivity (only the Turf.js geometry tools work offline)
- Fleet-scale optimization with time windows, capacity constraints, or multiple vehicles — the V2 Optimization API needs beta access and isn't registered by default
| - Users who need cloud multi-device sync or a hosted team memory service; moving between machines means locking the vault and copying the file
- Users who expect the server itself to run an LLM that extracts facts and decides what to remember; Compartment explicitly keeps no LLM inside and leaves that to the host model
- Users who cannot keep a passphrase safe or who need a recovery path if it is lost, since Compartment never generates a password, seed or recovery phrase
- Deployments that require network transports such as SSE or streamable-http; this server is stdio only and opens no ports
|
| Required permissions | - Requires a valid Mapbox access token (MAPBOX_ACCESS_TOKEN), supplied as a secret environment variable
- Local stdio deployment needs outbound network access to call Mapbox APIs
- Using the hosted endpoint requires network access to https://mcp.mapbox.com/mcp
| - Read and write the vault file under the user's home directory, by default ~/.compartment/memory.vault, and its sibling settings file
- Access the session directory holding the unlock credential (configurable with COMPARTMENT_SESSION_DIR), which also carries the shared embedding process's Unix socket
- Optionally use the macOS keychain (compartment unlock --keychain is an explicit opt-in, and it survives reboots)
- Write or merge an mcpServers entry into each MCP client's own configuration file, taking a byte-exact backup first
- Install a PostToolUse hook for Claude Code that captures memory files the agent writes
- Serve a read-only dashboard on 127.0.0.1 behind a one-time random URL token
|
| Risks and side effects | - A leaked Mapbox access token can be abused, incurring extra API charges or exceeding quota
- Geocoding, search, and directions tools send addresses, coordinates, and routing preferences to Mapbox APIs, subject to Mapbox's privacy policy
- render_map_tool renders an HTML panel via the MCP Apps protocol, which relies on the client's handling of rich content being trustworthy
- The advanced V2 Optimization API ships in the codebase but is unregistered by default, requiring deliberate beta opt-in
| - A leaked passphrase means the encrypted content can be decrypted; Compartment generates no recovery phrase and cannot recover a lost passphrase
- Enabling the memory_unlock tool places the passphrase in the model's context, which is why it is off by default
- If a 2FA keyfile is lost, for example a USB stick, the vault cannot be opened even with the passphrase
- `export --plaintext` writes the vault as unencrypted JSONL, so that file must be handled carefully
- Memory content can come from untrusted sources; recall wraps memories with a notice that they are stored data and content can be marked quarantined, but the host agent must still treat memory as data to limit prompt-injection risk
- The capture hook and client integration write into the user's own settings files, although the implementation backs up and merges rather than replacing
|
| Supported clients | Claude Desktop, Claude Code, GitHub Copilot, Goose, Cursor, Smolagents | Claude Desktop, Claude Code, Hermes Agent, OpenClaw, Cursor, VS Code, Codex, Gemini CLI, Cline, Roo Code, Zed, OpenCode, LM Studio, AnythingLLM, BoltAI, Goose, Kiro |
| Tools | 31 | 14 |